Post Job Free
Sign in

Security Management

Location:
New York, NY
Posted:
November 02, 2012

Contact this candidate

Resume:

Gary

Email: ****.********@*******.***

Address: *** **** **** ******, #**

City: Brooklyn

State: NY

Zip: 11203

Phone: 347-***-****

Skill Level: Any

Salary Range:

Primary Skills/Experience:

Director of InformationSecurity/CISO

Educational Background:

Job History / Details:

Gary Nicholas

491 East 52nd Street,C8, Brooklyn, New York 11203

CISSP, CISM, CRISC, SSCP, GIAC G7799, CISRCP, CEH, SECURITY +

Home: 718-***-**** ****.********@*******.*** Mobile: 347-***-****

Chief Information Security Officer

IT Security Solution Provider ~ Enterprise Strategic Development ~ Motivational Team Leader

Astute, results-oriented leader with proven success in strategic development, business communications, IT security operations and risk management. Exceptional ability to balance technical and business requirements paired with superior people skills, resulting in effectively managing projects, meeting deadlines and consistently concluding on business results. Critical thinker and solutions provider who can apply extensive knowledge of industry standards as a certified risk professional, information security manager and ISO 27001 framework. Expert direction in IT resources, technology and incident response management. Successful coordination of audit and compliance programs resulting in reduced organizational risk within business tolerance levels. Expertise in:

IT Security Operations Disaster Recovery Identity and Access Management

IT Auditing Problem Resolution Expert Policy & Standards Management

Security and Compliance Management Risk Management Professional Project Management

IT Process Improvement ISO 27000 Certified Information Security Governance

Career Accomplishments

? Security Solutions Provider

? Lead successful projects in providing security assessments on endpoint security, web security, data leakage prevention, integrity controls, regulatory retention controls, access governance, and LAN auditing reviews with a coordinated and successful implementation of new security solutions.

? Devised tactical and operational plans for monitoring, auditing and reporting on various high risk systems.

? Introduced the vulnerability management program that addressed the organization s concerns related to continual industry threats by proactive operations.

? Strategic Planning & Forecasting

? Innovator and visionary of identifying New York City Employees Retirement Systems information security program gaps and security risks with industry standard solutions seamlessly integrated into business processes to mitigate risks.

? Proposed and identified a business case to align policies and standards with agency procedures to maintain a visible security awareness program and compliance controls.

? Consolidated redundant technologies resulting in company savings of more than $30,000.

? Value Delivery

? Ensured the Total Cost of Ownership is defined for any new technological security solution to maintain budgetary constraints in addition to demonstrating Return On Investment.

? Maintain the value of existing security solutions and processes by performing regular reviews and assessments to forecast the agencies future security requirements and industry trends.

? Developed metrics to identify key performance indicators, key risk indicators and key goal indicators.

? Leadership & Communication

? Proven leadership skills in project management and communications under stringent timelines ensuring project completion from inception to implementation.

? Security Awareness communications developer initiating intranet and other educational solutions to improve user community security awareness.

? Key mediator and advisor in resolving inter-departmental issues and providing recommendations to rectify differences in operational approach.

Gary Nicholas

PAGE ONE

Professional Experience

Chief Information Security Officer

New York City Employees Retirement System (NYCERS), New York, NY November 2010 to Present

Promoted to Information Security Manager in 2008, then promoted to CISO in 2010, to architect, promote and enforce the agencies security initiatives pertaining to data privacy and integrity, in addition to a continual process improvement approach towards an enterprise information security program. Aligned policies, procedures and standards with business requirements to ensure consistent security controls and maintain regulatory compliance in the enterprise.

Provided a web security solution for the agencies internal internet presence to prevent malicious internet software and

undesirable websites from the agency network.

Created and maintained NYCERS Data Leakage Prevention program to ensure confidential information does not leave

the agency network without prior authorization.

Monitored endpoints or workstations for unauthorized transfers of confidential data to removable media and created

incident reports for investigations.

Sole source of all technical investigations on events, incidents and frequent trends based on factual data provided.

Recommended and implemented an audit solution for Active Directory to ensure internal configuration management

procedures are enforced and authorized before changes are implemented.

Project Lead for Security Architecture for Active Directory and network infrastructure to certify all security controls are

considered throughout any design requirements and implementation.

Created, standardized and enforced the agencies Vulnerability Management program to maintain consistent and timely

remediation updates to systems and software components including operating systems.

Enforced and promoted the agencies Data Classification Standards and promoted best practice encryption controls

seamlessly across the enterprise.

Promoted and developed an Information Security Management System based on ISO 27001 standards.

Managed and structured the logging, monitoring and reporting system of log events for all security related tools and

systems.

Coordinated and enforced all access control to systems including mainframe access to ensure authorization is granted and

procedures are maintained and enforced.

Maintained the risk management strategy to address and remediate risks across the agency and utilize risk assessment as

a business enabler.

Information Security Manager

New York City Employees Retirement System (NYCERS), New York, NY December 2008 to November 2010

Manage a team of three Information Security Analyst to provide direction for all information security initiatives and risk assessment; act as the agencies subject matter expert pertaining to data confidentiality, security controls, industry best practice recommendations, and compliance requirements.

Provided project lead and direction for all information security projects to successful completion within aggressive timeframes.

Responsible for the timely delivery of provisioning and de-provisioning staff in all agency systems by directing staff on effective communications with the end users.

Maintained operational compliance requirements for the IT/Server, Helpdesk and Network teams to ensure standards are adhered too.

Direct report to Executive Management on information security initiatives and project status to ensure alignment with organizational objectives.

Wrote, revised and edited agency policies, procedures and standards when change management or risk has been identified in the agency.

Architected the Information Security Management Program (ISMP) based on ISO 27002 and Citywide policy requirements as a perpetual and annual revision process.

Advised and consulted Executive Management on process improvements on the agency infrastructure to further reduce residual risk.

Gary Nicholas

PAGE TWO

Senior Information Security Analyst

New York City Employees Retirement System (NYCERS), New York, NY June 2007 to November 2008

Provide high level expertise for all aspects of systems security, including administrative controls- policy, procedure, and standard document creation and review; technical controls- assess and analyze risks to the business and mitigate those risks by means of technological countermeasures; physical controls- ensure the continual monitoring and walkthrough procedures to facilitate the enforcement of the agencies policies; ID card access control for all employees in the agency.

Vulnerability assessment and remediation, incident response, forensic development and log management review assures the Information Security continual practice of best industry standards.

Responsible for enforcement controls of the IT/Information Security unit and IT auditing procedures.

Review and recommended business continuity risk assessment strategy for the agency.

Successfully recommended auditing technologies to mitigate internal and external threats due to configuration changes and errors.

Created policies for content filtering controls to ensure the confidentiality of member information.

Proposed a security information program that encompasses all internal security technologies to conclude on the agencies security objectives.

A dynamic team leader with proven success in mentoring and motivational skill sets.

Formulate the organizations engagement strategy with the new ISO 27001 standard and the ITIL v.3 objectives.

Increase security implementations by providing an Assurance process to certify any security mitigation controls within the agency.

Audit internal access controls on the mainframe and Active Directory utilizing Scriptlogic auditing tools to ascertain privileged level access revisions.

Assign/revoke physical access control proximity cards to employees upon new hire and terminations.

Audit IT/Server Unit operational procedures to ensure security best practices are enforced from start of task/project to completion.

Revised the agencies Policies and Procedures and made recommendations to align the business objectives with the latest security policies and to propose and implement best industry standard practices; ISO 17799.

System Administrator/Chief Security Officer

Alliance for Health, Inc., New York, NY September 2005 to April 2007

Responsibility include a wide array of functions (Project Manager, Tech Lead, System/Security Administrator, Technical Business Analyst, Chief Security Officer); Maintained Access Control process and standards for the organization related to user access of systems information; Monitored all perimeter and internal security logs for auditing purposes; Ensured HIPPA compliance regulations are adhered to for organizational compliance; Reviewed Standards and Procedures for Business Continuity and Disaster Recovery planning; Proposed Data Security solutions as it pertains to the organizations business communications and objectives; Recommend, design, test, and maintain security solutions via policy and procedures in regards to Confidentiality, Integrity, and Availability.

Proposed and demonstrated Hot/Warm/Cold sites for remote office backup to enable Business Continuity for the organization.

Primarily responsible for all information tape backups and off-site storage procedures and implementations.

Responded successfully to all Virus/Trojan/Malware attacks by inside/outside intrusions.

Secured user access to specific information assets resulting in the least privilege principle.

Manage, maintain, and support all data and voice infrastructure for 7 branch office locations in the Tri-State area.

Utilized Orion Monitoring tool for auditing and monitoring infrastructure devices on the network.

Stabilized the consistent downtime, via the WAN, to the organization by implementing a fibre WAN infrastructure at the Central Office (CO).

Reviewed all single points of failures pertaining to business continuity and created contingency plans to enable 99.999% uptime.

Maintained access control methodologies and proposed a password policy for the East/West coast organization.

Secured the network infrastructure perimeter devices with various access control methodologies and practices.

Performed an audit of system access and relayed proposed solutions to harden information system access.

Proposed an escalation policy and procedure for the Helpdesk staff to adhere.

Gary Nicholas

PAGE THREE

Performed Due Diligence of Disaster Recovery plans for changes, and proposed recommendations for business continuity.

Possess expertise in securing a corporate environment including Access Control, Physical Security, Telecommunications/Network Security, Cryptography practices; incorporating the core tenet of security - Confidentiality, Integrity, and Availability.

Ensured HIPPA compliancy as the Chief Security Officer of the organization.

Enact trouble ticket with the organization s ISP regarding Data Communications; WAN related issues and document and record proceedings according to organizational policies.

Recommended Business Continuity strategies for the East coast organization.

Reviewed and recommended new PI(Private Information) processes for the organization pertaining to the IT Department and it s involvement in JCAHO surveys.

Reviewed and recommended new PI processes for the organization pertaining to the IT Department and it s involvement in JCAHO surveys.

System/Security Administrator

Planned Parenthood Federation of America, New York, NY August 2002 to April 2004

Member of the Advanced Technology Group responsible for providing integrated security solutions, support and management directive to facilitate administrative and technical roles for the Information Technology team. Highlights of tenure include the coordinated implementation of Cisco Security solutions, lead implementation project management for VPN access controls, creation of SOP (Standard Operational Procedures) documents, and network security policy and controls.

Coordinated and supervised contractors on building a new secure data center ensuring the use of physical access controls. Reviewed and recommended the appropriate fire suppressants, raised floor flood detection units, and access control proximity cards to all entrances to the data center. Also tested and ensured full redundancy (power and connectivity) for all electronic equipment responsible for the uptime of the computer systems; responsible for the physical security (access controls) of the data center.

Assessed all security LAN/WAN device implementations and devised secure Router, Switch and Firewall configurations for the new site. Monitored and executed configuration change-management on Cisco PIX Firewall, Host Intrusion Detection, VPN access, and RADIUS authentication changes (ACS).

Reviewed, tested and implemented security Patch Management solutions for all security devices on the network.

Pro-active prevention of Malicious code by diligent analysis of the security logs from the PIX firewall and other security technologies. Generated incident reports and investigated any infected systems or malicious activity.

Implemented a secure Cisco VOIP Solution notified and coordinated with upper management on applying critical security updates as well as any additional end-user change requirements as needed.

Developed Standard Operational Procedures supporting industry standard best practices for VPN, Authentication Servers, and other access control mechanisms.

LAN/Desktop Administrator

Sekani, New York, NY May 2001 to September 2001

Coordinated desktop support, space management issues, and interacted with LAN support organization, outside vendors and associates on a daily basis. Administered the Macintosh/PC network and maintained the Tape Backup Library schedule.

Supported the Desktop environments - fielding application questions concerning LAN/WAN networking issues; supported business telephone services using the Executone phone system; installed and configured the following applications- Microsoft Office 2000, Outlook 2000, Norton Antivirus Enterprise Edition, Microsoft Exchange 5.5, Oracle Client, VNC, Windows 2000 Server/Professional; analyzed and solved various network support areas TCP/IP, DHCP, IIS, Microsoft Access database connectivity problems; created, edited, and configured user and group accounts in a Windows NT/2000 system- applied the proper security access to various clients, as well as remote access.

Advised, configured, and installed Intranet/Extranet tools - including IBM s Websphere Commerce Suite; worked closely with IBM on various installation scenarios; provided basic website support to clients.

Responsible for the daily backup of all company data and restoration when necessary, used Veritas Backup Exec software.

Configured Fiber Optic RAID Arrays for video data storage use in a Windows 2000 environment.

Upgraded an NT 4.0 environment to Windows 2000.

Provided cost-effective solutions pertaining to equipment repairs, data storage, and remote access on users laptops.

Gary Nicholas

PAGE FOUR

LAN/Server Administrator

GettyImages, New York, NY March 2000 to April 2001

Assisted and maintained the integration of five different company systems into one primary location during the acquisition of FPG International. Provided primary support for over 150 users in a mixed environment.

Maintained and supported Macintosh internal/external Website Database Servers using 4D Tools; resolved client/server connectivity issues, e-mail problems, and remote setup support.

Supported and resolved FTP client related problems (over 100 connections) using Media Grid Software; administered the client PC access to the Windows NT domain, user rights, and group memberships.

Supported existing PC RAID systems; devised a maintenance procedure for optimal performance of all existing Liaison databases, as well as NT 4.0 file servers.

Resolved and maintained the Tape backup Library system for all company data. Restored data in a timely manner when needed.

Worked closely with my peers on their support issues in a Novell environment in differing locations.

Migrated a Peer-to-Peer Windows 95/98 network, Apple Macintosh workgroup, and 2 NT Domains into a single Network Operations Center (NOC).

Resolved DNS issues within the company s WAN and configured Trust relationships among the various NT Domains.

Integrated a cost effective solution for data transfers to overseas clients by implementing ISDN solutions.

Created a Test Lab for various Windows 2000 upgrade solutions and enhancements to the current network.

Helpdesk/Desktop Administrator

FPG International LLC, New York, NY May 1995 to March 2000

PC/Mac Technician and Helpdesk Support Analyst for a 200-user environment. Supported all aspects of basic network administration.

Rolled out the Point of Sales (POS) systems for the national and international offices.

Installed all hardware and software peripherals on workstations and servers.

Tested, troubleshoot, and upgraded all Workstations, Printers, Scanners, Monitors, Network cards, UPS, Modems, and Hard drives.

Configured and installed on the Windows NT workstations: Microsoft Office 97/2000, Microsoft Outlook, AJNA (in-house developed database), Oracle Client, and Norton Antivirus.

Supported the Client s Corporate PC users and Network Operations.

Added, created and configured users e-mail account using Microsoft Exchange 5.5.

Automated the installation of new systems by using Ghost software to clone images onto new systems saving hundreds of hours of installation time.

Supported the Macintosh network of 32 users. Implemented RAID solutions as well as configured Appleshare IP 6.1 to improve network performance.

Supported and resolved all forms of Macintosh troubleshooting issues.

Recommended and researched the best equipment for network solutions.

Completely eliminated the need for outside Mac consultants, saving the company over 85% in Macintosh related expenses; Integrated Macintosh workgroup within an NT Domain environment.

Utilized HP OpenView for monitoring and upgrading systems. Recommended upgrade solutions.

Education

Certifications Attained: Certified Information Systems Security Professional (CISSP), Systems Security Certified Practitioner (SSCP), Certified in Risk and Information Systems Control (CRISC), SANS G7799 (ISO 27001 Specialist), Certified Information Security Manager (CISM), CISRCP (Certified Information Systems Risk & Compliance Professional), Certified Ethical Hacker (CEH), Security+, Cisco Certified Network Administrator (CCNA), Cisco Certified Design Associate (CCDA), A+, Network+, Macintosh Service Technician, Microsoft Certified Professional (NT 4.0).

Gary Nicholas

PAGE FIVE

Academic Coursework: Some college coursework.

Professional Pursuits: PMI-RMP, CIPP, CISA.

.

Gary Nicholas

PAGE SIX



Contact this candidate