News & Press
» » Resume
Charles D. Tendell
CISSP CEH CHFI ECIH
Download the word version HERE
Summary of Qualifications
Certified Ethical Hacker, Certified Hacking Forensic Investigator, Certified Incident Handler & Certified Information Systems Security Professional. With a multitude of expertise and experience from a variety of areas; I have lead countless investigations into cybercrimes ranging from consumer scams to corporate espionage. Working with local and federal agencies nationwide and serving as a Fox News contributor on consumer and corporate cyber security issues and events.
I provide information assurance oversight for enterprises. Developing policies, procedures, plans and implementations for SSAE16 and ISO 27K series compliance. Coordinating with various teams I conduct internal audits, vulnerability assessments, incident response drills and activities, Ethical Hacking exercises. Lead remediation efforts, manage incident responses and provide executive management with guidance on industry best practices.
Core Competencies
Strategic Planning
Technical Direction
eDiscovery
System Security
Computer Forensics
Contract Negotiation
Policy & Procedure Development
Staff Training & Leadership
Ethical Hacking
Global Networking
Professional ExperienceRivet Software, Denver, CO 9/2011 6/2012Sr. Network Security AnalystServed as the subject matter expert (SME) on security architecture, compliance, policy incident response and trainingDeveloped, implemented and maintaining an Information Security Management Systems (ISMS) adhering to the ISO 27000 series controls.Developed and coordinated the efforts of the Information Security Response Team ISRT.Developed internal tools and procedures used to respond to active and post mortem incidents.Performed IT Risk Assessment and gap analysis on current company security postures and recommend solutions.Drafted RFPs and coordinated vendor selections for security appliances, testing and auditing.Developed and manage metrics to gauge the effectiveness of the incident response program.Proactively collected, assessed, and communicate information security intelligence to executive staff to reduce the risk of exposure and better prepare for potential security threats.Conducted and analyze weekly vulnerability assessments and coordinate remediation efforts.Meet with executive staff to help guide security postures in a direction that protects the company while not impacting business growth or function.Worked with executive staff and business unit leaders to educate them on current APT (Advance persistent threat) Malware and other security threats.Worked with the executive team to develop employee security awareness training programs.Conducted training to employees and staff.Served as the security liaison for customer inquires to security mechanisms.Deployed and monitored Network Security Monitoring Systems, Data loss prevention (DLP) Systems and network surveillance/forensics and security incident/event management technologies (SIM/SEM).
Forensic Pursuit, Denver, CO 10/2008 9/2011Chief Technology Officer / PartnerPartner and Chief Technology Officer for Colorado’s pioneer of computer forensics technology.Lead thousands of digital forensics investigations using industry standard tools including but not limited to FTK, FTK imager, PRTK, Helix, TSK (sleuthKit) Encase & various mobile phone software. As well as forensic imaging and duplication hardware.Designed and implemented forensics training programs, presented at college level and as CLEs for the legal community.Consulted counsel & judges on E-discovery best practices, forensic collection, preservation, key word search designs, case review & presentation.Preserved and analyzed data from electronic data sources, including laptop and desktop computers, servers, and mobile devices.Investigated network intrusions to determine the cause and extent of the breaches.Preserved, harvest, and process electronic data according to the firm s policies and practicesProduced high quality detailed expert findings and analysis reports for oral and written work product, presenting complex technical matters clearly and concisely.Formed and articulate expert opinions based on analysisConsulted with colleagues, engagement managers, and clients regarding case investigation and status.
United Launch Alliance, Denver, CO 2/2008 8/2008Sr. Network Security AnalystProvide support to a nation-wide company with over 4,000 member employees.Designed, implement and maintain best practices for network security and perform Security Risk assessments, enterprise wide, to ensure protection of sensitive corporate data.Designed and implement Juniper NSM/IDS/IPS, as well as FOSS solution NSM, for monitoring and tracking network assets.Aided in the development of Security Policies and Procedures, and assisted with a weekly end user Safe & Secure Computing newsletter, to help train and communicate best practices for network security, enterprise wide.Worked with infrastructure, network engineering, space operations and data managers to develop data recovery and data protection plans for each site.Coordinated and conducted several external vulnerability and penetration tests, bi-weekly, for the network enterprise.Lead Emergency Response Team in conducting network forensics, data protection, real time incident response management and tracking.Reviewed and approve/disapprove External Connection Requests based on risk levels.Performed weekly and monthly assessment of current vulnerability stand points and analyze tracking of enterprise level environment.Drafted Concepts for baseline data encryption and best migration techniques.Drafted baseline standards for the SRA process and aid in the draft of a multi-site DRP.Drafted and institute enterprise policies and procedures to meet ITARS, COTS, NIST and various industry enterprise security standards.Acted as liaison between Security Working Group and CIO, CTO and Infrastructure Group for clear understanding and coordination of best practices for security and implementations.Leaded all software security compliance and engineering group in support of DoD and Air Force regulations.Identified and drove remediation of deficiencies discovered from security assessments performed on operating systems and applications.Lead vulnerability management group in providing guidance in preventing, discovering and remediating vulnerabilities as it relates to systems, software and hardware.
Masley & Associates Colorado Springs, CO 6/2007 2/2008Sr. Consultant (Partner)As a technology consultant, assisted various enterprise companies with design and troubleshooting network technologies and security solutionsConsulted on a wide range of technical interactions. At several customer levels ranging from end user to executive level.
Boeing, Colorado Springs, CO 6/2006 6/2007Network & Security Infrastructure Administrator Responsible for security and maintenance of US Air Force AFSCN GPS control segment, with enterprise level Windows 2k mixed environment.Conducted network and system security scans to determine vulnerabilities; delivered solutions to correct security profile of individual system or network.Recommended security solutions to enhance the security profile of the perimeter and internal devices.Performed ST&E (Security Test and Evaluation) inspections following SAS70 requirements.Installed and instructed administrator s proper use of Juniper Netscreen IDP 200 and SonicWall firewall.
US Army FT. Brag, NC 10/2000 6/2006Missile Defense Systems CrewmemberNetwork Security Advisor, performing WLAN integration for Units wile deployed using FIPS 140-1 and 128-bit Advanced Encryption Standard to encrypt all data passing over the network, including inside subnet authentication process.Designed and advised on implementation of security perimeter infrastructures at Battalion level with Checkpoint firewall technologies.Provide network security assessments involving penetration testing, threat validation, and counter measure recommendations, using both commercial and open-source tools.Supervise Solaris 8 Implementation for 17 Early Warning Radar AMDEWS units.Tested US Army implementation of Nokia Network Voyager and IP40 platform to give LAN administrators and privileged super-users a secure web based system manager.Implement and manage NASE Network Migration from local Ft. Bragg domain, allowing local systems to interface with Army networks worldwide.
Education
University of Phoenix
Bachelor of Science: Information Technology
Professional Development
Certified Information Systems Security Professional (CISSP)
Certified Hacking Forensic Investigator (CHFI)
Helix Forensics Trainer
Certified Ethical Hacker (CEH)
Expert Whiteness
Certified Incident Handler (E CIH)
Tools and Operating Systems
Nessus, Retina, ISS
Linux, Solaris, Windows, MacOSX
Netscreen IDP, Sourcefire, Enterasys Dragon,
Cisco, Juniper and Checkpoint Firewalls
Symantec, McAfee AV s, HBSS
Encase, FTK, Paraben, Oxygen Forensic suit, TSK( The Sleuth Kit), Volatility
AppDetect, NMAP, NetCat, Entercept
FireEye, IP Tables
Compliance
Cobit 4.1
SOx
ITIL
ISO 9000, 27002, 27001, 27005
DITSCAP
PCI-DSS
SSAE 16/ SAS 70
DIACAP
HIPAA
Contact Me
Monday to Friday :
8am-6pm
Saturday: 8am-12pm
Sunday: Closed
Call at 720-***-****
iOS dictionary apps posting false piracy “confessions” onto users’ Twitter accounts
November 15, 2012 The Secret History of Hacking (Complete)
November 15, 2012 Factions 101 – “Insane Spawn PVP” – Episode 13
November 15, 2012 The Real Cyberforensics Used To Snoop On Petraeus (And You)
November 15, 2012 "My Hugo" Haley compares response to hacking case to storm
November 14, 2012
Recommendations
Charles is a true professional and a pleasure to work with. He has extensive knowledge in his field plus a wealth of personal experience which assists him in making people feel at ease. He gets on task and stays with it until finished. - Mark Niswonger
Charles is a very detailed-oriented person with a strong passion in Information security. He has a great desire to provide the highest customer satisfaction when carrying out his tasks. He has high integrity and it was my great pleasure to have worked with him in the past. The desires and drives that Charles has make him a well-rounded individual and a great asset in any partnership - Linh Tran
Charles was able to recover data from multiple drives on a failed server. His knowledge of digital forensics and exemplary work ethic were unparalleled. Without Charles, we would have spent countless hours to rebuild multiple database and restore 2 years of work. He is brilliant and I would not only use his services again, I would recommend him to all of my colleagues - Joy Mulu
I have had the opportunity to work with Charles on several occasions and his experience and knowledge computer security, electronic discovery and forensics is unmatched. Charles has great attention to detail, is a pleasure to work with, and overall a good guy. I highly recommend Charles - Dan Van Soest
-
PagesNews & Press
Follow Me!
Contact Info
Charles Tendell
Phone : 720-***-****
email :
Charles {at} Charlestendell.com
&
Charles Tendell Certified Ethical Hacker, Certified Information Security Professional, Computer Forensic Investigator, Computer Security Denver, Consultant Denver
Denver, Computer Security, CISSP, CEH, Ethical Hacker, Hacker, Computer Forensics, Denver, Colorado
copyright p.copy, .pos_navigation { border-color:##000000; }