THOMAS BRONACK, CBCP
Certified Business Continuity Professional from DRII
Director of Vendor Relations and Board member for the NYC Metro Chapter of
the ACP
***-** **** ******, **********, NY 11357
Phone: 718-***-**** Cell: 917-***-****
Email: ********@****.***
Objective:
To obtain a position where my thorough knowledge of Information Technology
and extensive experience in Enterprise Resiliency, Project Management (PM)
/ Project Management Office (PMO), Risk Management, Problem Management,
Incident Management, Disaster Recovery, Business Continuity, Emergency
Management Preparedness, Workplace Violence Prevention, and the
implementation of an optimized operation through automated tools, improved
work flow processes and industry best practices like Failover / Failback,
Data Deduplication, Virtual Tape Library, Snap Shots, Continuous Data
Protection, and Network Storage Services to achieve a zero downtime
operation. To further assist companies by implementing enhancements,
resolving problems, and mitigating Gaps, Exceptions, and obstacles to
achieve improved efficiency, lower costs, better protection of the
company's reputation, and a safeguarded environment that is in compliance
with all regulations, both domestically and internationally in countries
where business is conducted. Ability to implement, support, and manage a
company infrastructure, including messaging, database systems, and virtual
environment (Citrix, VDI, etc.) with a working knowledge of HIPAA, ePHI,
HITECH, and HHS Healthcare Industry regulatory requirements, and all
regulatory requirements for financial institutions.
Qualifications:
Business Workflow & Systems Compliance & Business Continuity
Development, Optimization Technology Risk and Disaster Recovery
Marketing and Sales Management Planning
Project Management Emergency / Crisis Data Sensitivity, Standards and
(PM) & Project / Incident / Access Controls, Procedures
Management Office Problem Management Security, Encryption Implementation (S&P
(PMO) and Emergency and Vaulting, Manual, User Guides,
Operations Center etc.)
Data Center Design Data Center Data Application
and Implementation Migrations and Synchronizations, Certification for High
Consolidations Migrations and & Continuous Recovery
Replications to sites
Enterprise Safe Workplace Definition of Help Desk, Problem
Resiliency and creation and Functional Management, and
Corporate Violence Prevention Responsibilities Incident Management
Certification
Zero Downtime, Flip Data de-duplication Snapshots and Continuous Data
/ Flop, HA and CA and Virtual Tape Snapshot Instance Protection and Data
Availability Library Repository Synchronization
Disaster Recovery Creation of Network Storage Testing Recovery Plans
Training and Recovery Manuals Services, and insuring RTO and
Awareness and Team RecoverTrak, RPO meet SLA and SLR
preparation DiskSafe, FileSafe guidelines
I possess technical, managerial, and consulting experience implementing
safeguarded and optimized environments that comply with business /
regulatory requirements and utilize IT industry best practices. I am a
Certified Business Continuity Professional (DRII), a member of the
Contingency Planning Exchange, and a Board of Directors member of the
Association of Contingency Planners with expertise encompassing:
Business Operations Requirements Definition Total Quality
Analysis Management
Strategic Planning Documentation & Production Acceptance
Training
Project Management Project Office Project Guidelines
Team Leadership Client &Vendor Marketing & Sales
Relations Systems
Compliance Web Site Development Standards & Procedures
Technical Skills
. Hardware: Full Range of mainframe, mid-range, servers, and personal
computers; along with control units and peripherals
. Software: Full range of mainframe, client server, and operating system
software, including specialized program products including MVS, VM/370,
JCL, Docu/Text, Job/Scan, ACF2, RACF, Top Secret, CA products, IBM
utilities, Windows; Office (Word, Excel, PowerPoint, Access); MS Project;
Adobe Products, Visio, Adobe, Strohl Systems LDRPS and BIA Professional
products.
. Familiar with: Citrix (XenDesktop,XenApp, NetScaler,TriScaler, and Cloud
Platform), Cisco, and SQL Server 2012 in support of Application
Development, Support, and Maintenance for Cloud Computing (Public,
Private, Hybrid).
. Compliance Knowledge: SOX, GLB, HIPAA, Patriot Act; EPA; Dodd, Frank,
COSO; CobiT; ITIL; ISO 27000; Basel III, BS 25999, CERT, FFIEC (BCP & IT
Security), PS-Prep, NFPA 1600; NIST 800-30, SAE16 and SSAE3402 for vendor
compliance management, Six Sigma and workflow management, ITIL v2, ITIL
v3, Workplace Violence Prevention, Help Desk, Incident Command System and
Emergency Operations Center, Enterprise Resilience and Corporate
Certification.
. Enterprise Resiliency and Recovery Planning: Project Initiation / Project
Plan Creation/ Coordination / Management Reporting, Recovery Team
Selection and Training, Risk Assessment, Business Impact Analysis (BIA),
Recovery Tool Selection, BCP Tool Implementation, Recovery Plan Creation
/ Testing / Prototyping / Implementation / and Roll-Out, Recovery
Training and Awareness Program, Community Coordination of Recovery
Activities (Business Park / Building Neighbors, etc.), Adherence to
Governmental Organization Guidelines (FEMA, OSHA, etc.), Integration of
Recovery Operations within the Organization, Recovery Plan Support and
Maintenance in an on-going basis.
Selected Accomplishments
. Solid Project Management, PMO, and Leadership abilities that have
achieved on-time and under budget business deliverables.
. I have managed staffs as large as 17 individuals who reported directly to
me on a project team or job function when serving as systems programming
manager, project manager, and on assignments at European American Bank,
ADP Proxy Services, and others.
. I have managed large projects having many sub-projects needing a common
project planning guideline and managed through the Project Management
Office administration to ensure: task completion, quality, time line
adherence, budgetary compliance, and management reporting.
. Converted the Global Business and Financial Services LOB of Bank of
America from their old Business Continuity Plans to LDRPS.
. Created a new division within Security Pacific Bank to provide Technology
Risk Management, Incident and Problem Management, Disaster Recovery and
Business Continuity consulting services called Security Pacific Risk
Asset Management (SPRAM);
. Produced a Five Year Business Plan for the IT Division of European
American Bank and Designed and Implemented a Communications Management
Controller based on VTAM/ACF/MSNF for mainframe Load Balancing and
Automated Recovery (like a mainframe VMware);
. Merged ADP Proxy and IECA into new $9.3 million facility, while
consulting directly to Brokerage Division President (Rich Daly);
. Implemented Standards and Procedures and re-engineered work flow to
optimize operations and reduce problems;
. Migrated and consolidated Data Centers for Chase and Citibank. Assisted
many other companies analyze and plan how best to migrate and consolidate
data centers through the use of automated analysis tools like: Docu/Text,
Job/Scan, CiRBA, AppScan, Foundstone, and others;
. Assisted clients implementing off-site recovery facilities or companion
data centers to address recovery needs (IBM, SunGard, Comdisco, etc.);
. Created Operations Control Centers (OCC), Network Control Centers (NCC),
Help Desk (HD), and Emergency Operations Centers (EOC);
. Provided sales and consulting to established offsite recovery facilities
for IBM Business Recovery Services clients;
. Provided offsite vaulting and professional services for Zurich Depository
Corporation;
. NY Regional Sales Manager / Agent for Docu/Text and Job/Scan software
from Diversified Software Systems Inc.;
. Provided presentations and workshops to major industry groups like IFSA,
ISACA, ISSA, ACP and CPE.
Career Synopsis
JPM Chase Bank, Delaware HA/DR Project Manager (through Modis)
12/12/2012 - 1/10/13
Consulting position as a Project Manager for the High Availability /
Disaster Recovery (HA/DR) project at Chase Bank, responsible for creating a
Charter that lead to a Project Number and funding for the HA/DR Project.
Created a Project Plan (using MS Project) to identify the Critical Jobs
within the Card Member, Auto Finance, and Student Lending Services (CMAFS)
Line of Business (LOB) that had to adhere to High Availability (2 hours or
more) and Continuous Availability (immediate failover). I then created a
meeting agenda and identified the personnel who were responsible for
infrastructure and applications that had to participate in this project and
established a meeting schedule and a three phase project plan, including:
Substantiation of the applications ability to recover within required time
frames (Recovery Time Objective), Testing of the applications ability to
recover within the RTO, Mediation / Mitigation of any obstacles impeding
the applications ability to recover, re-testing applications until they
achieved "Recovery Certification" for HA applications and achieving the
"Gold Standard" for CA applications by their ability to Flip / Flop
processing from a primary to a secondary location. Once these tasks were
completed the Chase HA/DR Team continued with the project.
FalconStor Software, Corporate Headquarters Disaster Recovery Process Lead
5/2012 - 06/26/12
In this position I was responsible for establishing a line of business to
create Disaster Recovery and Business Continuity plans for existing clients
and prospects so that clients would be able to take advantage of the
FalconStor product line to achieve automated Failover and Failback and also
have accompanying plans to direct their personnel during disaster events
and testing. Product line included Data Deduplication, Virtual Tape
Library, Network Storage Services, Disksafe, Filesafe, Continuous Data
Protection, and Single Instance Repository. Created Business Plan for the
division, produced White Papers, lead the Disaster Recovery Committee to
develop a company-wide disaster recovery and business continuity plan
development, wrote Disaster Recovery Process Professional Services Manual,
brought new clients and channel partners to the table and generally
improved the FalconStor reputation to the Business Continuity and Disaster
Recovery industry through presentations and industry events. As a result
of my efforts FalconStor can be known as a One-Stop-Shop for all your
recovery needs including off-site failover locations for disaster events
and the loss of an office. I led the negotiation of training and
certifications deals with DRII and BCI. I also led the negotiation of a
National Sponsorship Agreement with the Association of Contingency Planners
to introduce FalconStor to over 4,400 ACP members throughout the United
States.
This position required my being able to control multiple on-going projects,
potentially world-wide, having a common goal to achieve and a predefined
sequence of steps (DRII Ten Step Process was the foundation), so it was
imperative that I develop a universal project management system and Project
Management Office (PMO) that would be used to coordinate projects from
inception through completion and support. The PMO was responsible for
coordinating all activities, identifying problems, gathering information
and reporting to management on project activity, goal accomplishments,
budgetary adherence, and profitability. If needed, I would direct
additional staff to assist project personnel experiencing problems or
schedule elongations so that the company reputation of achieving project
goals on time and within budget would be protected. Unfortunately
FalconStor experienced financial problems and decided not to pursue this
line of business.
DCAG (Self Employed) Enterprise Resiliency and Corporate Certification
02/2009 - present
After leaving Bank of America, I wrote a book, executive presentation, and
magazine articles on how to "Achieve Enterprise Resiliency and Corporate
Certification" by combining Emergency Management, Business Continuity, and
Workplace Violence Prevention into a common recovery organization, while
complying with international and domestic laws to achieve Corporate
Compliance requirements (BS25999, NFPA 1600, ISO22313, ISO22318, CERT, and
Private Sector Preparedness Act). The goal of this project was to develop
a global understanding of recovery planning with a common language and
common set of tools that optimized the many Recovery Management disciplines
and recovery operations to provide the best protection for employees,
clients, suppliers, and business operations. It addresses Incident and
Problem Management techniques that reduce Crisis Level or Disaster Level
events. Starting with a solid requirements foundation and utilizing
industry Best Practices (COSO, CobIT, ITIL, ISO27000, FFIEC, etc.) this
paper goes on to outline a Business Plan and Project Plans to help guide
the development and implementation of Enterprise Resiliency and Corporate
Certification by defining Work Flow requirements, Functional
Responsibilities, Job Descriptions, and Standards and Procedures for
personnel to follow. I have presented this concept to the Association of
Contingency Planners (ACP), the Contingency Planning Exchange (CPE), and
other industry groups. The article has been published by industry
magazines. I am convinced that this is the direction that recovery
management is headed because of its many benefits.
I assisted. in developing a migration and data center consolidation plan
for a large financial organization using ADDM, WireShark, AppScan Secure
Application Development and Real-Time protections, ADDM, WireShark, Dell
x86, VMware vSphere 5, IBM P7 AIX, EMC SAN, NetApp NAS, Cisco Networking,
and CiRBA to provide workload balancing and data center optimization.
I assisted a startup firm, Market Network Agency (MNA), by creating their
business plan, executive presentation, and system design paper to create an
on-line automated marketing and bartering system that would tie buyers and
sellers of services and products together and perform all contract,
currency, fulfillment, and accounting for clients. Information is being
used to attract funding and prospective clients.
NYC Metro Chapter of the ACP, Director of Vendor Relations and Board Member
06/2010 - present
Was invited to join the ACP Board of Directors (Largest organization of its
kind) and to assume the role of Director of Vendor Relations where I was
responsible for recruiting vendors to join the ACP as a Sponsor. These
companies would be able to network with our members and sell their products
and services through tables provided at our monthly meeting. I am
responsible for ensuring that vendors addressed supply chain management and
recovery guidelines that would provide their clients with a heightened
level of protection from disaster events.
Collabera, Inc. Business Continuity Analyst Bank of America
10/2008 - 02/2009
I worked as the NYC lead consultant responsible for the conversion of
current Bank of America Business Recovery Plans to the LDRPS Release 10
program product from Strohl / SunGard. I was responsible for the General
Business and Financial Services Line of Business, where I had to: locate
the latest release of the Business Continuity Plan for each of over 160
locations world-wide; develop a Baseline to judge the current plans ability
to support Recovery Operations; agree upon Gaps and Exception guidelines
and resolutions, develop LDRPS Plan format / content in association with
the end-user; convert old recovery plans to LDRPS; publish LDRPS Plans,
obtain review and approval of LDRPS Plans, and define and deliver training
to end-users on recovery planning and the LDRPS product. After Bank of
America was converted, my project was scheduled to continue with the same
project objective at Merrill Lynch and other newly acquired companies. The
goal of this assignment is to insure that all components of Bank of America
use the same Business Continuity product and are trained on similar
recovery procedures.
I also proposed that the Bank of America implement Enterprise Resiliency to
combine recovery operations and create a common recovery language and
toolset to optimize recovery operations. I also recommended that they seek
Corporate Certification in Business Recovery so that they are in compliance
with the recovery management laws of the countries that they do business
in.
Data Center Assistance Group Inc. President/Consultant/Sales Manager
1980-10/2008
Provided consulting and sales agent services to client organizations
including: management and technical consulting; workflow analysis;
organizational structure definition; job function definition and job
description writing; data center requirements definition; implementation,
consolidation, migration, and termination; disaster recovery/business
continuity planning; project/systems management; productivity improvements;
system/business analysis; documentation; training, and recruiting /
placement of personnel for permanent/consulting positions. Defined and
implemented the Systems Development Life Cycle from Development through
Production Acceptance, Support, Maintenance, Configuration Management, and
Release Management. Defined documentation and support requirements and
insured that Testing and Quality Assurance procedures guaranteed that all
required documentation was included in the production acceptance turnover
process. I was responsible for the implementation of Help Desks, Network
Control Centers, Operation Control Centers, Incident Command Centers and
Emergency Operations Centers. I also designed and implemented an Inventory
Management System, Asset Management System, and Configuration Management
System to track product life cycles from Acquisition, through Redeployment,
and finally to Product Termination in accordance to SPA Standards.
Responded to audits and risk assessments identifying disaster
recovery/business continuity planning gaps and exceptions; upgraded and
created recovery plans, testing procedures, quality assurance guidelines,
production acceptance requirements, and production acceptance standards and
procedures to mitigate gaps and exceptions while optimizing operations.
Created data center recovery and business continuity plans for banks
(Manufacturers Hanover Trust, Chemical, EAB, Chase, Citibank, Security
Pacific), brokerage firms (New York Stock Exchange, Securities Industry
Automation Corporation, AIG Audit Department, Shearson, Salomon Smith
Barney, RMJ Securities, Lehman Brothers), pharmaceutical companies
(Sandoz), vendors (IBM, Computer Science Corporation, Storage Technology
Corporation), and others (United Nations, ADP).
Jefferson Wells International
10/2005 - 06/ 2006
Engagement Manager - Technology Risk Management
As an employee I was responsible for performing IT Audits, IT Sarbanes
Oxley Surveys, IT Risk Assessments, Business Continuity Planning, IT
Security, overseeing Basel II audits, and many other functions devoted to
selling and closing client contracts for Technology Risk Management
services. Directed personnel assigned to Technology Risk Management tasks
and performed Project Management over concurrent activities assigned to my
staff. Contracts had to adhere to FFIEC and NIST standards and procedures
when performing audits of financial institutions governed by federal and
state regulators. I also delivered presentations on Business Continuity
Planning at the NJ ICASA and the IFSA.
Securities Industry Automation Corporation Systems Programming
Manager/Systems Programmer 6/1979 - 1/1980
Managed the Systems Programming Group comprised of 8 Systems Programmers
responsible for supporting all mainframe computers and software for SIAC,
the NYSE, and AMEX, also implemented first NYSE / AMEX Security System.
Storage Technology Corporation Northeast Regional Systems Engineering
Manager 10/1978 - 6/1979
I conducted client needs analysis, hardware configuration planning, and
problem isolation/repair in support of 40+ sales personnel and 135 field
engineer professionals. Provided sales presentations and assisted in
product selection, configuration, and implementation.
Chemical Bank IT Capacity and Performance Manager
3/1978 - 10/1978
Performed Capacity and Performance evaluations of the IT environment and
recommended alternative methods for improving the operation and performance
of the IT environment as necessary. Assisted in DR/BC planning and
implementation.
Manufacturers Hanover Trust Company Computer Risk/Technical Support
Manager 3/1977 - 3/1978
Developed data processing security guidelines (physical and data) and
formalized security and recovery procedures for all Manufacturers Hanover
Trust Company's Data Centers. Established and supported the Trust Data
Center (first MVS data center).
IBM (NY Banking Office) Customer Engineer and Programming Systems
Representative 9/1968 - 3/1977
As a Customer Engineer (CE) I was responsible for the Design,
Implementation, Migration, Consolidation, Termination, Support, and
Maintenance of IBM mainframe hardware and peripheral devices. As a
Programming Systems Representative, I was responsible for mainframe
software systems contained in client bank environments. I was the first
person cross-trained between hardware and software and recognized as a
territory support specialist for NY Banking Office.
Education
. A.A.S., Electrical Technology, New York City Community College;
. B.S. Coursework, Computer Science, City University of New York;
. IBM Training in Systems Programming, Project Management; and
Business / Personnel Management;
. Knowledge of Storage Management Disciplines including: Data
Deduplication, Virtual Tape Library, DiskSafe, FileSafe, Single
Instance Repository, Snapshots, Continuous Data Protection, and
Network Storage Services.
. Certified Business Continuity Professional from Disaster Recovery
Institute International;
. Member of the Contingency Planning Exchange (CPE) and the
Association of Contingency Planners (ACP);
. Knowledge of HIPAA, Sarbanes-Oxley, Graham-Leach-Bliley; Patriot
Act; Basel II, and EPA Superfund regulations for DR/BCP, IT
Security, BS25999 / ISO 22301, NFPA 1600, Private Sector
Preparedness Act, CERT, ISO 27000, FFIEC and NIST standards and
procedures governing BCP and Information Security for financial
institutions governed by federal and state regulators. Further
knowledge of Data Center Consolidations and Migrations using
AppScan Secure Application Development and Real-Time protections,
ADDM, WireShark, Dell x86, VMware vSphere 5, IBM P7 AIX, EMC SAN,
NetApp NAS, Cisco Networking, and CiRBA to provide workload
balancing and data center optimization.
. Data De-Deduplication, Virtual Tape Library, Snapshots, Single
Instance Repository to store and recall Snapshots, Continuous Data
Protection, Network Storage Services, DiskSafe, FileSafe,
RecoverTrak product line to support automated Failover and Failback
operations.