Post Job Free
Sign in

Security Management

Location:
Cliffside Park, NJ
Posted:
March 11, 2014

Contact this candidate

Resume:

LAWRENCE M. GRANT, CISM, CISSP, MCSE

** ******* *******. ********* ******, NJ 07632 347-***-****

**********@*****.***

PROFESSIONAL SUMMARY

Chief Information Security Officer and Executive Information Security Consultant with

over 18 years experience as an Information Security professional with expertise in Information

Security Program development and implementation, Enterprise Operational Risk Management,

IT Audits, wireless and mobile device security, IT and Risk Assurance, Security Architecture,

Ethical Hacking, Threat Modelling, Risk Assessments and Corrective Action Planning

Led successful enterprise-wide Information Security Governance, Risk and Compliance

(GRC) and Information Security Technology Implementation programs at Merrill Lynch, JP

Morgan Chase, Chicago Mercantile Exchange Group (CME Group), Boeing Corporation,

Federal Courts Puerto Rico, Citigroup, New York Stock Exchange (NYSE) InvestCorp,

Williams Energy, Disney Corporation, IBM Business Continuity and Resiliency Services

(BCRS), Radianz Corporation, AT&T, Morgan Stanley, Deutche Bank, UBS, Irving Oil,

Depository Trust Clearing Corporation and Corning Corporation

Certified Information Systems Security Professional (CISSP), Certified Information

Security Manager (CISM), Microsoft Certified Systems Engineer (MCSE), Cisco Certified

Internetworking Expert CCIE Security (written), Sun Solaris Enterprise Engineer, IBM

Certified Ethical Hacker, Dale Carnegie HR Management, NY Institute of Finance, Banking

and Securities Industry

Courses: SAP GRC 5.2 and 5.3 SAP ADM940, SAP ADM950, SAP ADM960, Modulo

Risk Manager, Information Technology Infrastructure Library (ITIL) V3, Program and Project

Management

Author of forth coming book ‘How to pass your PCI-DSS audit in 30 days’

EXPERIENCE

APC Professional Services – IBM Contractor New York, New York

2012 – Present

Project: Fortune 100 Global Fiber Optics Manufacturer

Position: Chief Information Security Advisor (Consultant) – Global Cloud Security Project

Led the design and successful implementation of the enterprise cloud security proxy in

China, Taiwan, Hong Kong, Singapore, Germany, France, Latin America and North America

Advisor to the corporation’s executive steering committee regarding the project

technologies, its business impact and risk exposures

Managed a global team of sixteen systems and network engineers and operations staff

Represent the corporation as the Subject Matter Expert to the technology vendor, Cisco

Inc., regarding proof of concept, use case testing, security and availability, risk impact, global

VPN design and cloud proxy architecture

Reduced Information Security operational costs by $1.7M annually

Project: World’s Largest Clearing Firm (Equities, Derivatives, Fixed Income)

Position: Executive Consultant – IT Risk

Designed and managed vendor selection process for corporate IT risk analysis and risk

management technologies.

Created several algorithms for predictive IT Security Risk analysis covering country &

international risk, technology end- of-life risk & outsourced technology risk

Venda Inc, Leading eCommerce SaaS Cloud Platform New York, London, Bangkok

2011 – 2012

Chief Information Security Officer (CISO)

Page 1 of 4 Lawrence M. Grant Resume

Managed four senior technical managers and nine systems and network engineers.

Responsibilities included interviewing, hiring & terminations and guiding the career

development of direct reports and their reports. Also conducting performance evaluations of

direct reports and providing executive input on salary levels training and compensation of

technology staff

Corporate responsibilities included managing the information security budget of $3.7M,

selecting security technologies and services in support of the security program and allocating

funds to adequately meet the company’s security program objectives

Provided leadership to the security team in conducting an extensive internal NIST 800-53

rev. 3 gap analysis, assessing several hundred discrete security controls across the company’s

global SaaS, cloud computing infrastructure to provide transparency and decision support in

preparation for process reengineering, technology procurement and personnel acquisition

Implemented a program and road-map to address the critical need to acquire the Federal

Information Security Management Act (FISMA) Certification & Accreditation Moderate level

pursuant to the compliance requirements of a US Govt. contract valued at over $100M.

Led PCI-DSS 2.0 audit preparation activities and guided the CIO in implementing

supporting technology and effective security control processes within the development and

operation environments. This effort led to successful recertification of PCI-DSS 2.0 Tier 1,

which is a mandatory requirement, for the company’s Internet SaaS platform which processes

over $1B customer transactions world-wide.

Reengineered information security business processes globally including IS technology

vendor & services procurement, DDOS response and mitigation, PCI-DSS, ISO 27002 and

NIST/FISMA compliance programs. This resulted in greatly improving program efficiency,

reflecting an immediate cost savings of $580K and projected future savings of $1.5M over

three years

Implemented a risk-based governance, risk and compliance information security

management model by realigning each discrete security discipline such as incident

management, threat & vulnerability management, monitoring, logging and analysis with

internationally accepted best practices. This, in addition to implementing a reporting

mechanism to give the rest of executive management timely visibility into the status of security

controls and risks for enhanced business decision support

Researched and provided a blueprint of complementing technologies, including, Security

Information & Event Monitoring (SIEM), Information Security Management System (ISMS)

and identity Management System to provide a real-time internal Security Operations Center

(SOC) capability and customer facing Security Portal with feature sub-set functionality

Conducted the global security awareness training for company officers, executives and

managers and revised the awareness program to include an online Learning Management

System delivery component for anywhere, anytime information security policy education and

employee training verification

APC Professional Services, IBM Contractor New York, NY 2010 – 2011

Executive Consultant, Information Security

Projects: Global Derivatives Exchange

Chief Risk Consultant, Risk Assessment/IS Risk Program Implementation

Conducted a comprehensive enterprise Information Security risk assessment at a Global

Financial Futures and Options Derivatives Exchange

Presented to the CFO, COO, CIO and the Audit Committee an independent report of the

state of controls across its trading, clearing production, disaster recovery and testing

environments

Performed a risk analysis of the data collection results using ISO 27002 (formerly BS

17799) and NIST standards as the control foundation

Implemented a risk control foundation modeled on the Control Objectives for Information

and Related Technologies (CoBIT) framework

IBM, Security and Privacy Practice Armonk, NY 2006 – 2010

Senior Managing Consultant

Project Engagements:

Global Data Privacy Officer, International SAP/Finance Transformation Project

Responsible for the data privacy strategy and implementation for a global, enterprise-wide

SAP transformation project

Provided leadership to the team of four direct report data privacy officers in Asia, Europe,

USA and Latin America. Responsibilities included mentoring, day-to-day management of the

privacy program, career development, personnel evaluations, interviewing and hiring engineers

and operations staff in support of the privacy initiative.

Page 2 of 4 Lawrence M. Grant Resume

Led the data privacy risk assessment to determine the exposures and impact to an SAP

transformation project valued at 1.5 Billion dollars

Guided data owners in China, Germany, United Kingdom and European Union countries

in assessing and classifying privacy data and confidential data to prevent illegal trans-border

transfers

Implemented compliance programs in accordance with Anti-Money Laundering (AML),

Payment Card Industry (PCI), Federal Financial Institutions Examinations Council (FFIEC)

regulations and EU Directive 95/46/EC to minimize regulatory risk

Senior Managing Consultant, Several Global Financial Institutions

Projects: ISO 27002/NIST Assessments, FFIEC Risk Assessments, FISMA Assessments, SOX Program

Management and Federal Audit Preparation, Identity Management Implementation (IDM), CRM and

Cloud Security Implementation

Led a 12 person team of systems, network and security experts responsible for conducting

enterprise-wide information security assessments, security program development and cloud

computing security architecture design

Executed an in-depth examination of the corporations’ Operations and Security programs

covering Identity Management, Information Classification, Threat and Vulnerability

Management and Risk Management domains

Conducted a study of corporate user access and implemented Tivoli Identity Manager to

manage logical access

Advised CISOs in rapidly implementing processes and procedures to support large-scale

technology security upgrades and Risk & Compliance program improvements

Chief IS Risk Advisor, Global Network Transformation Project

Responsible for the strategic and tactical information security planning, risk assessment,

risk Identification and mitigation plan for the transfer of a global enterprise network,

$1.5billion in assets, to a third party for outsourced infrastructure management

Organized a global response-ready virtual team comprised of technical specialists in Asia,

Latin America, North America and Europe who were engaged to manage transition security

events on a 24x7 basis

Conducted daily conference calls and meetings with project managers and subject matter

experts globally to ensure that current issues and deliverables were communicated and acted

upon within required risk mitigation time-frames

Citigroup, Web Hosting Group New York, NY 2003 – 2006

Asst. Vice President, Security and Compliance

Managed a team of fifteen analysts locally and in India to conduct daily review and

reconciliation of systems activity across the Web Hosting environment

Led Sarbanes-Oxley (SOX) audit preparation activities and audits

Advised business units such as Travelers Insurance, CitiCards, and Smith Barney on

maintaining effective business controls and risk management processes in accordance with

Citigroup Information Technology Management Policy (CITMP)

Designed and implemented effective people, process and technology controls that led to

several satisfactory audit ratings, by the corporation’s internal auditors and the Office of the

Comptroller of the Currency (OCC)

Served as the Web Hosting Group’s representative in formal meetings with the internal

auditors, external auditors, and Office of the Comptroller of the Currency (OCC) Banking

Regulators

BT Radianz Inc. British Telecoms Financial Services Firm New York, NY

2001 – 2003

Head Hosting IS Consulting

Managed a team of nine technical consultants with responsibility for defining and

architecting firm-wide security policies and Infrastructure. Authored Enterprise Managed

Services methodology, standard Service Level Agreements for Managed Hosting, Managed

Security. Designed secure, custom architecture for clients’ datacenter deployments and other

core security service offerings worth in excess of 55 million dollars annual revenue

Exodus Communications New York, NY 1994-2001

Page 3 of 4 Lawrence M. Grant Resume

Director IS Consulting/Security Architect

EDUCATION & CERTIFICATIONS

University Of London, Royal Holloway,

UK

MSc: Information Security

(In progress)

Lic. Masters Competency

St. Joseph’s Maritime College 1987

Transport and Harbors, GY (WI) Lic. Mates Competency

Licensed Master, Shipping Vessels 50,000 1985

Gr. Tons

TECHNICAL SKILLS:

Security Architecture and Management: SAP GRC 5.3(Versa), Archer, Cisco Network Admission

Control, IBM Tivoli, IP Sonar, Retina, Site Minder, Etrust. Identity Management Systems, PKI,

Single Sign-On (SSO) technologies, VOIP Security, Wireless Security, Ethical Hacking, Firewalls,

Intrusion Detection/Protection, Enterprise and Web/Internet Infrastructure design and security

LAN/WAN Technologies: Ethernet, Frame Relay, ATM, TCP/IP, IPX/SPX, IGRP, EIGRP, OSPF,

RIP, BGP, SSL, IPSEC, PPTP, Multicast

Operating Systems: Windows Servers, AIX, Sun UNIX, HPUX, Linux, LAMP technologies,

Cloud Computing - Amazon EC2, Amazon Web Serices, Rightscale, VM Ware etc.

Software: SQL Server 6.0 -7.0, MS Office, VISIO, MS Project, Source Safe, IIS, MS Site Server,

Messaging: Microsoft Exchange 4.x, 5.x, 2000, Lotus Notes, Lucent Unified Messaging for

Exchange, POP3, IMAP 4.0, TIBCO, Instant Messaging, FIX Protocol

REFERENCES: Available upon request. Also available: White Papers, writing samples,

PowerPoint presentations and architectural designs. Languages: English and Portuguese

Page 4 of 4 Lawrence M. Grant Resume



Contact this candidate