LAWRENCE M. GRANT, CISM, CISSP, MCSE
** ******* *******. ********* ******, NJ 07632 347-***-****
**********@*****.***
PROFESSIONAL SUMMARY
Chief Information Security Officer and Executive Information Security Consultant with
over 18 years experience as an Information Security professional with expertise in Information
Security Program development and implementation, Enterprise Operational Risk Management,
IT Audits, wireless and mobile device security, IT and Risk Assurance, Security Architecture,
Ethical Hacking, Threat Modelling, Risk Assessments and Corrective Action Planning
Led successful enterprise-wide Information Security Governance, Risk and Compliance
(GRC) and Information Security Technology Implementation programs at Merrill Lynch, JP
Morgan Chase, Chicago Mercantile Exchange Group (CME Group), Boeing Corporation,
Federal Courts Puerto Rico, Citigroup, New York Stock Exchange (NYSE) InvestCorp,
Williams Energy, Disney Corporation, IBM Business Continuity and Resiliency Services
(BCRS), Radianz Corporation, AT&T, Morgan Stanley, Deutche Bank, UBS, Irving Oil,
Depository Trust Clearing Corporation and Corning Corporation
Certified Information Systems Security Professional (CISSP), Certified Information
Security Manager (CISM), Microsoft Certified Systems Engineer (MCSE), Cisco Certified
Internetworking Expert CCIE Security (written), Sun Solaris Enterprise Engineer, IBM
Certified Ethical Hacker, Dale Carnegie HR Management, NY Institute of Finance, Banking
and Securities Industry
Courses: SAP GRC 5.2 and 5.3 SAP ADM940, SAP ADM950, SAP ADM960, Modulo
Risk Manager, Information Technology Infrastructure Library (ITIL) V3, Program and Project
Management
Author of forth coming book ‘How to pass your PCI-DSS audit in 30 days’
EXPERIENCE
APC Professional Services – IBM Contractor New York, New York
2012 – Present
Project: Fortune 100 Global Fiber Optics Manufacturer
Position: Chief Information Security Advisor (Consultant) – Global Cloud Security Project
Led the design and successful implementation of the enterprise cloud security proxy in
China, Taiwan, Hong Kong, Singapore, Germany, France, Latin America and North America
Advisor to the corporation’s executive steering committee regarding the project
technologies, its business impact and risk exposures
Managed a global team of sixteen systems and network engineers and operations staff
Represent the corporation as the Subject Matter Expert to the technology vendor, Cisco
Inc., regarding proof of concept, use case testing, security and availability, risk impact, global
VPN design and cloud proxy architecture
Reduced Information Security operational costs by $1.7M annually
Project: World’s Largest Clearing Firm (Equities, Derivatives, Fixed Income)
Position: Executive Consultant – IT Risk
Designed and managed vendor selection process for corporate IT risk analysis and risk
management technologies.
Created several algorithms for predictive IT Security Risk analysis covering country &
international risk, technology end- of-life risk & outsourced technology risk
Venda Inc, Leading eCommerce SaaS Cloud Platform New York, London, Bangkok
2011 – 2012
Chief Information Security Officer (CISO)
Page 1 of 4 Lawrence M. Grant Resume
Managed four senior technical managers and nine systems and network engineers.
Responsibilities included interviewing, hiring & terminations and guiding the career
development of direct reports and their reports. Also conducting performance evaluations of
direct reports and providing executive input on salary levels training and compensation of
technology staff
Corporate responsibilities included managing the information security budget of $3.7M,
selecting security technologies and services in support of the security program and allocating
funds to adequately meet the company’s security program objectives
Provided leadership to the security team in conducting an extensive internal NIST 800-53
rev. 3 gap analysis, assessing several hundred discrete security controls across the company’s
global SaaS, cloud computing infrastructure to provide transparency and decision support in
preparation for process reengineering, technology procurement and personnel acquisition
Implemented a program and road-map to address the critical need to acquire the Federal
Information Security Management Act (FISMA) Certification & Accreditation Moderate level
pursuant to the compliance requirements of a US Govt. contract valued at over $100M.
Led PCI-DSS 2.0 audit preparation activities and guided the CIO in implementing
supporting technology and effective security control processes within the development and
operation environments. This effort led to successful recertification of PCI-DSS 2.0 Tier 1,
which is a mandatory requirement, for the company’s Internet SaaS platform which processes
over $1B customer transactions world-wide.
Reengineered information security business processes globally including IS technology
vendor & services procurement, DDOS response and mitigation, PCI-DSS, ISO 27002 and
NIST/FISMA compliance programs. This resulted in greatly improving program efficiency,
reflecting an immediate cost savings of $580K and projected future savings of $1.5M over
three years
Implemented a risk-based governance, risk and compliance information security
management model by realigning each discrete security discipline such as incident
management, threat & vulnerability management, monitoring, logging and analysis with
internationally accepted best practices. This, in addition to implementing a reporting
mechanism to give the rest of executive management timely visibility into the status of security
controls and risks for enhanced business decision support
Researched and provided a blueprint of complementing technologies, including, Security
Information & Event Monitoring (SIEM), Information Security Management System (ISMS)
and identity Management System to provide a real-time internal Security Operations Center
(SOC) capability and customer facing Security Portal with feature sub-set functionality
Conducted the global security awareness training for company officers, executives and
managers and revised the awareness program to include an online Learning Management
System delivery component for anywhere, anytime information security policy education and
employee training verification
APC Professional Services, IBM Contractor New York, NY 2010 – 2011
Executive Consultant, Information Security
Projects: Global Derivatives Exchange
Chief Risk Consultant, Risk Assessment/IS Risk Program Implementation
Conducted a comprehensive enterprise Information Security risk assessment at a Global
Financial Futures and Options Derivatives Exchange
Presented to the CFO, COO, CIO and the Audit Committee an independent report of the
state of controls across its trading, clearing production, disaster recovery and testing
environments
Performed a risk analysis of the data collection results using ISO 27002 (formerly BS
17799) and NIST standards as the control foundation
Implemented a risk control foundation modeled on the Control Objectives for Information
and Related Technologies (CoBIT) framework
IBM, Security and Privacy Practice Armonk, NY 2006 – 2010
Senior Managing Consultant
Project Engagements:
Global Data Privacy Officer, International SAP/Finance Transformation Project
Responsible for the data privacy strategy and implementation for a global, enterprise-wide
SAP transformation project
Provided leadership to the team of four direct report data privacy officers in Asia, Europe,
USA and Latin America. Responsibilities included mentoring, day-to-day management of the
privacy program, career development, personnel evaluations, interviewing and hiring engineers
and operations staff in support of the privacy initiative.
Page 2 of 4 Lawrence M. Grant Resume
Led the data privacy risk assessment to determine the exposures and impact to an SAP
transformation project valued at 1.5 Billion dollars
Guided data owners in China, Germany, United Kingdom and European Union countries
in assessing and classifying privacy data and confidential data to prevent illegal trans-border
transfers
Implemented compliance programs in accordance with Anti-Money Laundering (AML),
Payment Card Industry (PCI), Federal Financial Institutions Examinations Council (FFIEC)
regulations and EU Directive 95/46/EC to minimize regulatory risk
Senior Managing Consultant, Several Global Financial Institutions
Projects: ISO 27002/NIST Assessments, FFIEC Risk Assessments, FISMA Assessments, SOX Program
Management and Federal Audit Preparation, Identity Management Implementation (IDM), CRM and
Cloud Security Implementation
Led a 12 person team of systems, network and security experts responsible for conducting
enterprise-wide information security assessments, security program development and cloud
computing security architecture design
Executed an in-depth examination of the corporations’ Operations and Security programs
covering Identity Management, Information Classification, Threat and Vulnerability
Management and Risk Management domains
Conducted a study of corporate user access and implemented Tivoli Identity Manager to
manage logical access
Advised CISOs in rapidly implementing processes and procedures to support large-scale
technology security upgrades and Risk & Compliance program improvements
Chief IS Risk Advisor, Global Network Transformation Project
Responsible for the strategic and tactical information security planning, risk assessment,
risk Identification and mitigation plan for the transfer of a global enterprise network,
$1.5billion in assets, to a third party for outsourced infrastructure management
Organized a global response-ready virtual team comprised of technical specialists in Asia,
Latin America, North America and Europe who were engaged to manage transition security
events on a 24x7 basis
Conducted daily conference calls and meetings with project managers and subject matter
experts globally to ensure that current issues and deliverables were communicated and acted
upon within required risk mitigation time-frames
Citigroup, Web Hosting Group New York, NY 2003 – 2006
Asst. Vice President, Security and Compliance
Managed a team of fifteen analysts locally and in India to conduct daily review and
reconciliation of systems activity across the Web Hosting environment
Led Sarbanes-Oxley (SOX) audit preparation activities and audits
Advised business units such as Travelers Insurance, CitiCards, and Smith Barney on
maintaining effective business controls and risk management processes in accordance with
Citigroup Information Technology Management Policy (CITMP)
Designed and implemented effective people, process and technology controls that led to
several satisfactory audit ratings, by the corporation’s internal auditors and the Office of the
Comptroller of the Currency (OCC)
Served as the Web Hosting Group’s representative in formal meetings with the internal
auditors, external auditors, and Office of the Comptroller of the Currency (OCC) Banking
Regulators
BT Radianz Inc. British Telecoms Financial Services Firm New York, NY
2001 – 2003
Head Hosting IS Consulting
Managed a team of nine technical consultants with responsibility for defining and
architecting firm-wide security policies and Infrastructure. Authored Enterprise Managed
Services methodology, standard Service Level Agreements for Managed Hosting, Managed
Security. Designed secure, custom architecture for clients’ datacenter deployments and other
core security service offerings worth in excess of 55 million dollars annual revenue
Exodus Communications New York, NY 1994-2001
Page 3 of 4 Lawrence M. Grant Resume
Director IS Consulting/Security Architect
EDUCATION & CERTIFICATIONS
University Of London, Royal Holloway,
UK
MSc: Information Security
(In progress)
Lic. Masters Competency
St. Joseph’s Maritime College 1987
Transport and Harbors, GY (WI) Lic. Mates Competency
Licensed Master, Shipping Vessels 50,000 1985
Gr. Tons
TECHNICAL SKILLS:
Security Architecture and Management: SAP GRC 5.3(Versa), Archer, Cisco Network Admission
Control, IBM Tivoli, IP Sonar, Retina, Site Minder, Etrust. Identity Management Systems, PKI,
Single Sign-On (SSO) technologies, VOIP Security, Wireless Security, Ethical Hacking, Firewalls,
Intrusion Detection/Protection, Enterprise and Web/Internet Infrastructure design and security
LAN/WAN Technologies: Ethernet, Frame Relay, ATM, TCP/IP, IPX/SPX, IGRP, EIGRP, OSPF,
RIP, BGP, SSL, IPSEC, PPTP, Multicast
Operating Systems: Windows Servers, AIX, Sun UNIX, HPUX, Linux, LAMP technologies,
Cloud Computing - Amazon EC2, Amazon Web Serices, Rightscale, VM Ware etc.
Software: SQL Server 6.0 -7.0, MS Office, VISIO, MS Project, Source Safe, IIS, MS Site Server,
Messaging: Microsoft Exchange 4.x, 5.x, 2000, Lotus Notes, Lucent Unified Messaging for
Exchange, POP3, IMAP 4.0, TIBCO, Instant Messaging, FIX Protocol
REFERENCES: Available upon request. Also available: White Papers, writing samples,
PowerPoint presentations and architectural designs. Languages: English and Portuguese
Page 4 of 4 Lawrence M. Grant Resume