Douglas M. Concepcion
Secaucus, NJ 07094
*****@*******.***
EMPLOYMENT HISTORY:
Concepcion LLC: Consulting Company
HHC, New York, New York
Information Security Department Manager (consultancy) June 2011 to Present
. Project lead on the selection and implementation of the LRS printing
solution to ensure HIPAA compliance (clinical printing
. Technical lead on the Server Build Team, using MS Secure Compliance
Manager to develop the templates for each server build, and scanning for
compliance using Foundstone
. Lead engineer and architect in the deployment of a corporate Secure File
Transfer Solution for the organization, ensuring HIPAA compliance using
the Accellion solution
. Project manager in the deployment of McAfee Endpoint Encryption to the
enterprise including USB media
. Project manager in the deployment of MobileIron and MDM solution to
address mobility needs of the organization
. Project manager in the deployment of McAfee IDS/IPS across the
environment
. SOC Manager using ArcSight as our SIEM and McAfee EPO Manager
. Developed policies and procedures following NIST guidelines to ensure
HIPAA compliance
. Process manager of MS and Adobe patch management to the corporation using
SCCM
. Chair of the weekly divisional meeting covering projects and other
initiatives
. Introduced RFP process, subsequently adopted by HHC IT
. Introduced TCO, ALE, and ROI methodology, subsequently adopted and
applied to other IT Department initiatives
. Introduced Project Management methodology within the department, to
improve process control
. Created a department Security Portal in MS SharePoint with present,
future, and historical data with real time feeds
. Developed department roadmap covering five years, in a business plan
format
. Prepared department long term budget projections
United Nations Secretariat, New York, New York
Senior Project Manager (consultancy)
January 2011 to March 2011
. Made project recommendation to implement IT standardization for the
United Nations globally, to fulfill General Assembly Resolution A/62/793
. Provided the project strategy which was presented and accepted by the
Secretary General
. Reviewed governance, and policies and procedures to ensure harmony with
the General Assembly Resolution and project plan
. Reviewed organogram and made recommendations on the required personnel to
execute the project and maintain the standards
. Wrote the Term of Reference for the required personnel functions to be
submitted to the General assembly for ratification
Covance, Princeton, New Jersey
SOC Manager (consultancy)
December 2010 to January 2011
. Performed review of the organization's security posture, including
governance, disaster recovery, business continuity, policies, and
procedures
. Conducted gap analysis to addresses short and long term personnel needs,
and hired the required personnel accordingly
. Made long term recommendations for the corporation based on the findings
of the review, and gap analysis
. Daily management of Security Operations Center
HHC, New York, New York
Information Security Department Manager (consultancy) October 2010 to
November 2010
. Managed Security Team's day to day functions
. Created incident response reports and solutions
. Created procedural documentation for incident management
. Managed the organization security response to a business agreement
breakdown
. Prepared weekly presentations for executive management, covering security
issues and projects
United Nations Population Fund, New York, New York
Infrastructure/Security Specialist
November 2002 to August 2010
. Duties as Chief Security Officer
. Managed worldwide IT Infrastructures in countries such as China, Haiti,
Switzerland, South Africa, etc.
. IT Manager for 123 country offices, managing budgets, personnel, and IT
project approval and delivery
. Deputy to the agency lead in the relocation of UNFPA-NY to new
international facilities, which included managing architects, engineers,
and contractors both union and non-union, encompassing different trades
. Lead architect, engineer, and Project Manager for the deployment of a
worldwide VPN mesh used for VOIP, Video Conferencing, e-mail, data, and
AD synchronization
. Lead architect, engineer, and Project Manager in the deployment of
Riverbed WAN accelerators to address VSAT throughput
. Project Manager for the datacenter relocation, addressing cooling, power,
structural reinforcements, and coordination of entities involved in the
move of IT equipment
. Agency lead and Project Manager in the development and implementation of
the agencies Business Continuity Plan, ensuring business continuity for
HQ and Field Offices
. Member of the World Wide Pandemic Response team, addressing HQ and Field
Offices' issues, including education, preparation, and contingency plans
in case of an outbreak
. Lead Architect and Project Manager of the Disaster Recovery Plan for
UNFPA - addressing agency survivability both for HQ and 123 field
offices, with the DR site in Geneva Switzerland.
. Implemented off site, over the wire, backup for the HQ data to multiple
external locations
. Lead Architect and Project Manager in the development of IT based
security policies and best practices for UNFPA
. Architect and Lead Engineer in the implementation of the agencies
security posture, using CheckPoint
Firewalls in High Availability mode, BlueCoat content filtering with
A/V engine, and Enterasys Dragon IDS/IPS (in conjunction with Enterasys
Policy Manager for the network core policy enforcement). Subsequently
upgraded to Stonesoft Stonegate Firewalls and IPS, with a ForeScout
CounterAct NAC for access control.
. Project Engineer in the design and implementation of Network Topology and
Security Architecture for the UN Reform, encompassing all continents
(except Antarctica)
. Lead Engineer in the development of full communication redundancy for the
organization, implementing multiple T1s', T3, and Ethernet lines, using
an Alteon Link Optimizer 143 for load balancing; upgraded to Radware
Linkproof appliance
. Architect and Project Engineer in the implementation of the Alcatel VOIP
solution for the organization
. Agency lead in the implementation of the infrastructure and security for
the ERP (PeopleSoft) system using CA SiteMinder for access control.
Migrated 16 and 32 bit proprietary financial applications to Oracle
database
. UNFPA representative to the construction committee for the organizations
HQ renovation project, acting as onsite Project Manager. Dealing with
the negotiation of items with architects, contractors, and sub-
contractors of the project
. Project Manager in the agencies Novell 5.1 to Novell 6.5 upgrade, and
ZenWorks for Desktop 4.0 to 7.0
. Project Manager for the Implementation of ZenWorks for Desktop 4.0 for
remote support and automation of workstation processes
. Project Manager in the implementation of a new backup solution using
Veritas NetBackp for Sun Solaris, Windows NT, 2000, 2003,and Novell 5.1
. Architect and Project Manager of the Tandberg Video Conferencing
solution for the agency, using a Tandberg Gateway and Gatekeeper for both
IP and ISDN calls
. Lead in the selection of an external partner for ITIL implementation and
compliance
. Implementation of WebEx for worldwide ERP (PeopleSoft) training and other
training sessions, saving millions in training costs
. IT Lead for the Global Meeting in 2004, supporting network and security
access for the facility and Video Conferencing for worldwide viewing
. Implemented the usage of a ticketing system for Help Desk events and
process tracking
. Created network diagram standards and reconfigured the Datacenter to
these standards, with color coordination based on the diagrams for
quicker troubleshooting
Deutsche Bank, New York, New York
Latin America Project Manager August 2001 to June 2002
. Directed operations for Latin America continued operations, communication
recovery, and support, due to the September 11th incident. Brought Latin
America to full functionality in two months
. Member and lead engineer for the development of corporate Disaster
Recovery Strategy, covering worldwide communications and data
survivability
. Management of IT infrastructure staff and resource teams constituting of
over 200 personnel
. Project Manager and/or Lead Engineer of LAN and WAN projects, from
inception to completion. Project types were: OSPF, Norton ESM V.5
rollout and configuration, Messaging, Website deployment, RAS, DMZs' in
three tier and five tier architecture using CheckPoint firewalls, SNMP,
HOOT and Holler, QIP v.5 rollout and v.6 upgrade, VOIP using Cisco gear,
etc. Designer of IP/VPN solution for world wide access, using Checkpoint
Firewall v.5 on Nokia boxes
. Established, and coordinated vendor relationships for product procurement
and quick delivery, minimizing tariff costs for Latin America's branches
. Latin America representative for the Global Asset Center inception and
deployment
. Member of virus rapid response team, which has addressed NIMDA, CodeRed
worm, etc.
. Instituted procedural changes to better address audits, and security
issues for Latin America, which helped the department achieve higher
ratings consistently during audits
. Developed, directed, and formulated strategies for project presentation
and approval within the company
Advanced Medical Technologies, Kearny, New Jersey
Chief Technical Officer July 2000 to August 2001
( Directed development of an all-in-one operatory computer
( Established vendor and manufacturing relationships with national and
international partners
( Manage a twenty-three person Information Technology staff, including
the Web Development group
( Designed and installed a Terminal Server2000 and MetaFrame2000 farm
( Designed, implemented, and maintained disaster recovery platforms.
Using Backup Exec, Arcserve, and
NT/Win200 backup, with redundant UPS architecture
( LAN/WAN design and implementation, including a VPN mesh
( Designed and configured hybrid networks
. Implemented Z.E.N. versions 1 thru 2 with Netware 5.0 and 5.1, pushing
both 16 and 32 bit applications with NAL (Netware Application Launcher).
Performed several migrations from Netware 5.0 to Windows 2000
( Designed, implemented, and maintained a Win2000 network using Active
Directory in the enterprise
. Lecturer for computer technology addressing HIPPA regulations
Optimized Computer Solutions, New York, New York
Project Manager March 1999 to July 2000
. Supervised Information Technology staff of twenty-two people, including
Web developers
. Implemented access control for data center and secure premises
. Installed DMZ's in accordance with FCC regulations, using Cisco PIX
Firewalls for market data feeds
( Implemented an Application Service Provider and Application Hosting
solution using NT 4.0 Terminal Server,
Citrix MetaFrame 8.0, and 2000
. Instituted Citrix Metaframe 1.8, and 2000 farm for Application Hosting of
clients applications
( Designed and configured hybrid networks, including Win2000, NT 3.5
and 4.0, Novell 3.11-4.11-5.0-5.1, UNIX, Linux, Sun Solaris, and DOS.
( Installed, configured, and maintained WAN and LAN-based printing
( Installed and configured Cisco routers from 1000 to 7300, Cisco PIX
Firewalls, Catalysts, and CSU/DSU's
( Developed vendor relations for thin client providers
( Designed, implemented, and configured of trading floors for multiple
firms
( Installed market data feeds, including Bloomberg, LexRoc,
Archapeligo, etc.
( Managed 1.6 million dollar project for Wall Street brokerage firm and
trading floor, with
Voice over IP to Chicago
( Supervised 600K installation of LAN/WAN for a law firm in a clustered
environment
( Project lead for an 800K LAN/WAN design and implementation for a
hospital with remote sites
( Developed Information Technology staff changes and operational
procedures
SmithKline Beecham, Clifton, New Jersey
Project Manager/Programmer February 1990 to March 1999
( Project Manager and member of worldwide project teams, addressing IT
implementations, upgrades, manufacturing automation, and new building
constructions using PMI principals
. Installed and maintained an Exchange 5.5 cluster
. Project Engineer on the implementation of a NOC for nationwide management
of the P.L.C. network
( Managed the automation of the manufacturing process for the United
States
( Supervised the maintenance and programming of Robotic equipment
( Engineer in the conversion of the corporate network operating systems
for 800 personnel from NetWare 3.11 to
NT 4.0
( Designed and implemented a co-axial, twin-axial, and a multiplexers
LAN for Ethernet, using a fiber-optic backbone
( Programmed and maintained the largest Texas Instrument P.L.C. Network
system in the world, with over twelve thousand I/Os'.
( Managed multiple projects from design to inception, with the largest
being a 6.2 million automation initiative
( Managed budgets for multiple projects, from inception to completion
( Lead of project teams composed of contractors and internal
professionals, for construction, automation, and IT tasks and projects
( Conducted engineering training of personnel in areas of network usage
( Participated in presenting projects to corporate officers for
approval of funds
. Developed policies to achieve better audit scores, consistently
achieving one of the highest score in the company
LPS Industries
Electrical Supervisor September 1989 to January 1990
( Supervised electrical staff of five electricians
( Designed and maintained production equipment, both electrically and
mechanically
( Programmed and maintained control systems for high-speed web
machinery
ADT Inc.
Electrician May 1987 to September 1989
( Maintenance and programming of robots, as well as AC and DC drives
( Installation and programming of robotic and automation equipment
( Responsible for maintaining manufacturing equipment both mechanically
and electrically throughout the facility
Self-Employed July 1985 to April 1987
( Performed general construction, electrical, plumbing, and carpentry
projects
( Installed and maintained industrial power distributions
( Installed and maintained Delta, Delta-Y, and Y power distribution
systems
U.S. Navy, Patuxent River, Maryland
Supervisor July 1981 to July 1985
. Supervised a 30-men crew, with the functions of quality control
inspectors, safety officers, and air crew
. Flight Engineer and Communication Officer for Air Crew, addressing
mission objectives with over 500 flight hours logged
. Member of MP and Shore Patrol teams addressing; premises, perimeter, and
personnel security
( Responsible for maintaining the electrical, pneumatic, and hydraulic
systems on EC-130 aircrafts
( Participated in a team to implement a packet translation for the XNS
protocol
( Granted Top Secret clearance
LANGUAGES:
( Fluent in Spanish, and English
Published Articles
"Lexmark Printer", eWeek Magazine, May 2006
"NAC complexity stymies deployments", Network World Magazine, July 2008
"How the UN keeps its Network Safe", Network World Magazine, July 2008
"NAC secures U.N. agency", Network World Magazine, July 2008
"Me and my Job", SC Magazine, May 2009
Awards and Nominations
Nominated for Security Seven, Information Security Magazine 2008
Nominated for North American Security Executive of the Year, 2008
Conference Presentations / Webinars
Guest speaker at the MIT IT Conference, April 25-26, 2007
Guest speaker at the SC World Congress, November 10-11, 2010
"Managing Checked List Boxes from the UI to the Database", Visual Studio
Developer, October 2006
"Connection Pooling", Visual Studio Developer, September 2006
"SQL Server Management Objects", Visual Studio Developer, August 2006
"Using Metadata", Visual Studio Developer, July 2006
"Asynchronous Commands in ADO.NET 2.0", Visual Studio Developer, June 2006
"Using Bulk Copy in ADO.NET 2.0", Visual Studio Developer, May 2006
"Managing Checked List Boxes from the UI to the Database", Visual Studio
Developer, October 2006
"Connection Pooling", Visual Studio Developer, September 2006
"SQL Server Management Objects", Visual Studio Developer, August 2006
"Using Metadata", Visual Studio Developer, July 2006
"Asynchronous Commands in ADO.NET 2.0", Visual Studio Developer, June 2006
"Using Bulk Copy in ADO.NET 2.0", Visual Studio Developer, May 2006
QUALIFICATIONS:
PC Operating Systems: MS-DOS, Windows 3.x, Win95/98, WinNT, WinME, Win2000,
WinXP, Win 2003, Win2008, Win7
Services: Citrix, DNS, SMS, NT directory services, Active Directory,
Netware Directory Services, BorderManager, ZenWorks,
eDirectory
EDUCATION:
PC Technical Institute, Jersey City, New Jersey
Cisco Certified Network Administrator (CCNA), 1998
Certified Novell Administrator (CNA), 1998
Microsoft Certified Professional (MCP), 1998
Microsoft Certified Systems Engineer (MCSE), 1999
Citrix Certified Administrator (CCA), 2000
ITIL Foundation Certification, 2006
COBIT Foundation Class, 2010
References furnished upon request