Objective
Collaborate with financial and operational audit teams to identify IT Audit
scope of Applications, Systems and IT Infrastructure to follow risk based
approach to integrated audit.
Experience
PENN MUTUAL LIFE INSURANCE COMPANY
Information Security & Protection Analyst
February
2008 to December 2013
. Prioritize risks and create plans to mitigate such risks by
determining probable loss or impact
. Develop and execute process to test system compliance with standards
before implementation
. Enterprise security monitoring, testing and scanning across all
platforms
. Develop and maintain risk-based information protection policies,
standards and guidelines which are aligned with business culture and
in accordance with applicable laws and regulations
. Provide incident response handling and investigations reporting all
evidence and results to the Chief Legal Officer
. Partner with the Vendor Management Team in driving risk assessments of
third party providers to assess controls, identify gaps and validate
evidence of remediation efforts
. Support the business and operational areas in pursuing opportunities
retaining to new uses and access methods for data while balancing
protection and productivity
. Implemented and maintained information protection program with linkage
to industry frameworks such as, GLBA, HIPAA, Model Audit Rule, SOX,
ISO27001, and ISO27002
. Provide guidance on projects and initiatives on information protection
and test compliance with standards
. Encryption strategy & process development for the enterprise
. Address and develop controls relating to mobile device security
. Ensure audit & regulatory compliance and conduct access control
reviews
Security Operations Analyst
January 2007 to February 2008
. Perform Account Management functions; account creation, modifications
and terminations, while adhering to all policies and meeting defined
service level agreements
. Assist in addressing internal and external audit concerns, while
documenting all business and control issues
. Develop and maintain policies and procedures that support the Account
Management function
. Work in conjunction with the Information Security Officer in
addressing security concerns for the enterprise
Infrastructure Desktop Support
March 2005 to January 2007
. Purchase, setup and distribute all hardware for field and home office
associates
. Configure and maintain BMC Service Desk Express for incident handling
. Install and maintain various software applications and provide support
for workstations running Windows Operating Systems (All versions)
. Implement proper procedure to handle severity 1 calls
Education
LA SALLE UNIVERSITY
B.S. Information Technology
2004
Certifications
. Microsoft Certified Desktop Support Technician supporting
windows XP, MCP
May 2006
. Comp TIA A+
January 2007
. Certified Information Systems Security Professional (CISSP)
Expected April 2014
. Certified Information Systems Auditor (CISA)
Expected June 2014
Expertise
Risk Management, IT Audit & Regulatory Compliance, Incident Response &
Investigation, Policy & Standard Compliance, Testing & Metric Reporting,
Security Monitoring, Disaster Recovery, Business Process Improvement,
Threat Management