STEVEN M. STEINBERG
**** **** ***** ****, ********* FL 34203 ******.**********@*****.***
http://www.linkedin.com/in/stevenmsteinberg
INFORMATION TECHNOLOGY . INFORMATION SECURITY . AUDIT/RISK MANAGEMENT
Intelligent, solutions-focused IT and IS professional with 27 years of
experience providing IT and IS direction from planning to implementation to
audit management for companies with dynamic network, data center, service
center, security and performance requirements. Adept at bridging the needs
of business, technology and risk mitigation to offer elegant, cost
effective solutions to maximize ROI for IT and IS and ensure systems meet
evolving business imperatives.
Respected by colleagues, clients and staff, known as a tenacious worker
with ability to resolve difficult situations and possessing an unwavering
commitment to meeting service needs.
STRENGTHS & EXPERTISE
IT. IS . Technology Service Delivery . IS Controls . Risk Assessment . Risk
Mitigation . IS Audits . Business Analysis . Program Management . Project
Management . IS Controls . Compliance/ISO Framework . Product Lifecycle
Management . Authentication Controls . Budget Management . Vendor
Management . Service Level Agreements . Continuity of Business . Disaster
Recovery . ISO 27005 Framework . Sarbanes Oxley/GRC . Gramm-Leach-Bliley
Act . Change Management . Problem Management . Microsoft Platform Support .
BISO . Data Center Management . Network Control Center Management . Call
Center Technology Management
PROFESSIONAL EXPERIENCE
Self Employed - Private Consulting, IT/IS, NJ/NY/FL
7/2012 to Present
Self-owned LLC consulting company
Started business to provide IT and IS consulting services focusing on small
business and advanced home users to provide that sector with professional,
quality and affordable solutions. Provide support services including
design, proposals, implementation and trouble support.
. Designed, implemented, installed and supported systems in NJ, NY and
FL from unsophisticated configurations to complex firewall, server,
distributed systems installations
. Provided consultation services to numerous small businesses to ensure
compliance with customer privacy regulations
. Resolved countless IT service issues including access points,
firewalls, modems, routers, Wifi networks, distributed peripherals and
Microsoft platforms
. Developed numerous IT Control Manuals, Policy Manuals, System
Configuration Documentation and System User Manuals
RER International, Sarasota, FL
3/2011 to 7/2012
Information Technology, Information Security Consultant
Hired to work with partners to develop information technology solutions,
analyze, choose and integrate applications, implement information security
program and control documentation and assist with business analysis to
further company expansion.
. Implemented Ethernet and Wireless secure networks, created
documentation, operational procedures and security controls
. Provided analysis of cloud storage and backup solutions and
coordinated service level contracts on behalf of the company
. Established security and control standards for business Windows
servers and IP networks
. Created and presented a 1 year tactical IT/IS plan to address
immediate business expansion
. Created and presented a 3 year strategic IT/IS plan to accommodate
expected business growth
. Created service level agreement for server and network service and
support
. Selected service organization and coordinated contract for server and
network support
. Worked with partners on web services and creation of company web site
MetLife Bank N.A., Bridgewater, NJ
4/2009 to 7/2010
Business Information Security Director, Bank Compliance
Reporting to the Security Officer, Bank President, CIO and CFO, I was
responsible for the creation and management of IT Compliance and IS policy
(ISO 27001 framework based) within the banking group at MetLife, a startup
organization of acquisitions and mergers. Integrated policy enforcement,
audit management, tactical and strategic remediation plan creation and
management and providing overall IS direction including numerous boards and
committees. Created IS team, authentication team, process controls,
testing procedures and developed a five year strategic plan, presented
approved by the President and CIO as part of the Chief Compliance &
Security Officer's organization.
. Developed and managed an overall IS organizational operational
framework manual for the banking organization
. Established Technology Processes and standards for the bank in
alignment with MetLife Inc.'s IT, IS and controls standards against
governance, risk and compliance (GRC)
. Responsibility for audit and compliance programs utilized throughout
the bank
. Developed and managed an overall organizational communication
framework internal to IS Group and executives
. Managed teams providing local, remote and help desk support for in-
region system access across business units
. Developed an overall organizational performance accountability
framework and reporting metrics
. Established appropriate organizational service and operational
procedures
. Created and presented a 2 year tactical IS plan to address immediate
business audit findings and documented risks
. Created and presented a 5 year strategic IS plan to accommodate
business integration of acquired mortgage organizations and planned
acquisitions and mergers
CITIGROUP, New York, NY
3/1988 to 3/2008
Citi - Senior Vice President, NA Risk/Control Officer and Audit Manager
(2004 to 2008) New York City
Championed information security and risk management for multiple banking
business units delivering critical executive counsel and management of
internal and external audits. Evaluated systems controls and testing
processes. Cultivated strong relationships with support vendors, senior
auditors, and field IT support personnel, quickly mitigating risks via
superior communications, documentation, and resolution planning. Ensured
modified applications and hardware platforms complied with corporate
standards. Integrated Payment Card Industry Security Standards within
Consumer Bank and Private Bank sectors.
. Elevated business unit growth, delivering enterprise-wide cost-
effective systems and applications
. Spearheaded 16 technology ISO standards based audits, developing
resolution plans and managing change deployment
. Analyzed audit findings, isolating technical improvements and
procedural modifications
. Reviewed compliancy and managed process control integration during
corporate mergers
. Managed 80+ risk mitigation projects for multiple reengineering,
application and architecture initiatives from design to implementation
and support procedures
Citi - Vice President, Regional Service Delivery Director (2000 to 2004)
San Antonio, TX
Facilitated Retail Bank and Consumer Customer Service Call Center
operations, leading 41 local and 60 remote IT professionals and Cobol, SQL,
CICS, RPG, CRM, SAP, VSAM and DB2 developers. Directed help desk service,
national and international data networks, local LAN infrastructure, and
desktop support for 4,000 back office users, 12 T3 networks, and 6,000
desktops in over 12 locations. Managed integration change control,
application deployment,
continuity of business support, strategic technology planning, merger
integration, outsource coordination, and service level management.
Collaborated with site president, ensuring superb customer service and
resolving escalated support issues.
. Launched Kentucky call and service center, designing LAN
infrastructure and voice and data networks and associated contingency
planning
. Instrumental in outsourcing contract negotiations with India call
center vendors for support of banking customers.
. Project Managed merger of Golden State Bank technology and support
teams into Citigroup back office operations
Vice President, Regional IT Service Delivery Team Manager (1988 to 2000)
Tampa, FL
Orchestrated Latin America Consumer Bank and World Wide Personal Banking
technology support, directing 35 local and 30 remote IT professionals, and
multi-platform application developers.. Delivered exceptional help desk
support for 3,500 local users, with remote locations throughout North and
South America. Established technology goals and managed multi-million
dollar budgets, bringing technology requirements in-line with financial and
business goals. Served as key liaison between business units within Client
Technology Services for audit, business monitoring, and risk-related
issues, ensuring security, network robustness, and continuity of business.
Citi - International Business Development Tampa, FL
. Jumpstarted Latin American startup operations as 2-year Latin America
Country Head, designing and project managing deployment of voice and
data networks to key cities throughout North and South America
. Project managed Latin America data center relocation over 3-day
weekend, installing satellite, terrestrial, voice, and LAN
infrastructures without impacting consumer back office business
operations
. Managed international satellite, terrestrial, and sub-oceanic networks
with contingencies as part of Latin America support
Citi - Key Corporate Business Growth Tampa, FL
. Directed 5-building, 4,500 employee Tampa operations technology design
and installation
. Originated International Personal Banking voice over data network,
designing, budgeting and program managing upgrade
. Selected as key member of Citi's Global Information Networks Top 200
strategic management team, serving as team captain and focusing on
strategic technology goals and execution planning
. Created and managed multiple continuity-of-business plans mitigating
key business risks
. Project managed innumerable IT business initiatives over 20 year
Citigroup career
FORMAL EDUCATION
Electrical Engineering/Computer Science Coursework - Saint Petersburg
College, Saint Petersburg, Florida
Quarterly Corporate Technology Coursework - 20 Years, various locations and
Cleveland Institute of Technology
TECHNICAL SKILLS AND TRAINING
Applicati Word . Excel . Access . Power Point . Visio . MS Project . McAfee ePo
ons (Enterprise) . LAN Management Solution Suite . Intrusion Detection &
Prevention Systems (IDS/IPS) . CA SiteMinder . MS SharePoint
Application/Server . MS Live Meeting . Adobe Creative Suite 5.5 . Desktop
Security . Desktop Antivirus . Google Office . Citrix
Networks Cisco Routers/Switches/WiFi . Cisco VPN . Cisco Works . T1/T3/Frame Relay .
NetScout Network General Sniffers . Novell . Lucent Platform Management .
ATM/LAN/WAN/MAN Optimization . Satellite
Protocols DHCP . DNS . SDLC/Mainframe . Token Ring . IP/TCP/UDP . VoIP
Servers Microsoft Server . UNIX . Red Hat Linux . MS SQL . MS SharePoint . Novell
Netware . DOS . Android . MS Exchange . Lotus Notes
Hardware Distributed Systems Architecture . Desktops . Laptops . Smartphones .
Routers . Switches . Firewalls . IBM AS/400 . IBM System 38 . HP . IBM .
Patch Panels . Lucent Platform Management
Training CISSP Certification Training (ISC^2) . Network Design & Optimization .
Cloud Computing . Cloud Security . LAN Management Solution Suite .
Intrusion Detection & Prevention Systems (IDS/IPS) . Network General
Sniffer . Cisco Works . Enterprise Risk Management . Network Access
Management & Controls . SOX Management . GLBA Management . Enterprise IT
Risk Auditing . Process & Procedure Writing . Facility Infrastructure IT
Design & Implementation . COB Management . Disaster Recovery Management .
Security Standards . Corporate Tactical Planning . Corporate Strategic
Planning