Post Job Free
Sign in

Security Information

Location:
Zionsville, IN
Salary:
130k
Posted:
April 28, 2021

Contact this candidate

Resume:

Danny Albertson

**************@*****.*********:***********@*********.*** 678-***-**** Indianapolis, IN

Accomplished, results-oriented professional with extensive experience in creating and managing corporate-wide information technology, security, compliance, and risk management programs as well as having implemented these initiatives across a global organization. Core competencies include:

Regulatory Compliance (SOC 1, SOC 2, SOX, PCI DSS, PII, ePHI, FCRA, GLBA, MUSL, NASPL, WLA, FedRAMP)

PCI DSS Compliance

IT Security and Compliance

Symantec DLP

3rd Party/Vendor Management

Access Management

Business Impact Analysis

Change Advisory Boards (SDLC and PDLC)

Disaster Recovery and Business Continuity Plan Management

Emergency Response Plan

Enterprise Risk Management

IT Control Portfolio Management

IT Frameworks and Process Design (COBIT, ITIL, ISO)

IT Governance

IT Policy and Standard development

IT Process/Best Practice Implementation

IT Risk Management

Lottery Regulatory Agencies (MUSL, NASPL, WLA)

Dynamic management career with strong leadership, problem solving, clear communications and efficient operational and strategic skills. Ability to collaborate, organize and motivate a diverse staff into highly focused teams that deliver proven results. High-impact IT Management Professional with 30+ years’ experience leveraging best practices and industry standards through the effective management of compliance requirements, technical projects, and personnel resources. Instrumental in directing technology implementations, developing business-automation strategies, and cultivating high-functioning teams. Results-oriented, with exceptional leadership, organizational, communications, project management, and analytical skills.

Areas of expertise:

Governance Regulatory & Compliance (GRC), SOC 1 Type 1 & 2, PCI DSS, COBIT, SDLC, GLBA, SOX, FedRAMP, BIA, ERP, BCP, ERM, PII, ePHI, Symantec DLP, Change/Patch Advisory Boards, Control Vendor Management/Relations, Access Control, Information Security, IT Security Best Practices, ISO 27001/02, PII, 3rd Party Relationships, Identity Management, Team Building, Project Management, IT Operations, IT Infrastructure, Budget Management, Public Speaking, Customer Relations, Troubleshooting, Negotiations, DR and BCP, MUSL, NASPL, WLC.

Specialties:

Transformative security, audit, and compliance change through the use of technology and collaboration

Large-scale, cross-functional business technology projects

Enterprise security, audit, and compliance strategy, development and operations

Work Experience

Information Security Senior Advisor

Southern California Edison / iSite Techologies – Indianapolis, IN

May 2020 to Current

Facilitated and contributed to high-level Cyber projects for the CSRP division of SCE. This division manages all CSRP cyber related activities across the enterprise in order to go-live with their new Customer software delivery in 2021. All projects involved review, creation, and implementation of security and compliance mandates in order to protect all PII of SCE customers while ensuring security controls are implemented internally. Offered guidance and direction for current processes that connect to SAP and other 3rd party services. Key member of team designing, evaluating, and managing the Symantec DLP console for the enterprise. Reviewed, created, and tested DLP policies across all channels including Network and Endpoint. Developed monitoring techniques and reports to capture transmissions and storage for all data points. Point person for managing the revised Security Exception and Risk Assessment Review process in order to reduce the vulnerabilities and risk profile.

Information Security Senior Advisor

Anthem / Infosys – Indianapolis, IN

Jul 2019 to Apr 2020

Managed and facilitated high-level projects for the BST/FHPS division of Anthem. This division manages all medical, dental, and vision claims for the FEPOC (Federal Government). All projects involved review, creation, and implementation of security and compliance mandates in order to protect the PII and ePHI of all Federal Government Employees. Offered guidance and direction for both historical and current data reposed in both the production and non-production environments to include all applications. Point person for managing our published and unpublished Security Exceptions in order to reduce the vulnerabilities and risk profile.

Conducted quarterly Separation of Duties (SoD) audits to ensure all code migration controls were met. Coordinated SoD activities and 14 Application packages with Internal Audit.

Responsible for the De-Identification Project which involved the research and identification of where PII or ePHI was reposed in the non-production environments. Developed retention periods and data purge schedules to ensure only necessary data is reposed and purged according to both regulatory and internal policy. As of Q120, over 8.2B records purged of both structured and un-structured data.

Managed the published and unpublished Security Exceptions through closure. Published Security Exceptions are risk-based and prioritized accordingly.

Led and conducted the Data Mapping Initiative. The scope of the project was to track and identify every transit and repose point for PII/ePHI data through the FHPS enterprise.

Assisted with the review and update of all DLP Policies to ensure all data at rest and in transit was being recorded, captured, and reported appropriately

Conducted a comprehensive sensitive data review and project plan for assessment and prioritization.

Corporate Compliance Manager

Knowledge Services – Indianapolis, IN

Aug 2017 to Jun 2019

Managing and responsible for the newly created Compliance Program. Accountable for the creation and execution of strategic projects including Business Impact Analysis (BIA), Emergency Response Plans (ERP), Team Member Risk Assessments (TMRA), Enterprise Document Management Repository (EMDP), and Enterprise Risk Management (ERM). Ensuring that team members are aware and that policies/practices are in place to abide by State/Federal Regulations and best practice. Sought for advice and counsel while providing independent and objective reviews of internal/external processes, controls, and best practice. Point of contact for established or new compliance activities within the organization.

Led and conducting Knowledge Services first comprehensive Business Impact Analysis (BIA). This effort spanned the entire enterprise to capture the Critical Business Functions, Key Business Processes, and supporting Systems/Software in order to conduct business as usual. Phase 1 of 4 of the Business Continuity Program creation and roll-out.

Created, implemented, and managing the Corporate Emergency Response Plan (ERP). This is a comprehensive ERP for all Knowledge Services locations detailing event types, team member responsibilities, evacuation plans, and periodic testing.

Created, implemented, and managing the Team Member Risk Assessment in order to evaluate potential risks an individual could present to the organization. Risk level equals the likelihood of occurrence multiplied by the severity of impact based on role, job knowledge, or physical/logical access rights.

Created, implemented, and managing the Enterprise Document Management Repository in order to ensure all procedures for more than 1,000 Key Business Processes are reposed, available, and current.

Creating the Enterprise Risk Management Program to fully integrate operational, strategic, reputational, financial, fraud, privacy, security, and general complaint risk categories among others.

Managed internal/external 3rd Parties relationships and or SLAs

Oversight of the creation and ongoing development/roll-out of our Policies and Procedures across the enterprise.

Continually provide independent compliance training and education to both internal team members and or contractors/3rd parties.

Assisted in the creation and roll-out of the Software Asset Management System in order to fully comply and obtain a comprehensive listing of software/licenses utilized.

IT Compliance Lead

Insight Global - Atlanta, GA

Feb 2017 to May 2017

Lead and accountable for supporting the achievement of regulatory and non-regulatory IT compliance through effective management of information technology issues and enhancements identified through audits, examinations, and self-assessments. Accountable for the execution of strategic projects to support the CTO’s initiatives and business objectives.

Acted as an SME in managing cybersecurity issues end-to-end, from reporting through remediation.

Provided business units sustainable action plans to address identified risks.

Responsible for annual reviews and updates to the IT security, privacy, and other policies based upon risk of emerging threats, regulations, and best practices

Responsible for facilitating internal and external audits, internal control and compliance assessments, and vendor risk assessments.

Managed projects related to cybersecurity, privacy and control initiatives to reduce identified risk to support IT Security, Privacy, Operational Controls, and Regulatory Compliance strategy.

Manager – Regulatory Compliance

Scientific Games - Alpharetta, GA

Jul 2014 to Nov 2016

Managed and implemented Security, Compliance, and Audit projects and initiatives across Lottery, Gaming, and Interactive business units throughout U.S. Lead through driving innovation, collaboration with system, customers, and their stakeholders, delivered results, and inspired others.

Provided leadership for the governance and compliance of the company’s policies pertaining to security, compliance, audit, standards, procedures, and guidelines to ensure adherence with those federal, state, and regulatory agency requirements.

Provided business security stewardship for Global Technology Operations (GTO)

Provided oversight on Internal and External Audit activities.

Proactive member of the Access Management Operating committee to ensure role design and governance processes adhere to security and risk mitigation standards through sustainable design.

Established and implemented the Company’s security, compliance, and audit programs to identify protection goals, objectives and metrics used to monitor compliance.

Delivered continuous improvement thru Operational Excellence (OE) initiatives and driving significant improvements in Service Management activities (Incident, Problem, Change, and Request management). Identified and implemented best practices and process improvements in the various areas of concern and institutionalizing those practices.

Provided leadership, direction and coaching to support resources to achieve work objectives and improve performance and skills, Ensure direct reports and project team members have clarity about their role and responsibilities.

Partnered with cross functional teams from applications development, client engagement, and business teams and vendors to deliver key performance metrics and SLAs.

Analyzed risk and control solutions pertaining to management identified concerns, audit comments, analysis results of controls monitoring, project reviews and requests, and or operational risks.

Maintained SOC 1 / 2, MUSL, ISO, and NASPL narratives to reflect the most current control environments and models.

Assessed risk to the company’s SOD / SA rule set design through the review of security changes due to projects and system updates/upgrades, as well as inquiries and notifications from business stewards, process leads, or compliance partners.

Created standards and guidelines for enterprise applications. Evaluated our environment, newly identified control gaps, industry best practices and proposed adjustments. Ensured that the proposed adjustments to the standards aligned with the security solution architects and were effectively implemented.

Managed and was the main point of contact for the SOC 1 / 2 Audits, MUSL, and NASPL audits.

Responsible for governance and the maturity of processes and controls related to the GRC.

Chaired the IT Controls Monitoring team in order to monitor IT risks and help ensure compliance with company policy and continually improving the strength of our control environment.

Reviewed all security, audit, and compliance changes to ensure they do not include unintended access risks and were in compliance with the company’s Information Protection Policy and other regulatory requirements.

Provided subject matter expertise on security, controls, compliance & risk matters related to enterprise applications.

Director – IT Security, Audit, and Compliance

ista North America - Alpharetta

Feb 2010 to Feb 2014

Directed and implemented Security Operations and Compliance, IT Risk Management, Access Management, and Audit Governance and Compliance.

Leader for the U.S. Security Compliance function responsible for managing internal and external auditor engagement, liaison for security compliance and information security risk assessment activities delivered for strategic account relationships. Developed the IT Baseline Security framework and performed oversight of IT Governance.

Core technical and management leadership resource that sets direction for all IT Governance, Risk and Compliance activities for ista North America including SAS70/SOC1/PII/PCI DSS/ISO 27001.

Partners with internal and external auditors as well as technology experts and vendors to direct, implement, deliver, and integrate appropriate IT General controls to support overall compliance. Managed, developed, and deployed third party security standards for risk assessment methodologies to ensure compliance with standards.

Partnered with business to educate on appropriate IT Controls and identification of business benefit, and equipped IT process owners with the skills, knowledge and/or tools needed to effectively manage IT Controls and enable pro-active control management and the realization reduced IT Risk.

Directed all aspects of IT Governance including developing and deploying best practices (including SDLC and Project and Portfolio Management) as well as providing and managing enterprise framework and tool sets that enables implementation of best practices across the entire infrastructure.

Implemented a three-year information security roadmap to address complex regulatory and business requirement. Developed comprehensive security policy and compliance measures, Third Party security policies and assessment mechanisms, designed and managed SAS70, SOC 1, PII, PCI DSS processes.

Key member of management team. Interfaces with Board, Audit Committee, Executive Management, Internal / External Audit teams, and Legal.

Led ista NA through multiple unqualified SAS 70 and SOC 1 Type 2 audits across several Service Organizations.

Managed all aspects of IT Security including user administration, policy development, risk assessment, perimeter and internal security architecture, internal consulting, project management, awareness programs, incident response and auditing. Represented ista NA to regulatory bodies, customers, and clients.

Developed and managed Identity & Access Management policy, processes and procedures. Directed all aspects of IT governance including developing best practices and providing and managing enterprise framework and tool sets that enable implementation.

Audit & Compliance Director – Technical Services

EQUIFAX INC – Atlanta, GA

Jan 1988 to Nov 2009

Managed and implemented procedures, policies, and controls for SAS 70, SOX, GLBA compliance.

Developed, implemented, and maintained core operational processes critical to the compliance of SAS 70, SOX, Security Policy and Best Practices, and controls that resulted in no qualified opinions or findings.

Leader of cross-functional special projects - resolving major issues that required Sr-level leadership, negotiation and technical skills to complete. Collaborated with security, architecture, development, sales, and operations. Successful at using influence to align the goals of many teams, both inside and outside the IT domain.

Achieved significant Audit cost reductions by reducing the reducing the number of in-scope activities, associated time, and research requirements. Leveraged these efficiencies to increase revenue generating projects by 17% in 2008.

Led effort for driving internal knowledge of compliance regulations, associated practices, and policies. Rebuilt and designed the document repository. Directed cross-functional teams on how operational processes and measurements coincide with methodologies. This initiative resulted in a 40% decrease of redundant audits and significant cost savings (1.2m).

Implemented an alternate audit schedule in 2007 that minimized internal gaps and proactively strengthened processes which assisted in the successful passing of both internal and external audits.

Developed and implemented controls using the COBIT framework which drove best practices in defined controls, security, and process governance. In conjunction, ISO requirements were implemented and applied to establish and formalize standardization to obtain certifications.

IT Information Security Manager, Security Administration

EQUIFAX INC

September 1998 to June 2006

Managed the administration and support of 50+ logical and physical systems. Managed the Customer Support Team responsible for approximately 9,500 customers.

Executed Disaster Recovery and Business Continuity Plans across the enterprise.

Implemented and supported 28 new logical systems and or applications in a 7-year span.

Demonstrated expertise for integration of functions and execution of special projects, to include lending expert advice or consultation.

Advised senior leadership on resolution of complex security and compliance issues worldwide.

Led efforts in gathering, deciphering, and interpreting information to both internal and external auditing firms and customers. Facilitated customer reviews and audits.

Developed and executed database design via collaboration with 90 districts worldwide to house all resources and associated access controls. Recognized by internal and external auditing firms for its ability to close security and compliance gaps, Using IT General Controls (ITGC), Developed and implemented IS strategy and security policy to ensure proper development, and implementation of controls that applied to all system components, processes, and data controlled or maintained.

Created the CVO database which centralized all systems and users. Enabled our finance, procurement, human resources and legal teams to track non-employee data. This database enabled Finance to review expenditures, procurement to administer PO’s, HR to track vendors and off/on shore contractors: and protected Equifax from legal exposures.

Technical Specialist III – Security Administration Support

EQUIFAX INC

January 1994 to August 1998

Established a proven ability to provide resolutions in the support and administration of systems and services worldwide.

Chosen by management to direct all security and audit questions and or issues.

Diagnosed problems; and developed and executed solutions.

Conducted tours of our datacenter facilities and spoke to strategic clients about our services and capabilities.

Other Equifax roles

EQUIFAX INC

December 1988 to December 1993 - Details available upon request

Education

Business Administration

Georgia State University

Business Administration

Southern Adventist University

References

Available upon request

Links

http://www.linkedin.com/in/dalbertson



Contact this candidate