Data Protection
As an Information Systems Security Administrator/Engineer /Lead I have 12 years experience in Incidence Resonponse, vulnerability and risk management quantitative, Compliance and Reporting, Access management, Identity Management, System architecture design, Data Loss Prevention, Cyber Alert monitoring. Proficiency in and
understanding of data privacy regulations (PCI, HPAA,PII etc.) and compliance
industry/federal standards and guidelines such as (NIST sp 800-30 (NIST 270**-***-**, CIS, ISO27002.
I have an extensive knowledge of data protection and privacy enabling technologies and IT security tools Proofpoint,Symantic DLP, OneTrust, Microsoft Compliance or Information Protection. I have expertise to conceptualize and develop Data Protection solutions to address customer's data and security needs.
As an IT security operations lead I trained security analysts in investigating incidents and the policy to respond,
I also created policies and procedures. Managed the data loss prevention department lowering false positives, determining severities training DLP analysts working closely with the director reporting and keeping documentation.
Acted as a subject matter expert for the team and attending weekly meetings and hosted weekly training meetings.
Lead and managed various projects involving migrations upgrades etc.
Areas of Experience
Valued Skills in Network Environments Employing various Arenas
Discipline
Description
Data Protection and Monitoring Tools
McAfee, Symantec, Crowdstrike, Digital Guardian, Pece,Peca, Olympic, Instinct, arcsight. Splunk
Network Protocols & Tools
Servers, Routers, Switches, Load balancers TCP/IP, HTTP/HTTPS,SMTP, SSH, DNS
Servers
Exchange Servers, Application Servers, Development Server
Cloud platforms
AWS, Microsoft Azure
Ticketing Systems
Remedy, Service Now, Landesk
Data analysis tools
Splunk, Peca, Pece,AppHQ,BICs, Instinct,Permit to Send,vendor list
Networking Environments
VPN, LAN, AWS, WLAN, Cloud
Operating Systems
Windows Server 2003-2008,2016, Linux, Windows 7,8,10,Win9X thru 10, Win2K/Win2K3 Pro/Win2008/2012 Server, Microsoft Office 97,2000,20008, thru 2010, VMware vSphere Clientk
Penn Testing and Code Review Tools
Kali,Linux, Nessus, HPE Fortify
Risk Assessments
Brain Storm
Vulnerability management
Qualys, Burp suite,
Scripting Languages
Python, Powershell
Professional Experience
Western World an (AIG company) October 2018- Present
Data Loss Prevention Engineer III
Performed continuous monitoring data in motion resolving various incidents
Analyzed vulnerability scan results, system audits, log events and troubleshoot software issues
Configured Tenable to operate and discover security, application and operating system related items
Processed and enhanced the security operations of applications and software
Utilized data protection methodologies to resolve unstructured data incidents
Established data standards and processes/workflows, providing recommendations for privacy and data governance programs, processes and controls and supporting data breach response planning and playbook development
Supported implementation of data privacy compliance processes, risk management and control implementation efforts, including data inventory and mapping tasks
Reported any updates of projects exceptions to policies, new authored policies procedures, and added processes to the CISO in a timely manner
Utilized Qualys to run vulnerablility scans on endpoints and worked with owners to remediate the vulnerability and ran a demand scan to validate the fix.
Developed targeted playbooks for L1 response
I initiated the threat management processes, to ensure that every aspects of an event is documented,remediated, and and reported to the Director in a timely manner
Implemented, established, developed and maintained an efficient vulnerability,access management, data loss prevention and incident response process
Initiated the use of information and Digital Rights Management (DRM)
Created various groups and applied policies
Performed deep data analysis using various tools
Reviewed asset management documentation for all, hardware, and software changes that may impact the firms standard information security posture; security technology policies, procedures, processes, and technologies
Provided quality assurance,appraisal and approval of security deliverables, to include revising and drafting test plans, security specification reviews and standards, and technical documentation
Worked with relevant stakeholders within the various Technology groups and business units to guarantee security awareness and issues were communicated effectively with documentation and verbal communication
Conducted the reviews of applications from a security and privacy perspective; review and contribute to the client's IT Standards used in the solution security review process and provide security recommendations and better practices regarding secure software development.
Initiated the use of Exact Data Match (EDM)
Provided recommendations to protect the business against industry known threa
Interacted with IT and vendor auditors, both internal and external, including coordination of interviews and walkthroughs and outlining key risks and controls. Understands risk impact and likelihood to business goals and objectives.
I could guarantee the accuracy and timely completion of audit tasks within established guidelines
Performed general control oversight and reviews to verify compliance with McAfee, Qualys and PCI.
Developed a working relationship and Coordinated with IT departments and financial, operations
I was instrumental in remediating issues found from the compliance reports.
Followed compliance procedures and Best Practices for internal operational risk Assessments and controls in accordance with the national standards, requirements, and policies.
Made recommendations after the review of systems to assess the adequacy of management controls, efficiency, and compliance with policies, regulations.
Constantly monitored performance of assets and performed risk assessments
Ran Queries and Reports Daily and emailed to management in regards to the progress of the remediation of issues found as a result of the compliance scan
Food and Drug Administration May 2017-October 2018
Data Protection Engineer
Provided recommendations information to protect the business against industry known threats by utilizing Tenable
Ensured all Cyber security threat response strategies are integrated with governance and compliance processes.
Performed execution of security root cause analysis and forensics as part of the enterprise’s Cyber Incident Response Plan.
Initiated monitoring/reporting and developing processes and procedures.
Analyzed incidents to solve issues and improved incident handling procedures
Configured Qualys to report and alert through external systems
Initiated the use of information and Digital Rights Management (DRM)
Analyzed vulnerability scan results, system audits, log events and troubleshoot software issues
Configured Qualys to operate and discover security, application and operating system related items
Supported multiple Information security projects as assigned
Performed Data Protection solution rollout or operations support
Performed automated and manual run-time assessments
Established governance and operating model for large scale organizations
Designed and implemented Cyber Threat hunting for organizations, including threats and enacting identification, containment, and eradication measures while supporting recovery efforts
Developed, reviewing, updating data protection policies for a large scale enterprise
Technical knowledge of Active Directory including user account and security groups creation and maintenance process
Implemented a Data Protection solution (e.g., DAG, DLP, Data Classification) and integrating it with other technology solutions such as Identity and Access Management and Security Information and Event Monitoring for in-depth security
Developed application security standards and policy documentation
Gathered Data Protection solution specific requirements and assist with framework development, policy development and design governance and operating model
Performed log Correlation Security monitoring by using tools such as Splunk
Acted as subject matter expert to provide insight, guidance and engaging in the discussion to adopt various methodologies, processes and policies.
Developed requirements, designed, built an operational documentation for Data Protection solution roll out and support
Identified, reduced, and reported on unstructured data risk
Conducted periodic integrity checks for Process Control equipment power supplies, control processors and analyze their performance to continuously drive improvements
Participated in site investigations, self-assessments, risk assessments, and audits providing information evidence of the local compliance to cyber security requirements.
Performed detailed source code of old and new application
Utilized Qualys to run vulnerablility scans on endpoints and worked with owners to remediate the vulnerability and ran a demand scan to validate the fix.
Researched, initiated the evaluation of tools, technologies, processes to enhance the security of application software produced
Received Tier 2/3 incident escalation from detection operations and assist with realtime, continuous (24x7) security event monitoring, response, and reporting
I was the automation subject matter expert in the development and implementation
Deployed new products, product upgrades, patches
Analyzed incidents to solve issues and improve incident handling
Performed risk assessments and/or threat modeling to articulate the levels and types of security controls appropriate application/product initiatives
Performed Search and Reporting with Splunk and License management
Conducted the reviews of applications from a security and privacy perspective; review and contribute to the client's IT Standards used in the solution security review process and provide security recommendations and better practices regarding secure software development.
Provided recommendations to protect the business against industry known threa
Interacted with IT and vendor auditors, both internal and external, including coordination of interviews and walkthroughs and outlining key risks and controls. Understands risk impact and likelihood to business goals and objectives.
I could guarantee the accuracy and timely completion of audit tasks within established guidelines
Performed general control oversight and reviews to verify compliance with McAfee, Qualys and PCI.
Developed a working relationship and Coordinated with IT departments and financial, operations
I was instrumental in remediating issues found from the compliance reports.
Followed compliance procedures and Best Practices for internal operational risk Assessments and controls in accordance with the national standards, requirements, and policies.
Made recommendations after the review of systems to assess the adequacy of management controls, efficiency, and compliance with policies, regulations.
Constantly monitored performance of assets and performed risk assessments
Ran Queries and Reports Daily and emailed to management in regards to the progress of the remediation of issues found as a result of the compliance scan
Bed Bath and Beyond, Union, NJ June 2016- May 2017
Data Loss Prevention ANalyst/Engineer
Analyzed data in motion incidents to resolve issues
Utilized data protection methodologies to resolve incidents involving unstructured data
Performed scanner configuration, asset inventory, triage of output and remediation guidance, workflows, continuous monitoring
Worked hand in hand with development teams to remediate application vulnerabilities detected through security scanning tools
Configured Qualys to report and alert through external systems
Analyzed vulnerability scan results, system audits, log events and troubleshoot software issues
Configured Qualys to operate and discover security, application and operating system related items
Provided remediation guidance to partners, and recommended appropriate measures to manage and mitigate risk.
Provided leadership regarding best practices for vulnerability scanning, configuration baselines, security designed reviews.
Guided a team in the completion of security assessments, vulnerability scans, penetrated testing, and continuous monitoring activities
Managed the security activities associated with Secure Software Development to address existing and evolving risks and threats appropriately
Leveraged enterprise standards for data domains and data solutions, focusing on simplified integration and streamlined operational and analytical uses
Guided high level data architecture design (functional, non-functional) and ensures teams adhere to data architecture standards
Developed information processes for data acquisition, data transformation, data migration, data verification, data modeling, and data mining
I was Accountable for cost viability and technical estimation of data platform usage
Designed data solutions for data distributions and partitions, scalability, disaster recovery and high availability
Designed security for data policies and standards
Monitored and optimizes data solutions
Actively governed and automated standard data architecture patterns and blueprints
Partnered with architecture, security, infrastructure, and application teams to design and implement the automation of data, data platforms, and tools
Created and updates automation to eliminate routine management processes
Articulated the need for scalability and understand the importance of improving quality through testing
Provided and/or organize appropriate application security training and awareness for technical and non-technical staff
Orchestrated the requirements determination, threat modeling, and security vulnerability assessments on new and existing systems, products, product updates, patches, operating systems and databases
Performed automated and manual run-time assessments
Created vulnerability reports on spreadsheets, detailing the security requirements, risks, business impacts, and remediation guidance to the customer and to my CISO
Performed code review and threat modeling
Established attack baselines and using threat research results to operationalize findings into security analytics and detections for our clients advanced Security Analytics and Threat Detection platform.
Contributed to the Security efforts of our clients cutting-edge Threat Research & Labs team
Developed ways to detect threat activity using security analytics, machine learning, behavioral analysis.
Analyzed latest threats in the lab.
Reproduced real-world attacks.
Analyzed security log data to identify adversary activity
Discovered vulnerabilities in System Architectures, Builds, infrastructure configurations, and 3rd-party product deployments
Cyber Security System Plus, Inc. @ AIG April 2012- June 2016
Information Systems Security Engineer
Configured, deployed, monitored, operated, secured, and maintained two (2) central ePolicy Orchestrator (ePO) servers, and numerous Enterprise Super-Agent Distributed Repositories
Initiated a Custom workflow and developed Feature additions and improvements to the Aspera Orchestrator,
Prepared, developed and maintained organizations best practices; Responsible for installing, patching and maintaining Servers
Utilized the use of VMware Configured VLANs and Administrated VDI accounts
Responded to threats and incidents and acted independently of the team as well as working with the team to analyze and react to events
Performed security patching and updates on servers; Initiated Backups for endpoints nightly
Collaborated with Service Vendors by conducting meetings for planning security solutions
Performed automated and manual run-time assessments
Conducted the reviews of applications from a security and privacy perspective;
Reviewed and contributed to IT Standards used in the solution security review process and provide security recommendations
Provided recommendations to protect the business against industry known threa
Interacted with IT and vendor auditors, both internal and external, including coordination of interviews and walkthroughs and outlining key risks and controls. Understands risk impact and likelihood to business goals and objectives.
Guaranteed the accuracy and timely completion of audit tasks within established guidelines set in place
Performed general control oversight and reviews to verify compliance with McAfee, Qualys and PCI.
Developed a working relationship and Coordinated with IT departments and financial, operations
I was instrumental in remediating issues found from the compliance reports.
Followed compliance procedures and Best Practices for internal operational risk Assessments and controls in accordance with the national standards, requirements, and policies.
Made recommendations after the review of systems to assess the adequacy of management controls, efficiency, and compliance with policies, regulations.
Constantly monitored performance of assets and performed risk assessments
Ran Queries and Reports Daily and emailed to management in regards to the progress of the remediation of issues found as a result of the compliance scan
Performed network traffic monitoring and log analysis
Managed Splunk apps performed configuration files, index management Users roles, and authentication.
Performed System modifications to meet official requirements
I was a liaison with the stakeholders within the IT groups and business units to ensure security awareness and issues are communicated effectively
Performed Secure Development Lifecycle process assessments
Provided technical direction, leadership, and training to staff and remote users and engineers
Worked closely with developers to remediate applications and vulnerabilities detected through security scanning tools
Initiated the use of risk assessments and/or threat modeling to articulate the levels and types of security controls appropriate application/product initiatives
Managed the security activities associated with Secure Software Development
Performed Threat Intelligence Exchange server installation and implementation
Identified threats, vulnerabilities and exploitations using Security Tools to remediate them
Utilized Threat Intelligence Exchange to protect against network Threats
Defined project scope and objectives, involving relevant stakeholders and ensuring technical feasibility
Cisco Systems, Richardson, TX June 2010- April 2012
Information Systems Administrator
HBSS Administrator in a Multi-Security Enclave supporting a 1100+ customer base Enterprise
Investigate IT security incidents and issues to identify root cause, assess impact and to make specific recommendations for containment, mitigation and future improvements to security posture
Configure, deploy, monitor, operate, secure, and maintains three servers, and eight (8) Enterprise Agent Distributed Repositories
Receives daily Anti-Virus (VSE) and periodic Host Based Intrusion Prevention System (HIPS) (Block High, Medium, and Low) signature updates from Support.
Conducted Benchmarks and File Integrity Monitor checks through Policy Auditor
Implemented, managed and deployed the Security Software on Citrix Servers master image.
Perform SQL Server administration and management;
Perform System modifications to meet official requirements
Provide Tier 3 support to remote sites as well as, troubleshooting, planning, and upgrade implementation
Assist other departments, directorates, and agencies with –related Security questions and issues
Conducted the reviews of applications from a security and privacy perspective; review and contribute to the client's IT Standards used in the solution security review process and provide security recommendations and better practices regarding secure software development.
Provided recommendations to protect the business against industry known threa
Interacted with IT and vendor auditors, both internal and external, including coordination of interviews and walkthroughs and outlining key risks and controls. Understands risk impact and likelihood to business goals and objectives.
I could guarantee the accuracy and timely completion of audit tasks within established guidelines
Performed general control oversight and reviews to verify compliance with McAfee, Qualys and PCI.
Developed a working relationship and Coordinated with IT departments and financial, operations
I was instrumental in remediating issues found from the compliance reports.
Followed compliance procedures and Best Practices for internal operational risk Assessments and controls in accordance with the national standards, requirements, and policies.
Made recommendations after the review of systems to assess the adequacy of management controls, efficiency, and compliance with policies, regulations.
Constantly monitored performance of assets and performed risk assessments
Ran Queries and Reports Daily and emailed to management in regards to the progress of the remediation of issues found as a result of the compliance scan
FEMA May 2005-June 2010
System Administrator
FEMA Site-Admin for a 3000+ Multi-Security Enclave customer base Domain\Experience in managing, updating, and deploying antivirus updates and software
Initiated Intrusion Detection System/Intrusion Prevention System device administration for malware detection
Deployed Endpoint Encryption to manage machines; Responded to malware threat events
Constant Monitoring of server/storage related processes and performance insured server uptime
Analyzed and resolved faults, such as major system crashes; Initiated distributed patches using Servers
Schedule reports, extract data, review for errors/incidents and troubleshoot to resolve
Used an Intrusion Detection System to help track and provide advice on critical emerging threats
Performed Patch auditing with Policy Auditor
Initiated Systems Support which included vulnerability scanning and monitoring by using
Performed Malware Analysis in response to alerts
Installing, supporting and maintaining new server hardware and software infrastructure
Analyzing and resolving of faults, ranging from a major system crash to a forgotten password
Undertaking routine preventative measures and implementing, maintaining and monitoring of systems
Monitoring of server/storage related processes and performance to insure server updates
Education and Certifications
ITT Technical Institute: BA– Cyber Security
NJIT: Cyber Security (BootCamp)
Certification: Security + CISSP