ROBERT L. HICKS SR.
SENIOR CYBER SECURITY ENGINEER
Professional Summary
• High performing Senior Cyber Security Engineer with diverse professional experience ranging from medium information assurance team supervision to enterprise class, Department of Defense level infrastructure man- agement. Having 23 years, seven months of honorable active-duty military service, of which 15 plus years were spent developing and honing experience in the U.S. Army’s Military Intelligence and Electronic War- fare/Cyber Corps. A proven record of creating, leading and developing effective functional teams at all lev- els of the enterprise. Strong analytical, diagnostics and troubleshooting skills - ability to solve complex problems at scale.
• Since my retirement from the United States Military, I have performed at increasingly higher levels of re- sponsibility with extensive scope of accountability. Proven track record of delivering optimal results in high-stress environments that have yielded measurable, successful outcomes: Professional Certifications/Training Certified Information Systems Security Professional (CISSP) Review Course, Functional (Security +), Infrastructure Library (ITIL), Information Security Officer Certification (ISOC), Information Technology SharePoint Content Managers Course, Network Manager Security (NMS), ZenGRC Administrator Certification, Rapid7 Scanner Certified Administrator, Microsoft Azure (AZ-900), Microsoft (SC-500) Civilian Education Saint Martin’s University Lacey, WA 2018-2020
Computer Science – 52 Hours
Electrical Engineering – 48 Hours
University of Maryland Adelphi, Maryland 2014-2016 Cybersecurity Management and Policy - 50
Computer Science
Military Education Information Security Officers Certification Course Ft Gordon, GA Cyberspace Operations Integration Course (COIC) Fort Belvoir, VA Critical, Analytical and Divergent Thinking Course JBLM, WA Defense Cyber Investigation Training Academy (DCITA) Linthicum, MD Tactical Information Operations Course Fort Sill, OK Information Operations Capabilities, Application and Planning Course Fort Belvoir, VA Electronic Warfare Integration Course Fort Belvoir, VA Military Intelligence Collection Managers Course DIA, VA Functional Skills
• High Level Emotional
Intelligence
• Executive Presence
• Critical Thinking
• Excellent Interpersonal Skills
• Strong Communication Skills
(written and verbal)
Cyber Security
• SOC 2 Compliance
• SOAR Administration
• Vulnerability Management
• Extended Detection and Response
• MS 365 Defender
• SAST and DAST Analysis
• NIST Control Integration
Executive Management
• CI/CD pipeline security
administration
• AppSec Dev
• SIEM Administration
• Battalion Information Assurance
Security Officer
• AWS and Azure Cloud Scanning
************@*****.***
www.linkedin.com/in/robertlhicks
Professional Experience Senior Group Manager, Cyber Security
Avanade, Seattle, WA
Responsible for large scale technology implementations and transformations in North America, India and the European Union. I serve as the senior security and technical IT advisor to large clients navigating complex technical issues: i.e. Cloud Migration, Data Breaches <$7,000,000, and mergers/acquisitions. Expertise in delivering and leading Information Security programs including IT Security Strategy, Security Or- chestration, Automation, and Response - SOAR, Security Training and Awareness, NIST Controls Compliance
& Audit Management, IT Forensics, Identity and Access Management, GDPR, CI/CD Pipeline, and Data Privacy
& IT Risk analysis.
• Cloud Migration Team Lead – Project Value $5,210,000. o Supervised Cloud Architect Team for large international client. o Successfully provided migration strategy from on-premises/hybrid to full Azure Cloud environment. o Maintained security integration and full project delivery within budget and on-time.
• Senior Discovery Team Lead – Project Value $70,000,000. o Supervised Cloud Architect Team, Security Team, and for large US based client undergoing separation from parent company.
o Responsible for identifying dataspace ownership, key stake holders, roles and responsibilities and landing space architecture.
Senior Security Engineer
iSpot TV, Bellevue, WA Feb 2021 to Feb 2022
Responsible for maintaining a high-level enterprise cybersecurity posture across a multi-state, hybrid architecture. Work directly subordinate the CISO, and adjacent to engineering team leads to establish, monitor, access and improve the security posture of the organization.
• SOC2 Compliance
o Managed corporate SOC2 compliance program. Developed 10 risk control programs for recent company acquisition.
o Maintained accountability for artifacts and delivery to external auditing agency. o helped design, develop and deliver security and compliance objectives and have the ability to help drive product security phase of the CI/CD pipeline.
• Vulnerability Management
o Responsible for managing the Rapid7 InsightVM and Carbon Black AV vulnerability management systems. Reduced active vulnerability count by 60% by 2nd quarter 2021. Streamlined threat miti- gation process.
o Coordinates with engineering, DEVOPS and TECHOPS teams to proactively assess risk, fix securi- ty issues and provide policy guidance.
o Ensured SAST and DAST availability to ensure the CI/CD pipeline was not interrupted by latent malware threats.
• SIEM Management
o Implemented and managed InsightIDR SIEM
o Managed and deployed 25 event sources throughout the AWS and on premises.
• CCPA and GDPR
o Manage CCPA and GDPR compliance programs. Successfully created companywide system for tracking and ensuring compliance with all state and federal regulations. Senior Security Engineer
Ziply Fiber, Everett, WA Feb 2020 to Feb 2021
Responsible for developing, implementing and maintaining the enterprise-wide cybersecurity, physical security and work-from-home information security framework. Worked directly with the Security Director, CTO, and senior technical team leads to establish and maintain the security posture of the organization.
• Conduct network/host penetration tests and web application penetration tests.
• Maintain and performed assessments of security awareness training using social engineering and internal phishing attack campaigns.
• Maintained KnowBe4 security awareness program.
• Conducted datacenter, web applications and network security audits for security vulnerabilities.
• Maintained Carbon Black endpoint security and threat intelligence platform and Exabeam SIEM. Senior Security Engineer
CED Systems, LLC, University Place, WA 2018 to 2020 Directed the design, integration and implementation of information security systems, maintenance plans, and best practices for securing client’s systems, networks and enterprise architecture. Led the Information Vulnera- bility Management (IVM) process at CED Systems, LLC to ensure compliance and increase our network's secu- rity posture. Responsibilities included: Network Scanning and threat identification and classification.
• Supervised a SecOps team composed of 6 level II Security Engineers, 4 security analysts, 3 software engi- neers, 2 electrical engineers, 10 computer science interns, and 8 interdisciplinary professionals.
• Performed application penetration tests and security scans against client networks.
• Guided clients and engineering team in understanding and navigating information security threat landscape
(attack vectors and tools, best practices for securing systems and networks, etc.
• Reported to and communicated directly with senior level managers, technical and engineering officers, and corporate officials regarding controversial and/or sensitive issues such as the scope and impact of a data breach, mitigation and remediation procedures and root cause analysis to identify the source(s) of the attack.
• Assisted clients in implementing and maintaining NIST 800-53 compliance. Senior Security Engineer (Offensive) United States Army United States Army Oct, 1993 to May, 2018
Supervised 50 to 60 highly talented military professionals in skillsets ranging from cyber security analysts to level II cyber security engineers, to white hat penetration testers. Responsible for overseeing and conducting vulnerability scanning, malware analysis, threat modeling, and accurate identification of system and network vulnerabilities. Vulnerability assessment tools included Nessus and Metasploit.
• Maintained an operating budget of $350,000 and $3,500,000 in hardware and software.
• Managed team functions and missions in accordance with higher command directives while operating within stick national intelligence parameters.
• Developed first cyber security curriculum and operating policy for the JBLM, WA cyber team, managed team resources while operating within stick national intelligence scope and parameters, mitigated “budget creep”, communicated project – mission status to higher command element, successfully completed three real-world and 1 simulated cyber mission.
• Trained over 200 staff officers, senior enlisted advisors, and Department of Defense professionals in the appropriate prevention, detection, mitigation and remediation of Department-of-Defense-Information- Network (DoDIN) data breaches and information security vulnerabilities.
• Performed forensic analysis of malware infected devices to identify threat origin, scope and level of hardening required to mitigate future breaches.