Robin LoCasale
Downingtown, Pennsylvania
Professional Highlights
IT Risk leader with a proven track record of delivering positive results for financial services organizations through strong project management and risk reduction strategies. Innovative thinker with more than 17 years of expertise in managing and motivating individuals and groups in IT Risk and Technology. Self-motivated and driven Program Leader resulting in successful execution of enterprise-wide initiatives impacting multiple Lines of Business. Professional Experience
Mass Mutual, Downingtown, PA July 2021 – Current
Director, Identity and Access Management
● Manage multiple employees, contractors and consultants covering IAM Governance, IAM Core Operation Services, IAM Engineering and IAM Strategy
● Portfolio Owner for the IAM Program – provide a monthly status update on progress of multiple initiatives underway as well as OKRs and additional metrics
● Work with the business to improve processes to make it more end user friendly when trying to on-board a new employee or to obtain new access for current employees
● Work with multiple business partners and other teams within Cyber to redesign the definition of “birthright access” and removed access from thousands of employees that did not require that access as part of their job functions so we stay in line with our standard of least privileged access
● Attend daily audit meetings to review open audit items as we continue to reduce risk across the program by fulfilling audit findings and implementing new tools and processes
● Management of multiple projects and build outs:
o Implementation of building a Data Warehouse
o Passwordless login
o nFront Password Filter
o Privileged Access improvements (interactive log on and onboarding service accounts)
o Clean-up of AD environment
o Upgrade to our IGA tool
o Work with the Data Science team to build out internal processes to reduce our dependencies on our IGA tool o Reduce the number of certifications that are sent out on a monthly basis for access reviews
o Design a permit to build to operate for new applications moving into production
o Management of our decentralized application program o Monthly meetings to discuss budget oversight and management to reduce spending across IAM
TIAA, Downingtown, PA June 2015 – July 2021
Senior Lead Info Sec Manager, Identity and Access Management
● Managed a team of 44 employees covering IAM Governance, IAM Core Operation Services and IAM Credential Management
● Reviewed and adjusted existing IAM processes (joiner, leaver, mover, certifications, etc.) to ensure they are aligned with industry best standards
● Lead on Bank acquisition into TIAA processes and platforms
● Assisted in strategic design of WorkDay integration with life cycle management processes
● Designed a decentralized IAM governance program to ensure compliance to security standards for application portfolio
● Lead a monthly access management working group stakeholder meeting to drive policy and control improvements across the enterprise to drive culture changes from a security standpoint
● Implemented process and controls of separating privileged access from a user’s primary account and secondary account (elevated and highly privileged) and vaulted in CyberArk
● Phase two of Privileged Access Model build out:
o Governance and Oversight of privileged controls
o Privileged Access Provisioning and Entitlement Reviews o Password Management and Monitoring
o Affiliate Integration and Governance
● Reduced by 60% the number of users that had Elevate on Demand Access (EOD)/Privileged Access
● Partner with Internal and External Auditors to drive and improve efficiencies for the overall Identity and Access Management Program
● Assisted multiple teams within Cybersecurity to streamline their operational processes, and defining new metrics and dashboards to allow future analysis of these processes to be measured Senior Information Security Analyst and Operations Lead
● Partner with the Business Information Security Officers to enhance the End User Exception Program to implement a more standardized request process and ensure proper controls were in place to review a user’s access bi-annually
● Assist in improving overall functional performances and processes by automating manual processes, reducing errors to continuously improve performance across Cybersecurity
● Participate in the development of new strategies to enhance the overall Identity and Access Management program
● Created an application in our RSA Archer tool to allow application owners to have a “one stop shop” for onboarding their application into multiple tools in our IAM program
● Create daily, weekly, and monthly metrics/reports via the Data Warehouse to improve the overall mechanism of
Operational Reporting and our Executive Reporting needs for the IAM program
● Drive continuous improvement to access management processes and improvements – full lifecycle management and ensuring all account management tasks are conforming to compliance.
● Participated in multiple Rapid Improvement Events (RIE’s) to identify processes that needed matured, automated or revamped to provide a better service to the business
BNY Mellon, Pittsburgh, PA June 2011 – June 2015
Privileged Access-Top Ten IT Risk Projects
● Managed the strategic initiative to reduce 60% of the privileged and elevated access to reduce IT risk
● Partnered with Senior Risk Officers within the Lines of Business to implement an optimal risk to cost objective
● Performed re-certification of all 33,000 users with local PC administrative rights
● Designed detailed metrics-based dashboards for senior management and regulatory status reporting
● Developed approved use cases that would require an end user to have elevated privileges and delivered alternative solutions for users with remaining use cases to align with information security standards
● Implemented an innovative entitlements program for the user rights environment and a certification process using the enterprise standard tool, SailPoint, and successfully institutionalized the program across the organization
External Remote Access-Top Ten IT Risk Projects
● Responsible for the coordination and management of multiple related projects directed toward strategic business and other organizational objectives around Remote Desktop Solutions
● Built credibility and rapport with stakeholders at multiple levels, including those external to the organization
● Designed and presented dashboard reports on current programs
● Partnered with Information Risk Management to reduce the risk and standardize a consistent technological methodology for remote access Access/Risk Management – Adoption Program
● Responsible for project planning and managing a full lifecycle of onboarding high risk applications into SailPoint
● Managed the High Risk Application Entitlements conversion program from initial requirements gathering to production implementation and business as usual processing
● Partnered with Business aligned Information Risk Officers to identify common requirements for the new access request platform
● Participated in working sessions for the new Enterprise Access Management Program to help develop the strategy which focuses on simplification and standardization across the Identity and Access Management Lifecycle
● Involved in the development of business requirement documents to onboard the top five databases into SailPoint
ITT Transformation Project
● Managed global build for Altiris infrastructure for Win 7 Deployments on extremely tight project timeframes
● Partnered with IT and business Project Managers across multiple work streams ensuring overall project financial and delivery success
● Lead working committees along different lines of businesses to manage successful Win 7 Deployment
● Responsible for the development of complex project plans United Lender Services, Pittsburgh, PA May 2009 - December 2011 VP, Appraisal Management
● Managed input, preparation and coordination of strategic business updates for President/CEO and Board of Director meetings
● Led the creation of an Appraisal Operations Division for a privately owned company, resulting in the generation of $4MM in new revenue for the firm in the first year of business.
● Implemented new technology systems to support the operations of a new Appraisal Management Company
● Hired, trained and managed team of 20+ Customer Service/ Quality Control representatives, adhering to quality and service metrics National Real Estate IS, Pittsburgh, PA May 2003 – May 2009 Department Manager
● Played an integral role in solidifying a partnership with HSBC to manage 100% of their valuation business
● Created a team of 150 employees providing more than 40,000 appraisals per month
● Consistently generated new revenue of $500k per year by aggressively managing appraiser and agent fees and developing new revenue streams
● Recognized need for enhanced employee education to improve delivery margin; developed program for continuous education and improvement
● Partnered with IT Director to reduce internal cycle times and increase productivity with development of innovative features Education
Indiana University of Pennsylvania, Indiana, PA 1997-2002 Skills/Program Experience
● Solid organizational skills including attention to details and multi-tasking
● Strong team player with proven collaboration skills
● Strong communication at all levels of the organization
● Self- motivated, responsible and a passion for excellence and operationalizing new tools and processes
● Excellent organization skills and resourceful to adapt to a constantly changing environment
● Knowledge of associated technologies: Microsoft Office Suite, SailPoint IdentityIQ, Active Directory, RACF, Mainframe, ServiceNow, CyberArk Enterprise Password Vault, Okta, NFront, Accepto