** ***** ** *********** (Startup-Tier* & Government) Technical & Management experience in the following areas:
IT Architecture & SW Development EDI & Cloud Computing DC / Facilities Development & Management
Employee On-boarding Sr. IT Security & Network Engineering Enterprise Capacity & Storage Management
DR/Continuity & Contingency IT Call Center & Support Domestic & International Experience
Enterprise Asset Management Helpdesk, Call Center & On-boarding Document Control & Classification
Large MIS & IT Operations High-Availability Monitoring Services E-commerce & Business Development
Staff & Cost Management Relationship building & Service Delivery GRC (Governance, Risk & Compliance)
PM & Strategic Leadership Team Building & Diversity Leadership Government Cleared Classified -Top Secret
• Staff management (Local & Remote), training, development, evaluation and Staff Augmentation/Outsourcing.
• Information System Security and Business Continuity experience, VPN/Remote Access, Installation, Encryption, Virus detection/prevention, Network (Firewall, Switches, Routers) Sr. Architecture/Staging & Installation/Configuration/Contingency, Disaster Recover & Planning, Incident Response & Risk Assessment.
• GRC/Compliance experience with SOX, HIPAA, GLBA, COBIT, FFIEC, PCI, FDA, COSO, FISMA, CA SB1386, EU, ISO 270**-*****: polices, procedures and technical controls.
• Unix/Linux Administration, Application Development & Integration.
• Cloud Computing and developing consumer-facing mobile apps utilizing N-tier.
• Operational computing, GRC Audit, Automation and Implementation.
• Hands-on Level 3 Core Network Administration, Architecture, VPN/Remote Access, Installation, Encryption, Virus detection/prevention, Network Metrics, Net Backups, Production Quality Assurance, IDS, Proactive Network 24/7 Real Time Monitoring and LAN/WAN management across all business enterprise verticals.
• Cross Platform ERP, Endpoint Protection Platforms, Network, Infrastructure, distributed computing, Tier 1-3 Security Mitigation Planning, Tools Implementation & Monitoring, Helpdesk Enterprise Data Center Operations experience and Software Development Quality Assurance and Release Management.
• Full Life-Cycle Management & Production Scheduling, Vendor Service Level Agreement (SLAs), IT to IT Operational Level Agreement (OLAs), IT As A Service (ITAAS) and Strategic Business Partner Management.
• Standards Development and Compliance Analysis expertise as well as physical Data Center Security and Infrastructure management.
• Cleared Government customer client Security Awareness, Incident Management & Planning, Application Development & Management, Data Center Stand up, Managed Services & Business Development, Operations & Automation (NRO, DOD, DMA, ICE, FBI, DHHS, NIH, NSA, CIA, DOE)
PROFESSIONAL EXPERIENCE:
Consulting 04/2014 - Present 2017
Soal Tech Consulting - Austin Tx, Independent Sr. Technical, GRC Expert, Analyst, IT Security, Operations & Management Consultant:
The Judge Group - Air Liquiid, Houston Tx, Independent Sr. Technical, GRC Expert, Operations & Management Consultant:
Atlantic Systems Group- Sr. Eng & GRC Analyst/Consultant:
Hewlett Packard - Sr. GRC & IT Security Consultant :
DELPI - Sr. NW Eng & IT Sec Consultant:
DADS/HHSC State of Texas Sr. Specialist ( Sr. Architecture, NW Eng, Sec Eng, GRC Analyst, Consultant:
Xelorgat LLC CEO – Austin TX Currently
IT Services & IP Development
Lead the design for the overall Virtual Private Cloud VPC environment including server instance, storage instances, subnets, network access controls, security groups, availability zones, etc
Lead the effort to design the AWS network architecture including VPN connectivity between regions and colocations
Ability to design and deploy AWS AMIs and build machine templates using various infrastructure as code tools.
Lead the design, implementation, testing, documenting of infrastructure technologies with varying degrees of hands-on execution tasks
Knowledge of designing the HA / DR strategies across various AWS services
Familiar with AWS Simple Calculator for estimating costs and factors that impact cost control factors
Lead Forensics, Vulnerability Management, remediation and Contingency.
Cloud monitoring implementation and strategy (Solarwinds nagios, splunk, and elastic search)
Defines/develops roadmaps and plans to migrate current application infrastructure to AWS Cloud and reduce hardware footprints and devises cost-effective ways to support cloud-computing environments.
Strong technical understanding to be able to validate that an environment meets all security and compliance controls
Strategic Governance Advisory Group, Inc. – Houston TX
Sr. VP IT Operations & Technology Remote Services 12/2013 – 03/2014
SGAG is Focus on Governance, Risk and Compliance (GRC) programs and solution implementation for tier 1-3 business organizations or government agencies, with an emphasis on GRC Architecture strategy and planning, GRC product strategy and messaging, maturity assessments, ERP, program definition and oversight, risk management, remediation strategies, business development, GRC Automation & Data Workflow, Business Intelligence, Remotely managed or managed services and IT security.
SGAG’s suite is focus encompasses’ regulatory mandates, and compliance frameworks like: ITIL, FERC, NERC-CIP, Sarbanes Oxley, GLBA, BASEL, GLBA Healthcare IT (ICD), COSO, ISO-IEC, PCI-DSS, ACA (Obama care), HIPAA, COBIT, FISMA, NIST (800-Series 3&4, 30,37,53, 153;Etc), ISF, TIA-942, ISO 270**-******, DIACAP/DISTCAP, SCACA, 16085/17799/15026/31000, EU, CA SB1386, FIPS 199 & 200, OSHA, NOAA (Tsunami Warning Center) and others for vendor best of breed technologies and custom business computing solutions.
• Determined enterprise wide vision for Information Security issues, policies and standards
• Identified and communicated security protection goals and objectives with suitable measurement KPI’s to support the business security requirements
• Created and managed a Qualitative risk register conforming to all appropriate standards
• Ensured effective levels of data asset protection are in place and monitored including data loss / data leakage and Intrusion detection
• Initiated, facilitated and promoted activities to create information security awareness within the organization.
• Provided direct Information Security Training to the workforce and executive level QA of all GRC related products
• Monitored compliance with the organizations security policies and procedures among employees, contractors and other third parties for corrective action where necessary
• Monitored changes in legislation and accreditation standards to ensure HID compliance
• Worked alongside the ASSA ABLOY Global Information Security Council to ensure alignment and refinement of evolving risk postures
• Served as a executive level IT interface into all theBusiness accreditation requirements
• Provided leadership and management to the IT Security & Governance Team, and 3rd parties providing IT Security services
• Monitored and reviewed regulatory updates and issues relative to pertinent security regulations (which could include HIPAA, PCI, ISO, SOX, etc.).
• Supported Information Security Related audits (Internal Audits, PCI, notified body, etc.)
• Proactively engage with the broader Information Security community and proactively lead IT Security team to address technology shifts and threats on the industry horizon
• Mentor, develop, and grow next generation IT Security leadership
Insight Global-Verizon Business- Reston VA, (Ashburn VA, INC in NJ)
Sr. Consultant- Technical Architecture, Networking, Security, PM, Compliance & Testing 11/2012 - 11/2013
National Grid Project - Undertaking to upgrade all technology associated with management of the nations critical (power grid, water, energy, highways& bridges, communications) resources. This project was a collaborative effort involving our partners in the UK and South America.
HEALTH CARE IT CORP.- Rockville MD 09/2009 - 11/2011
Sr. Manager of MIS, IT GRC & Operations
• Director of Management Information Systems & Operations to Enterprise Network Engineering & Architecture Team, IT Hardware and Software Selection Group, ITaaS, Cloud Hosted Services, Operational Support Services Team, IT & Facilities Physical Security Group, and IT Privacy & Policy Team
• Responsibility for direct management and coaching of all corporate IT Staff resources
• Led projects and provided hands-on programming expertise to automate the exchange of product content information between vendors and suppliers in a real-time, secure environment. Leveraged existing business logic used for exchanging data between business storage and other applications Developed system using Java, JPS, Servlet, web services, XML, MS SQL Server Database, RMI, and Websphere Application Server.
• Designed and developed the security architecture using .net Cryptography namespace ensuring PHI, 800-53, HIPAA and SOX compliance of sensitive data reusable in all inter/ intra/ desktop and mobile applications.
• Managing approval of all reports and updates of systems status to customers and C-level staff: CTO/CEO/CFO/CSO.
• Budget and financial planning/forecasting for Data Center and network infrastructure purchases and operations.
• Developed escalation procedures to ensure reliable operations and response to incidents. Delivers improvements and changes as necessary to repair recurring issues and proactively identify and prevent other issues affecting the site operation or customer experience.
• Architecting and hands on implementation of Cisco Pix, ASA Firewalls, Snort, Big IP, Cisco, Juniper, Dell, D-link and other core cross platform technologies used secure or insure the data confidentiality, integrity and availability of customer networks.
• Responsible for Briefing the Network Operations CTO on Development plans for necessary upgrades and reengineering of the network architecture and Server Systems.
• Data Center budgeting for purchases, and migration of our Lexington Data Center operations to our Rockville Data Center.
• Developed custom applications, analytics, schemas, query content, hardware selection and metadata collaboration for National Cancer Institute (NCI) first-ever large scale online cohort research effort.
• Provided analysis, communication, liaison, and environment support for data conversions for strategic partners like IBM Corp.
• Executed migration of the current enterprise servers to the new virtualized consolidated enterprise servers Department of Health & Human Services (HHS) and National Institute of Health (NIH).
• Designed and managed company principal Data Center Managed Hosting Facilities in MD, Mass and customer satellite hosting facilities (hosting, co-hosting & custom hosting) Services.
• Developed and successfully deployed the corporate C&A framework and processes to ensure customer, or strategic partner to regulatory alignment.
• Perform Certification and Accreditation (C&A) activities for Department of Homeland and Security (DHS), Department of Transportation (DOT), Department of Veterans Affairs (VA) using the NIST Risk Management Framework, ITIL Framework and HIPAA.
• Perform Certification and Accreditation (C&A) activities for nine major Department of Defense (DoD) applications and sites using the Department of Defense Information Technology Certification and Accreditation Process (DITSCAP).
• Review System Security Authorization Agreements (SSAA) and System Security Plans (SSP), document vulnerabilities, document accreditation recommendation to the Certification Authority (CA) for final review/approval.
ICS (INTEGRATED COMMUNICATION SOLUTIONS)- Fredrick MD 02/2009 - 07/2009
Sr. MANAGER OF DATA CENTER OPERATIONS & PROJECT MANAGER
• Manager of National Data Centers serving as manager of direct reports concerning Enterprise Network, IT Security, Policy & Privacy), Manager of Physical Security/Guard Staff contractor services, Sr. Facilities Manager, Sr. Helpdesk Services & Call Center Manager
• Sr. Advisor on Executive Advisory Board Member for Business Development Services (ITaaS) as Technical Principal
• Network Operations Center Management to include: 24x7x365 NSOC operations, Remote Network & Security Management, Network Monitoring, IDS management, Disaster Recovery, Contingency Planning, Application Hosting & Computer Security Incident Response Teams Principal business/technical Manager.
• Provided Sr. technical support, maintenance and administration of MS Exchange email software suite.
• Sr. Manager of Helpdesk, Call Center Services and Support (Call center, backup services, levels 1-3 support, Etc).
• Designed complex enterprise-scale solutions, integrated into larger network security architectures.
• Sr. Level project manager responsible for C&A, Product Evaluation of all COTS and GOTS, Testing, Security Assessment.
• Established documentation developed and executed COOP, Risk Assessment, and SSAA meeting NETWARCOM and NMCI directives.
• Designed, developed and implemented Business Continuity Plan consulting services that include COOP and Disaster Recovery services to Navy, DISA, DLA, and others.
• Provided Information Assurance, Security Engineering, Continuity of Operations design and management implementation for the USAF and other DoD – all in support of the BRAC and GWOT.
• Integrated server monitoring tools and scripts to minimize downtime and increase resource efficiencies.
• Provided, sustained and executed Active Directory Administration.
• Performed network vulnerability assessments using tools on Unix/Linux and windows based systems.
• Analyzed, designed and developed network security policies and plans for various high profile DOD Agency networks.
• Assessed emerging security technologies, clarifying the pros and cons for clients.
• Lead Remedy IT Application development, testing, training & support team in enhancement, maintenance, & upgrade of latest versions of BMC Remedy & Atrium Solutions.
BRABEION SOFTWARE CORP.- Reston VA, 2005 - 2009
Senior GRC Policy Controls Manager & Technical Controls Analyst/Creato5
• Management of regulatory mapping of standards to regulatory policies, procedures and technical controls
• Sr. Analyst for strategic partner content development & Compliance Testing controls (Atlantic Systems Group and PWC.)
• Sr. POC, Compliance Analyst & Technical Engineer for technology partners (MS, SAP, Oracle, ASG, Cisco, Juniper, Nokia) technical control development and technical control alignment.
• Sr. POC, Compliance Analyst & Technical Engineer for customer services and collaboration for Chevron, American Airlines, Coke, Burlington Northern.
• Responsible for researching evolving holistic enterprise technologies for compliance dashboard suite selection and associated risk, policy or configuration/procedure.
• Development and management of content product quality assessment and release distribution
• Responsible for management of vendor/ strategic partner SLA’s, associated product alignment agreement oversight and RFP principal contributor.
• Management of regulatory mapping of standards to regulatory policies, procedures and technical controls
• Designed managed Software Configuration Management (SCM) release structure and SCM operational services.
• Customer/Post Sales services, end user product training, policy/content gap analysis and development of post implementation strategies.
• Authored all of Company automated IGRC product tools dashboard (Industry watchdog Gartner rated best of breed) Policy, Procedure and Technical controls content.
• Co-development of multi vendor platform queries for integration into automated compliance assessment dashboard with the Sr. Engineering team.
AMERICAN AIRLINES- Ft Worth Texas 2002 – 2004
Network Security Management
• Security Management of 30,000-workstation upgrade project - replacing systems that average 12 years old to new Intel based windows XP systems.
• Established corporate Policy, Procedure and controls for partner transactions concerning worlds largest credit card clearing house.
• Oversight and development of security awareness programs, and security custom compliance and security audit dashboard.
• Global enterprise management and administration of corporate enterprise email security, web availability and integrity.
• Sr. Member of Threat/Patch management program - team responsible for patch management assessment and deployment.
• Developed security strategy for corporate policy, procedure, technical controls assessment and risk matrix.
• Responsible for Network security testing, client/server hardening, diagnostic or forensics review of cross platform systems.
• Responsible for firewall architecture, web server security, VPN and application configuration engineering teams.
• Responsible for remote (Authentication hardware and account oversight) and local Access and Identity Management, edge computing technology platform evaluation and selection.
• Responsible for Sr. administrative enterprise Security processes (Security Awareness Training, Documentation updates, Annual Audits, IG Investigative support) .
• Ecommerce security (PKI, EDI), Intrusion Detection, Cyber Crime Incident Response and Forensics.
• Created Steering Committee and Incident Response Team consisting of corporate communications, privacy, IT security, finance, HR-health, corporate security, General Council and other Sr. Executive staff.
• Sr. Principal and POC for IT oversight of outsourced services for (Flight Reservation Systems, Weights & Balances).
• Sr. Principal and POC for enterprise computing with principal vendors (EDS, PWC, Saber, UUNET) at AA Corp, Airline Hub, Tech Com, EDS-Tulsa.
• Established and Sponsored 1st annual Aviation Industry collaborative conference on industry security, privacy and compliance post 911.
• Establishes and administered process for receiving, documenting, tracking, investigating, and taking action on all complaints concerning the organization's privacy policies and procedures in coordination and collaboration with legal counsel.
• Served as CEO and Sr. Vice President of corporate employee diversity (AAERG) principal sponsor AA COO and Board Member Founder Earl Graves.
• Instituted Employee diversity culture building program in collaboration with Dallas Dinner Table Foundation.
• Represented American Airlines as fundraising spokesman for National Sickle Cell and Future Aviators.
Additional Prior Work History 1988 -2002:
Nokia - Sr. IT Security & Network Manager
Airband Wireless - Principal founder (Dedicated Wireless network founded in 1998 Dallas Texas)
INS (International Network Services) AVAYA/Lucent/Network Care- Sr. Security & Network Engineer Consultant
E-Systems/Raytheon - Sr. Systems Admin & Network Manager (Top Sec Clearance with reoccurring Full Lifestyle Polygraph)
Texas Instruments – Sr. Computer Operator (Sec/Top Clearance)
EDUCATION:
• Grambling State University
• Dallas County Community College
CERTIFICATIONS & TRAINING:
Governance Risk Compliance (GRC):
ITIL, GLBA, ISF, FISMA 800-53, SOX, NIST(800-53,rev3&4, SP 800-39), PCI, HIPAA, NERC/FERC, TIA-942, DIACAP/DISTCAP, SCACA, ISO-IEC 16085/17799/15026/31000, COBIT, COSO, EU Directives, CA SB 1386,FIPS 199 & 200, OSHA Work Environment Standards and others.
Government Agencies-Clearances Held (TOP Secret Full Lifestyle Polly, Secret, Classified):
FBI, CIA, DOD, NRO, JDFPG, DOE, NSA, NIH, DMA, ICE, COST GUARD
Some Technology Proficiencies (Not all inclusive):
Lotus Notes, Nokia Enterprise Suite, F5, RACF, Raptor FW, SAP, PeopleSoft, Dell Laptop and Enterprise Tech, IP Multicasting, Avaya/Lucent-Frame/Voice, 4xFiber or Copper, Alteon, PKI/EDI, VoIP, Oracle xxG, Blackberry Enterprise Server Suit, SharePoint, SQL, RSA Suite, MSS Connection Kit, Source Fire IPS/Management/Firesight, ISS Safe Suite, VM Ware, DB2, Juniper SSG, Cisco Enterprise-Router/Switch/Hub & Firewall, I Planet Web, Windows Suite, Remedy, PeopleSoft, JBOSS, INS Helpdesk Metrics & Knowledge Base Suite, CheckPoint Firewall, MS-Exchange Server, Sugar SCM, Vital Suite, Solaris, NT Security, Novel Administration, UUNET, Saber Suite, INS Knowledge Tree, BEA Weblogic 9.X, Sun Java Web Server, Mac OS X Server, Windows,Tomcat, SharePoint Server, LDAP, IBM Mainframe, Cray, OS 390/400,Citrix, Network Protocols (MPLS, BGP, ATM, OTN, CDMA Data, S/FTP, API’s, OMP, OSPF, VRRP, XML, SSLT, REST, WSDL, Message Ques ;Etc.)
Other Training & Certification:
CCSA/CCSE/CCNA/CCNP, Project Management, NISPOM Defense Security Service (annually), Advanced Relational Databases, Trend Enterprise Suite, Management, Technical Writing, INS Professional Consulting, Advanced Unix Host Security, Franklin Covey Time Management & Principles of Leadership, Computer Security, Ethical Hacking & Networking Essentials, Six Sigma Methodologies (Brown Belt-Executive Level Sponsor), VPN Architectures & Configuration Management, Wireless Hacking (U.S Secret Service), CISSP trained not yet Certified (Set as Sr. advisor to SW regional Steering Committee in Las Colinas Texas two years), Technology Instructor School, TQM Management, Maintenance of PC's & Compatibles, Software Engineering Principles, Discreet Mathematics, Advance Operating Systems Fundamentals, C programming, ADA Programming, Advanced Data Structures, FORTRAN Programming, Human Resources Essentials, TQM Fundamentals, Understanding TCP/IP, WAN Architecting, Employee Supervision & Leadership, AIS Risk Management & Security Concepts, Introduction to Word Processing, Advanced Word Processing, Global Satellite & Communications(Joint Defense Facility at Pine Gap), IT Lucent/AVAYA Networking Principles, Security & Emergency Destruction, Physical Security Management, Circuit Protection, Customer Service, Served as CEO of 123,000 Diversity Employee Resource Group American Airlines