Post Job Free
Sign in

Senior Compliancy-IT Auditor

Location:
Chicago, IL, 60091
Salary:
100,000
Posted:
July 22, 2009

Contact this candidate

Resume:

Experience

Tek Systems

Contractor

Allstate Insurance

Security Governance

Compliance Project Manager

August 2006- Present

www.allstate.com

• Perform project management and area audit responsibilities for Security & Privacy Governance on multiple projects primarily for SOX, PCI DSS, HIPAA and ISO9000 compliancy as well as remediation of software and hardware security/vulnerability issues, and Six Sigma. Total projects managed: 15

• Manage projects through Portfolio Management Tools (PMT) including identifying and allocating hours for resources in project phases, completing detailed expense budget documents, and Request for Proposals.

• Manage and facilitate the use of SOX DS 5.3, 5.5 and 5.7 (COBIT Controls) security compliancy throughout Allstate. Audit controls and solutions once implemented for asrea validation; work with Internal Audit to conduct audit tests and post results. Remediate weaknesses and current gaps based on compliancy.

• Provide risk assessment on current security environment with Allstate. Prioritize vulnerability rankings; request for remediation and/or controls that can be classified as compliant. Tier breakdown of issues and gaps based on lack of controls.

• Manage and facilitate PCI DSS which includes but is not limited to: Restrict Physical Access to cardholder data; Install and maintain a FW configuration to protect cardholder data; Protect stored cardholder data; Encrypt transmission of cardholder data across open, public networks; Use and regularly update anti-virus software; Develop and maintain secure systems and applications; Maintain a policy that addresses information security; Regularly test security systems and processes (pertains to SSL 2.0/encryption and encryption of data at rest for proof of concept is complete

• Facilitate the creation of security solutions, policies and procedures for all compliancy Infrastructure processes that require testing and implementation.

• Write business cases for cross-area involvement, power point presentations for executive management, charters for project plans, facilitate SDLC through MS project

• Maintain managerial and technical responsibility for all assigned projects

• Serve as a primary liaison between Security Architecture, client stakeholders, user groups, and the project team developing the solution

• Identify and analyze vendor tools, define project scope, requirements, and deliverables

• Coordinate resources, project schedules, and communications for internal and external projects

• Facilitate, manage and delegate action items and milestones with one or more of the following areas in each project: Oracle, SQL, SAP, Mainframe, AS/400 Windows and UNIX infrastructure

• Conduct quantitative/analytical and qualitative research on technology (IT) segmentation

• Manage project activities and ensuring all project phases are documented appropriately

• Facilitate organizational change while providing expertise on technical, functional and business topics during the design, development and /or implementation of projects

High-Level Projects Overview

• SOX and PCI DSS compliancy for UNIX, AS/400, SQL, Oracle, Windows and Mainframe Platforms that host sensitive applications (28 months) - Completed Cobit Control DS 5.7 security monitoring for privileged users on the following platforms as a requirement for SOX compliancy. PCI DSS compliancy was addressed in addition for SQL & Oracle. Identified SOX servers, databases, help produce and manage pearl scripts to parse security events and filtered events activities through Arcsight SIM agent to Arcsight central repository. Created and operated Arcsight process to monitor red flags and provide automated email alert to managers and/or supervisors of users who executed functions. Identified, evaluated and created test environments for vendor tools to run monitoring for SQL and Oracle databases. Allocated hours for resources, submitted status updates, presentations and handled budget for Governance on DS 5.7 hard and soft expenses. Created and set privacy and security policies for administrator privileges to sensitive databases and SANs. Facilitated involvement with IS to create test environment for both development and production areas. Created privacy policies for files and databases that had restricted access from user as well as set global security settings on platform access via LAN and remote VPN. Monitored applications via monitoring tools (agents) implemented in development and/or production environments: Charles River; IBM Tivoli Monitoring; CA eAccess Control, Guardium DBMS, TripWire.

• VISA/PCI Implementation Control of Terminal Encryption (12 months) - Project managed the full life cycle of a security architecture project in order to the implement Terminal Encryption methodology with controls to maintain compliancy for all application files and directories that retain credit card data on all operating platforms (Windows, UNIX, AS/400, Mainframe, DB2/IMS, and SQL). Inherent risks were addressed for PCI DSS 1.1 compliancy.

o Phase I: Identified organizations, roles, entities and relationships that exist or should exist to perform a set of security processes.)

o Phase II: Security Architecture- Completed analysis on current architecture and whether it was supportive of Terminal Encryption methodology as well as detailed information on how processes will be executed and secured.

o Phase III: Security Design-Completed requirements for implementation of Terminal Encryption and business case scenario in terms of compliancy towards PCI DSS and overall impact on business performance. This included details on how security controls for Terminal encryption operated.

o Phase IV: Terminal Encryption Testing- Development on all operating platforms; identified inherent risks with countering mitigating controls and break down of performance and compliancy gap analysis;

o Phase V: Security Implementation to Production- Rollout in production—live controls, conduct post audit feedback. Project was necessary to meet internal control requirements as expressed by acquirer Payment Tech, as a part of the PCI DSS 1.1 compliance effort.

• Client Security Suite Evaluation (9 months) - Managed a project to enhance the security posture at Allstate endpoints. Improved technology and resource efficiencies through integrated manageability. Proactively re-worked anti-virus contracts for potential cost savings. Implemented a suite instead of individual products that save roughly $1,000,000 per year. Identified a solution which provided a Client Security Suite for Wintel workstations and servers. Created and set privacy policies for admin access to Firewall; set security global settings for user privileges to SharePoint and NetApp. Suite included: Antivirus (including email servers) SharePoint, and NetApp, Anti-spyware, Host Firewall, HIPS, and NAC

• Vontu Protect Deployment (4 months)- Project managed and executed the deployment of the Vontu Discover and Protect products in a manner effective to enhancing the Data Leak Prevention capabilities at Allstate. Executed an SDLC which allowed the product to initially be capable of performing scans for sensitive and/or critical information located on network shares which eventually was configured to scan for SQL databases. This also included: Server deployment and configuration; Credential acquisition; Testing plan development; Capacity planning; Operational policy development; and Scanning protocol development. Developed and executed a migration plan from development to production hat included test, communication strategy, conversion and support within the constraints of time and resources.

Morgan Stanley

Riverwoods, IL

Senior Security Compliancy Auditor

July 2005 – July 2006

www.morganstanley.com

• Delegated, managed and lead the Sarbanes-Oxley compliancy team for infrastructure and operational audits based on 404 and 304 standards.

• Managed a staff of 6 that included members of Business Technology to perform auditing tasks that request for compliancy measures on Security Architecture through PMI methodology in Change Management, Logical Security, Administrative and Policies & Standards measures.

• Reviewed policy standards on software use by users and administrators. Audited security policies against actual events to determine if policy was dynamic within the corporate environment.

• Conducted audits on Discover Financial Network Infrastructure. Review, investigate and record findings on application and utilities review. Recommend solutions to rectify lack of compliancy measures. Last 5 audits included: (1) Oracle Security Audit; (2) SQL DB 1 & 2 audits; (3) LDAP audit; (4) Firewalls Audit (Checkpoint and PIX); (5) VOIP IVR Audit.

• Assessed cost effectiveness with VOIP IVR and Dialer systems currently generating $1 million in customer payment billing.

• Audited database servers in Edinburgh, Paris and Munich offices against EU Data Protection Directives and 1995 EU privacy controls. This included: 3rd party discrepancies on access to sensitive data, controlled party access to data and cross border information from Europe to the United States or Safe Harbor Law; EU security and data integrity. Conducted comparative analysis with auditing between US federal and EU laws.

• Investigated privacy breaches by 3rd party companies against consumer personal information by tracking and monitoring Morgan Stanley databases and legitimate access to 3rd party companies

• Validated accountability controls through Pentana audit software for Paris and Edinburgh data processes that determine if sensitive customer data collected under EU privacy laws has ‘use and collective limitation’ thereby not infringing supplemental information, i.e. bank accounts, health and/or family information.

• Project managed SOX infrastructure goals for financial quarters. Monitor, budget and record work hours, billing, and progress on all financial infrastructure projects for 404 work-related orders and audits.

• Involved in JAD sessions with Application Development team and Infrastructure to:

a) Reviewed the main business processes, review the technical processes, tasks, user roles, input, and output.

b) Recognized specific technical areas of agreement or disagreement.

c) Divided team into smaller groups to study specific issues and assign group leaders with response reports at the end of case studies.

d) Budgeted $400,000 in audit technology inventory for 3rd and 4th fiscal quarters and implement Pentana software standardization in Morgan Stanley IT Infrastructure.

• Conducted individual audit reviews derived from risks and subprocesses, which include the identification of internal controls, an evaluation of adequacy of the internal controls, and audit tests of key controls.

• Create risk assessments and gap analysis for gap controls. Assess expected and actual controls. Implement COBIT methodology in audit findings and administer to COBIT audit standards for SOX.

Health Connections

Lisle, IL

Corporate Audit Project Manager

January 2004 – July 2005

• Directed the full system compliance life cycle of healthcare requirements gathering, analysis, design, development, testing, deployment, training and documentation for third party reimbursement applications at a private health care firm.

• Developed all corporate security and privacy policies for the company on admin access to infrastructure access via remote (VPN) as well as software restrictions. Built procedural steps through selection criteria process of billing systems.

• Audited operational procedures for all departments on $2.5 million Soft-Aid patient and McKesson Accelerated Secondary Billing applications as well as HIPAA and OSHA compliancy.

• Project managed the integration build of EPIC system for 3rd party clearing house billing system.

• Implemented Web EDI ANSI ASC x12 to process x12 documents (INS for series 270-278), patient health information and billing codes for desktops and VPN.

• Conducted risk assessments and gap analysis on customer service for both patient and billing services and provided solutions for more efficient and effective strategies to compensate for time management among all employees.

• Audited operational procedures for national support center staff based on OSHA and SOX compliancy (Sec.302 & 802).

• Audit operations for HIPAA compliancy. Write all privacy and security policies that comply with HIPAA standards and audit HR for compliancy standards and ISACA (404 & 409) compliancy with federal requirements.

• Established and audit Disaster Recovery Plan to formulate a coherent method of revitalizing data systems in cases of emergency.

• Developed corporate strategies that monitor the effectiveness of billing software and document procedures that comply with HIPAA and SOX (302 & 802).

• Implemented standardization of services and integration of infrastructure across company through plans and to support project requirements internally with the infrastructure.

University Healthsystem Consortium

Oakbrook, IL

IT Systems Analyst

December 2001 - December 2003

www.uhc.edu

• Lead role in managing all of client’s security issues and the creation of new security issues as they relate to UHC in accordance to HIPAA security regulations.

• Managed HIPAA online website for members and provide statistics on policy trends and new usage of medical benchmarking tools.

• Created own functional security requirements on all UHC information systems and Siebel Enterprise.

• Maintained and managed records of users with admin access on UNIX and Windows servers through Siebel 7

• Lead all planning, project, maintenance efforts relating to technical security services.

• Implement provision of information security requirements to TS development and infrastructure projects.

• Developed Disaster Recovery Recover Plan and investigate information security breaches; reported to FBI.

High-Level Projects Overview

• Deployment of IDS and IPS (9 months) - Project managed and team led the implementation and rollout of the Intrusion Detection and Prevention System. Currently working and budgeting process selection on $300,000 intrusion detection system expected to rollout September of 2003. Provided research on Symantec, Manhunt and Snort security. Facilitating integration of PIX firewalls and routers with detection and prevention system.

• Encryption Product Rollout (6 months) - Developed a full-life cycle project of encryption product rollout at UHC. Project managed entire operation; budgeted services and expenditures for encryption rollout; created test plans for alpha and beta designs of encryption product; deployed encryption product to over 350 UHC members. Handle all technical problems pertaining to troubleshooting with issues on encryption product.

• Policy Regulation (3 months) - Created all security policies that are compliant to HIPAA security regulations at UHC. Wrote over 40 policies that manage and monitor the access of PHI data electronically. Strategically rolled out seven HIPAA privacy policies that dealt with patient identifier data.

• Gap Analysis (3 months) - Conducted an internal audit on security architecture and network. Wrote risk assessment and gap analysis after audit was conducted by outsourcing firm. Managed and budgeted for new security hardware. Currently developing disaster recovery plan that would mirror PHI data on external network while maintaining HIPAA compliancy.

National Restaurant Association

Chicago, IL

Network Applications Analyst

October 1999 – November 2001

www.edfound.org

Web Responsibilities

• Administered, developed and maintained the corporate web environment for several websites and intranet site using site server and IIS 5.0

• Developed a customer-centric active server page directory that allows the portal to narrow searches and directly connect to products that are requested by users.

• Integrated dynamic e-commerce site with http://www.edfound.org/

• Created web management flow charts through MS Project 98 and Visio.

• Developed policies and security standards related to information security for all processing environments with specialization for the Internet.

• Migrated all websites to partner host site and setup Checkpoint Firewall for ftp migration of .asp files.

Administrative Responsibilities

• Handled all administrative and project plan project management initiatives on Alpha and Beta portal processes.

• Managed the development of a $225,000 e-commerce portal for company, fully integrated life cycle plan in Windows environment.

• Handled hosting specifications and provide information on web server requirements.

• Maintained the Instructor Resource Center, www.edfound.org with CGI database and Access.

• Reported survey files from log reports and generated log reports using Web Trends and Site Server Analysis Tool.

• Maintained sole authority on updating intranet, internet and government sites; conduct usability testing on site through HTML, JavaScript, Front Page 98 and Interdev.

• Created business documentation on Internet marketing strategies; manage IIS 4.0 console and operate Site Sever 3.0 Commerce edition

• Integrated and produced database reports using Access and SQL Server 6.5 on website

• Coordinated the development of new dynamic web pages to site, including marketing products and information to purchase, through implementation of C+ and Access applications to the site as well as JavaScript and ASP functions.

• Documented installment and publication of new content to the Internet site including help facilitate www.oag.com to hosting server; was part of the consulting team to determine the specs on the internet server as well as help approve RAID 1 database storage system.

Education

June 2003: M.A.Journalism: Michigan State University, E. Lansing, MI

Specialization: Web Development

May 1995: B.A. in International Relations, University of Wisconsin, Madison, WI

Minors: Economics & Journalism

Certifications

Summer 2009: Six Sigma (Green Belt) Certification, Expert Training

Spring 2002: HIPAA Certification, Health Stream Management.

Spring 2000: Checkpoint Firewall Administration and Engineering Certification (CPSA/CPSE)



Contact this candidate