As an information security program manager, my role revolves around crafting and refining policies that strengthen our data security framework. With a focus on Controlled Unclassified Information (CUI), I ensure operational strategies and training materials are up-to-date and in line with legal and organizational requirements. I have an active Federal Tier 2 Moderate Risk background investigation from OPM.I manage data security compliance, represent our agency in multi-agency working groups, and review and help identify all categories of controlled unclassified information. My team's commitment is to maintain the integrity of sensitive information, and continuously improve the agency's information security posture against cybersecurity threats.
-
Gs-14 Information Security Program Manager - Controlled Unclassified Information (Cui)Us General Services Administration Mar 2020 - Oct 2024Temple, Texas, United StatesPolicy Development and Documentation: • Create and maintain agency policies, operational strategies, and training materials, focusing on CUI and data protection. • Analyze and refine policies based on research, stakeholder input, and legal considerations, ensuring alignment with organizational goals. • Manage data security relationships and review security plans, PIAs, and PTAs; represent the agency in working groups.CUI Communications Development and Enforcement: • Develop and implement emergency response scenarios and strategic communication plans for managing CUI. • Establish and enforce communication guidelines for handling CUI; conduct audits and training to reinforce compliance. • Collaborate with leadership and other federal agencies to enhance CUI strategies and integrate them into organizational operations.Contracting and Program Management: • Assist in creating statements of work and manage project activities for CUI programs using tools like Smartsheets, MS Office, and Google Suite. • Oversee CUI contractors and deliver training courses for agency employees on CUI and privacy. • Conduct training via various methods, including mandatory annual sessions and virtual platforms.Regulatory Compliance: • Develop COOP plans, emergency scenarios, and conduct Tabletop exercises; convene the Agency Full Incident Response Team. • Ensure compliance with Executive Orders, federal regulations, and agency policies by interpreting relevant guidance and using compliance tools like GEAR and ARCHER. • Collaborate with teams to develop security and privacy plans, assessments, and other documentation; develop 508-compliant content. -
Information Systems Security AnalystUs General Services Administration Nov 2012 - Mar 2020Emergency Management and Support: • Design and execute emergency scenarios, maintain COOP plans, and act as SERT and IT support representative during exercises. • Foster relationships across the agency to enhance joint emergency response effectiveness. • Maintain and regularly inspect hot and cold COOP sites, ensuring they are fully equipped and operational.Analyze and Report IT Security Posture: • Analyze IT security trends, approve vulnerability reports, and recommend improvements based on Cybersecurity principles. • Develop system security plans and ensure compliance with federal guidance (NIST, FISMA, etc.) to protect PII. • Persuade senior officials to adopt new security practices and assess the effectiveness of security controls.Apply Cybersecurity Principles: • Apply confidentiality, integrity, and availability principles to IT systems, and maintain knowledge of FIPS, FISMA, and other regulations. • Represent the Agency IRT on CUI and PII incidents, and recommend improvements to security posture. • Develop and maintain POA&Ms, ensuring security policies meet compliance objectives.Customer Support: • Design and analyze online surveys to gather user data, supporting evidence-based decisions for new technology products. • Act as a Cybersecurity SME, liaising between management, customers, and IT staff to improve service and operations. • Lead IT COOP activities, meet emergency program requirements, and interpret risk management policies for agency planning. • Anticipate and address potential IT issues before they impact customers, providing timely and effective solutions to ensure seamless operations and customer satisfaction. • Tailor IT support services to meet the unique needs of each customer, delivering clear communication, technical expertise, and follow-up to ensure all concerns are fully resolved. -
Senior Information System Security OfficerUs General Services Administration Jan 2007 - Nov 2012Colorado•Serve as an advisor in the execution of the Risk Management Framework for GSA’s IT systems and the agency Information Security Performance Plan to ensure compliance with the Federal Information Security Act Management Act and the Federal Information Security Modernization Act (FISMA).•Support the development and implementation of effective security requirements for new IT projects and emerging technologies.•Ensure that audit activities effectively evaluate compliance of IT systems with National Institute of Standards and Technology (NIST), GSA, and relevant security policies, Presidential Directives, and Federal standards.•Support the development of the system security policy and ensuring compliance on a routine basis in coordination with my team of information system security officers (ISSOs) and systems owner (SO).•Develop and update the System Security Plan, managing and controlling changes to the system, and assessing the security impact of those changes.•Support multiple projects and planning efforts to ensure Cyber Security and IT Security compliance requirements. -
Team Lead It Desktop Support Technician And Project ManagerUs General Services Administration Oct 2000 - Jan 2007Denver, Co•Review and approve assessment of configuration management processes.•Skill in adapting analytical techniques and evaluation criteria to the measurement and improvement of program effectiveness•Ability to prepare special studies and staff reports, including the ability to meet emergency and/or changing program requirements within available resources and with minimum sacrifice of quality or quantity of work.•Lead, review, and/or approve the results of the assessment of the effectiveness of security controls, to include recommendations for corrective action when necessary. •Develop procedures and assist in testing fail-over for system operations transfer to an alternate site based on system availability requirements.•Knowledge of information technology (IT) risk management policies, requirements, and procedures.•Review, approve and/or report to senior leadership the status of systems security operations and maintenance activities.•Team Lead for all IT COOP activities for hot, warm, and cold sites.•Represent the IT department to Senior Regional Officials regarding IT training needs•Discover, evaluate, review, and suggest new technologies for enterprise implementation.•Develop training plans, resources, and informational presentations for Regional employees for all types of access to the GSA IT network infrastructure. •Function as the primary team POC for all IT questions, initiatives, IT pilot groups. •Lead and organize the Regional Veterans Special Emphasis Program for all activities related Veterans holidays, programs, and special events. •Partner with multiple Federal agencies for combined Veterans events.•Liaised with GSA HR, colleges, and military bases to set up and attend recruiting events and job fairs around the state of Colorado for both Veterans and civilian talent. •Effectively build networking relationships with multiple educational and professional institutions, and help to recruit several talented individuals into Region 8. -
Federal Police Officer / Senior Security SpecialistUs General Services Administration Jan 1993 - Oct 2000Greater Denver Area•Conduct physical security and risk vulnerability inspections, evaluate and provide recommendations•Lead security and/or safety awareness training for personnel•Recommend actions to avoid conditions conducive to threats such as vandalism, terrorism or theft•Evaluate clearances for management and personnel according to the information and property they may access•Protect citizens by preventing crime, enforcing laws, apprehending suspects, and monitoring traffic.•Prevent crime by explaining and enforcing applicable federal, state, and local laws and ordinances; teaching preventive, protective, and defensive tactics; mediating disputes; patrolling assigned area; responding to notices of disturbances;•Apprehend suspects by responding to complaints and calls for help, observing violations, and making arrests.•Conduct criminal investigations by gathering evidence, interviewing victims and witnesses, and interrogating suspects.•Document observations and actions by radioing information and completing reports.•Maintain safe traffic conditions by monitoring and directing traffic, enforcing laws and ordinances, investigating accidents, providing escort, and reporting unsafe streets and facilities.•Minimize personal injury by rescuing and reviving victims and radioing for medical assistance.•Maintain operations by following department policies and procedures and recommending changes.•Ensure operation of equipment by practicing responsible use, completing preventive maintenance requirements, following manufacturer’s instructions, troubleshooting malfunctions, notifying supervisor of needed repairs, and evaluating new equipment and techniques.•Maintain professional and technical knowledge by studying applicable federal, state, and local laws and ordinances; attending educational workshops; reviewing professional publications; practicing skills; and participating in professional societies.
-
Signal Officer / Space Operations OfficerUnited States Army Reserve (Retired) Nov 1990 - May 2012Colorado Springs, Colorado AreaOfficer in Charge / Team Leader for CIO (G-6) Army Reservists:Space and Missile Defense Operations:Developed detailed plans for space and missile defense operations, aligning with higher headquarters' strategic objectives.Oversaw mission execution, coordinated with military branches and allied forces for unified command, and ensured effective communication within the command.Provided technical expertise, addressed operational issues, and contributed to the development and enforcement of policies and doctrines.Conducted regular assessments of unit readiness, implemented training programs, and developed long-term strategies and contingency plans.OPSEC (Operations Security) Plans:Created and maintained comprehensive OPSEC plans to protect sensitive information, integrating them into all mission aspects.Provided ongoing OPSEC training and distributed awareness materials across the command to enhance compliance.Acted as the primary OPSEC contact, coordinating with security disciplines, monitoring adherence, and enforcing compliance through inspections and corrective actions.Foster an environment where team members are encouraged to take initiative, contribute ideas, and grow in their roles by providing support and resources tailored to their development needs.Actively ensure the well-being of the team by being attentive to their needs, offering guidance, and addressing challenges that may impact their performance or morale.Demonstrate ethical behavior, accountability, and a strong work ethic, setting a standard that inspires team members to follow suit.Focus on the collective achievements of the team, recognizing individual contributions while emphasizing the importance of collaboration and shared goals.
Andy Riordan Skills
Andy Riordan Education Details
-
University Of Phoenix (Denver / Cospgs Campus)Computer And Information Sciences And Support Services -
Criminal Justice And Criminology -
Criminology -
Wheat Ridge High School1969 Chevelle Ss 396
Frequently Asked Questions about Andy Riordan
What is Andy Riordan's role at the current company?
Andy Riordan's current role is Fed Gov’t Information Security Program Manager | U.S. Army | Federal Law Enforcement.
What schools did Andy Riordan attend?
Andy Riordan attended University Of Phoenix (Denver / Cospgs Campus), Metropolitan State University Of Denver, Red Rocks Community College, Wheat Ridge High School.
What skills is Andy Riordan known for?
Andy Riordan has skills like Leadership, Team Building, Information Technology, Information Security, Personal Development, Human Resources, Cybersecurity, Interviewing, Security Operations, Servant Leadership, Operational Planning, Army.
Not the Andy Riordan you were looking for?
-
Andy Riordan
Chandler, Az2quizlet.com, chemistreeapps.com -
-
Andy Riordan
Sales Professional/Marketing Strategist//Event Planning/Brand Development/FundraisingPlano, Tx1yahoo.com -
2emeriodesign.com, faustro.com
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial