Senior Director Of Network Operations And Chief Information Security Officer (Ciso)
CurrentDirect the design, implementation, and management of infrastructure and security for the organization. Develop and manage an annual budget of over $4 million for network operations and security. Lead the development and implementation of policies and procedures that protect sensitive data and preserve information security in an effective and reasonable manner. Developed a standardized schedule for security audits, risk assessment, and penetration testing, and then adjusted the security strategy accordingly. Developed, implemented, and regularly tested comprehensive business continuity and disaster recovery plans for infrastructure components to ensure their success. Initiated an external risk assessment to ensure compliance with PCI, GLBA, and data protection regulations. Under my leadership, the technology organization fostered a culture of collaboration, innovation, and continuous education. Select, evaluate, and manage IT infrastructure and security vendors and service providers in order to deliver high-quality, cost-effective services; negotiate contracts, SLAs, and pricing. Periodically conducted security awareness training and phishing campaigns. The Managed Detection and Response (MDR) solution was assessed and implemented. Supervising the vulnerability management system, Microsoft O365, Microsoft Entra ID (Azure Active Directory), DNS layer security, SPAM filtering, on-premise and cloud backup, VMWare infrastructure, telecommunication, WebEx, various firewalls and granular firewall rules, micro-segmentation of networks, WIFI infrastructure, and access to mission-critical applications utilizing SSO and MFA. Protect against cyberattacks, data breaches, and other security incidents by monitoring the threat landscape, identifying vulnerabilities, and implementing proactive security measures. Member of the Multi-State Information Sharing and Analysis Center (MS-ISAC), Cybersecurity and Infrastructure Security Agency (CISA), and other regional CISO groups.