Ben Tomhave

Ben Tomhave Email and Phone Number

Security Architect, Technical Leader, Security Leader, Cloud Transformation, Cloud Security, AppSec, Container Security, DevOps/DevSecOps, Enterprise Security @ First Citizens Bank
Ben Tomhave's Location
Herndon, Virginia, United States, United States
About Ben Tomhave

Ben Tomhave is a security industry veteran, progressive thinker, and culture warrior. He holds a MS in Engineering Management from The George Washington University, a BA in Computer Science from Luther College, is a CISSP, and is a graduate of the BJ Fogg Behavior Design Boot Camp. He's previously held positions with Hilton, Gartner, AOL, Wells Fargo, ICSA Labs, LockPath, and E&Y. He is former co-chair of the American Bar Association Information Security Committee, a senior member of ISSA, former board member for the Society of Information Risk Analysts, and former board member for OWASP NoVA. He is a published author and experienced public speaker, including engagements with the RSA Conference, MISTI, ISSA, RMISC, Secure360, RVAsec, DevOps Connect, as well as Gartner events.

Ben Tomhave's Current Company Details
First Citizens Bank

First Citizens Bank

View
Security Architect, Technical Leader, Security Leader, Cloud Transformation, Cloud Security, AppSec, Container Security, DevOps/DevSecOps, Enterprise Security
Ben Tomhave Work Experience Details
  • First Citizens Bank
    Senior Information Security Architect
    First Citizens Bank Jan 2024 - Present
    Raleigh, North Carolina, Us
    Doing security stuff.
  • Falcon'S View Consulting, Llc
    Principal
    Falcon'S View Consulting, Llc Jun 2015 - Present
    As a solo consulting practice, providing cybersecurity professional services to multiple industries. Project work includes content development, security architecture, security product strategy and development, high-level security assessment and advisory services, specialized security training, and DevOps/DevSecOps architecture. Engagements include technical security ghost writing, program assessment based on NIST CSF, security advisory services on topics including risk management and container security, and general enterprise security architecture. My practice has been idle since mid-2019.
  • Smithrx
    Senior Corporate Security Engineer Iii
    Smithrx Nov 2023 - Jan 2024
    San Francisco, Ca, Us
    First full-time security hire for the company. Brought in to build out security program and security architecture roadmap, as well as to assist with completing critical audits and implementing various security practices. Work efforts completed include:• Core Security Program Design: Designed and created a roadmap for the build-out of core security program capabilities, including vulnerability management, risk management, data security, application and product security, third-party risk management, and business continuity management.• Critical Security-Related Processes: Designed and began implementing critical security processes through cross-team collaboration, including identity lifecycle, access management, routine security testing, vendor security reviews, cloud security monitoring, audit support, and policy revisions.• Security Tooling, Services, and Architecture: Identified security capability needs, designed solutions, evaluated vendors, and shepherded associated budget requests through review and approval. Solutioning included evaluating vendors for Managed Detection and Response (MDR), Cloud Security Posture Management (CSPM), application security testing, password vault/management, identity governance and administration (IGA), network remote access controls for sensitive environments, and container workload protection. Additionally, provided security architecture support to engineering teams around software designs and security-related questions.
  • Entegral
    Enterprise Security Architect
    Entegral Oct 2022 - Aug 2023
    Madison, Wisconsin, Us
    Time was split between providing security architecture leadership, participating as an Enterprise Architect (EA) within the Engineering Board, participating in and helping evolve the Technology Adoption Process, and overall providing technical leadership for the organization. Additional EA support was also provided to the internal team responsible for user endpoints and corporate IT services. * Security Architecture: Led initiatives and provided guidance in several areas, including security program management, security policies and standards, security roadmap and strategy, prioritization of resolving security capability gaps, identification and implementation of security solutions, and generally representing security across the organization. * Engineering Board: The Engineering Board was comprised of all Entegral Enterprise Architects and provided technology oversight for the organization. Our stated mission was to “relentlessly pursue the iterative delivery of evolutionary, right-sized, secure, scalable software products.” We collaborated to facility awareness and cooperation across our respective value streams, as well as helping set standards and guide technology decisions that were aligned with strategic direction from the executive leadership team. * Technology Adoption Process: Participated as an EA in the review of new technology requests, as well as working collaboratively to evolve and optimize the process. The purpose of this process was to provide some high-level governance around introduction of new technologies (whether tools or services) into the organization without proper planning, consideration, or support.
  • Equifax
    Security Enterprise Architect
    Equifax Jul 2022 - Sep 2022
    Atlanta, Ga, Us
    Security EA assigned to cover SSDLC and container security, as well as other DevSecOps-related topics as they arise.
  • Equifax
    Security Solutions Architect
    Equifax Mar 2021 - Jul 2022
    Atlanta, Ga, Us
    Performed security reviews of project designs to evaluate adherence to security technical requirements and for appropriateness of security controls and practices, including ensuring that a proper data flow diagram was in place and assisting teams with threat modeling during the project lifecycle. Assisted project teams with security solutioning when defined patterns meeting technical requirements did not exist. Participated in training delivered to technical architects and project leads on how to compose a data flow diagram and how to perform threat modeling. Completed foundational training on Google Cloud Platform.
  • Hobsons
    Cloud Security Architect
    Hobsons Jun 2020 - Feb 2021
    Cincinnati, Ohio, Us
    Provided technical security leadership within the CloudOps team and across the Technology division. Day-to-day responsibilities included working with software development project teams to ensure proper cloud security measures were in place and maintained, leading tooling evaluations (e.g., log management, container and serverless security tools), leading log management platform migration (from Splunk to Devo), and leading clean- up of AWS IAM configurations (including a transition to AWS SSO). Worked in a matrixed relationship with the Security team to also provide input and propose direction on key capabilities such as security standards and operational security practices. Hobsons was dissolved in February/March 2021.
  • Hilton
    Principal Application Security Architect
    Hilton Mar 2019 - Jun 2020
    Mclean, Va, Us
    Provided security architecture and strategy guidance to projects and teams on a variety of topics, including DevSecOps, application security testing, secure coding, secure application and system design, cloud and container security, and enterprise security. My day-to-day activities included reviewing or advising project designs, working within internal security resources on testing approaches, planning and developing security standards, and being a general advocate for information security across the organization.
  • Pearson
    Manager, Security Engineering And Architecture
    Pearson Sep 2017 - Apr 2018
    London, Gb
    Provided front-line management of a team of security engineers and architects responsible for identity and access management (IAM), multi-factor authentication (MFA), cloud security, container security, and data security (including encryption and certificate management). Provided technical leadership for the IAM and MFA initiative, including support for solution design and program communications.
  • New Context
    Principal Security Scientist
    New Context Jun 2016 - Jul 2017
    San Francisco, Ca, Us
    Served in a variable role performing research, product management of in-house development projects, and conducting business development. Efforts included creation of materials around the "Lean Security" methodology, development of presentations for conferences, and writing copy for sales collateral, blog posts, and byline articles. New Context has a focus on secure DevOps services and product development.
  • Ellucian
    Manager, Information Security Architecture
    Ellucian Oct 2015 - Jun 2016
    Reston, Va, Us
    Evaluated current security processes, tools, and practices as a member of the information security team reporting directly to the CISO. Charged with evaluating the effectiveness of current solutions and identifying gaps in security protection. Developed a comprehensive security architecture framework to evaluate and manage security architecture strategy for both traditional on-premises and cloud environments. Worked with vendors and cross-organizationally to identify, evaluate, and test (pilot) solutions. Technologies evaluated included data loss prevention (DLP), endpoint detection and response (EDR), traditional endpoint security, email security solutions (on-premises and Office 365), enterprise mobility management (EMM), network security tools and capabilities, identity and access management tools and capabilities, application security practices, cloud security tools (such as for AWS) and container (Docker) security tools. Technologies in-scope included AWS, Okta, Digital Guardian, IBM BigFix, Symantec EPP, Zscaler, Microsoft Adallom, FireEye, Splunk, Ansible, Rapid7, Tenable, CloudCheckr, StackRox, Jump Cloud, among many others.
  • K12
    Security Architect
    K12 Mar 2015 - Oct 2015
    Herndon, Va, Us
    As a member of the enterprise architecture team, charged with broad responsibilities to inject security practices into the overall application stack. Reviewed overall environment and developed an incremental roadmap for addressing critical gaps and charting a progressive course to more effective enterprise security over time. Included collaborating with the team driving a DevOps initiative, as well as initiating changes to implement and leverage security operations automation.
  • Gartner
    Research Director
    Gartner Jun 2013 - Mar 2015
    Stamford, Ct, Us
    As a member of the Security & Risk Management Strategies team within Gartner for Technical Professionals, I conducted research into topics including risk management, security programs, security planning and management, application security, DLP, and SharePoint security. Additionally, I contributed content as a speaker at several Gartner and non-Gartner events and webinars, as well as delivering advisory services to clients and providing direct support to the sales team, both virtually and in-person, in multiple regions.
  • Lockpath, Inc.
    Principal Consultant
    Lockpath, Inc. Aug 2011 - May 2013
    Overland Park, Kansas, Us
    Although originally hired to build a professional services team (put on hold due to a change in sales strategy), redeployed as needed to provide a number of value-add services, including customer training (development and delivery of comprehensive product onboarding curriculum); writing (blog posts, articles, and white papers); sales support and public speaking (including talks delivered at RSA USA, Secure360, Rocky Mountain InfoSec Conference, ISC2 Security Congress, and the ISSA International Conference); partner enablement; and, a variety of other one-off projects (e.g., market analysis, security policy development).
  • Gemini Security Solutions
    Sr Security Analyst / Business Development Manager
    Gemini Security Solutions May 2010 - Jul 2011
    Helped deliver security professional services. Assisted with business development.
  • Raytheon Foreground Security
    Senior Security Engineer
    Raytheon Foreground Security Oct 2009 - Dec 2009
    Performed product implementation and project management work for a security architecture project at a major government agency.
  • Highwinds
    Technical Director Of Information Security & Compliance
    Highwinds Feb 2009 - Sep 2009
    As Director of Security & Compliance, it was my opportunity to establish and build a formal security program for the enterprise.
  • Bt
    Senior Security Consultant
    Bt Sep 2007 - Feb 2009
    London, Gb
    Security consultant (via BT Global Services acquisition of International Network Services) providing professional services to a broad range of organizations. Direct experience with security architecture, access management, privileged identity management, cryptographic key management, Encryption Key Management Infrastructure (EKMI), development of policies and standards, SSE-CMM, ISO 27000 series standards, pre-sales support, and client presentations.
  • Aol Llc
    Sr Technical Security Engineer
    Aol Llc Dec 2003 - Sep 2007
    New York, Ny, Us
    Served in a team leadership role within the security assurance team. Responsibilities included working with project teams to inject security requirements, development and delivery of technical security training, contribution to policy development, and thought leadership within the security organization.
  • I_Tech Corporation
    Wan/Security Engineer
    I_Tech Corporation Aug 2003 - Oct 2003
    Recruited to take over leadership of a comprehensive network security re-architecture project. Responsible for all aspects of operational security within supported systems, including OS and router hardening, perimeter and internal firewalls, AV maintenance, etc.
  • Sofast Communications
    Senior Systems Engineer
    Sofast Communications Dec 2002 - Aug 2003
    Served as lead systems administrator and secondary network administrator for national Internet Services Provider. Responsibilities included supporting dial-up, broadband and DSL customers for connectivity, email and web hosting. Also provided systems administration to systems used for web hosting and portal services.
  • Icsa Labs (Cybertrust)
    Network Security Lab Analyst
    Icsa Labs (Cybertrust) Jul 2002 - Dec 2002
    Mechanicsburg, Pa, Us
    Conducted comprehensive security testing and certification of firewall products. Worked with vendors to coordinate resolution of issues. Testing involved use of common penetration assessment tools, including Nessus, CyberCop, Nmap, hping, nemesis and tcpdump, among others. Testing was conducted in a process-oriented, scientific environment aimed at applying a consistent measure to a variety of firewall products, ranging from consumer appliances to enterprise solutions.
  • Sofast Communications
    Senior Systems Engineer
    Sofast Communications Oct 2001 - May 2002
    Served as lead systems administrator and secondary network administrator for national Internet Services Provider. Responsibilities included supporting dial-up, broadband and DSL customers for connectivity, email and web hosting. Also provided systems administration to systems used for web hosting and portal services.
  • Wells Fargo
    Information Security Analyst
    Wells Fargo Nov 2000 - Aug 2001
    San Francisco, California, Us
    Provided technical project management to a team of 30+ engineers throughout the country. Responsibilities included design review, workflow management, special project leadership, and point-of-contact for regular work requests. Team was responsible for managing 500-600 firewall, web and application servers, based on Sun Solaris, Compaq Tru64, and Windows NT.
  • Born Information Services
    Security Consultant
    Born Information Services Jan 2000 - Oct 2000
    Brought onboard to help establish and grow a security consulting practice. Executed engagements, developed collateral, trained sales and technical staff, and assisted in the sale of services. Customer engagements included incident response, security assessments, and the development of security standards for Windows 2000.
  • Ernst & Young
    Senior Security Consultant
    Ernst & Young May 1999 - Jan 2000
    London, Gb
    Participated in and led Information Technology audits, including documenting and providing expert analysis of system and network security. Presented audit and security assessment findings and provided business justification for recommended changes. Involved with both standard IT audits and SAS-70 Type I and Type II reviews.
  • International Network Services
    Associate Network Systems Engineer
    International Network Services Jul 1998 - May 1999
    Us
    Provided network professional services to a variety of clients in the Chicago, Illinois, and Minneapolis, Minnesota, metropolitan areas. Services included troubleshooting, network design and implementation, and fulfilling numerous other network administration functions on behalf of customers.
  • Luther College
    Student Tech Worker
    Luther College Oct 1994 - Apr 1998
    Decorah, Ia, Us
    Completed various small-scale technical projects as assigned as a student tech/computer worker.
  • Luther College
    Systems And Network Adminstrator
    Luther College Oct 1994 - Dec 1996
    Decorah, Ia, Us
    As a student worker, performed systems and network administration, including everything from bare metal installation to support and management, on HP/UX, FreeBSD, Novell Netware, and Microsoft Windows platforms. Duties included access management, hardware rack-n-stack (including network card installation, cable pulls and terminations), and supporting endusers with various needs (including virus removal from PCs and floppy disks). This position concluded when I took a co-op internship.
  • Andersen Consulting
    Intern
    Andersen Consulting Jun 1997 - Aug 1997
    As an intern, participated in two projects: 1) helping document an in-house software development project to achieve the desired CMM level, 2) providing technical assistance to a client, particularly in support of IBM AIX UNIX.
  • Argonne National Laboratory
    Co-Op Intern
    Argonne National Laboratory Jan 1997 - May 1997
    Lemont, Il, Us
    Wrote application software using National Instruments LabViEW to do 360-degree image acquisition using a radioactive source (industrial CT-scan system). You can read about the experience here:http://www.secureconsulting.net/Classic/argonne.html

Ben Tomhave Education Details

  • The George Washington University
    The George Washington University
    Engineering Management
  • Luther College
    Luther College
    Mathematics (Minor)
  • Moorhead Senior High School, Moorhead, Mn
    Moorhead Senior High School, Moorhead, Mn
    General

Frequently Asked Questions about Ben Tomhave

What company does Ben Tomhave work for?

Ben Tomhave works for First Citizens Bank

What is Ben Tomhave's role at the current company?

Ben Tomhave's current role is Security Architect, Technical Leader, Security Leader, Cloud Transformation, Cloud Security, AppSec, Container Security, DevOps/DevSecOps, Enterprise Security.

What is Ben Tomhave's email address?

Ben Tomhave's email address is be****@****ian.com

What is Ben Tomhave's direct phone number?

Ben Tomhave's direct phone number is +170348*****

What schools did Ben Tomhave attend?

Ben Tomhave attended The George Washington University, Luther College, Moorhead Senior High School, Moorhead, Mn.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.