Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp Email and Phone Number
Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp work email
- Valid
- Valid
Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp personal email
- Valid
- Valid
- Valid
- Valid
- Valid
Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp phone numbers
I am a multi-skilled cybersecurity and risk management veteran with over 15 years of experience, adept at integrating security practices with strategic business objectives. My approach views cybersecurity as essential to strategic risk management, customized to align with specific business goals and regulatory demands.I excel in developing security strategies, framework alignment, vulnerability programs, and advancing compliance efforts. I specialize in technology risk and vulnerability management, insider threat mitigation, and security enhancements in software development lifecycles. My expertise also spans cloud infrastructures (IaaS, PaaS, SaaS) and adapting to evolving threats.
-
Sr. Manager | Information Security Risk ManagementOptumFlorida, United States -
Founder And Principal Consultant | VcisoAbi Consulting, LlcFlorida, United States -
Vp | Head Of Global Cybersecurity, Compliance, & Technology RiskPole Star Defense Jun 2023 - PresentSt Petersburg, Florida, UsAs VP of Cybersecurity, I continuously develop and execute a comprehensive information security strategy aligned with business objectives, ensuring robust policy communication/enforcement and continuous adaptation to emerging threats. I provide strategic guidance to the executive leadership, offering regular updates on cybersecurity program status. My role additionally encompasses risk management, including real-time threat analysis, and the establishment of a security governance framework and POA&M compliant with ISO27001:2022, NIST Cybersecurity Framework (CSF), Cybersecurity Maturity Model Certification (CMMC), FARS/DFARS, and Federal Information Security Management Act (FISMA) standards. Additionally, I lead incident response efforts, manage security operations, oversee vendor security assessments, and efficiently allocate resources within the information security budget.High-Level Achievements:• Spearheaded the successful attainment of ISO27001:2022 certification in 6 months, ensuring alignment with industry-leading standards and bolstering organizational security posture.• Orchestrated the seamless integration of cutting-edge security technologies within complex technological ecosystems, elevating operational resilience.• Revamped vulnerability management and incident response protocols, driving a substantial reduction in risk exposure across mission-critical infrastructures.• Executed a comprehensive third-party evaluation to meticulously assess and fortify our alignment with the NIST Cybersecurity Framework, thereby enhancing our strategic security posture and ensuring rigorous adherence to industry best practices. -
Health And Well-BeingCareer Break May 2023 - May 2023In pursuit of preserving my well-being and achieving a balance between professional commitments and personal growth, I made the mindful decision to step away from my previous role. This brief sabbatical served as an intentional period of introspection, restoration, and preparation for the next chapter, focusing on fortifying my mental health and augmenting my leadership skills.
-
Svp | Sr. Manager - Offensive SecuritySecu Feb 2022 - May 2023Raleigh, Nc, Us• Responsible for leading and providing programmatic creation, direction, and maturity for the following cybersecurity domains at NC SECU: Vulnerability Management, Application Security, Secure Design Architecture, Red/Purple Teaming, Penetration Testing, and Threat Intelligence.• Lead an organization of four VPs with a total of 12 FTE's. • Assist Chief Security Officer and EVPs in the development and maintenance of security initiatives and roadmap considerations toward NIST-CSF framework alignment and execution. • Collaborate with the Security Operations team ensuring proper Security Operations Center (SOC) performance, threat strategy, management, and reporting across the organization.• Maintain and enhance the credit unions' security vulnerability program and board-driven metrics. • Manage the oversight of security vulnerabilities and risks including identifying and supporting application/system owners to manage risks and remediate vulnerabilities.• Drive resolution of any vulnerabilities with other engineering teams including app/dev and infrastructure.• Own and manage all penetration tests and red/purple team engagements both internally and externally. • Lead efforts in ensuring the necessary security requirements and reference documentation are established and utilized in the project-oriented implementations.• Provide strategic guidance for the establishment and enforcement of security tools embedded into the SDLC process and integrated into current & future CI/CD pipelines.• Participate in 3rd party security partner/vendor selection and subsequent contract negotiations.• Mentor, train, and educate cybersecurity professionals toward aspirational career growth and development. -
Sr. Advisor, Insider Risk & SecurityCode42 Aug 2021 - Feb 2022Minneapolis, Mn, Us• Lead advisory practices for customer engagements via prescriptive, program-centered approach to Insider Risk Management, tailored to their industry priorities.• Provide thought leadership to CISO's, Directors, and engineers on best practices for Insider Risk reduction and/or mitigation. -
Principal | Enterprise Security Program ManagerVeracode Mar 2021 - Aug 2021Burlington, Massachusetts, Us• Establish and drive enterprise-wide risk management programs for application vulnerability testing.• Advise customers on how to best utilize the Veracode solutions within their organization.• Advise customers with creating, educating, and delivering rollout plans, security policies, and integrated SDLC processes.• Advise customers with onboarding of development teams, understanding compilation policies, and executing Consultation Calls to drive adoption and utilization.• Ensure consistently positive customer experiences by working closely with Veracode Support, Consulting, and Operations teams and providing oversight and management of customer issues and initiatives.• Create and manage account plans with customers which cover the entire customer journey.• Prepare and lead customer program reviews; maintain an accurate record of discussions and action items.• Serve as customer advocate while capturing feedback and reporting requests to Product Management. -
Technical Manager, Security Assurance And RiskRaymond James Nov 2017 - Mar 2021St. Petersburg, Florida, Us• Program manager and developer of the Secure Design Consulting program within Raymond James. There I primarily serve as the principal liaison between project teams (program/project managers, AppDev teams, etc.) InfoSec Engineering, residing underneath the guidance of the IT Governance, Risk, and Compliance division.• Coordinated and established Red Team, Purple Team, and pentesting engagements (White Cell), both internally and externally, in conjunction with leadership approved remediation efforts for business-critical applications and regulatory compliance.• Maintain oversight of the Secure Coding governance program, ensuring the necessary application code is being scanned from a security, compliance, and regulatory standpoint – through metric-driven analytics.• Provide operational security oversight for onboarding of new suppliers though extensive audits and regular gap analysis sessions. • Participant in the Cloud Center of Excellence for Raymond James to establish a formal adoption, implementation, and sustenance strategy.• Serve as a subject matter expert and information security risk and control advisement, to facilitate the identification and assessment of technology/security risks toward the effectiveness and efficiency of IT security controls.• Provide risk and security advice for RJ service agreements and third-party relationships and contracts.• Responsible for providing independent assessment and assurance of the effectiveness and efficiency of the IT control environment within the organization and external 3rd parties/vendors.• Monitors IT compliance, legislative, and regulatory trends for impact and potential non-compliance/gaps within the organization. -
Instructional FacilitatorSans Institute 2019 - 2019Rockville, Maryland, UsAssisted Adrien de Beaupre in performing course facilitation for the SEC460: Enterprise and Cloud | Threat and Vulnerability Assessment course. -
Sr. Security EngineerCloudpassage Sep 2016 - Nov 2017San Francisco, California, Us• Technical subject matter expert on CloudPassage Halo solution guiding the customer to properly deploy, configure, and maximize product usage toward a DevSecOps methodology.• Configuration hardening, assessment, and forensics with Linux and Windows servers. • Host-based intrusion detection and prevention (state-based, event-based, signature-based).• Management of software & package vulnerabilities, patching, and related technical & operational functions.• Guided customers in implementing host-based security strategies on a large scale across a variety of environments using project management-based methodologies. • Educated user communities by assisting with the production of security-related blog postings, how-to-videos, and answers to questions.• Demonstrated our solution to prospective customers and working with them to demonstrate how our solution would integrate and add value to their environment.• Assisted new customers in the onboarding process, both initial deployment and in some cases optimizing their configuration and assisting with operational integration.• Maintained all CRM activities within SalesForce.com. Also utilize collaboration tool suites such as Slack, JIRA, and Google for Work. -
Instructional FacilitatorSans Institute 2017 - 2017Rockville, Maryland, UsAssisted G. Mark Hardy in performing course facilitation for the MGT512: Security Leadership Essentials for Managers course. -
Technical Program ManagerWhitehat Security Nov 2015 - Sep 2016San Jose, California, Us• Provided technical account management for customers (at C-level down through support) who purchase Gold or Platinum support from WhiteHat's SaaS-based services (DAST, SAST, and Mobile), driving satisfaction, adoption, and retention.• Trusted advisor to the customer's AppSec program and SDLC development process providing guidance and best practices to mitigate OWASP Top 10, et al. within multiple complex applications.• Responsible for overall post-sales relationship (account administration, on-boarding, escalations, diagnosing technical issues, delivering user interface training, and facilitating/participating in vulnerability reviews). • Provide a high-touch experience for key clients – including monthly trending reports, providing business insight to their use of WhiteHat product lines, ensure quick onboarding and adoption of their purchased products. • Initiated and presented Quarterly Business Reviews in order to reinforce WhiteHat's value, review product usage, establish mutual attainable metrics and expectations, and align with customer’s goals.• Assist customers in the evaluation of web application vulnerabilities, web application business logic flaws, and threats. • Work with customers to deploy satellite devices (VM or physical) for internal or SAST source code scanning. -
It Strategy - CoordinatorInformationweek Jun 2011 - Feb 2016New York, Ny, UsEngagement Coordinator for the IT Strategy division of InformationWeek.com. InformationWeek is the world's most trusted online community for business technology professionals like you. Our community members include thought-leading CIOs, CTOs, IT VPs and managers, along with hundreds of thousands of other IT professionals.Primary responsibility includes moderating and interacting with today's IT industry leaders on topics such as information security, cloud computing, mobile strategies, virtualization, end-user computing, and storage. -
Cloud And Product Security EngineerCitrix Nov 2013 - Nov 2015Fort Lauderdale, Fl, Us• Primary responsibility was maintaining security and compliance efforts in a fully cloud-based infrastructure (Amazon AWS and Azure) with working knowledge of application architectures, web front-ends/server-side apps, and RMDB's.• Developed, established, and maintain the Security and Vulnerability Management Program for Citrix ShareFile with an Agile run environment. • Performed automated and manual web/infrastructural vulnerability assessments to identify exploit/configuration/patch related vulnerabilities. (Tools/Vendors include Rapid7 Nexpose, Whitehat Sentinel, Trustwave, & McAfee/Qualys [PCI]). • Manually assessed web application vulnerabilities discovered in house, by third-parties, and security researchers. Tools included Burp Suite, ZAP, custom python scripts, and various sites to test for verification (SSLlabs, web-sniffer.net, etc.)• Monitored network, system, and application logs for security events via IDS/IPS, SIEM, host-based firewalls, configuration, and file integrity monitoring. (Tools include CloudPassage, Alert Logic, Dome9, nmap, and Wireshark).• Assisted in the evaluation process of vulnerability management tools and ultimately vendor selection.• Collaborated with infrastructure administrators and application developers to remediate infrastructure and web application related patch management, vulnerabilities, and incidence response efforts.• Work closely with product management to determine vulnerability priority and severity for sprint inclusion. • Facilitated and coordinated secure code training efforts with developers throughout the organization.• Deployed, maintained, and managed endpoint security efforts through the use of McAfee ePO anti-virus/anti-malware solution. • Performed routine audits and assessments to ensure compliance with security policy, legal requirements, and industry accepted standards. -
Network Security Engineer - Managed Security ServicesAt&T Apr 2013 - Nov 2013Dallas, Tx, Us• Responsible for Managed Security Services for AT&T Security Operations Center performing Tier 1.5 and Tier 2 level troubleshooting skills to devices such as Cisco PIX firewalls, Routers, Switches, Checkpoint firewalls that run on Solaris and Nokia IPSO platforms, Fortinet FortiManager, Web Sense URL servers, Blue Coat and Net Cache Proxy servers, Cisco Intrusion Detection, Baytech modems, US Robotics modems and other network elements.• Supported and Troubleshot multiple assignments using knowledge, skills, and abilities that are demonstrated in the following network technologies: such as Cisco Systems, Cisco Application Control Engine, ASA series Firewalls, Juniper, Network Management Applications: Cisco works, LMS, DHCP, DNS, Nagios and many other Network based firewall and policy routing. Also support and troubleshoot Secure Email Gateway.• Utilized FortiManager 3000C for firewall, web filter, and VPN (et al) policy review for network based firewall customers for troubleshooting and the MACD change process. • Provided security event analysis and support via SEIM monitoring, looking at security event logs, investigating and troubleshooting. Utilize and monitor network daemons including Hobbit and Nagios.• Chiefly utilized basic troubleshooting: ping, traceroute, whois, netstat, dig, grep - via SSH and telnet. • Network protocols: TCP, UDP, DNS, NTP, RPC , FTP, SMTP, SSL, TLS, etc. • Routing protocols managed: BGP, MPLS, IGRP, EIGRP, OSPF, • Managed authentication, authorization, and accounting (AAA).• Contract-to-hire position, chose not to renew.• Security Clearance: Public Trust designation. -
Security Project Analyst IiFirst Citizens Bank Dec 2009 - Apr 2013Raleigh, North Carolina, Us• Customer facing technical analyst providing 1st and 2nd level support to community banks’ technical, procedural, and business related questions, within an ITIL based change environment. • Primary role was to manage, train, support, audit, and administer the Security Application (user access) in the FIS Horizon core banking platform for 5 client banks. • Collaborated with system administrators and IT managers to customize and configure workflow and enabling technology to facilitate all software interface applications between the Horizon Core system and compatible external software. • Conducted ongoing and quarterly security assessments and implemented security solutions to assist business with assessment and improvement of the core application and IBM's AS/400 server, (i.e. IT SOX, GLBA.).• Assisted in departmental policy and procedural writing for the security application, interface products, and AS400 extract files.• Participated in annual software release through test and production implementation verification and accountable for validating security module system quality. Back up application owner for FIS’s online banking platform. • Developed training sessions to clients (and train-the-trainer) using customized training methodologies based on the size and structure of the banking organization. (i.e. DAC, MAC, RBAC access control models). • Supported the organizations Information Security program by participating in or leading efforts requiring application security subject matter expertise in line with secure frameworks ISO and COBIT. -
Supervisor, Client ServicesSquare 1 Bank Jan 2007 - Dec 2009Durham, Nc, Us• Managed and built a client service cycle (staff of 10), monitored timeframes and deadlines, oversaw workflow, report maintenance, schedule management, and trained employees.• Responsible for onboarding and maintaining all customers' account portfolios and any additional services, including remote deposit check technology.• Assisted clients in product selection, implementation, and training. Product familiarity included credit cards, online banking, positive pay, ACH, controlled disbursement, etc.• Examined and resolve compliance and regulation issues on client accounts to identify potential problems or status of high-risk accounts and situations. • Worked thoroughly with both the Horizon Core system as well as the Fiserv core.• Serviced a portfolio of clients from Palo Alto and San Diego by actively partnering with the Relationship Managers to discuss prospects, current customers, and trends. • Served as a member of the "Values Team" which sought to ensure potential candidates were the right cultural fit. -
Client Officer - Government BankingJp Morgan Chase Bank Feb 2005 - Jan 2007New York, Ny, Us• Accountable for managing a portfolio of NYS government clients within the Middle Market/Commercial banking line of business.• Identified potential new business opportunities for JP Morgan Treasury Services and provide the appropriate solution(s). • Accompanied Relationship Manager, Treasury Services Officers, and other product specialists on sales calls to develop and improve the portfolio. Worked closely with the relationship managers to expand existing business with current clients while providing feedback to product managers. • Operational familiarity included all account reconcilement and banking functions as well as numerous computer applications and database operations performed. • As TSC (Technical Support Analyst) Primary technical contact for critical issues between the local office and the information technology department. Acted as the first line support of all technical and computer hardware/software troubleshooting. -
Assistant Branch ManagerHudson River Bank And Trust Sep 2001 - Feb 2005Buffalo, Ny, Us• Managed a staff of 8 while responsible for all branch operations, customer service issues. In addition, responsible for supervising and coordinating the activities of the Head Teller and the Relationship Bankers to meet and maintain sales, referral goals and customer service standards.• Lead and supervised the branch’s operational and administrative success through process improvement in accordance with customer transactions to prescribed policies and procedures.• Assist in managing overall sales performance of the branch to reach productivity and growth goals through maximizing cross-selling efforts with walk-in to service requests opportunities.• Leveraged sales tools, in-branch routines, call lists and best practices to increase sales productivity.
Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp Skills
Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp Education Details
-
Carnegie Mellon UniversityInsider Threat -
Western Governors UniversityComputer/Information Technology Administration And Management -
Western Governors UniversityCybersecurity And Information Assurance (Bscsia) -
The Sans InstituteSec460: Enterprise And Cloud | Threat And Vulnerability Assessment -
The Sans InstitueSec501: Advanced Security Essentials - Enterprise Defender -
The Sans InstituteMgt512: Security Leadership Essentials For Managers -
Wake Technical Community CollegeInformation Systems Security: Systems Security Practitioner - Certificate -
Wake Technical Community CollegeInformation Technology: Linux Security Specialist - Certificate -
The Sans InstituteSec542: Web Application Penetration Testing And Ethical Hacking -
The Sans InstituteSec503: Intrusion Detection In-Depth -
Wake Technical Community CollegeMicrosoft Certified It Professional - Mcitp -- Certificate -
Wake Technical Community CollegeGlobal Certified Windows Security Administrator (Gcwn) -
Global KnowledgeAutomated Administration With Windows Powershell -
Wake Technical Community CollegeNetwork Security Administration -
Hudson Valley Community CollegeComputer Applications And Business Management. -
Ravena Coeymans Selkirk High SchoolRegents Diploma
Frequently Asked Questions about Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp
What company does Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp work for?
Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp works for Optum
What is Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp's role at the current company?
Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp's current role is Sr. Manager | Information Security Risk Management.
What is Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp's email address?
Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp's email address is da****@****sec.com
What is Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp's direct phone number?
Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp's direct phone number is (408) 343*****
What schools did Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp attend?
Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp attended Carnegie Mellon University, Western Governors University, Western Governors University, The Sans Institute, The Sans Institue, The Sans Institute, Wake Technical Community College, Wake Technical Community College, The Sans Institute, The Sans Institute, Wake Technical Community College, Wake Technical Community College, Global Knowledge, Wake Technical Community College, Hudson Valley Community College, Ravena Coeymans Selkirk High School.
What skills is Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp known for?
Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp has skills like Ibm, Iso, Community, Jira, Penetration Testing, Agile Methodologies, Mentoring, Frameworks, Private Networks, Ssh, Siem, Robotics.
Who are Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp's colleagues?
Damian Romano - Mba(C) B.Sc, Giacx 4, Ccsp, Sscp's colleagues are Nagendra Kumar Singh, Daisy Rian Malveda, Jayson Corpuz, Deepa Chhetri, Kimberly Specht, Deepak Bhambri, Wilfredo Sabay Jr..
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial