Professional Development
CurrentAttend webinars, CBTs, and local industry meetings to stay current with industry current events and trends.
Please complete the CAPTCHA to continue
A concise factual answer block for searchers comparing this professional profile.
Dave S. is listed as Seasoned InfoSec Professional, Scrum Master Certified based in Orange, Massachusetts, United States. AeroLeads shows a matched LinkedIn profile for Dave S..
Dave S. previously worked as Client Solutions Architect II at Optiv Inc and Information Security and Risk Management Professional at Seeking New Opportunities. Dave S. holds Bachelor'S Degree, Business Administration - Management from Fitchburg State University.
This section adds company-level context without repeating Dave S.'s masked contact details.
Review company-level records connected to Dave S. before choosing the right outreach path.
Experienced Chief Information Security Officer with a demonstrated history of working in various industries. Skilled in Enterprise Risk Management, Computer Forensics, Data Center, Privacy, Compliance, and Information Assurance. Strong information technology professional with a Bachelor's Degree focused in Business Administration - Management from Fitchburg State University.
Company context helps verify the profile and gives searchers a useful next step.
A career timeline built from the work history available for this profile.
San Francisco, California, Us
Attend webinars, CBTs, and local industry meetings to stay current with industry current events and trends.
San Francisco, California, Us
Seasoned Information Security Professional with focus on Privacy, Compliance, and Information Security. Seeking new opportunity to share my knowledge and skills while growing a business and the individuals therein.
Responsible for the strategic leadership for Information Security and Risk Management.Provide guidance and counsel to the CEO and key members of the senior management leadership team in the area of IT security and Information Risk ManagementLead information security planning processes to establish an inclusive and comprehensive information security program for the entire organization.Establish annual and long-range security and compliance goals, define security strategies, metrics, reporting mechanisms and program services; and create maturity models and a roadmap for continual program improvements.Stay abreast of information security issues and regulatory changes affecting transportation at the state and national levelDevelop, document, and implement a robust Information Security Program that satisfies the needs of regulatory requirements, contractual agreements, and industry best practices.Identify, acquire, and implement security tools and protections to support a cloud based SaaS environment, including IDS, Vulnerability Scanning, SEIM, MFA, Static and Dynamic Code Analysis, Patch Management, and others.Perform special projects and other duties as assigned.Lead efforts to internally assess, evaluate and make recommendations to management regarding the adequacy of the security controls for the information and technology systems.Create education and awareness programs within a DevOps environment relative to security issues, best practices, and vulnerabilities.Keep abreast of security incidents and act as primary control point during significant information security incidents.Develop, implement and administer technical security standards, as well as a suite of security services and tools to address and mitigate security risk.Provide leadership, direction and guidance in assessing and evaluating information security risks and monitor compliance with security standards and appropriate policies.
IT Security Program LeadershipResponsible for the strategic leadership.Provide guidance and counsel to the CIO and key members of the senior management leadership team in the area of IT security,Working closely with senior business and IT management in defining objectives for information security, while building relationships and goodwill.Work with leadership to oversee the formation and operations of an information security organization that is organized toward a common goal in information security.Manage organization wide information security governance processes, and lead Information security personnel in the establishment of an information security program and project priorities.Lead information security planning processes to establish an inclusive and comprehensive information security program for the entire organization.Establish annual and long-range security and compliance goals, define security strategies, metrics, reporting mechanisms and program services; and create maturity models and a roadmap for continual program improvements.Stay abreast of information security issues and regulatory changes affecting transportation at the state and national levelLead the development and implementation of effective and reasonable policies and practices to secure protected and sensitive data and ensure information security and compliance with relevant legislation and legal interpretation.Lead efforts to internally assess, evaluate and make recommendations to management regarding the adequacy of the security controls for the information and technology systems.Risk Management and Incident Response Convene a Security Incident Response Team (SIRT) as needed, or requested, in addressing and investigating security incidences that arise.Develop, implement and administer technical security standards, as well as a suite of security services and tools to address and mitigate security risk.
• Mitigate risk by providing consistent direction and providing subject matter expertise in network vulnerability assessments, design and deployment of security technologies and solutions• Facilitate and drive the design and implementation of complex enterprise IT infrastructure security, processes, standards, regulatory issues, and assessment in technical project leadership role• Drive the implementation of Standard and Custom Security Solutions to IT and Business projects• Assess and evaluate the risk (design mitigation) and ensure any accepted risk is fully documented• Support the design of secure infrastructure, applications and mobile solutions• Assist in the implementation of protective and mitigating controls• Provide support to security operations and assists in providing technical security consulting services of technical security projects• Research, design, and implement information security solutions for the organization• Architect systems and products that comply with all applicable security policies and standards• Architect innovative solutions for wide range of complex problems• Interface with management to report on project and milestones• Develop new methodologies or processes, re-evaluates existing processes• Web Application Security Analysis findings and provides remediation strategies as well as Security Thread Modeling
• Lead remediation activities stemming from security event analysis, vulnerability management and intrusion detection • Define non-functional security requirements for corporate technology projects; identify exceptions and articulate security gaps.• Develop standards for and ensure proper placement of assets on company networks to align with network segmentation standards.• Focus on technologies in the web application, Network, Firewall and Cloud environments • Create and maintain baseline configuration standards for all technical assets.• Establish requirements for remediation of legacy application limitations or exceptions to standards• Establish guidelines for timely retirement of non-conforming assets or applications• Serve as a security engineer/consultant on projects, RFP’s & internal/external requests for security specific information.• Take a lead role in conducting security research on threats and remediation techniques/ technology, make recommendations to the IS/IT teams and oversee their implementation.• Support corporate operational information security responsibilities, including the development maintenance of standards, procedures, and baselines necessary to meet security requirements.• Assist in investigation of network/infrastructure/application security alerts from managed security service provider and in-house security tools.• Assist information risk managers (IRMs) & IT Controls function in conducting risk assessments to evaluate the effectiveness of existing controls and determine the impact of proposed changes to business processes, applications and systems. • Provide security SME support to requests from Audit, Compliance, Legal and/or other control functions.
Build and maintain strong and lasting client relationships through the delivery of value added servicesAssist in engagement management activities, where needed including but not limited to support of:o Assignment of peer reviewers for quality control activitieso Statement of Work creationo Scoping of projectso Project management activities• Support resourcing for engagements• Assist in development of sales collateral• Support identification and closing on sales opportunities• Provide thought leadership and create associated documentation such as presentations and whitepapers
Worcester, Massachusetts, Us
*Participate in cost/benefit analyses of systems, implement cost controls*Anticipate expenses and identify potential budgetary concerns to VP*Review and mange system capacity, utilization and growth*Provide expert support on new system selection and project related initiatives*Implement, manage and refine department processes so there is repeatability and predictability from within the department*Monitor staff workload and adjust assignments accordingly*Ensure team has appropriate resources to complete department goals and objectives*Ensure the timely and accurate exchange of information/data with relevant stakeholders*Define roles and accountabilities for staff*Facilitate cross functional development*Hire, develop and recognize the experience and knowledge/skills/abilities required for a successful team*Provide for the orientation and welcome of new staff*Define performance expectations and goals for staff*Train and mentor staff on the application of policy and procedures, use of supporting systems/applications, appropriate soft skills*Monitor work of individual staff for efficiency, effectiveness and quality. Provide ongoing constructive feedback and guidance to staff*Evaluate staff on achievement of goals and deliverables and assessment of competencies*Mentor staff in their careers to the benefit of the department and organization. Manage performance issues in consultation with Human Resources as appropriate*Establish and maintain an open communication channel with staff*Monitor effectiveness of communication with other groups (internal and external)*Collaborates with VP to implement changes as necessary to ensure an open, productive exchange of information*Represent the department as requested*Act as a senior resource person for team members in all areas of the work*Assist the team in resolving administrative and routine operational issues as they arise. Escalate with internal and external customers as necessary to resolve issues
Worcester, Massachusetts, Us
* Analyzes information security systems and infrastructure to recommend, develop and implement security measures to protect against unauthorized access, modification or destruction. * Implements security policies and procedures in order to protect information. * Maintains and supports network security access issues. * Provides technical support for various security systems and monitors processes. * Monitors performance and provides off hours support when required to resolve issues and perform maintenance. * Knowledge of forensic techniques for investigating incidents, determines root causes and assesses risks, threats and vulnerabilities associated with infrastructure, architecture design and applications. * Works with the Privacy & Security Committee, internal and external audits to determine applicability of risks, remediation, and correction and addresses regulatory issues. * Creates, audits and reports the enforcement of policies, procedures * Contributes to the design and implementation of the BCP/DRP* Monitors systems for unusual or suspicious activity and determines recommendations based on those findings. * Recommends and classifies the severity of security fixes and patches, discovered vulnerabilities and breaches. * Monitors, evaluates and maintains systems and procedures * Responsible for the communication and education of security * Builds teams * Provides senior technical leadership, monitoring and tracking SLA’s * Establishes and manages security administration standards * Provides customer satisfaction * Plans and manages assignments * Effectively manages teams * Establishes best practices * Optimizes business to IT alignment
Alexandria, Virginia, Us
This role is a senior level position providing in depth IT Audit and Information Security Risk Assessment services to financial institutions throughout the country. The services provided are focused on regulatory compliance; including GLBA, FACTA, SOX, and FFIEC Guidance. This position involves participation in the development of the methodologies used throughout the various work programs. I was the lead in the development of the methodologies and deliverables for the company’s Information Technology Control Review service and am presently tasked with redefining the methodologies and deliverables for the company’s Information Security Risk Assessment service. All methodologies are developed in accordance with COBIT and incorporate guidance from ISACA, ISC2, the FFIEC, and the regulatory agencies.The services which I have been directly responsible for providing include:• In depth review of financial core systems including COCC, Jack Henry, OSI, and Fiserv (Premier, Vision, Galaxy) among others• Information Technology (IT) Audit • Sarbanes-Oxley (SOX) IT Audit • GLBA IT Controls Assessment • GLBA Information Security Risk Assessment • Information Technology (IT) Vulnerability Assessment • Information Technology (IT) Technical Vulnerability Assessment • External Vulnerability Assessment (inc. External Pen Test) • Security Awareness (Social Engineering) Assessment • Social Engineering Vulnerability Testing
This role was a senior level information security position providing a wide range of IS/IT Assurance activities to financial institutions throughout the country. The services that I was responsible for providing included:• Network Vulnerability Assessments• Enterprise Security Assessments• Core Application Security Reviews• External Penetration Testing• Social Engineering Exercises• GLBA GAP and Compliance Audits• IS/IT Risk Assessments• IT Strategic Planning Consulting ServicesI was responsible for conducting these activities while also leading and mentoring other junior team members. The activities included performing the actual technical tests, associated personnel interviews, and writing the final reports in a format presentable to Board level management. The final presentation also included occasional in person presentations to the institution’s Board and/or Audit Committee.
Newton, Massachusetts, Us
In this position, I was responsible for the support of all hardware, software, and telecommunications services for the bank. The key responsibilities of this position included:• LAN/WAN design, implementation and management• Network Infrastructure management and security• Telecommunications design, implementation and management• Physical security of hardware & software• Design, Documentation, Implementation, & User Training of all IT related policies and procedures • User and System Access Control Security, Management and Enforcement• Active participation in the development and Implementation of Disaster Recovery Planning, Business Continuity Planning, Risk Assessment and Business Impact Analysis, and Incident Response Planning as they relate to IT and integrate with the business functions of the bank• Implementation, Integration, Management, and Security of multiple Operation Systems such as WinNT, WinXP, Win2000, Win2003 and Novell• Design and Implementation of Data Analysis and reporting tools • Project Management• Keeping current with technology updates and trends • Keeping current with regulatory requirements such as FDIC and FFIEC mandates, GLBA requirements, and applicable IT related laws and regulations• Implementation and Support of all Bank specific software and services such as Fiserv Vision Suite, Fiserv Data Warehouse, Sound Loan Origination, and SER MacroSoft COLD report system.
Quick answers generated from the profile data available on this page.
Dave S. is listed as Seasoned InfoSec Professional, Scrum Master Certified.
Dave S. is based in Orange, Massachusetts, United States.
Dave S. has worked for Optiv Inc, Seeking New Opportunities, Split Limit Studios, Cynet Systems - Contracted To Massdot & Mbta, and Millennium Consulting - Contracted To Emc2.
You can use AeroLeads to view verified contact signals for Dave S., including work email, phone, and LinkedIn data when available.
Dave S. holds Bachelor'S Degree, Business Administration - Management from Fitchburg State University.
Search by job title, company, industry, location, and seniority. Export verified B2B contact data when you need it.
Start free trial Search contacts