David Alston work email
- Valid
- Valid
- Valid
- Valid
David Alston personal email
- Valid
David Alston phone numbers
A results-driven Cyber Security Engineer with over 20 years of experience in Information Security, Data Privacy and Protection, and Governance, Risk and Compliance. CISSP and CIPP certified, with extensive knowledge of cloud service models, technical and data safeguards, and regulatory standards such as HIPAA and NIST.
-
Cyber Security EngineerDexian Sep 2021 - Jun 2024Mclean, Virginia, Us• Collaborate with the CareFirst BlueCross BlueShield Cyber Security and IT Operations teams on developing and implementing data protection and DLP solutions based on NIST and HIPAA guidelines.• Provide project and technical guidance on deploying data protection tools such as Microsoft Purview Information Protection and Netwrix StealthAudit to ensure compliance with HIPAA and other relevant regulatory standards.• Manage project planning throughout design/implementation phases for data access controls that include determining sensitive data standards, searching file systems, creating custom workflows and reports, and access limitation.• Develop and implement data protection solutions and controls, such as data access governance, data classification, data discovery, DLP, and IRM, that align with CareFirst business, technology, and regulatory drivers to improve security posture and reduce risk exposure of sensitive data across cloud and on-premise environments. • Establish and revise security standards and technical criteria for data security and compliance requirements such as data classification and secure data transfer in line with HIPAA, FIPS, and NIST security/privacy guidance to enhance management of confidential data across cloud and on-premise environments.• Perform reviews/assessments of third-party DLP, data protection and cybersecurity training vendors and solution providers.• Assist with the development of CareFirst's role-based / targeted cybersecurity training program, including drafting workforce communications, creating targeted cybersecurity training plans, and evaluating third-party vendors. -
It Risk ManagementFreddie Mac Sep 2019 - Feb 2021Mclean, Va, Us• Led projects related to risk assessments of internal technology processes, current and emerging risks, and evaluation of design and implementation of existing and target state controls.• Provided guidance and recommendations regarding existing and target state on-premise and cloud-based technology solutions.• Advised management and technology stakeholders on risk-related matters to technology programs and activities, including documenting and evaluating IT processes, risks, and controls.• Assisted security and infrastructure teams with establishing and adhering to new and existing technology processes, procedures, and standards. -
Senior Cyber Security AnalystElectrosoft Mar 2019 - Aug 2019Reston, Va, Us• Evaluated Nessus compliance and vulnerability scan findings for AWS cloud-hosted applications; coordinated with stakeholders to address and remediate vulnerability scan findings.• Acted as the point of contact between IT project teams throughout the security assessment lifecycle, including organizing security assessment-related artifacts, developing, and maintaining system security documentation, reviewing results of the security assessment.• Coordinated with system stakeholders to remediate Corrective Actions and Plan of Action and Milestones (POA&Ms) of security vulnerabilities, and weaknesses identified through vulnerability scans and/or security assessments. -
Senior It Risk AdvisorFannie Mae Apr 2016 - Nov 2018Washington, District Of Columbia, Us• Trusted risk advisor to Fannie Mae management on matters related to technology and information security programs and activities.• Executed risk assessments related to subsets of internal technology and information security processes, including assessing design, effectiveness, and implementation of existing and target state control environments.• Implemented IT/security dashboards and metrics (e.g., Key Risk Indicators, Key Performance Indicators) for cyber/information security and technology processes, platforms, and applications.• Assisted stakeholders with identifying and evaluating existing and emerging risks and corresponding technology and security controls.• Addressed IT and Cybersecurity risk events which caused an adverse impact on the availability or quality of IT/security related services, which included performing root cause analyses, specifying reputational, financial, or technical impact, identifying control gaps, and corrective actions. -
Senior Cyber Security Engineer / Privacy EngineerCsra Inc Sep 2013 - Mar 2016Falls Church, Va, Us• Privacy Engineering Subject Matter Expert (SME) assigned to the TSA Secure Flight program.• Ensured compliance with privacy controls and data governance requirements, including internal directives, Privacy Impact Assessments, System of Record Notices (SORNs), data retention schedules, and uses of data throughout the Data Lifecycle.• Reviewed formal information sharing agreements, e.g., Memorandums of Understanding (MOUs), regarding shared data elements, information sharing purposes, and retention periods. -
Senior Systems ArchitectUrs Corporation Oct 2011 - Mar 2013San Francisco, Ca, Us• Designed and integrated cyber security solutions and proposed design recommendations and strategies, consisting of Identity and Access Management (IAM) and Network Data Loss Prevention (NDLP), into SEC enterprise infrastructure and processes.• Architected IAM and NDLP system design, production implementation strategies and use cases, including researching applicable information security standards and system architecture, identifying integration issues and risk, and scoping technical and logical system boundaries.• Performed analysis of vulnerability management systems which directly addressed systemic issues within the operational security domain, determined contributing factors to the varying outputs of the vulnerability management systems, and provided recommendations on achievable enterprise-wide solutions. -
Information Security SpecialistChickasaw Nation Industries, Inc. Apr 2010 - Oct 2011Norman, Ok, Us• Provided guidance on implementing security controls in accordance with FISMA, NIST SP 800-53 and other applicable NIST publications.• Analyzed vulnerability and compliance scan reports to assess the security posture of FDA systems.• Responsible for the management and execution of Plan of Action and Milestones (POA&Ms), including remediating or mitigating weakness findings.
David Alston Skills
David Alston Education Details
-
University Of Maryland Eastern ShoreComputer Science
Frequently Asked Questions about David Alston
What is David Alston's role at the current company?
David Alston's current role is Cyber Security Engineer | CISSP, CIPP/G.
What is David Alston's email address?
David Alston's email address is da****@****ail.com
What is David Alston's direct phone number?
David Alston's direct phone number is +170364*****
What schools did David Alston attend?
David Alston attended University Of Maryland Eastern Shore.
What skills is David Alston known for?
David Alston has skills like Computer Security, Information Security Management, Information Security, Security, Network Security, Servers, Enterprise Architecture, Vulnerability Management, Windows Server, Networking, Disaster Recovery, Fisma.
Free Chrome Extension
Find emails, phones & company data instantly
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial