Duane Patterson, Cissp

Duane Patterson, Cissp Email and Phone Number

IT Security Governance, Risk, and Compliance (GRC); and Process/Procedure Leader @ Kansas Office of Information Technology Services
Topeka, KS, US
Duane Patterson, Cissp's Location
Topeka, Kansas, United States, United States
Duane Patterson, Cissp's Contact Details

Duane Patterson, Cissp personal email

About Duane Patterson, Cissp

In this fast-changing IT/IS Security world we live in, you need someone who can adapt quickly to learn new skills and facilitate change honestly and ethically to enable smooth transitions and continuous improvement. I am an advocate for process and procedure standards. I helped author, support, and test for compliance, several IT project management, methodology and security standards. My peers regard me as a highly detail oriented analytical problem solver with the ability to relate at their various levels clearly and concisely. I possess a Public Trust Fitness Determination of 6C (Tier 4, Critical-Sensitive).• 35+ years in IT/IS Information Technology (IT) / Information Systems (IS) o Managed compliance for IT/IS development and Change Management (CM) processes o Well versed in SDLC methodologies and project management procedures o Established procedures for environment with 15+ developers working on an average of 25-30 projects daily to prevent unauthorized updates to object o Managed complex relational database for Dairy Industry ERP system.• 10+ years in IT/IS Security Compliance o NIST SP 800-53, Risk Management Framework (RMF), Cybersecurity Framework (CSF) o Maintain documentation (SSP, CP, BIA, CMP, IRP, DRP, PTA, PIA, SIA, MOU, ISA, SORN, etc.) o FISMA Assessments for Authority to Operate (ATO)• 25+ years using a variety of IT/IS development, CM and Governance, Risk and Compliance (GRC) tools#NIST #800-53 #RMF #CSF #FISMA #GRC #compliance

Duane Patterson, Cissp's Current Company Details
Kansas Office of Information Technology Services

Kansas Office Of Information Technology Services

View
IT Security Governance, Risk, and Compliance (GRC); and Process/Procedure Leader
Topeka, KS, US
Duane Patterson, Cissp Work Experience Details
  • Kansas Office Of Information Technology Services
    Kansas Office Of Information Technology Services
    Topeka, Ks, Us
  • Kansas Office Of Information Technology Services
    Information Security Officer
    Kansas Office Of Information Technology Services Jan 2023 - Present
    Topeka, Kansas, Us
    Supported state agencies OITS, Dept. of Corrections and Highway Patrol:• Created/Maintained IT Security policy, procedure, guideline and related documents to comply with state laws, NIST SP 800-53, RMF, CSF, and Criminal Justice Information Services (CJIS)• Performed IT Security GRC assessment and audit support services• Organized MS Teams and SharePoint for optimal team collaboration• Provided OITS liaison services during major cybersecurity breach recovery at KS Judicial Center• Submitted process improvements suggestions to management• Performed required periodic continuous monitoring activities• Created and performed Security Awareness presentations and tips sent via email
  • General Dynamics Information Technology
    Grc Information Security Analyst Advisor
    General Dynamics Information Technology Jun 2022 - Oct 2022
    Falls Church, Virginia, Us
    Supported US Dept. of Veterans Affairs (VA):• Assisted with creation of DevSecOps SOP documentation.• Organized MS Teams and SharePoint for optimal team collaboration.• Provided IT security compliance expertise.
  • Ls3 Technologies, Inc.
    It Security Compliance Analyst
    Ls3 Technologies, Inc. Dec 2019 - Jun 2022
    Crofton, Maryland, Us
    Supported multiple teams at US Dept. of Agriculture (USDA) and US Dept. of Education (ED):• Supported ATO Assessments to demonstrate compliance with NIST SP 800-53.• Provided FISMA audit support using NIST CSF and RMF.• Created/Maintained standard operating procedure (SOP), policy and directive documents.• Created/Maintained Memorandum of Understanding (MOU) and Interconnection Security Agreement (ISA) documents.• Created/Maintained Implementation Statements in CSAM tool for generating System Security Plan (SSP).• Created/Maintained Inheritance relationships in CSAM.• Generated a variety of reports as needed from CSAM.• Created/Monitored Plan of Action and Milestones (POAM) in CSAM.• Created/Maintained privacy documents, including Privacy Threshold Analysis (PTA), Privacy Impact Analysis (PIA) and System of Record Notice (SORN) to reduce compromising Personally Identifiable Information (PII).• Created/Maintained Security Impact Analysis (SIA) used to comply with Change Control Management.• Created/Maintained ICAM intranet website, including cybersecurity news articles, using SharePoint.• Implemented process improvements by organizing email and SharePoint folder structures.• Performed required periodic continuous monitoring activities.• Created presentations for training and demonstration to executives and all levels of development personnel.• Met daily with Subject Matter Experts (SMEs) using Microsoft Teams and various online meeting apps.• Utilized Planner tool within Microsoft Teams and Atlassian Jira for project management.
  • Spry Methods, Inc.
    Fisma Compliance Specialist
    Spry Methods, Inc. Jan 2019 - Oct 2019
    Mclean, Virginia, Us
    Supported the US Dept. of Interior (DOI), Bureau of Reclamation (BOR):• Performed ATO Assessments to demonstrate compliance with NIST SP 800-53.• Provided FISMA audit support using NIST CSF and RMF.• Created/Maintained standard operating procedure (SOP), policy and directive documents.• Created/Maintained Implementation Statements in CSAM tool for generating System Security Plan (SSP).• Created/Maintained Inheritance Relationships in CSAM.• Generated a variety of reports as needed from CSAM.• Created/Monitored Plan of Action and Milestones (POAM) in CSAM.• Created/Maintained privacy documents, including Privacy Threshold Analysis (PTA) and Privacy Impact Analysis (PIA) to reduce compromising Personally Identifiable Information (PII).• Created/Maintained Security Impact Analysis (SIA) used to comply with Change Control Management.• Implemented process improvements by organizing SharePoint folder structures.• Performed required periodic continuous monitoring activities.• Created presentations for training and demonstration to executives and all levels of development personnel.• Provided weekly status reports to management. Some included exports from Jira.
  • Nelnet
    It Risk Analyst, Compliance
    Nelnet Aug 2013 - Jan 2019
    Lincoln, Nebraska, Us
    • Managed annual IT self-assessment in compliance with NIST RMF for over 60 systems to maintain Department of Education, Federal Student Aid, Authority to Operate (ATO).• Conducted continuous monitoring for FISMA compliance for IT General Controls (ITGC), Software Development Life Cycle (SDLC) methodology and change management processes.• Reviewed/Updated System Security Plans (SSP) quarterly in compliance with NIST SP 800-53.• Created presentations for training and demonstration to executives and all levels of development personnel.• Performed required periodic continuous monitoring activities to produce metrics documentation.• Facilitated continuous monitoring results review meetings with leadership personnel.• Contributed to discussions regarding process improvement for Agile and Waterfall methodology policies and standard operating procedure (SOP).• Created annual Computer Based Training for Information Systems Security Officers (ISSO).
  • Body And Sole Healing Connection
    Owner, Business Manager
    Body And Sole Healing Connection Jan 2012 - Sep 2016
    Lakewood, Co, Us
    • Launched alternative complimentary healthcare business.• Developed business plan, IT infrastructure, and all aspects of marketing.• Received local media awards and built relationships in chamber of commerce through marketing efforts and public speaking.
  • Dean Foods
    Deployment Manager
    Dean Foods Jun 1999 - Feb 2012
    Kansas City , Ks, Us
    • Established change management procedures for environment with 15+ developers working on an average of 25-30 projects daily to prevent unauthorized updates to objects.• Maintained development environment providing 3 levels of secure testing (unit/system, regression, and user acceptance) before promotion to production environments.• Maintained Software Development Life Cycle (SDLC) manual establishing Requirements gathering, Development, QA testing, and Implementation methodology. • Managed Sarbanes-Oxley (SOX) IT General Controls (ITGC) compliance for development and deployment process earning public commendation from CIO.• Implemented new Change Management (Deployment) tool for the automated promotion of an average of 30-50 objects in weekly software updates to over 60 production sites. • Collaborated with Change Control tool vendor to add Project Management component to aid in status tracking of approximately 50-60 active projects.• Trained new, and mentored all, employees in proper use of all above documents and tools.• Facilitated migration of Microsoft Office documents from local server to SharePoint to support collaborative updating by team.
  • Dean Foods
    Database Architect
    Dean Foods Jun 1999 - Feb 2012
    Kansas City , Ks, Us
    • Modeled complex relational database for Dairy Industry ERP system using design tools such as MS Visio.• Ensured relational database integrity rules for IBM midrange (AS400, iSeries, System i) using LANSA development tool to prevent the deletion of vital data, while also safely purging unneeded data.• Created documentation procedure to clearly communicate needs and identify relationships for an average of 50-70 file/table definition changes per year.
  • Dean Foods
    Sr. Software Engineer
    Dean Foods Jun 1999 - Feb 2012
    Kansas City , Ks, Us
    • Re-engineered application for customer who was displeased with initial implementation. Business analysis with end users revealed workflow improvements. I delivered a presentation to executive management which resulted in an additional $40,000 in consulting fees for successful completion of project.• Maintained over 50-page manual defining programming and design standards for a complex Dairy Industry ERP system providing a consistent appearance and operation. Trained new employees and provided continuous mentoring to all employees regarding compliance with these standards.• Assisted QA and users with testing to assure all test cases were evaluated.• Researched new technologies to determine whether they provided productive business benefits and ROI.
  • Lansa
    Pre-Sales Application Consultant
    Lansa Jul 1998 - Jun 1999
    Austin, Tx, Us
    • Partnered with salesman to generate the largest sale in LANSA history.• Demonstrated software development tools to audiences ranging from personal to group presentations of 10–20 developers, project leaders, IT managers and executive management to illustrate gains in productivity by using these tools. • Re-designed standard demonstration to show customers how they can create a complete maintenance suite application in less than 30 minutes.• Developed proof-of-concept projects to convince the prospective customer of the tool’s increased productivity value in their current system.• Addressed concerns of development staff regarding the tool’s value to them and eased their transition toward learning a new technology.
  • Synon, Inc.
    Pre-Sales Application Consultant
    Synon, Inc. Jul 1996 - Jun 1998
    • Demonstrated software development tools to audiences ranging from personal to group presentations of 10–20 developers, project leaders, IT managers and executive management to illustrate gains in productivity by using these tools. • Developed proof-of-concept projects to convince the prospective customer of the tool’s increased productivity value in their current system.• Addressed concerns of development staff regarding the tool’s value to them and eased their transition toward learning a new technology.
  • Excel Corporation - A Division Of Cargill
    Senior Programmer / Analyst / Team Leader
    Excel Corporation - A Division Of Cargill Sep 1994 - Jul 1996
    • Convinced IT management to conduct research project using new tool to graphically document existing system. Provided data models for complex database and process flow diagrams to help identify areas for process improvement, resulting in lower cost development.
  • Cessna Aircraft Company
    Senior Programmer / Analyst / Team Leader
    Cessna Aircraft Company Sep 1993 - Sep 1994
    • Created and maintained online Tips & Techniques and Development Standards manuals to improve programming methods and implementation of Object Oriented techniques. Manuals provided faster development of more efficient code for entire team and consistent design of user friendly screens.• Developed QA system to facilitate and track testing.• Established Synon User Group to educate development team in an inexpensive and collaborative manner. Negotiated with local IBM office for use of facility, persuaded developers at local businesses to attend. Regularly attended by 10-20 developers per meeting.
  • Csc Partners
    Senior Programmer / Analyst / Team Leader
    Csc Partners Apr 1992 - Sep 1993
    • Trained developers to use Synon development tool using combination of lecture and practice exercises. Continued students’ education through mentoring while working on projects together.• Facilitated workshops for Business Systems Analysis & Redesign of our local office Project Management methodologies. Incorporated these methodologies as a team leader on 2 large projects for Cargill.

Duane Patterson, Cissp Skills

Team Leadership Requirements Analysis Relational Databases Data Modeling Software Development Lansa Change Control Organizing Microsoft Office Visio Ibm Iseries Detail Orientation Strong Business Acumen Fast Learner Persistence Technical Presentations Public Speaking Staff Mentoring Coaching Classroom Training Sales Support Business Analysis Software Documentation Management Training Quality Assurance Sharepoint Process Improvement Leadership Project Management Software Project Management Change Management Databases Testing Requirements Gathering Business Process Business Process Improvement Small Business Marketing Communications Sdlc Mentoring Software Development Life Cycle Business Development Marketing

Duane Patterson, Cissp Education Details

  • University Of Nebraska-Lincoln
    University Of Nebraska-Lincoln
    Business Administration

Frequently Asked Questions about Duane Patterson, Cissp

What company does Duane Patterson, Cissp work for?

Duane Patterson, Cissp works for Kansas Office Of Information Technology Services

What is Duane Patterson, Cissp's role at the current company?

Duane Patterson, Cissp's current role is IT Security Governance, Risk, and Compliance (GRC); and Process/Procedure Leader.

What is Duane Patterson, Cissp's email address?

Duane Patterson, Cissp's email address is du****@****ail.com

What is Duane Patterson, Cissp's direct phone number?

Duane Patterson, Cissp's direct phone number is +140246*****

What schools did Duane Patterson, Cissp attend?

Duane Patterson, Cissp attended University Of Nebraska-Lincoln.

What are some of Duane Patterson, Cissp's interests?

Duane Patterson, Cissp has interest in Football, Community Theater, Social Services, Backyard Projects, Religious Scholarship, Gardening, Snorkeling, Civil Rights And Social Action, Economic Empowerment, Education.

What skills is Duane Patterson, Cissp known for?

Duane Patterson, Cissp has skills like Team Leadership, Requirements Analysis, Relational Databases, Data Modeling, Software Development, Lansa, Change Control, Organizing, Microsoft Office, Visio, Ibm Iseries, Detail Orientation.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.