Frederick D Cox, Cissp

Frederick D Cox, Cissp Email and Phone Number

Information Security - Retired @ FDC Associates, LLC
Frederick D Cox, Cissp's Location
Palo Alto, California, United States, United States
Frederick D Cox, Cissp's Contact Details
About Frederick D Cox, Cissp

Information Security and cyber risk management thought-leader with executive presence and extensive experience in financial and clinical information security environments, with a strong understanding of IT compliance, security architecture, auditing, and third party management, including:•Network & Application Security•Breach Response Management•Cloud-Based Security•Third Party and Vendor Risk Management•Develop, Implement and Monitor Strategic IT Risk Management Programs•Establish and Maintain a Company-wide Information Security Program•Maintain and Publish up-to-date Information Security Policies, Standards and GuidelinesSSAE 16 SOC2 | FFIEC | HIPAA | HITECH Security reviews | Security Best Practices. Subject matter expert Information Security Risk Assessment, Security Architecture, Technical security.Author – “Information Security: Risk Management of GLBA and Service Provider Oversight”. (Amazon e-Book).

Frederick D Cox, Cissp's Current Company Details
FDC Associates, LLC

Fdc Associates, Llc

View
Information Security - Retired
Frederick D Cox, Cissp Work Experience Details
  • Fdc Associates, Llc
    Ceo And Founder
    Fdc Associates, Llc Jul 2006 - Present
    Key Accomplishments:- Identified security control points for Oracle monitoring of network infrastructure security, (Defined Security infrastructure, Server and Firewall Configuration metrics, acceptable / failure definitions matrix and Application Separation of Duties, Access violation attempts etc.) that was used to create the GRC Security operations dashboard. - Zero data breach events for all Security Architecture clients.- Achieved no material weaknesses for SOX clients, and automated 90% of SOX testing.- Created Information risk management process that included: • Risk analysis and management, identification of information risk• Information Security training and response program• Information Security Awareness program• Off-site access and use of ePHI from remote locations; • Storage of electronic Protected Health Information on portable devices and media; • Disposal of equipment containing electronic Protected Health Information; • Business associate agreements and contracts; • Data encryption; • Virus protection; • Technical safeguards in place to protect information assets and electronic Protected Health Information; and • Monitoring of access to electronic Protected Health Information.
  • Varian Medical Systems
    Retired - Director Information Security
    Varian Medical Systems May 2015 - Apr 2022
    Palo Alto, Ca, Us
    Retired
  • Himss
    Member Of The Himss Identity Management Task Force And Himss Risk Assessment Task Force
    Himss Jun 2014 - 2017
    Chicago, Il, Us
    I am a contributing member of the HIMSS Identity Management Task Force and of the HIMSS Risk Assessment Work Group. | Identity Driven Enterprise ( Information Security) Architecture [IDEAs] subject matter expert - Enterprise Architecture and Information Security
  • John Muir Health
    Interim Chief Information Security Officer - Ciso
    John Muir Health Nov 2014 - May 2015
    Walnut Creek, Ca, Us
    I developed a risk based entity wide strategy for the hospitals Information Security Compliance program - integrated with their EPIC EMR, including guidance for their HIPAA Security Rule, Privacy Rule and Breach Notification Rule Compliance efforts. - Created an action plan to achieve PCI 3.1 compliance.
  • Nthrive
    Ciso - Director Of Information Security
    Nthrive Mar 2012 - Oct 2014
    Plano, Tx, Us
    Developed, implemented, and maintained an Enterprise-wide information security program that defined security infrastructure that supported the business strategic plan and goals. Provided the design of and leadership for IT Security, including prioritizing and leading security and compliance (PCI and HIPAA) initiatives and incident response program accros IT Operations, Applications, Firewall and data. Directed and coordinated IT security (engineers, technical staff, and external resources) in the performance of security functions and provided oversight of external resources and service providers. Subject matter expert on cyber-security risk assessment and risk management programs, [Contributing member of the HIMSS Information Risk Assessment Task Force], Security Architecture, Security Information Event Management (SIEM) and Data Leak Prevention (DLP) technologies.
  • Seacoast Bank
    Vice President Chief Information Security (Ciso )And Privacy Officer
    Seacoast Bank May 2010 - Apr 2012
    Stuart, Florida, Us
    Reported to the Board of Directors as their VP Information Security | Privacy Officer | Dean, College of Compliance and Regulation, Seacoast National University. Developed and implemented an enterprise-wide information security program and security infrastructure. Created an information security awareness program, annually revised corresponding strategic plan and goals. Provided the design of an information security strategy including prioritizing and leading security and compliance initiatives, and implemented the use of a portfolio of controls & safeguards. Directed and coordinated IT security operations (engineers, technical staff, and external resources) in the performance of security functions and provided oversight of external resources and service providers. Subject matter expert on e-commerce and cyber security risk assessment and risk management. Security Architecture, Security Information Event Management (SIEM) and Data Leak Prevention (DLP) technologies. Obtained Satisfactory or higher ratings from the regulators.
  • Oasis Outsourcing
    Sas 70 - Ssae16 Soc2 System Description And Internal Control Design
    Oasis Outsourcing 2006 - 2010
    West Palm Beach, Fl, Us
    Created an enterprise-wide SAS70 II, /SOC2 Type II Information Security operations and Control design and process, including Information Risk Analysis and Assessment for this e-commerce PEO. Established a SOC2 control process that obtains unqualified opinions and a strong security posture.
  • Accume Partners
    Director Information Security
    Accume Partners 2000 - 2006
    Jersey City, Nj, Us
    Managing Director - IT Security | Audit ServicesManaging Director, IT Security and Audit Services (May 2003 – June 2006) Directed, planned, and managed all aspects of the IT Security and Audit practice for the New York and Florida office. Audit effort included Firewall Internet Vulnerability testing, COBIT based SOX 404 reviews for over 40 firms. Third Party Controls, SAS 70’s (Type II), IT General controls, / entity level control reviews. Managed a staff of fifteen to twenty (15 to 20) professionals. RACF, AS/400, Windows NT, Oracle GRC Migration. FFIEC Guidance expert, Achieved Regulatory compliance with FRB, FDIC, OCC for all clients.
  • Sumitomo Mitsui Banking Corporation
    Vp Information Security Audit
    Sumitomo Mitsui Banking Corporation 1997 - 2000
    Tokyo, Jp
    VP | IT AuditorVice President and Project Manager, Year 2000 Project (Y2K) - February 1998 – April 2000Managed the Y2K project for the Bank. Liaison between Information Technology and Management to scope, and verify the functionality of the Bank’s computer systems for the Y2K transition. Managed multiple Bank departments (clients) needs and projects, integrating Y2K and regulatory concerns simultaneously.Vice President and Information Technology Auditor - December 1997 – January 1998Directed the Information Technology Audit program for bank operations in the Americas (North and South America), including annual audit scope, planning, staffing and presenting audit reports to the Audit Committee.
  • Bank Of Tokyo-Mitsubishi
    Information Security
    Bank Of Tokyo-Mitsubishi 1996 - 1997
    Chiyoda-Ku, Tokyo, Jp
    Senior IT AuditorTogether with the IT Audi team at Bank of Tokyo, we implemented a risk assessment methodology that was used to focus the Internal Audit department's efforts and address higher risk areas first, and as a basis for the annual audit planning effort.
  • Salomon Brothers
    Information Security | Information Technology Auditor
    Salomon Brothers 1993 - 1994
    Senior Technology AuditorResponsible for audits of front, middle and back operations, including derivative trading (CAPS, Floors, Swaps and Options), futures and options. Conducted Information Technology and Assurance audits of wire transfer and out-trading. Established data mining program using ACL
  • Jp Morgan
    Information Security | Information Technology Audit
    Jp Morgan 1989 - 1993
    New York, Ny, Us
    Assistant TreasurerAssistant Treasurer (formerly titled Information Technology Auditor Officer)Responsible for audits/reviews in private banking, futures/options, and third party software, (McCormick & Dodge) accounts payable, payroll, and general ledger. Performed additional third party reviews on mortgage-backed securities vendor, (Cantor Fitzgerald) and Global Custody, using Dyatron’s International Information Security Processing System
  • Us Navy
    Information Security | Edp Audit
    Us Navy 1985 - 1989
    Washington, Dc, Us
    Senior IT AuditorManager EDP Auditing Created a global Technology Audit Department from scratch for NAVRESSO. Received a Citation for excellence from the GAO

Frederick D Cox, Cissp Skills

Security Information Technology Computer Security Risk Assessment Sas70 Risk Management Hipaa Cisa Management Cobit Cloud Computing Information Security Management Cissp Business Continuity Vulnerability Management Identity Management Security Architecture Design Pci Dss Information Security Information Assurance Enterprise Risk Management Program Management Cism It Risk Auditing It Governance U.s. Health Insurance Portability And Accountability Act Data Privacy Iso 27001 Information Technology Audit Cyber Security Ssae 16 It Audit Risk Analysis Dlp Ffiec Supply Chain Security Service Provider Security Oversight Crisc Policy Writing Data Leakage Ehr

Frederick D Cox, Cissp Education Details

  • Harvard T.H. Chan School Of Public Health
    Harvard T.H. Chan School Of Public Health
    Executive And Continuing Professional Education - Effective Risk Communication -
  • Carnegie Mellon University - Tepper School Of Business
    Carnegie Mellon University - Tepper School Of Business
    Management
  • Tulane University
    Tulane University
    Corporate Governance
  • University Of California, Santa Cruz
    University Of California, Santa Cruz
    Economics And Bachelors Psychology

Frequently Asked Questions about Frederick D Cox, Cissp

What company does Frederick D Cox, Cissp work for?

Frederick D Cox, Cissp works for Fdc Associates, Llc

What is Frederick D Cox, Cissp's role at the current company?

Frederick D Cox, Cissp's current role is Information Security - Retired.

What is Frederick D Cox, Cissp's email address?

Frederick D Cox, Cissp's email address is fr****@****ian.com

What is Frederick D Cox, Cissp's direct phone number?

Frederick D Cox, Cissp's direct phone number is +156142*****

What schools did Frederick D Cox, Cissp attend?

Frederick D Cox, Cissp attended Harvard T.h. Chan School Of Public Health, Carnegie Mellon University - Tepper School Of Business, Tulane University, University Of California, Santa Cruz.

What are some of Frederick D Cox, Cissp's interests?

Frederick D Cox, Cissp has interest in Collecting Antiques, Home Improvement, Reading, Gourmet Cooking, Sports, The Arts, Home Decoration, Photograph, Cooking, Electronics.

What skills is Frederick D Cox, Cissp known for?

Frederick D Cox, Cissp has skills like Security, Information Technology, Computer Security, Risk Assessment, Sas70, Risk Management, Hipaa, Cisa, Management, Cobit, Cloud Computing, Information Security Management.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.