Sr. Security Engineer
CurrentFunction as the lead representative of security during on site customer and external auditor network security assessments, audits, risk assessments and vulnerability testing. Developed policies and designed security controls and risk mitigation strategies to address audit finding and client contractual requirements. Identified as being instrumental in the creation of a cultural of security and compliance. Function as the lead interface to key vendors and technology suppliers. Provide direct oversight, direction and guidance to vendors and contractors performing desktop support, PC security patching, Firewall/IPS/IDS MSSP, WAN/LAN management, PC Antivirus and hands on day to day security remediation efforts.Led the design, implementation, and daily operation of key innovative security technologies deployed by Acosta to ensure cost effective compliance with ISO 27001/27002 controls standards and industry best practices. Responsible for effective communications and direct interaction with project managers, business relationship managers, application developers, data center services, platform support services and our external clients to meet organizational needs and delivery requirements while also addressing security and compliance concerns. Performed oversight and auditing of external suppliers, business partners and clients who connect to our network or systems. Primary author of all posted security policies and accountable for IT general controls and compliance standards gap analysis. Performed password compliance audits using a variety of open source and commercial tools. Designed the architecture and performed day to day management of the distributed vulnerability management and remediation system used throughout the enterprise. Responsible for auditing organizational firewall rules and data flows and for providing guidance on the proper placement of physical security and technical access controls for key technology platforms.