With 27 years in information security, I've recognized the need for a transformative approach that goes beyond traditional compliance-focused methods. My philosophy centers on capability-driven strategies, quantitative risk management, and the integration of diverse management principles.If you're interested in discussing innovative, capability-focused approaches to information security, exploring quantitative risk management, or sharing insights about integrating diverse management principles into cybersecurity, I'd be delighted to connect. Together, we can work towards creating more resilient, adaptive, and effective security frameworks for organizations worldwide.Key Aspects of My Approach:• Advocating for capability-focused methodologies like C2M2 and CMMC• Prioritizing quantitative risk management in security processes• Integrating quality management, and agile approaches into information securityI believe effective information security extends beyond technology, encompassing:• Capability-driven security policies• Efficient processes aligned with organizational goals• Flexible security controls adaptable to changing threatsI see the future of information security as:1. Shifting from compliance-centric to capability-driven security models2. Embracing quantitative risk management for informed decision-making3. Seamlessly integrating security capabilities into business processes4. Fostering a culture of continuous improvement in security practicesIn addition to my technical expertise, I bring a unique set of natural strengths to my work. My Kolbe A Index results (Specify: 8, Systematize: 7, Stabilize: 2, Restore: 4) indicate that I excel in detailed analysis, systematic planning, and thoughtful decision-making. These innate tendencies complement my extensive experience in cybersecurity, allowing me to approach complex security challenges with both thoroughness and structure.
-
Solution ArchitectComputacenter Jul 2020 - Oct 2024Greater Toronto Area, Canada• Led complex sales motions, including RFP and proposal preparation for major government and healthcare sector clients, involving detailed analysis of requirements, pricing strategies, and competitive landscapes across a wide range of security technologies and services. • Designed and executed multi-vendor marketing and sales campaigns focused on critical information security topics. One such example was cyber resilience against ransomware, with an emphasis on cyber resilience and business continuity planning in its role as part of a comprehensive security strategy. • Maintained and expanded partnerships within Computacenter's ecosystem, staying current with partner capabilities, participating in technical pre-sales training, and vetting new service partners to augment existing capabilities in areas such as continuous security testing, multi-cloud risk management, and incident response. • Contributed to Computacenter's partner status maintenance through regular technical training across multiple vendors, including Palo Alto Networks, Cisco, Tanium, F5, Tenable, and Splunk, ensuring the company's ability to deliver cutting-edge solutions to clients. -
Senior Manager Cyber SecurityMnp Digital Apr 2010 - Jun 2020Toronto, Ontario, Canada• Delivering a range of security services including readiness reviews, gap analysis, roadmap to compliance, general consulting against PCI, ISO27001, NIST CSF, OSFI, etc.• Delivering a risk assessment services mainly based on the OpenFAIR risk analysis framework.• Developing new information security services and offerings in consultation with business development people and MNP Partners. The focus has been on quantified risk assessments and cyber security maturity.• Overseeing a team of 12 consultants who deliver PCI assessments, security assessments, offensive security and incident response. This included ensuring quality of the work product, client satisfaction, and mentoring of team members in their careers.• Responsibility for the financial performance of the "Cyber Solutions" team. This includes profitability of the division, billable performance of the members of the team, improving performance of year-over-year projects.• Giving talks at various security conferences, client user groups, and specific clients, about cyber security topics, both general and specific.• Delivering a range of PCI services including: PCI DSS readiness reviews, gap analysis, roadmap to compliance, general PCI consulting.• Delivering a risk assessment services mainly based on the OpenFAIR risk analysis framework.• Overseeing a team of between 6 and 12 consultants who deliver PCI assessments, security assessments, penetration testing, and vulnerability assessments. This included ensuring quality of the work product, client satisfaction, mentoring of team members in their careers.• Delivery general security assessment services as needed. This included policy development, security assessments against non-PCI frameworks, and general security consulting work. -
Senior AssociatePwc Feb 2010 - Mar 2010Greater Toronto Area, Canada• Delivering a range of PCI services including: PCI DSS readiness reviews, gap analysis, roadmap to compliance, general PCI consulting.• Delivering a range of network security assessment services including network vulnerability assessments, wireless assessments, penetration testing, database assessments, network architectural review. -
Senior Security ConsultantAllstream Aug 2005 - Jan 2010Greater Toronto Area, Canada• Delivered a wide range of PCI services including: PCI DSS readiness reviews, gap analysis, roadmap to compliance, general PCI consulting, documenting Reports on Compliance, and providing Attestation of Compliance.• Conducted network architecture reviews for perimeter (firewall/VPN), core, and wireless networks including remediation recommendations to improve the security stance of a client’s network environment.• Performed vulnerability assessments against clients’ infrastructure from the application, database, OS, and wired and wireless network perspective. This included external assessments, internal assessments, ASV scans, penetration testing and rogue AP scanning.• Researched existing and potential vulnerabilities to determine false positives, potential risk, possible outcomes, and recommended mitigation.• Developed, and administered, the MTS Allstream PCI ASV program. This included performing the scanning of the Council’s test environment to gain and retain the ASV certification.• Acted as the “National Solution Champion” for the network security service offerings (including network VA, penetration tests, network security, wireless security, DB VA). This included defining the service/solution, preparing marketing collateral, approach/methodology templates, educating the sales team on our capabilities, accompanying sales staff on visits to clients, and coordinating with the cross-Canada team to ensure consistent deliver quality results.• Participated in responses to numerous requests for proposal for potential clients in differing market segments including, financial, retail, and government. This also included developing and delivering presentations when Allstream was a “short listed” vendor.• Presentation of findings to various reporting levels, including front-line technical staff, middle level managers, and executive officers. -
Security Architecture ConsultantCgi Apr 2002 - Jul 2005Greater Toronto Area, Canada• Involved in pursuit of a large multi-party centralized fare payment system. This involved security architecture, including a federated approach to identity management, use of smart cards to hold credentials and monetary value, and wireless and wired connections to a central computing environment.• Coordinated and wrote security sections for a large outsourcing and development bid for a large multinational manufacturer. This bid involved network and telecom infrastructure conceptual design, assessing an existing application for deficiencies in its security model, and recommendations for rearchitecting the application to provide an improved security stance in future revisions.• Designed and deployed a highly available mail environment using various Microsoft technologies, including MS Exchange, MS Active Directory, MS Cluster Services.• Developed and documented a Logical Security Architecture for a major government project. This included network architecture, system architecture, application architecture, and database architecture.• Developed and delivered information security policy for an operational environment.• Delivered security components for application, database, system and network architecture.• Assisted developers with cryptographic messaging application.• Hardening of operating system configuration, both Windows and Solaris servers of various versions, in both network and stand-alone variants, including using some Windows machines in a kiosk fashion.• Specification of firewall and network filtering policy. Including determination of application traffic profile, writing an ACL generation tool for router ACLs, and verification of the filtering policy against previously collected traffic logs.• Involved in customer pursuits, including initial scoping of the requirements, proposal generation, project planning, etc. -
Lan/Wan & Security SpecialistGroup Telecom Feb 2001 - Feb 2002Greater Toronto Area, Canada· Reviewed billing application and process, including the architecture, operating systems, database, application, and processes involved in use of the systems. Recommended changes that were adopted to mitigate risk and reduce exposure to vulnerability.· Performed audit of corporate network architecture, and recommended changes to remedy identified weaknesses, including scalability issues, performance problems, and security deficiencies, · Lead the team responsible for selecting a new enterprise anti-virus product, that will provide automated distribution of signature updates, on-demand and on-access scanning, and a centralized console for managing virus outbreaks.· Spearheaded the effort of hardening existing servers in order to close security vulnerabilities discovered by a third party audit.· Evaluated the security impact of product offerings on Group Telecom systems infrastructure.· Reviewed and approved any changes to existing systems that had potential security implications.· Monitored various security mailing lists and informed application owners about possible threats to their systems.
-
Security SpecialistClearnet Sep 1996 - Jan 2001Greater Toronto Area, CanadaSecurity Specialist (June 1999 – Feb 2001)Conducted comprehensive security reviews of company systems and processesPerformed focused reviews on WAP server cluster, network perimeter architecture, and web portal architectureProvided technical and procedural security expertise across the companyReviewed and approved security-related system changesUpdated and improved existing security policies, writing new ones as neededManaged distributed firewall cluster (10 firewalls nationwide)Designed, deployed, and monitored intrusion detection system (4 network sensors, 100+ host sensors)Performed ongoing vulnerability assessments and assisted with remediationMonitored security mailing lists and informed application owners of potential threatsAdministered external DNS systemInvestigated load balancing and SSL acceleration for myclearnet.com portalNetwork Engineer (March 1998 - June 1999)Designed and implemented perimeter network and security architecture for Internet point of presenceContributed to design, evolution, and maintenance of national IP backboneDesigned, deployed, and maintained iDen mobile IP infrastructureEngineered and installed PCS circuit switched data infrastructureImplemented backbone router performance monitoring systemNetwork Analyst (May 1997 – March 1998)Evaluated, selected, deployed, and administered performance management systems for two wireless networksShared pager responsibilities for network equipmentInternet Developer (Sept 1996 – Dec 1996)Designed and developed email delivery system for MIKE handsetRedesigned web-based message delivery system for MIKE handset
Jason Murray Education Details
-
Applied Science -
Computer Engineering
Frequently Asked Questions about Jason Murray
What is Jason Murray's role at the current company?
Jason Murray's current role is Solution Architect at Computacenter.
What schools did Jason Murray attend?
Jason Murray attended University Of Waterloo, University Of Toronto.
Not the Jason Murray you were looking for?
-
2kleinlyons.com, emlawyers.ca
-
Jason Murray
Toronto, On -
2computershare.co.uk, computershare.com
-
Jason Murray
Victoria, Bc
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial