Jamie Tomasello work email
- Valid
- Valid
Jamie Tomasello personal email
- Valid
Jamie Tomasello phone numbers
Security technology and policy leader with a strategic focus on practical, sustainable operations and outcomes aligned with business risk. Builds trust with internal teams and external customers through inclusive & accountable actions. Has repeated success hiring and building global multidisciplinary security operations, compliance, and trust and safety teams. Architects global policies, procedures, and investigations. Leads and directs security and compliance initiatives including PCI-DSS, SOC 2, and FedRAMP across engineering, legal, product, and security departments. Advises executive, legal, policy teams, and government officials on cybersecurity, trust and safety, data protection, and privacy issues.Specialties: Policy creation, subpoena compliance, incident response, information security, operational security, anti-abuse, trust and safety, risk assessments, vulnerability management, vendor security assessments, security awareness training, insider threats, gap analysis, audits, FedRAMP, PCI-DSS, SOC 2, spam, phishing, counterfeit pharmaceuticals, investigation and analysis, intelligence collection, behavior analysis, pattern recognition, non-obvious relationships, big data, cyberlaw, privacy, and transparency reports.
-
Senior FellowSuperbloomAnn Arbor, Mi, Us -
Managing DirectorSuperbloom Aug 2023 - PresentNew York, New York, Us -
Advisor, Operations And SecuritySuperbloom Mar 2023 - Aug 2023New York, New York, Us -
FounderKeel Paradox May 2023 - Present -
Startup MentorTechstars Detroit Powered By J.P. Morgan Sep 2022 - PresentDetroit, Michigan, Us -
Board AdvisorBytechek Dec 2020 - Dec 2022Miami, Fl, Us -
Chief Operating OfficerBytechek Mar 2022 - Jul 2022Miami, Fl, Us -
Vice President Of OperationsBytechek Feb 2022 - Mar 2022Miami, Fl, Us -
Head Of Security Programs And GrcGusto Apr 2021 - Jan 2022San Francisco, California, Us -
Peer ReviewerFord Foundation Nov 2020 - Apr 2021- Conducts peer review and provides feedback and guidance on the Cybersecurity Assessment Tool.
-
Head Of Trust And ComplianceDuo Security Aug 2019 - Mar 2020Ann Arbor, Mi, Us -
Head Of Security Operations And ComplianceDuo Security Oct 2018 - Aug 2019Ann Arbor, Mi, Us -
Senior Manager, Security OperationsDuo Security Jan 2018 - Oct 2018Ann Arbor, Mi, Us- Led security operations team of information security analysts across three time zones responsible for risk management, vulnerability management, incident response, security awareness training, phishing simulations, and vendor security assessments.- Provided guidance on NIST SP 800-37, 800-53, 800-61, 800-63, 800-171, and PCI-DSS compliant policies, procedures, controls, and implementations to engineering, sales, and legal teams.- Drove Credential Service Provider (CSP) compliance and audit initiatives to meet DEA requirements for Electronic Prescribing Controlled Substances (EPCS).- Developed insider threat detection and mitigation strategies.- Developed FedRAMP compliant policies and procedures and reviewed the development of compliant technical controls.- Presented at True University on “Breaking Down Silos with Human-Centric Multidisciplinary Approaches”, and at Society of Environmental Journalists 28th Annual Conference on “Keeping Your Data Safe and Secure”. -
Manager, Trust And ComplianceDuo Security Jul 2016 - Dec 2017Ann Arbor, Mi, Us- Built a multidisciplinary Trust and Compliance team within Duo’s Security department to provide sales enablement services to address how Duo meets information security framework requirements and how Duo’s products help customers meet their compliance and regulatory needs.- Evolved Duo’s information security policy, business continuity and disaster recovery plan, incident response plan, data classification policy, and vendor security assessments to be in alignment with NIST SP 800-53 and ISO 27001 and 27002.- Successfully led cross team initiatives to complete SOC 2 Type 2 and customer-initiated audits.- Conducted semi-annual risk assessments- Partnered with legal team on contract reviews.- Analyzed FedRAMP technical and policy requirements and drafted initial strategy for FedRAMP authorization.- Presented at M3AAWG on “Lessons Learned from Phishing Assessments”, and at University of Michigan’s Influence Panel: Women in Computing -
Board Advisor, Trust And SafetySift Science Mar 2015 - Oct 2016San Francisco, California, Us- Advised organization on building brand reputation based on Trust and building company culture around privacy and security by design.- Advised CEO, sales, marketing, and compliance team on email best practices, US - EU Safe Harbor, privacy, data protection, data ethics, and working with law enforcement.- Provided guidance on PCI-DSS, ISO 27001, ISO 27002, SOC 2 Type 2 gap analysis, compliance, and audit process.- Provided guidance on information security and operational security best practices and policies. -
Technology DirectorAccess Now Dec 2014 - Jun 2016New York, Ny, Oo- Managed a technical organization composed of a 24/7 digital security incident response team, software development engineers, and research staff across five countries.- Set strategic direction for technical initiatives within Access Now.- Provided guidance regarding handling of inbound legal process (subpoenas, court orders, warrants, pen registers, national security letters) and warrant canaries.- Provided advice to funders, foundations, nonprofits, NGOs, and human rights activists regarding information security policies and best practices.- Led Access Now through its first ISO 27001, ISO 27002, and SAFETAG gap analysis and management response.- Drafted Theory of Change processes within the organization.- Presented at Citizen Lab Summer Institute on "Analyzing and Defending Targeted Threats", at Messaging Malware Mobile Anti-Abuse Working Group (M3AAWG) on "Combating Abuse for At-Risk Users", at RightsCon on "Internet Startups and Human Rights". -
Policy And InvestigationCloudflare, Inc. Oct 2012 - Nov 2014San Francisco, California, Us- Managed CloudFlare’s Trust and Safety team to handle inbound privacy, legal, and abuse complaints and escalations.- Served as the Compliance Officer, Custodian of Records, and primary point of contact for law enforcement inquiries, DMCA complaints, and for reporting of child sexual abuse material to the National Center for Missing and Exploited Children.- Evaluated and established CloudFlare’s vulnerability disclosure program.- Established CloudFlare’s security incident response team.- Reviewed all inbound legal process (subpoenas, court orders, warrants, pen registers), created subpoena compliance policy, and responded accordingly.- Authored CloudFlare transparency reports.- Conducted annual privacy policy reviews and obtained U.S. - EU Safe Harbor for CloudFlare.- Drafted and established PCI compliant policies and procedures.- Led CloudFlare through its first PCI-DSS assessment as a level 1 service provider.- Worked with Enterprise customers to address compliance and information security concerns and completes due diligence questionnaires.- Conducted information security, privacy, and data protection evaluations of CloudFlare vendors.- Provided security awareness training to CloudFlare employees.- Trained law enforcement agents on cloud service provider technologies.- Presented at Messaging Malware Mobile Anti-Abuse Working Group (M3AAWG) about email validation services and DDoS attacks, and at RightsCon on protecting user rights at startups. -
Technical Committee Co-ChairMessaging Malware Mobile Anti-Abuse Working Group (M3Aawg) Jul 2013 - Oct 2014
-
Program Committee Co-ChairMessaging Malware Mobile Anti-Abuse Working Group (M3Aawg) Jun 2011 - Jul 2013
-
Training Committee Co-ChairMessaging Malware Mobile Anti-Abuse Working Group (M3Aawg) Feb 2010 - Jun 2011
-
Principal EngineerComcast Aug 2011 - Oct 2012Philadelphia, Pa, Us- Maintained mail transport and anti-abuse application layers of residential and commercial mail platforms for over 30 million mailboxes.- Crafted workflow rules within Cloudmark Gateway MTA.- Developed next generation anti-abuse policies and strategic approach for platform evolution.- Conducted analysis of email-based attacks and works closely with third-party vendors to reduce both false positives and spam to the subscriber inbox.- Provided leadership, guidance, and oversight to junior engineers on anti-abuse team.- Provided industry expert insight to other teams within Comcast regarding abuse vectors.- Implemented RBLDNSD to replace Nominum Centris and decrease DNSBL update times.- Hosted first ESP summit at Comcast to promote open and transparent communication between ESPs and ISPs. -
Director, Security OperationsCloudmark Feb 2011 - Aug 2011San Francisco, Ca, Us -
Abuse Operations ManagerCloudmark Jul 2008 - Feb 2011San Francisco, Ca, Us- Managed Cloudmark’s Security Operations Center responsible for maintaining Cloudmark Sender Intelligence (CSI) IP reputation service and tactical accuracy for Cloudmark Authority messaging security product.- Performed analysis of email, SMS/MMS, and social networking content to determine tactical approaches to reduce delivery of spam, phish, and viruses and increase delivery of legitimate, permissioned messages.- Identified non-obvious characteristics and patterns in spam and feedback reporter behavior.- Worked closely with Engineering to develop and improve backend fingerprinting technology.- Evaluated third-party data feeds for inclusion into backend systems.- Maintained Cloudmark's honeypot / spam trap network.- Led outreach to sender / ESP community to standardize best practices and promote transparent and open communication between Cloudmark and senders / ESPs.- Researched and presented data on spam trends and accuracy to internal and external customers.- Investigated malicious reporters and senders through behavioral analysis.- Acted as a Cloudmark subject matter expert spokesperson to the press on major spam attacks and cybercrime. - Presented at industry conferences (such as M3AAWG) on best sending practices messaging trends.- Served as the Compliance Officer for reporting child sexual abuse material to the National Center for Missing and Exploited Children. -
Anti-Spam Operations ManagerTrend Micro Feb 2008 - Jul 2008Tokyo, Japan, Jp- Managed DNSBL (RBL, DUL, OPS, RSS, QIL) IP reputation team. - Worked with xSPs regarding blocklist concerns and best practices.- Acted as Project Manager of internal spam trap / honeypot project.- Acted as Project Manager overseeing development of Email Reputation Services.- Led operational and development meetings for Email Reputation Service projects.- Networked with industry peers for business development. -
Rbl+ InvestigatorTrend Micro Oct 2007 - Feb 2008Tokyo, Japan, Jp- Responsible for maintaining DUL (dynamic DNSBL) blocklist and researching technical characteristics to evaluate static or dynamic IP assignment.- Acted as escalation contact for major ISP clients.- Reviewed procedures and tools to increase productivity and efficiency.- Revised procedural documentation and produced benchmarking reports.- Promoted to Anti-Spam Operations Manager in February 2008. -
Manager Of Investigations And DevelopmentInternet Law Group Mar 2006 - Oct 2007- Investigated cases involving spam, phishing, botnets, identity theft, fraud, unauthorized release of sensitive personnel data, distribution of counterfeit and pirated products, online pharmacies, illegal importation of pharmaceuticals, and abuse of wireless networks.- Independently conducted civil investigations that involved jurisdictional problems/considerations, such as suspects committing wrongful acts or conduct that was the concern of Federal, state, and/or local agencies, that required cooperation and collaboration to advance investigations.- Operated in an undercover role while conducting Internet buys of counterfeit products.- Acted as a liaison between attorneys and clients, and technical and investigative staff.- Acted as Project Manager, interfacing with Production Manager and third party developers, during refinement of in-house investigation database and data acquisition tool.- Managed anti-spam/anti-fraud investigative team. -
Anti-Spam InvestigatorInternet Law Group 2004 - 2006- Performed forensic header and body analysis of spam email.- Performed multi source intelligence collection.- Reviewed and analyzed subpoena responses and investigative reports.- Developed suspect profiles and investigation candidate dossiers.- Specialized in identifying non-obvious relationships and recognizing patterns with fragmentary and historical data points.- Evaluated case data for appropriate legal causes of action (e.g. CAN-SPAM Act, Computer Fraud and Abuse Act, Lanham Act, common law torts, and other state anti-spam, anti-fraud, and identity theft laws).- Managed junior analysts during data acquisition and initial data review.- Drafted legal pleadings, subpoenas, affidavits, and declarations.- Handled sensitive and privileged information in a secure and appropriate manner. -
Abuse And Security CoordinatorTime Warner Cable 2002 - 2004Stamford, Ct, Us- Enforced and educated subscribers on the TWC Subscription Agreement, AUP, DMCA, CAN-SPAM Act, Patriot Act, and other state and federal laws.- Primary point of contact for questions regarding identity theft, network intrusions, firewalls, spam, and viruses for employees and subscribers.- Negotiated spam block and RBL issues between affected customers and ISPs.- Presented seminars for general public and local business leaders about spam, Internet security, and abuse in a broadband environment.- Processed and handled incidents for over 90,000 subscribers. - Took ownership of abuse and security issues, coordinated efforts with a variety of TWC departments and divisions, handled high priority escalations, and saw issues through to resolution.- Researched unsecured/infected customer equipment and educated residential and business subscribers on appropriate resolutions.- Monitored and tracked customer bandwidth consumption and network security scans. -
Road Runner/Misp Level Three Technical Support SpecialistTime Warner Cable 2001 - 2002Stamford, Ct, Us- Provided education, trouble-shooting, and fault-recovery through technical analysis by telephone to employees and subscribers who may not be technically skilled.- Provided support to Commercial Road Runner subscribers and to the business and engineering staff of the division.- Responded to escalated customer service trouble reports.- Analyzed, diagnosed, and corrected hardware, software, and/or operating system errors associated with all mISP equipment under the division's control in such a way as to minimize system downtime.- Monitored the technical operation of the mISP server complex and network, maintained records of performance standards, and followed procedures to effectively respond to out-of-tolerance conditions or outages.
Jamie Tomasello Skills
Jamie Tomasello Education Details
-
East Tennessee State UniversityInterdisciplinary Studies Major / Sociology And Trauma And Resilience Minors -
Washtenaw Community CollegeLiberal Arts And Sciences/Liberal Studies - Concentration In Psychology -
Brevard CollegeVocal Performance
Frequently Asked Questions about Jamie Tomasello
What company does Jamie Tomasello work for?
Jamie Tomasello works for Superbloom
What is Jamie Tomasello's role at the current company?
Jamie Tomasello's current role is Senior Fellow.
What is Jamie Tomasello's email address?
Jamie Tomasello's email address is jt****@****ail.com
What is Jamie Tomasello's direct phone number?
Jamie Tomasello's direct phone number is +160956*****
What schools did Jamie Tomasello attend?
Jamie Tomasello attended East Tennessee State University, Washtenaw Community College, Brevard College.
What skills is Jamie Tomasello known for?
Jamie Tomasello has skills like Privacy Law, Anti Spam, Spam Filtering, Security, Investigation, Data Privacy, Cybercrime, Big Data, Linux, Email, Computer Security, Data Analysis.
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial