Ciso
Maryland Dhs
As the Chief Information Security and Privacy Office for the $ 500M MD THINK Cloud Platform I led the agencies Digital Transformation to AWS Cloud. Responsible for Security Strategy and Architecture, Security Engineering and Operations, Vulnerability Management, Identity and Access Management, Data Protection, Cloud Service Posture Management, Security Assessment, Application Security, Business Resiliency, Policy and Procedures, Endpoint Security, Pen testing, Red team assessment, Security Incident and Event Monitoring (SIEM) and Incident Response of the platform and the applications running on the platform. Made all Executive decisions regarding budgeting, finance, procurement for Security, Privacy and Governance Risk and Compliance functions.• Successfully migrated multiple agencies onto the platform including all applications from Department of Human Services, Maryland Health Benefits Exchange, pilot applications for Maryland Department of Health with an M&A mindset• Completed ATO for 10 major business applications on the platform supported by 50 other applications maintaining compliance with NIST 800-53, FISMA, IRS PUB 1075, MARS E 2.0, HIPPA,ISO, NACHA, and Maryland DOIT IT Security frameworks• Instituted the Governance, Risk and Compliance program, setup the Security Operations Center, Incident Response program and Continuous Monitoring program focused on Business Risk• Serve as a Trusted Advisor to the CTO and the Executive Committees for all security related decisions