Larry Moore

Larry Moore Email and Phone Number

Chief Information Security Officer at Texas Division of Emergency Management @ Texas Division of Emergency Management
Larry Moore's Location
Austin, Texas, United States, United States
About Larry Moore

I preserve your company's critical data and infrastructure assets by translating executive business requirements to strategic and tactical security objectives throughout the organization.Experience includes audits, business impact analysis, cloud/data center security, disaster recovery & operational continuity, governance, risk & compliance (GRC), incident investigations, mobile and alternative payments, risk assessments & analysis, security awareness training, trusted platform systems, threat/malware intelligence & analysisFrameworks: Anti-Money Laundering (AML), Bank Secrecy Act (BSA), CoBIT, DREAD, GDPR, HIPAA, HITRUST CSF, ISO 27001, 27002, 27017 & 27018, Know-Your-Customer (KYC), NIST, PCI-DSS, SOC 1 & 2 (SSAE-18), SOX

Larry Moore's Current Company Details
Texas Division of Emergency Management

Texas Division Of Emergency Management

View
Chief Information Security Officer at Texas Division of Emergency Management
Larry Moore Work Experience Details
  • Texas Division Of Emergency Management
    Chief Information Security Officer
    Texas Division Of Emergency Management Sep 2021 - Present
    Austin, Texas, Us
  • Pivot Point Security
    Senior Governance Risk & Compliance Consultant
    Pivot Point Security Jun 2018 - Sep 2021
    Hamilton Township, New Jersey, Us
    Conducted internal audits, risk and gap assessments for clients using the ISO 27001, GDPR, CMMC, HIPAA and HITRUST CSF frameworks and develops strategic remediation plans to improve the clients’ security portfolios.Served as the client representative to external auditors by presenting evidence, detailing established policies and procedures and creating remediation plans for identified gaps.Performed security incident and disaster recovery table top exercises to test clients’ current plans. Created remediation procedures to correct plan deficiencies based discovered during the exercises.
  • Tangoe
    Security, Risk And Compliance Manager
    Tangoe Jan 2017 - Jun 2018
    Indianapolis, Indiana, Us
    Software-as-a-Service (SaaS) security SME. Coordinates all aspects of Tangoe's global security program, including data privacy enforcement and risk assessments, with internal business teams and external audit firms. Manages all internal audits of critical controls, identifies and reports correlating events with senior management. Performs vendor and client risk assessments in accordance with company policies and works with the internal legal team in SLA negotiations.Architected the first governance and training program to protect the company's software intellectual property from potential open source license violations.Team lead and SME for the company's annual PCI DSS, SOC 1 and SOX compliance audits.Subject matter expert in the company's incident response exercises. Introduced process improvements that mitigated serious flaws in the response process.
  • Ntt Data, Inc.
    Senior Information Risk Management Consultant
    Ntt Data, Inc. Dec 2015 - Dec 2016
    Plano, Texas, Us
    Delivered comprehensive risk management solutions from executive directives to mitigate data and cyber infrastructure risks to align with PCI, SOX and ISO 2700* standards.Performed risks assessments to identify critical threats to customer data from a business, legal, financial, regulatory and HR perspective. Audited service provider cloud facilities to identify physical or logical deficiencies that may put customer data at risk. Findings and recommended solutions were presented to executive management for remediation.Audited logical network and access controls for employees and contractors and implemented measures to eliminate improper access controls to reduce threat probability to critical customer data. Identified dormant user and service accounts that were terminated.
  • Gemalto
    Solutions Security Officer, North America
    Gemalto Oct 2013 - May 2015
    Meudon, Fr
    Cyber security lead for all of Gemalto’s clients in the U.S., Mexico and Canada. Security supervisor for eight projects involving smart cards, mobile payments, health records, trusted platform services, SaaS solutions and operational continuity. Supervised teams up to fourteen people and mentored two new-hire SSO's.Delivered risk assessments that identified integrity weaknesses of mobile phone payment systems.·Successfully communicated risk and threats to client executive management such as CEO’s, CIO’s, General Counsel, etc.Delivered the second highest global passing rate for the company’s annual security awareness program for the North America region.Directed internal penetration test teams to test the security of various customer services. Identified and corrected critical vulnerabilities.Security subject matter expert for the company’s new data center in Singapore to meet customer demand in the Asian market for financial transactions, communications and SaaS operations. Created and tested all data center-centric security operations policies and procedures. Produced the data center’s two-year trusted computing strategic expansion plan and implemented that plan into the data center design. Designed dual factor physical and logical authentication controls for the company's highly critical trusted platform services for financial transactions. Tested, audited and delivered new physical and logical security solutions in accordance with company requirements. Remediation included security operational budget prioritization. Collaborated with the MasterCard & Visa auditor to create the initial operational certification.
  • Rêv Worldwide
    Director Of Security, Risk And Compliance
    Rêv Worldwide Jun 2011 - Oct 2013
    Austin, Tx, Us
    Delivered a successful risk management program to executive stakeholders that exceeded Payment Card Industry (PCI) requirements for a global $12 million multi-currency debit card and travel card program.Implemented an improved, more mature comprehensive global strategic risk management program that implemented the ISO 2700* standards and the PCI DSS standards which included a vendor data center.Identified up to eleven gaps that could have disclosed sensitive financial information for the security operations co-located primary and backup cloud facilities. Audited existing internal controls in accordance with the Bank Secrecy Act/Anti-Money Laundering and Office of Foreign Asset Control. Identified significant controls that reduced attack probability by roughly one third.Clarified Know Your Customer policies and procedures including customer identification and acceptance, monitoring and account risk categorization to improve efficiency.Led security incident investigations that included established chain-of-custody requirements for possible law enforcement intervention.Conducted an enterprise-wide Business Impact Analysis, as part of a Disaster Recovery, and Operational Continuity Plan with executive support; identified errors in communication and recovery procedures which reduced average recovery time by roughly 15%.Established security requirements for the development and implementation of the company’s first iPhone mobile payment software system. Reduced software vulnerabilities by roughly 15%.Created and documented a new Change Management Process that reduced audit times by approximately 50%. Governed Physical Security, including access controls, for the company’s headquarters and audited cloud facility vendor that ensured compliance with established regulations.
  • Texas Department Of Information Resources
    Information Security Officer
    Texas Department Of Information Resources 2007 - 2011
    Austin, Tx, Us
    Conducted agency-wide risk assessments and prioritized and remediated vulnerabilities in accordance with state and agency requirements.Developed a comprehensive technical and managerial information risk management program for a Texas state agency in accordance with the Texas Administrative Code, Section 202, the Governor, and the state’s Chief Information Security Officer.Served as the official security representative on two Governance Boards for Texas.gov, the state’s official web site. Directed and audited strategic security plans with managing third party in accordance with state objectives and FISMA and NIST guidelines. Directed and audited the implementation of the state’s strategic security requirements to third parties charged with managing the state’s primary and backup cloud facilities that were aligned to FISMA and NIST guidelines.Obtained the first PCI-DSS compliance report for state’s cloud facilities and Texas.gov enabling credit card transactions to enable expeditious remote payment options for Texas citizens.Created and delivered the 2010-2014 State Strategic Plan for Information Resources Management to the state legislature and agencies as the security representative on the agency’s executive steering committee, achieving legislative support.Authorized Controlled Penetration Tests and wireless scan results for the agency, the state’s cloud facilities and for Texas.gov. Developed and executed plans to remediate vulnerabilities, prioritizing on protecting data according to established criticality levels.Assisted the Texas Engineering Extension Service, Teex.org, in the development of its cyber security awareness training program for IT engineers and law enforcement.
  • The Home Depot
    Lead Security Program Manager
    The Home Depot 2004 - 2007
    Atlanta, Georgia, Us
    Project Management: Served as a security leader for all internal projects within the company's backup cloud facility. Consulted with senior vice president, stakeholders and project managers to recommend security requirements and cost-effective solutions for all projects in accordance with company policies, requirements and regulatory requirements.Governance Boards: Advised steering committees and review boards as an official security representative. Wrote security requirements and approved or denied internal projects based upon implementation of requirements. Recommended solutions to project managers for all denied projects.Risk Assessments: Performed risk assessments and enterprise-wide business impact analysis under the ISO 20001, Sarbanes-Oxley and PCI standards (where applicable) of internal projects to provide a current state of appropriate IT controls.PCI DSS: Performed numerous service provider PCI audits of vendor’s internal controls to address access to customer credit card data. Security Operations and Testing: Enforced security requirements by testing projects (e.g. penetration testing, code reviews, web and server assessments). Identified vulnerabilities, recommended solutions and created variances to ensure that effective security and business needs are satisfied.Security Awareness: Developed and implemented an updated security awareness presentation for all new associates located in Austin. Modified presentation to increase emphasis on regulations, laws and company policies, and provided real-world examples of consequences of inadequate security.Promoted to interim team manager for five months. Responsible for managing the daily operations of the Austin security team. Reported weekly status to senior management.Volunteered to manage firewall change requests for six months. Authorized or denied requests based on company security policies and regulatory requirements.
  • Gray Hat Research Corporation
    Part Time Software Consultant
    Gray Hat Research Corporation 2005 - 2006
    Us
    Reviewed C and Assembler source code for a retail software package to identify security vulnerabilities.Identified severe vulnerabilities in data checking that, if applied in a runtime environment, could abort the application and allow confidential information to be exposed to an attacker.Presented findings and recommended solutions to the customer.
  • Ibm
    Software Engineer - Aix Security
    Ibm 1998 - 2004
    Armonk, New York, Ny, Us
    Developed and maintained core security software in C for the AIX operating system. Maintained audit component and assisted development of Kerberos, PKI and shadow passwords.Member of team that improved AIX security to meet requirements for Common Criteria.As part of the company’s enterprise server plan, created Enterprise Identity Mapping (EIM) component to provide a single sign-on capability to all IBM platforms while providing unique access control to each individual system.Coordinated multiple EIM test case plans with other IBM divisions. Developed test scripts to reduce testing time and reporting by 60%.
  • Ibm
    Software Engineer - Os/2 Postscript Driver
    Ibm 1991 - 1998
    Armonk, New York, Ny, Us
    Developed and maintained C and Assembler software for the OS/2 Postscript driver. Provided strategic direction for driver development.Conceived, designed and implemented an improved user interface for all OS/2 print drivers that not only dynamically supported high-end printers, but added new print features, simplified printer selections for end users and reduced development time 20%.Served as a liaison between IBM and stakeholders of printer manufacturers. Prioritized strategic goals to align OS/2 development with printer manufacturers’ development plans.Volunteered to manage a computer test lab. Responsible for user access authorization and equipment inventory within the lab.

Larry Moore Skills

Information Security Security Pci Dss Disaster Recovery Business Continuity Information Security Management Cloud Computing Risk Assessment Enterprise Software Iso 27001 Vulnerability Assessment Data Center Security Audits Risk Management Computer Forensics Enterprise Risk Management Incident Management Cobit Risk Analysis Hipaa Information Security Policy Nist 800 53 Network Security Management Emv Leadership Project Management It Audit Business Process Improvement Soc It Strategy Incident Response Security Consulting General Data Protection Regulation Iso 27002 Privacy Regulations Iso 27001 Lead Auditor

Larry Moore Education Details

  • Florida Institute Of Technology
    Florida Institute Of Technology
    Computer Science

Frequently Asked Questions about Larry Moore

What company does Larry Moore work for?

Larry Moore works for Texas Division Of Emergency Management

What is Larry Moore's role at the current company?

Larry Moore's current role is Chief Information Security Officer at Texas Division of Emergency Management.

What is Larry Moore's email address?

Larry Moore's email address is la****@****ity.com

What is Larry Moore's direct phone number?

Larry Moore's direct phone number is +151292*****

What schools did Larry Moore attend?

Larry Moore attended Florida Institute Of Technology.

What are some of Larry Moore's interests?

Larry Moore has interest in Education.

What skills is Larry Moore known for?

Larry Moore has skills like Information Security, Security, Pci Dss, Disaster Recovery, Business Continuity, Information Security Management, Cloud Computing, Risk Assessment, Enterprise Software, Iso 27001, Vulnerability Assessment, Data Center.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.