Mark Merkow, Cissp, Cism, Csslp Email & Phone Number
@aexp.com
7 phones found area 602, 480, 973, and 402
LinkedIn matched
Who is Mark Merkow, Cissp, Cism, Csslp? Overview
A concise factual answer block for searchers comparing this professional profile.
Mark Merkow, Cissp, Cism, Csslp is listed as Online Faculty at University of Denver, based in Tempe, Arizona, United States. AeroLeads shows a work email signal at aexp.com, phone signal with area code 602, 480, 973, 402, and a matched LinkedIn profile for Mark Merkow, Cissp, Cism, Csslp.
Mark Merkow, Cissp, Cism, Csslp previously worked as Application Security Engineer at Freeport-Mcmoran and Founding Member at Threat Modeling Connect. Mark Merkow, Cissp, Cism, Csslp holds Bachelor Of Science (Bs), Computer And Information Sciences, General from W. P. Carey School Of Business – Arizona State University.
Email format at University of Denver
This section adds company-level context without repeating Mark Merkow, Cissp, Cism, Csslp's masked contact details.
AeroLeads found 1 current-domain work email signal for Mark Merkow, Cissp, Cism, Csslp. Compare company email patterns before reaching out.
About Mark Merkow, Cissp, Cism, Csslp
Applied Application Development Security program development for large IT organizationsAdvocate for Building Security In to the SDLC with software-quality and security activities, tools, and processes, and education for provable, high-assurance software securityExpert in Information Security Policies and Standards/Training and Awareness Programs, especially as they apply to software securityAuthor or co-author of 14 published books on IT and IT Security, including 2 titles specific to software security:o Secure and Resilient Software Developmento Secure and Resilient Software: Requirements, Test Cases, and Testing Methods
Mark Merkow, Cissp, Cism, Csslp's current company
Company context helps verify the profile and gives searchers a useful next step.
Mark Merkow, Cissp, Cism, Csslp work experience
A career timeline built from the work history available for this profile.
Application Security Engineer
CurrentWorking on the Application Security Team at Freeport to help develop a culturally-appropriate and effective end-to-end software security practice.
Founding Member
Current
Online Faculty
CurrentCourse developer and instructor in University College for the Information and Computer Technology courses. Specialize in Computer Security Fundamentals, Security Education, Training, and Awareness (SETA) Programs, Application Software Security, and Access Control Systems.
Visting Professor
CurrentAdjunct faculty in College of Engineering and Information Systems (E&IS) for DeVry and Keller online programs.
Application Security Architecture/Design/Engineering
• Served on Security Architecture Team working to migrate legacy Web applications to MS Azure through reusable architecture patterns and reference architectures, code reuse, and application decomposition into microservices with REST API communications.• Worked on evaluating vendor security programs and questionnaires via Graphite Connect in support of People and Partner Security• Developed and delivered annual role-based Application Security Refresher training for all scrum teams• Assisted in corporate-wide security awareness campaigns and National Cybersecurity Awareness Month (NCSAM)
Technical Director, Application Security
-Developed and implemented a holistic secure software development lifecycle for all enterprise-level applications in both RUP and Scrum/Agile development methodologies-Trained over 700 development team members across 8 development roles in secure application requirements analysis, design, development, testing, and rollout-Maturing the program as new Agile teams come onboard and as new vulnerabilities pop up-Developed and began implementation of a Talent Strategy to map employee roles to the NICE Framework Work Roles to determine coverage and depth of Information Security Program. Further mapping of employee work roles with the Knowledge, Skills, and Abilities (KSAs) helps to assure coverage sufficient to succeed or excel in a work role, and filling in any gaps with continuing education.
Manager, Information Security Policies And Standards/Security Training And Awareness Programs
Developed, managed, assured adequate reviews, and maintained the Information Security Policies and Standards Library for PayPal worldwide access and use. Applied the requirements within the standards to establish and run an effective security training and awareness for 14,000 employees worldwide. Leveraged effective media and tools to create culturally- and geographically -appropriate Security Awareness and Training campaigns to help people understand that “Security is Everyone’s Responsibility.” Led the development and implementation of security awareness campaigns for Lock It When You Leave It, Compliance Jeopardy Game, an Information Security Related Haiku contest and in-person events that bring industry experts to PayPal to share their experiences and knowledge with PayPal software developers, Site Operations Personnel, and Information Security personnel. Our rotating Data Protection Weeks reach thousands of Call Center personnel with security training and security awareness that rapidly reminds them of their responsibilities for handling sensitive customer information and offers them a forum to answer specific questions -- given their limited time for training and contact.Using a variety of measurement tools to gauge the effectiveness of a campaign, we were able to prove that the Lock It When You Leave It campaign alone effected positive behavior changes in 65% of the participants we surveyed.
Director,Cto Security Technical Excellence Center
Established and implemented the Application Development Security (ADS) program for American Express which included developer training, rollout of IBM’s Rational Tools for source code analysis, Web app penetration testing program, and remediation authority for bugs and other security issues that were found.Responsible for inculcating the Application Development Security Program as a natural aspect in all phases of the Software Development Life Cycle at American Express.Created CBT courses and instructor-led courses for software developers, analysts and designers, and leaders of employees engaged in the SDLCLed a group of IT Security Subject Matter Experts in Project Governance activities that include Product Evaluations for proposed COTS implementation, development of standards, strategies, and prescriptive frameworks for reusable security servicesResponsible for conducting Proof-of-Concept evaluations on new IT Security tools to determine the suitability of use and supportCollaborated with CISO Office on policy enforcement mechanisms and joint reviews of CISO Policies and Standards and CTO Standards and Strategies for implementing IT Security Controls across the AMEX Enterprise.Developed IT Security Strategies for Enterprise Technology Roadmap using TOGAF tools and techniquesServed as American Express Technologies Representative to BITS/Financial Services Roundtable Security and Risk Assessment CommitteeServed as American Express Technologies Representative to the Financial Services Information Sharing and Analysis Center (FS-ISAC)Served as American Express Technologies Representative on Financial Services Sector Coordinating Council on Homeland Security and Critical Infrastructure Protection (FSSCC) R&D Committee and Cybersecurity Committee
Information Security Strategist
Critical Infrastructure Protection for Finance and Banking CybersecurityBITS Security and Risk Assessment Committee as Executive Subcommittee Member and Member of the Lab Governance Committee (LGC) for Financial Institutions Data Evaluation Security (FIDES)Site Coordinator for Financial Services Information Sharing and Analysis Center (FS/ISAC)Developing and implementing policy and standards base for long-term security strategy and operationsSynthesis and migration of IT Security policy and standards library to RSA Archer Security Management PlatformAdvanced Payments (chip cards, RFID cards, key fobs) securityKey Signing Officer for AMEX related cryptographic keys and Certificate AuthorityProject consulting, issues resolution, and security exceptions dispositioning
Mark Merkow, Cissp, Cism, Csslp education
Bachelor Of Science (Bs), Computer And Information Sciences, General
M.Ed., Distance Education And Learning Technologies
Ms, Decision And Information Systems
Frequently asked questions about Mark Merkow, Cissp, Cism, Csslp
Quick answers generated from the profile data available on this page.
What company does Mark Merkow, Cissp, Cism, Csslp work for?
Mark Merkow, Cissp, Cism, Csslp works for University of Denver.
What is Mark Merkow, Cissp, Cism, Csslp's role at University of Denver?
Mark Merkow, Cissp, Cism, Csslp is listed as Online Faculty at University of Denver.
What is Mark Merkow, Cissp, Cism, Csslp's email address?
AeroLeads has found 1 work email signal at @aexp.com for Mark Merkow, Cissp, Cism, Csslp at University of Denver.
What is Mark Merkow, Cissp, Cism, Csslp's phone number?
AeroLeads has found 7 phone signal(s) with area code 602, 480, 973, 402 for Mark Merkow, Cissp, Cism, Csslp at University of Denver.
Where is Mark Merkow, Cissp, Cism, Csslp based?
Mark Merkow, Cissp, Cism, Csslp is based in Tempe, Arizona, United States while working with University of Denver.
What companies has Mark Merkow, Cissp, Cism, Csslp worked for?
Mark Merkow, Cissp, Cism, Csslp has worked for University Of Denver, Freeport-Mcmoran, Threat Modeling Connect, The Purple Book Community, and Devry University.
How can I contact Mark Merkow, Cissp, Cism, Csslp?
You can use AeroLeads to view verified contact signals for Mark Merkow, Cissp, Cism, Csslp at University of Denver, including work email, phone, and LinkedIn data when available.
What schools did Mark Merkow, Cissp, Cism, Csslp attend?
Mark Merkow, Cissp, Cism, Csslp holds Bachelor Of Science (Bs), Computer And Information Sciences, General from W. P. Carey School Of Business – Arizona State University.
Search by job title, company, industry, location, and seniority. Export verified B2B contact data when you need it.
Start free trial