AeroLeads people directory · profile

Michael Arends Email & Phone Number

Information Security and Compliance Specialist at (not disclosed)
Location: Melissa, Texas, United States 13 work roles 2 schools
LinkedIn matched
✓ Verified July 2026 3 data sources Profile completeness 100%

Contact Signals

LinkedIn Profile matched
3 free lookups remaining · No credit card
Current company
Role
Information Security and Compliance Specialist
Location
Melissa, Texas, United States

Who is Michael Arends? Overview

A concise factual answer block for searchers comparing this professional profile.

Quick answer

Michael Arends is listed as Information Security and Compliance Specialist at (not disclosed), based in Melissa, Texas, United States. AeroLeads shows a matched LinkedIn profile for Michael Arends.

Michael Arends previously worked as Information Security at Thompson Reuters and Manager at Baker Tilly. Michael Arends holds B.S., Bcis from St. Cloud State University.

Company email context

Email format at (not disclosed)

This section adds company-level context without repeating Michael Arends's masked contact details.

(not disclosed)

Review company-level records connected to Michael Arends before choosing the right outreach path.

Profile bio

About Michael Arends

Accomplished internal controls, information security, and audit professional with proven ability to identify and mitigate technology risks. Dedicated to continuous improvement through professional development and keeping up-to-date on technology trends. Over 13 years in information technology as a data security analyst, information security manager, auditor, and technology risk consultant and Director of Information Security.PRACTICAL EXPERIENCE:Payment Card Industry (PCI)IT Audit (Internal and External)IT Due Diligence during a merger/acquisitionSecurity and Privacy AwarenessControl Gap AssessmentsNetwork Vulnerability AssessmentsInformation Security ComplianceCONTROL ENVIRONMENT FRAMEWORKS:FFIECCOBITCOSONIST 800-53SysTrust and WebTrust PrinciplesINDUSTRY STANDARDS:Payment Card Industry (PCI)HIPAA Sarbanes-Oxley (SOX)SOC1, TYPE 2 AssessmentsSOC2, TYPE 2 AssessmentsGLBA ComplianceISO27001

Listed skills include Hipaa, Glba, Ffiec, Financial Risk, and 31 others.

Current workplace

Michael Arends's current company

Company context helps verify the profile and gives searchers a useful next step.

(not disclosed)
(Not Disclosed)
Information Security and Compliance Specialist
Melissa, TX, US
AeroLeads page
13 roles

Michael Arends work experience

A career timeline built from the work history available for this profile.

Information Security And Compliance Specialist

(Not Disclosed)

Melissa, Tx, Us

Information Security And Compliance Specialist

(Not Disclosed)

Information Security

Thompson Reuters
Mar 2015 - Jul 2018

Manager

London, Gb

Managed IT audits, Sarbanes-Oxley compliance, SSAE 16, IT due diligence, Payment Card Industry (PCI) and information security improvements for our clients. Identify risks related to their organization and the controls in place to manage those risks.* Documenting client current control environments while identifying any areas of improvement.* Prepare reports for both the technical audience and executive management.* Think strategically to address clients’ business plan and overall organizational risks.* Team with clients to develop solutions to problems and drive positive change.* Deliver exceptional client service in all interactions and projects.* Communicate effectively, both internally and to clients, including those at an executive level.* Provide coaching, mentoring and performance counseling to consultants, clients and project team members.* Assist with strengthening existing client relationships and developing new business opportunities by participating in sales meetings and working on proposals.* Identify security and compliance risks while developing remediation or help develop compensating controls to minimize risks within the enterprise.* Assist clients with meeting the requirements of the Payment Card Industry for those that meet the thresholds based on volume of transactions.* Managed engagements including client interactions for SSAE 16/SOC 1 engagements when just stating with the firm.* Assist clients in documenting risks to their organization along with their controls to meet those risks. Utilized Cobit, COSO and NIST in developing risk assessment strategies and controls.For clients developing applications internally, perform change management controls testing and review controls around the source code.* Review server configurations based on industry best practices (NIST and Center for Internet Security).

Oct 2011 - Mar 2015

Information Security Manager

Carol Corporation

Managed corporate compliance including gathering and reviewing information to confirm the activities are being performed. Managed and executed numerous improvement programs and technical risk assessments.* Served as Carol’s Privacy Officer and Compliance officer including Health Insurance Portability and Accountability Act (HIPAA).* Managed the Compliance program while reporting status and resolutions to management including results from audits, internal compliance efforts, * Provided responses to client security assessments and external parties regarding the controls over data provided by Partners.* Performed physical security assessments of sites for new offices when evaluating an office relocation and external data centers.* Developed Carol's Information Security Framework and associated policies.* Created Carol's Disaster Recovery and Business Continuity plans to be used by the organization when disruptions of service or outage occurs.* Lead the project to purchase a vulnerability scanner and incorporate the results into the patch management process.* Performed the vulnerability scans, communicated results to management and assisted in developing mitigation plans.* Created the incident management policies and plan to respond when an incident has been identified or reported to the organization.* * Provide ongoing awareness of data privacy and security through the delivery of formal presentations, email alerts, and company meetings.* Leading the project to consolidate our system logs into one server, analyze the logs, generate alerts, and respond using the incident response process. * Review all data sharing agreements to validate Carol’s security concerns are documented.* Collaborate with various areas to establish and manage the process for receiving, documenting, tracking, investigating and resolving all privacy and/or data security incidents.

Jan 2011 - Oct 2011

Supervisor, Risk Advisory Services

Chicago, Illinois, Us

Managed and executed numerous audit programs and technical risk assessments. Audit experience included application and platform audits; compliance readiness audit, mapping controls to CobiT framework Performed and supervised engagements for SOX, SAS 70, PCI, FFIEC and HIPAA.* One multi-billion dollar holding company had four subsidiaries in four different states. Managed each remote team to ensure consistency of services performed and communication to the client. . * Perform services for a variety of industries including financial, printing/manufacturing, service processing and retail. The ability to perform various services for a variety of industries has resulted in becoming a main resources for engagement managers.* Add value by identifying process improvements that are part of the audit process but will save time/money for the clients. Clients’ vendor management processes typically lack a formal process to review critical vendors on a regular basis. Provide tips on coordinating the efforts and tracking the results. * Take ownership of the engagement when assigned resulting in my preparing the deliverable, establishing the time line for fieldwork, staffing for the engagement, presenting findings to the executive management team, and delivering the final report to the client.* Performed network vulnerability assessments for banking clients and those complying with Payment Card Industry (PCI) standard. Documented the testing performed, risks from results and any corrective actions that are needed.* Performed the testing ensuring compliance with the Payment Card Industry Data Security Standard (PCI DSS) and presenting the report to the Payment Council on behalf of our clients.* Perform IT General controls reviews ensure safety and soundness of operations to ensuring controls are adequate to protect and recover the clients information systems.* Member of RSM McGladrey’ s FDICIA Methodology Team.

Oct 2009 - Jan 2011

Senior Associate - Technology Risk Management Services

Chicago, Illinois, Us

Key resource on larger engagements, mentoring staff when necessary and managed the process for smaller clients. Performed engagements regarding SOX, FFIEC, and SAS70. Industry expertise includes, finance/banking, printing/manufacturing and retail. * Managed small engagements where I was the only resource taking ownership of the engagement when assigned resulting in my preparing the deliverable, establishing the timeline for fieldwork, staffing for the engagement, presenting findings to the executive management team, and delivering the final report to the client.* Provide mentoring for Associates assigned to larger engagements by evaluating the work they perform, answer questions regarding audit techniques, possible findings, and interview techniques.* Self-starter and always seeking ways to improve our processes and work papers. Enhanced our SOX test tables by adding areas for population and sample sizes by each test.

Aug 2007 - Oct 2009

Internal Auditor

Us

Planned and conducted larger and more complex audits supervising one to five staff members. Areas of concentration included Investments & Insurance, Executive Compensation and General Controls for Information Technology.* Member of the Records Retention Steering Committee representing the Audit Department. Duties included identifying, tracking and reporting on the departments activities to ensure compliance with the retention policy of the organization.* Participates in all aspects of engagement planning from communicating the information required for the audit, ongoing status of testing and finally the results of the examination. * Provide consulting services for both our Financial Services and Information Technology areas within TCF regarding security, controls, policy adherence and protections for various applications both financial and functional. * Preparing a risk assessment and make assessments on controls form an internal audit and Information Security perspectives.* Participates in all aspects of engagement planning from communicating the information required for the audit, ongoing status of testing and finally the results of the examination.* Review and evaluate controls within a computer facility (mainframe, distributed systems) including management, operation, system development, security, contingency and application controls.* Ensure all audit work is clearly documented in work papers and audit issues are supported.* Participated in the Vendor Management reoccurring assessment process to confirm current vendors are monitored and do not pose an undo risk to the organization.* Participated in the evolution of new vendors to confirm they are both financially and operationally secure minimizing the risk to the organization.

Sep 2005 - Aug 2007

Information Security Manager

Us

* Managed the Information Security efforts of the department regarding the non-mainframe systems and applications. Directly supervised four security administrators ensuring all systems access requests are properly authorized and access provided is based on job responsibilities.* Manage the Networked Systems Security Steering Committee that reviews and establishes security controls for the corporate network.* Developed, implemented, communicated, and maintained all TCF Information Systems Security Policies and Procedures. Developed & implemented security standards for multiple system platforms & environments. * Lead a cross-functional team to research, select and implement a Vulnerability Assessment tool. * Developed the strategy to incorporate the tool into the current patch management process to help focus patching efforts on the system that are vulnerable and validate the systems have been properly mitigated.* Responsible for coordinating all audit activities (internal and external) associated with IT Security and ensuring ongoing compliance with established Security Policies and Procedures.* Responsible for responding to Information Security incidents, providing timely reporting to management, documenting the resolution.* Responsible for reporting Information Security related events, projects and directives to Executive Management.* Ensure the department is meeting the stated SLA for access requests and help desk ticket response.* Managed the selection, implementation, process, procedures and operational parameters for our Vulnerability Assessment Tool, Intrusion Detection System and Hard Drive Encryption initiatives* Responsible for conducting Security Awareness throughout IT and business units to communicate necessary Security Policies and Procedures and respective individual accountabilities.People supervised directly: 4

Oct 2004 - Sep 2005

Data Security Analyst

Us

Primary responsibilities were to install, monitor the organizations intrusion detection system and report the information to executive management. Additional responsibilities include responding to information security incidents.* Oversees general activities within security management, participates in the annual planning and budget process within IT, develops and recommends annual resource plan that supports the Corporate Security program, & conducts Security Risk Assessment investigations.* Developed the process used by the Information Security department in responding to phishing attacks directed at the bank. The process included identifying the location of the phishing site, contacting the hosting company to request the site be removed. The team removed over 200 phishing sites using this process.* Lead a cross-departmental project to implement an Intrusion Detection System on the network. * * Developed the process and procedures for monitoring and reporting security violations noted by the Intrusion Detection System. * Participated on project teams as the security representative to ensure all new or modified systems aligned with the information security policies and standards. * Developed security awareness training programs, corporate data security guidelines and standards.* Coordinates efforts to find solutions to specific security problems across all lines of business. * Coordinate security issues, concerns, and potential problems with Corporate Audit and Legal Departments.* Managed the Vulnerability Assessment project to completion ensuring that all items were resolved.* Review new applications to ensure they meet our established standards. When the standards are not met, that other mitigating controls exist ensuring the security of our data and network.

Oct 2002 - Sep 2004

Senior Security Administrator

Dallas, Tx, Us

* Executed process for creating, changing, deleting and maintains user trisection security profiles. * Adheres to established procedures for processing requests for mainframe or LAN access.* Assists customers and employees with problems determination and resolution by using appropriate security policies and procedures to provide timely and effective second level problem resolution and data security support.* Identify potential risks and responds to security violations. Recommends appropriate security controls, policies and procedures.* Monitors, approves and files security reports and access request forms.* Provides consulting on security solutions to Information Technology and Business colleagues.* Interface with customers to determine security needs and implement procedures that accommodate the business need, without sacrificing the appropriate level of control.* Researched and created job related profiles in the Mainframe.* Proposed methods for closing open ports in our firewall.* Prepared the documentation for departmental processes and procedures.

Jan 2001 - Oct 2002

Systems Security Analyst

Minnetonka, Minnesota, Us

* Monitored, administered and completed security access requests to create new users, modify existing accounts (grant, remove access), disable accounts, and delete user accounts. * Provide level 3 support to end users, resolve problems and questions, monitor and address violations of security standards including parameters set on various platforms for passwords, accounts, and events. * Administer campus and external user security across multiple platforms including NT 4.0, MVS (Top-Secret 4.4 & 5.0), Microsoft Mail, Microsoft Exchange, Lotus Notes, Remote Access, Internet, POP3 Mail and NT print queues. * Maintain documentation for exceptions, review logs and accounts.* Represent Security Management’s interests in cross-functional teams and project implementation. * Maintain documentation on company procedures and policies.* Install, move, and delete print queues across our domain and trusted domains.* Assign static IP addresses for the print queues and servers using a third party product, QIP.* Create directories on network, assign permissions, and the appropriate groups.* Mentorship and technical skills training to new team members.* Developed a company process for dealing with virus alerts, warnings and hoaxes among various departments.* Created a Virus Information Website that is posted on our Intranet. This provides information on viruses, hoaxes, myths and chain mail to our users. This site is also used to communicate new threats/viruses to our environment.* Developed a security awareness program that would communicate information to our Minneapolis based offices.* Designed and developed an Intranet site as a vehicle to communicate information.* Managed tasks, conformed to deadlines, turned in deliverables when appropriate and make recommendations when appropriate.

Jan 1999 - Jan 2001
2 education records

Michael Arends education

B.S., Bcis

St. Cloud State University

Mba, Finance

Saint Mary'S University Of Minnesota
FAQ

Frequently asked questions about Michael Arends

Quick answers generated from the profile data available on this page.

What company does Michael Arends work for?

Michael Arends works for (not disclosed).

What is Michael Arends's role at (not disclosed)?

Michael Arends is listed as Information Security and Compliance Specialist at (not disclosed).

Where is Michael Arends based?

Michael Arends is based in Melissa, Texas, United States while working with (not disclosed).

What companies has Michael Arends worked for?

Michael Arends has worked for (Not Disclosed), Thompson Reuters, Baker Tilly, Carol Corporation, and Mcgladrey.

How can I contact Michael Arends?

You can use AeroLeads to view verified contact signals for Michael Arends at (not disclosed), including work email, phone, and LinkedIn data when available.

What schools did Michael Arends attend?

Michael Arends holds B.S., Bcis from St. Cloud State University.

What skills is Michael Arends known for?

Michael Arends is listed with skills including Hipaa, Glba, Ffiec, Financial Risk, It Audit, It Risk Management, Risk Assessment, and Sas70.

Find 750M verified contacts

Search by job title, company, industry, location, and seniority. Export verified B2B contact data when you need it.