Information Security Manager
ResponsibilitiesReported directly to Information Security Officer for day-to-day operations.Established and maintained risk management programs to include vulnerability identification, reporting, tracking, resolution and Metrics.Developed Information security policies, standards, and guidelines within the corporate vision and goals.Created and managed corporate security awareness and training programs for staff and contractors.Reviewed and certified new and existing systems, networks and applications for security policy compliance.Managed the development of enterprise-wide security architecture and operations to include system vulnerability scanning, Anti-Virus, Email/Spam and Internet filters, Intrusion Detection Systems, Microsoft and Oracle patching process, password compliance, and system security alerting.Worked with Internal and external audit teams to facilitate review of NASDAQ systems for regulatory compliance with SOX, HIPAA, SEC, and GAO.Participated in Industry-wide information security committee within the financial services industry (FS/ISAC) working with Department of Homeland Security and Infragard (FBI).Developed and maintain vendor and contractor relationships for all security products and services.Conducted computer forensics investigations and Incident responses.Developed and maintain information security metrics program.Conducted internal information security risk assessments and contract with 3rd party providers for penetration testing.Managed Information Privacy Program and TRUSTe certification.