Managing Security Consultant
CurrentEstablished and managed security and privacy programs aligned with NIST 800-53, overseeing Security Operations Center (SOC) functions and team training. Deployed advanced endpoint tools (OSSEC, Trend Micro, CrowdStrike) and Data Loss Prevention solutions (Forcepoint, Trend Micro) to strengthen organizational defenses. Integrated Splunk for data aggregation and analysis, enhancing threat detection and incident response. Developed technical testing platforms for vulnerability management, conducting network penetration tests, vulnerability assessments, and web application security assessments. Implemented perimeter security solutions using Cisco ASA, enabling secure remote access and IPSEC VPNs. Provided quarterly executive briefings on cybersecurity program performance, supporting compliance readiness for SOC 2 Type 2, NIST 800-53a, ISO 27001, and PCI standards. Managed a cybersecurity budget of $800K.Designed and implemented physical security build requirements for new and retrofit construction projects, mitigating blended threats through advanced perimeter security, access control, and surveillance solutions (Avigilon, Verkada) compliant with national and international standards. Directed global physical security training and OSINT investigations to support strategic objectives. Conducted vulnerability assessments, target assessments, and penetration tests on high-value assets, ensuring optimal protection. Managed a $2M physical security budget and delivered executive-level reports to drive informed decision-making.