Deputy Ciso
UT is a federation of hundreds of departments with no central IT authority. My mandate was to find ways to move behavior toward security in this challenging environment. Thus, I was involved in IT governance negotiations, building automation and reporting, leading penetration tests of our campus and external campuses, and performing architecture and regulatory evaluations of new and existing systems. I act as CISO for UT Austin when our CISO is unavailable. I also manage a team of 6 direct reports who do risk analysis, penetration testing, application assessments, and vulnerability research.Major Accomplishments:Created a container-based vulnerability management program using python, splunk, docker-on-yarn, nmap, Tenable.sc and various other security tools. I architected this service to be scalable, so we were able to extend this program to the other campuses in the UT System at no cost, serving hundreds of thousands of endpoints and thousands of users. Using this program, we were able to increase UT Austin's BitSight score by over 40%, which in turn decreased our breach insurance premiums.Created a high-quality external penetration testing program and offered it to other UT System campuses at cost recovery, increasing our headcount by 2.Leveraging our automation, we are consistently able to achieve organizational root compromises (Domain Admin or similar) ~50% of the time while producing high-quality reports during a 2-3 wk engagement. These outcomes compare favorably with penetration testing providers that charge 5-10x as much.Represented the security office on two high-impact governance committees: endpoint management and next-generation platform. On both committees I was able to drive our objectives by creating high-quality presentations using vulnerability data, and leveraged my experience with both endpoint management and platform engineering to help lead the committees to good architectural decisions.