Information Technology Security Manager
Current Govern daily operational security activities in alignment to company objectives and regulatory standards. Protect company assets and maintain vulnerability requirements using Carbon Black for regular scans. De-escalate potentially disastrous phishing attacks using PowerShell, KnowBe4 PhishER, and the Microsoft 0365 compliance center features to remove unwanted malicious content. Host security meetings for executive management regularly. Perform secure code review using VeraCode scanner. Organize security documentation utilizing Microsoft Word and Visio. Recommend changes in the security policy to augment and improve best practices and procedures. Introduce and manage Exchange Mail Flow rules and connections for forced TLS 1.2 Encryption. Deploy Zscaler to provide an enterprise-wide network security standard. Approve SOW and negotiate SLAs saving the company thousands of dollars per year. Enforce compliance with HIPAA regulations and requirements and function as a liaison during Department of Health and Human Services audits. Executive Incident Response with rudimentary forensics using Microsoft’s Unified Audit Log. Govern security advisories from services such as MS-ISAC, SANS ISC, and CERT as needed. KEY ACHIEVEMENTS: Governed SIEM/SOC roll out investigating cost and feasibility of internal security operations. Sourced third party vendor options selecting the most affordable with the best quality capable of supporting security operations while cutting costs by $700K YoY. Deployed program and gained clear access with the added benefit of scalability. Pioneered the cloud security implementation project resolving the problem of having no centralized network. Discovered prospective solutions selecting Zscaler which routed all traffic through the cloud security infrastructure significantly reducing the cost of business per site.