Sr. Architect – Information Security
Great-West
Created the enterprise blueprint for information security and successfully focused the program on standards, change management, risk analysis, awareness, and monitoring. Handled incidents involving numerous partners within the health insurance and financial services industries. Designed and implemented physical, administrative, and technical controls to safeguard information covered by HIPAA, GLB, and SOX.• Founded the computer security incident response team (CSIRT) to support multiple divisions and business units while minimizing incident response time, maximizing protection, and meeting compliance objectives. • Aligned security expenditures with business objectives by creating a risk assessment and management approach based on ROI.• Redesigned the enterprise network infrastructure through a series of strategic incremental changes without a budget or officially sponsored program. Seized opportunity created by a fast-tracked datacenter move to successfully culminate the project. • Organically developed in-house computer forensics team by mentoring Security Operations staff and guiding their annual training plan reducing investigation times and outsourcing costs. • Senior technical resource for Cisco routers, switches, ASA and Checkpoint Firewalls, VPN, IPS/IDS, RSA SecurID, and Bluecoat content filtering platforms.