Tim S.

Tim S. Email and Phone Number

Information System Auditor @ Payspan, now part of Zelis
Tim S.'s Location
Metro Jacksonville, United States, United States
About Tim S.

Enterprise information security professional with extensive experience identifying and remediating known and emerging threats targeting the confidentiality, integrity, and availability of financial institution data assets. Well versed in adapting to swift and significant change when necessary to achieve organizational goals. Expertise in end-point security monitoring and response, vulnerability detection/remediation, IAM administration, SEIM and incident management

Tim S.'s Current Company Details
Payspan, now part of Zelis

Payspan, Now Part Of Zelis

View
Information System Auditor
Tim S. Work Experience Details
  • Payspan, Now Part Of Zelis
    Information System Auditor
    Payspan, Now Part Of Zelis Nov 2022 - Present
    Jacksonville, Fl, Us
    • Responsible for the planning, preparation and pre-assessment exercises related to PCI-DSS version change to version4.• Responsible for translating regulatory and compliance requirements for critical business operations into actionable project activities• Provide oversight and assist coordinating activities such as internal and external IT audits and IT compliance activities including SOC 1&2, PCI DSS, SSAE 18, HITRUST, and HIPAA• Conduct and oversee continual internal assessments to ensure compliance is maintained• Monitor and assist with IT governance including researching compliance frameworks as the environment changes, creating and/or updating corporate policies, standards, and procedures• Assess compliance and operational risks• Collaborate with other non-IT compliance organizations (Human Resources, Finance, Development, others) for organizational compliance requirements• Responsible for the administrating and maintaining the organizations Governance, Risk and Compliance (GRC) tool including building control objective templates aligned to compliance goals (SOC, PCI, etc), creating, assigning and tracking tasks• Responsible for evidence collection and review to ensure adherence to compliance objectives• Provide oversight of all identified control vulnerabilities• Coordinate, track and report control finding and observation remediation efforts• Lead the organization through successful HITRUST certification • Maintained SOC/PCI/EHNAC certification status
  • Healthcare Payment Solutions
    Information System Auditor
    Healthcare Payment Solutions Jun 2019 - Present
    • Responsible for translating regulatory and compliance requirements for critical business operations into actionable project activities• Provide oversight and assist coordinating activities such as internal and external IT audits and IT compliance activities including SOC 1&2, PCI DSS, SSAE 18, HITRUST, and HIPAA• Conduct and oversee continual internal assessments to ensure compliance is maintained• Monitor and assist with IT governance including researching compliance frameworks as the environment changes, creating and/or updating corporate policies, standards, and procedures• Assess compliance and operational risks• Collaborate with other non-IT compliance organizations (Human Resources, Finance, Development, others) for organizational compliance requirements• Responsible for the administrating and maintaining the organizations Governance, Risk and Compliance (GRC) tool including building control objective templates aligned to compliance goals (SOC, PCI, etc), creating, assigning and tracking tasks• Responsible for evidence collection and review to ensure adherence to compliance objectives• Provide oversight of all identified control vulnerabilities• Coordinate, track and report control finding and observation remediation efforts• Lead the organization through successful HITRUST certification (2019)• Maintained SOC/PCI/EHNAC certification status
  • Florida Blue
    Information Security Engineer
    Florida Blue Dec 2018 - Jun 2019
    Jacksonville, Florida, Us
    Responsible for performing scans against the environment to identify and lead the remediation of discovered vulnerabilities, respond to audit inquiries and ensure enterprise-wide DISA/NIST compliance. Core Job Functions• Monitor and analyze vulnerabilities within the enterprise including the prioritization and tracking of remediation efforts and plans of actions and milestones (POA&M)• Liaise with SPOC, leadership and SME’s on vulnerabilities discovered to drive remediation efforts • Evaluate and test controls in accordance with DISA, NIST STIGs • Provide oversight and support for incident escalations where applicable• Perform regular policy and procedure documentation reviews/updates
  • Deustche Bank
    Security And Risk Manager
    Deustche Bank Oct 2017 - Jul 2018
    ● Direct line manager - VP of Security and Risk (America’s)● Responsible for security exception and change governance pertaining to:o DLP controls (in partnership with CISO)o Full disk encryption (in partnership with eDiscovery)o Data preservation (in partnership with eDiscovery)o Non-Standard/Unpackaged applications and browserso Symantec end point protection change management ● Facilitated the deactivation of unused or abandoned Networked applications and IBAC firewall rules closing likely security gaps● Liaison with the central data-leakage policy team for the change management and implementation of DLP policy changes and exceptions● Implemented a confidential data preservation lookup solution to meet existing and future regulatory needs
  • Bank Of America
    Malware Detection And Response
    Bank Of America Apr 2016 - Sep 2016
    Charlotte, Nc, Us
    Accountable for the daily monitoring, identifying and responding to infrastructure vulnerabilitiesProven ability to gauge threat and risk ratings based on adversary and partner intel and disseminating these findings to minimize the organizations threat surfaceResponsible for proving, documenting and indexing threat indicators to ensure reliable and effective control and process techniques are implementedEstablish and maintain partnerships across the organization to drive swift threat mitigation efforts through testing and developmentProven ability to work with multiple FI organizations regarding new and emerging threats, best practices and minimizing deployment impact Utilized 3rd party tools to detect, assess and eradicate known threat actor techniques, tools and delivery
  • Bank Of America
    Vulnerability Analysis And Remediation
    Bank Of America Feb 2014 - Apr 2016
    Charlotte, Nc, Us
    Role requiring advanced knowledge of information security regulations, best practices, attack vectors and security incident management including tracking and monitoring violations and breaches from detection to remediationAccountable for the daily monitoring, identifying and responding to infrastructure vulnerabilities and disseminating these findings and offer subject matter expert guidance and leadership throughout the enterpriseResponsible for the enforcement of enterprise policies and best practicesEstablish and maintain partnerships across the enterprise to drive remediation and enhance the organizations security postureRemediation control owner responsible for vetting and publishing control metrics on an executive levelIntroduced security process optimization and performance tuning solutionsAccountable for the development, implementation and management of enterprise security processes, including security event and incident management playbooks, training decks, and global policiesResponsible for leading remediation efforts in an environment that requires manual configuration and/or source code changes to resolveAccountable for proactively identifying and correcting critical control gaps
  • Bank Of America
    Cyber Event & Incident Response
    Bank Of America Feb 2013 - Feb 2014
    Charlotte, Nc, Us
    • Responsible for owning multiple security events/incidents of various severity and following through until the threat is eradicated or contained • Security event intake point responsible for the expeditious deprovisioning and mobile data remote wipe requests to aid aligned security teams during sensitive leaver and/or legal events• Ensured security controls and data assets are supported and performing as expected by providing support in an on-call, follow the sun capacity• Responsible for the intake, assignment, documentation, tracking and monitoring of various security events to ensure all resolutions meet or exceeds the organizations standards pertaining to indicators of compromise and validated intel (CVE/NVD’s, Definitions, Hash’s etc)) in a fast paced, highly visible, request based corporate environment
  • Bank Of America
    Identity & Access Management
    Bank Of America Jun 2008 - Feb 2013
    Charlotte, Nc, Us
    • Supported the integration of legacy operational teams into a single functional entity during a time of acquisition  This role was responsible for creating an encapsulated environment and testing tool compatibility / integration through virtualization as a precursor to an organizational roll out• Responsible for the daily implementation and monitoring of enterprise RBAC/DAC/MAC controls• Responsible for the provisioning / deprovisioning and administration of various enterprise assets including non-interactive service accounts, security groups, testing (UAT), end user, secondary user accounts (Privileged) and Unix accounts; shared directories, corporate LDAP management, Exchange access requests and mailbox creation, shared mailing lists and distribution group access in active directory (Quest Active Roles Server) supporting Windows, Solaris and Unix/Linux environments• Remote/Mobility user administration: RSA Token/FOB access request administration• Performed ongoing access control assessments to identify process and/or control gaps and security concerns in addition to identifying opportunities for improvement • Provided leadership and consultation regarding requests for access to legacy transaction management systems and frameworks (CICS app servers/TSO environment) which required working closely with various mainframe RACF administrators to satisfy access requests• Maintained various script repositories comprised of PowerShell, bash, visual basic, SQL (Oracle, MySQL, MSSQL) and Excel macros used in the creation of bulk access and revocation requests in active directory• Responsible for the daily assignment, processing, tracking, documentation and follow-up of multiple IAM requests in a fast paced, SLA driven environment• Accountable for maintaining the accelerated account on-boarding process for critical business function accounts• Maintained Identity and Access Management (IAM) process documentation and training decks
  • Merrill Lynch
    Helpdesk Support Specialist
    Merrill Lynch Nov 2006 - Jun 2008
    New York, Ny, Us
  • Comcast
    Internet Provider Support Specialist
    Comcast Apr 2004 - Sep 2006
    Philadelphia, Pa, Us

Tim S. Skills

Information Security Business Continuity Active Directory Incident Management Pci Dss Sdlc Enterprise Architecture Information Technology Cissp Disaster Recovery Information Security Management Network Security Vulnerability Assessment Itil Risk Management Information Assurance Vendor Management Security Virtualization Computer Security System Administration Help Desk Support Technical Support It Management It Operations Data Security Vmware It Service Management Business Analysis Windows Server Visio Data Center Dns It Strategy Identity Management Microsoft Exchange Citrix Sharepoint Operating Systems Servers Identity And Access Management Business Process Improvement Troubleshooting Customer Service Microsoft Office Networking Consulting Financial Risk Leadership Software Documentation

Tim S. Education Details

  • Capella University
    Capella University
    Information Assurance And Security
  • University Of Phoenix
    University Of Phoenix
    Information Technology/Information System Security
  • Itt Technical Institute
    Itt Technical Institute
    Electronic Engineering

Frequently Asked Questions about Tim S.

What company does Tim S. work for?

Tim S. works for Payspan, Now Part Of Zelis

What is Tim S.'s role at the current company?

Tim S.'s current role is Information System Auditor.

What schools did Tim S. attend?

Tim S. attended Capella University, University Of Phoenix, Itt Technical Institute.

What skills is Tim S. known for?

Tim S. has skills like Information Security, Business Continuity, Active Directory, Incident Management, Pci Dss, Sdlc, Enterprise Architecture, Information Technology, Cissp, Disaster Recovery, Information Security Management, Network Security.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.