Director Information Security Operations Resume
Knoxville, TN
SUMMARY
- I is an Information Security professional with nearly 30 years’ experience implementing security and managing IT infrastructure in a functional and meaningful way. As a sought - after speaker and educator,
- I have enjoyed many opportunities to train and lead teh next group of security professionals, whether as a faculty instructor or most recently leading a team of security professionals as teh Director of Information Security Operations.
- I is seeking a leadership position dat will enable me to synthesize my background in security, information systems, team building, problem solving and business enablement.
PROFESSIONAL EXPERIENCE
Confidential, Knoxville, TN
Director Information Security Operations
Responsibilities:
- Accountable for teh performance of teh Cyber Security Operations Center team and managed a hybrid 24/7 staff of 2 FTE analysts, 9 contractor analysts, and an MSSP provider.
- Partnered with business unit leads to define and enable success while maintaining required security controls.
- Developed and implemented more than 30 runbooks for security incident response.
- Facilitated tabletop exercises with critical business units to simulate security incidents and ensure preparedness.
- Coordinated strategy and technology for response to high-volume attacks, such as credential stuffing and DDoS.
- Built and implemented phishing response program and provided feedback to user awareness and education initiatives.
Information Security Architect
Confidential
Responsibilities:
- Architected and implemented security controls and related systems, including deception technology systems, SIEM, enterprise EDR system, IPS, NextGen Firewall (NGFW) based internet access content monitoring and filtering solution, and SSL VPN.
- Designed and administered security awareness and phishing defense programs with customized internal phishing, targeted education, positive reinforcement, media drop tests, and actionable metrics; simulations reduced click-thru rates from 42% to 12% and reporting rates increased to over 45%.
- Evaluated and adapted system architectures and security controls for cloud-based environments.
- Implemented password audit program; findings from dis semiannual effort drove revised password policies and enhanced user education. A follow-up audit revealed over 80% reduction in weak passwords.
Systems Engineer
Confidential
Responsibilities:
- Implemented enterprise antivirus, Host-Based Firewall (HBFW), and Host Intrusion Prevention System (HIPS) infrastructure.
- Administrated and maintained Active Directory.
- Installation, support, and maintenance for Citrix environments.
- Planned and operated enterprise server patch management program in coordination with business owners.
- Developed multi-level disaster recovery strategy with tested recovery methods.
- Course Instruction: Introduction to Information Assurance & Security; Ethical Hacking; Introduction to LAN Technologies; Foundation of Local Area Networks.
- Course Development: Sniffing and Network Analysis; Global Cyber Ethics; Infrastructure Administration.
TECHNICAL SKILLS
Skills: Leadership experience; Analytical thinker; CISSP-ISSAP; Public speaking; Problem solving; Enterprise security policy and implementation; Communication skills; Business enablement mindset.
Technologies: Endpoint Detection Response (EDR); Deception Technologies; Security Information and Event Management (SIEM); Patch Management; Linux; Windows; Active Directory; Microsoft Exchange; O365; Citrix; Cisco; Palo Alto Networks; LAN/WAN
Interests: Clock Repair; Photography; Coffee; Podcasts