Technical Information Security Officer Resume
4.00/5 (Submit Your Rating)
PROFESSIONAL EXPERIENCE
Technical Information Security Officer
ConfidentialResponsibilities:
- Reports IS issues toIT as applicable with appropriate recommendations and documentation
- Implement security solutions according to Security Policy and Practices established by Citigroup
- Work withIT to develop processes and procedures to ensure information security policies and standards are integrated
- Promote awareness of current policies and standards, as well as revisions and developments; provide consistent interpretation of policy to IT
- Build and maintain relationship with IT, to increase IS awareness
- Interfaces with the business where technical IS solutions are required and advises on the impact to the bottom line while still satisfying business objectives.
- Establishes and maintains relationships with domain architects, project managers, and others within the technology development unit.
- Defines secure configurations leveraging technical knowledge and problem solving skills in the network, database, server and desktop technology areas in accordance with the secure SDLC process.
- Manages risk by analyzing the root cause of issues, impact to technology and required corrective actions leveraging advanced analytical skills.
- Schedules, hosts, and drives meetings with multiple levels of technology management requiring strong communication, influence, and diplomacy skills to ensure that secure development procedures are addressed.
- Participates in the definition and implementation of procedures to control developer access to production according to corporate guidelines and standards.
TECHNICAL SKILLS
- Undergraduate Degree with 5+ years of IS experience or very strong IT knowledge
- Experience with interpretation and application of IS Policy and Standards
- A good understanding of application security (web apps/services and/or, mainframe) and development processes and proven ability to identify security threats.
- Experience working under minimal supervision from management with a strong commitment to team participation.
- An understanding of the system development lifecycle as it relates to Information Security.
- Ability to work with and influence developers, development managers, project managers, technology peers, and business contacts are required.
- Application security architecture, a plus
- Strong risk analysis and problem solving skills
- Consultative / advisory skills.
- Some influence / conflict resolution skills.
- Verbal and written communication skills.
- Industry IS standards
- CISSP, CISA/M or equivalent certifications (preferred)