kerry green professional resume - 7-21-2016

5
Kerry W.A. Green 5824 120 th Pl SE Snohomish, WA 98296 Phone: (509) 899-0113 E-Mail: [email protected] Objective Full-time permanent employment as an IT Security Manager, IT Security Consultant, IT Security Compliance Manager, IT Audit & Compliance Analyst, or Senior IT Security Analyst. Experience BrickRed Systems LLC January 2015– Present Security Compliance Manager, (WWIT CP ISRM EBCM) Manage a team of Risk Treatment/Compliance Analysts for MSIT global services at Microsoft (internal) working in the Information Security and Risk Management (ISRM) group impacting enterprise Governance, Risk and Compliance (GRC). As a Senior Consultant and Compliance Security Officer I manage Security Policy (processes and procedures) and Regulatory Controls (SOX-404, GLBA, HIPAA, PCI-DSS, FedRAMP, FIPS etc.) aligning to standard frameworks (COBIT, ITIL, ISO- 27001/20000, FISMA/NIST 800-53/30, DIACAP, etc). I manage and enforce enterprise wide standards and regulatory controls impacting internal policy/control violation exceptions/remediation, Data Loss Prevention programs (remediation/mitigation), streamlined security assessments consulting, all the while improving security, compliance and regulatory control to the organization. In my tenure I created a Security Exceptions/Compliance program which realized 80% reduction in scope, impact and exposure of risks to the organization with quicker engineering assessments, threat/vulnerability analysis and C-Level acknowledgment. Launch Consulting/Direct Apps Inc. May 2014– October 2014 SDO Escalation Management, Major Incident Manager (WWIT CP WWISDM) Level 3/Tier 3 escalation management of MSIT global services at Microsoft (internal). Coordinate, communicate, resolve Major Incident’s and Crisis Management with high visibility, high impact and large scope. Act as liaison between disparate groups, manage resources to resolve major crises and mitigate issues that have a service, business or financial impact. DBBuilder, Inc. November 2013 – April 2014 Systems Analyst Independently service/support, assess, evaluate and manage MSSQLSERVER services for a Point of Sale application program based on a VB6 database, being ported over to .NET services, to include Centralized services/server’s, Window’s Server 2003/2008 administration (Active Directory, WSUS, Forefront, etc.), Terminal Services, remote access (VPN/VNC/MSSQL), system setup (Win7 32/64-bit), credit card services (to include end-to-end encryption), and auditing PCI-DSS Compliance.

Upload: kerry-green

Post on 19-Feb-2017

155 views

Category:

Documents


5 download

TRANSCRIPT

KerryW.A.Green5824120thPlSE��Snohomish,WA98296��Phone:(509)899-0113��E-Mail:[email protected]

Objective

Full-timepermanentemploymentasanITSecurityManager,ITSecurityConsultant,ITSecurityComplianceManager,ITAudit&ComplianceAnalyst,orSeniorITSecurityAnalyst.

Experience

BrickRedSystemsLLC January2015–PresentSecurityComplianceManager,(WWITCPISRMEBCM)

ManageateamofRiskTreatment/ComplianceAnalystsforMSITglobalservicesatMicrosoft(internal)workingintheInformationSecurityandRiskManagement(ISRM)groupimpactingenterpriseGovernance,RiskandCompliance(GRC).AsaSeniorConsultantandComplianceSecurityOfficerImanageSecurityPolicy(processesandprocedures)andRegulatoryControls(SOX-404,GLBA,HIPAA,PCI-DSS,FedRAMP,FIPSetc.)aligningtostandardframeworks(COBIT,ITIL,ISO-27001/20000,FISMA/NIST800-53/30,DIACAP,etc).Imanageandenforceenterprisewidestandardsandregulatorycontrolsimpactinginternalpolicy/controlviolationexceptions/remediation,DataLossPreventionprograms(remediation/mitigation),streamlinedsecurityassessmentsconsulting,allthewhileimprovingsecurity,complianceandregulatorycontroltotheorganization.InmytenureIcreatedaSecurityExceptions/Complianceprogramwhichrealized80%reductioninscope,impactandexposureofriskstotheorganizationwithquickerengineeringassessments,threat/vulnerabilityanalysisandC-Levelacknowledgment.

LaunchConsulting/DirectAppsInc. May2014–October2014SDOEscalationManagement,MajorIncidentManager(WWITCPWWISDM)

Level3/Tier3escalationmanagementofMSITglobalservicesatMicrosoft(internal).Coordinate,communicate,resolveMajorIncident’sandCrisisManagementwithhighvisibility,highimpactandlargescope.Actasliaisonbetweendisparategroups,manageresourcestoresolvemajorcrisesandmitigateissuesthathaveaservice,businessorfinancialimpact.

DBBuilder,Inc. November2013–April2014SystemsAnalyst

Independentlyservice/support,assess,evaluateandmanageMSSQLSERVERservicesforaPointofSaleapplicationprogrambasedonaVB6database,beingportedoverto.NETservices,toincludeCentralizedservices/server’s,Window’sServer2003/2008administration(ActiveDirectory,WSUS,Forefront,etc.),TerminalServices,remoteaccess(VPN/VNC/MSSQL),systemsetup(Win732/64-bit),creditcardservices(toincludeend-to-endencryption),andauditingPCI-DSSCompliance.

2

Apple,Inc. April2013–August2013SystemSupportEngineer(Tier2–CPU/iOS)

Independentlydesign,acquire,install,maintain,troubleshoot,andprovideconsultationforsystem,application,project,andoperationalneedsinanassignedareaofresponsibility.Establishworkmethodsandinnovativeapproachestocompleteassignmentsandcoordinateprojectssuchasconductingneedsassessmentsandevaluatingproducts;creatinginstallationplans;independentlyinstallandconfigurehardware/software;collaboratewithvendorstoresolveproblems;analyzeandcorrectnetworkmalfunctions;instructusers;serveasaLead;andserveasatechnicalmentortolower-levelstaff.

WesternGovernorsUniversity March2012–March2013Faculty/Mentor,CollegeofInformationTechnology

Assess,evaluate,manageandmentorCompetency-BasedITPrograms(ONLINE),andacademicactivity,astheyrelatetostudentsactivelyenrolledandengagedinBachelor/GraduatedegreeprogramswithintheCollegeofInformationTechnologyatWesternGovernorsUniversity.Specifically,IspecializeinGraduateDegreeprogramtracksfocusedontheMasterofScienceinInformationSecurityandAssurance(MSISA)andNetworkManagement(MSITNM).Mybackground,experience,education,certificationandexpertisesupportthesuccessofmystudentsthroughexpertconsultationandimpactstheirexperienceoftheirdegreeprograms/tracksofferedatWGU.

CapellaUniversity February2003–February2012AdjunctProfessor,GraduateSchoolofBusinessandTechnology,InformationAssuranceandSecurity

Multipleyearsofgraduatelevelteaching(ONLINE)hasprovidedmewithexperienceincurriculumdevelopmentandinstructionaldesign,studentassessmentoflearningachievements,useanddistributionofapplicableLearningResources,andgradedevaluations.TheNationalSecurityAgency(NSA)andtheDepartmentofHomelandSecurity(DHS)havedesignatedCapellaUniversityaNationalCenterofAcademicExcellenceinInformationAssuranceandEducation(CAEIAE).Alistingofcoursestaught,designedandadministeredareasfollows;

• TS5120–ProjectManagementforITProfessionals

• TS5270–CyberThreatstotheEnterprise

• TS5507–NetworkTechnology

• TS5508–EnterpriseSecurity

• TS5516–Client/ServerArchitectureandDesign

• TS5517–NetworkEnterpriseArchitectureandDesign

• TS5518–AdvancedNetworkTechnology–Routing

• TS5520–OperatingSystemTheoryandPractice

• TS5521–AdvancedNetworkTechnology–Switching

• TS5522–AdvancedNetworkTechnology–RemoteAccess

• TS5524–AdvancedProjectManagement

• TS5525–ProjectRiskManagement

• TS5531–SecurityManagementPrinciples

• TS5532–SecureSystemDevelopmentandCryptography

CentralWashingtonUniversity October2000–February2012InformationTechnologySpecialist(ITS)III,ClientSupportServices(WashingtonStateCivilServiceclassificationcode479K,Range58)

3

Independentlydesign,acquire,install,maintain,troubleshoot,andprovideconsultationforsystem,application,project,telecommunication,andoperationalneedsinanassignedareaofresponsibility.Establishworkmethodsandinnovativeapproachestocompleteassignmentsandcoordinateprojectssuchasconductingneedsassessmentsandevaluatingproducts;creatinginstallationplans;independentlyinstallandconfigurehardware/software;collaboratewithvendorstoresolveproblems;analyzeandcorrectnetworkmalfunctions;instructusers;serveasaLead;andserveasatechnicalmentortolower-levelstaff.

ComputerCentral May1999–October2000Sales/MarketingManager

• Managed,recruitedandtrainedsalespersonnelandservicetechniciansintheserviceandsupportofInternetServiceProvider(ISP)technicalsupportandhardware/softwaretraining.

• Providedindividual,anddepartmentalleveltraining,intheinstructionandprofessionaldevelopmentinbusiness,marketingandinformationtechnologyconceptsandtheories.

EffectrixCommunication’s,LLC June1998–May1999CallCenterManager(Telephony/Computing)

• Managed,recruitedandtrainedHelpDeskpersonnelforremoteservice/supportofapplicationsystems,hardwareplatforms,andtelephonysystemstoincludeVoice-overIP(VoIP)andUnifiedMessaging.

• Created,implemented,andintegratedtrainingprogramsfortheinstructionandprofessionaldevelopmentofHelpDeskpersonnelinthebasic,andadvanced,theoriesandconceptsoftelecommunicationssupportdealingwithVoIP,UnifiedMessaging,dial-upnetworking,aswellasPC/MACsoftwaresupportofsuchproducts.

Education

ColoradoStateUniversity 2004

• GraduateCertificate,InformationTechnologyProjectManagement

UniversityofPhoenix 2002

• MasterofArts,OrganizationalManagement

CentralWashingtonUniversity 1999

• BachelorofScience,AdministrativeManagement

YakimaValleyCommunityCollege 1997

• AssociateofArtsandScience

AwardsGoldStarAward(2015)

• BrickRedSystemsLLC-OutstandingITSecurityConsultantand‘ExcellenceinServiceAward’

UpsilonPiEpsilon(2009)

• NationalBusinessHonorSociety

• HonoraryMember,ColoradoStateUniversity

OmicronDeltaKappa(2004)

4

• NationalLeadershipHonorSociety

• Honorary“Charter”Member,CWUChapter,CentralWashingtonUniversity

EpsilonPiTau(2003)

• InternationalHonoraryforProfessionsinTechnology

• HonoraryMember,GammaDeltaChapter,CaliforniaPolytechnicStateUniversity(CalPoly)

Certification(IATLevelIIandIAMLevelIcertifiedperDoD8570.01/FISMA)

ComputingandTechnologyIndustryAssociation(CompTIA)

• A+hardwareandsoftwarecertified(multipleplatformsandapplications)

• Network+certified(Internettechnologies,TCP/IP,LAN/WAN,hardware)

• Security+certified(SecurityManagementPrinciples)

HamptonGroup/ProjectManagementInstitute(PMI)

• ITProjectManagement,graduatecertificate

NationalSecurityAgency

• INFOSECAssessmentMethodology(IAM)

• INFOSECEvaluationMethodology(IEM)

ProfessionalDevelopment

1. NationalSecurityAgency(NSA)Level-IIINFOSECAssessmentMethodology(IAM)andINFOSECEvaluationMethodology(IEM)trainingandcertification.**(CSIRTRedTeamlevel-IIsecurityaudittraining)

2. CapellaUniversityandWesternGovernorsUniversitybothhaveprogramsinInformationAssuranceandSecuritywherecurriculummeetsandexceedsCNSSrequirement’sandsystemstandards4011(NSTISSI4011–INFOSECProfessionals,NationalTrainingStandard)and4013(CNSS4013–SystemAdministratorsinInformationSystemsSecurity,NationalTrainingStandard)andhasreceivedrecognitionasaNationalCenterofAcademicExcellenceinInformationAssuranceEducation(CAEIAE).

3. FISMA,SOX,GLBA,PCI-DSS,HIPAA,ISO27001traininganddevelopment.

4. DIACAP/DITSCAPtraininganddevelopment.

5. ITILandCoBITtraininganddevelopment.

6. Peregrine(HewlettPackard-HP)ServiceCenter6.xtrainingandcertification(SCW050)(SC100).

7. CiscoCertifiedNetworkAssociate(CCNA)traininganddevelopment.

8. ISACACertifiedInformationSecurityManager(CISM)traininganddevelopment.

9. CertifiedInformationSystemsSecurityProfessional(CISSP)traininganddevelopment.

10. MicrosoftWindows2000/2003/2008Server/Professional(MCP)traininganddevelopment.

11. MacintoshOS-Xtraininganddevelopment.

12. CertifiedNovellAdministrator(CNA)professionaltraininganddevelopment.

5

13. 10+yearsofcorporateanduniversitytrainingandinstructioninthebasic,andadvanced,conceptsandtheoriesofbusiness,marketingandinformationtechnology.

TechnicalExpertise

1. Networkhardware/software(Cisco)

2. PChardware/software(x8632/64-bit,WinXPSP3Pro,Vista,Win7Pro/Enterprise,Win8Pro/Enterprise,Win10Pro/Enterprise,MSOfficeSuite2000/2003/2007,O365)

3. WindowsServer2000/2003/2008deploymentandadministration(ActiveDirectory/WSUS/Forefront)

4. SecuritySoftware(RSAArcher/EGRC,PGP-PKI,SophosA/V,SymantecA/V,MacAfeeA/V,ForeFrontA/V,SolarWinds)

5. SecurityHardware(Single-chipdevices–SmartCards,SafeNetiKey,RSASecureIDtokens,TPMchip’s,RFIDtag’s)

6. MAChardware/software(OSX/iOS)

7. Printer’s(laserjet’s/deskjet’s)

8. Protocol’s:TCP/IP,IPX/SPX,AppleTalk,FTP,UDP,DHCP,DNS,HTTP/S,IEEE802.11standard’sWEP,WPA(specializinginthe802.1ximplementationofWPA2–EAP/TTLSw/PAP),X.509,SSH,SSL,VNC,VPN,VoIP

9. HRISplatforms(PeopleSoft)

10. RDBMSplatforms(Oracle,MySQL,MSSQL)

11. LMSplatforms(Blackboard/WebCT/Elluminate,OutlookWebAccess)

12. AcademicAdministration(Banner,Peoplesoft)

13. SoftSkills:Manage,administer,assess,evaluate,recruit,train,advise,consult,budget,customerservice

Associations

• ComputingandTechnologyIndustryAssociation(CompTIA)

• CommitteeonNationalSecuritySystems(CNSS)

• NationalSecurityAgency(NSA)IATRP

• ProjectManagementInstitute(PMI)

• UpsilonPiEpsilon

• OmicronDeltaKappa

• EpsilonPiTau

• DisabledAmericanVeteran’s(DAV)