Global Security Consulting Manager, VeriSign, Inc.
Fayetteville, Arkansas Area
Global Security Consulting Manager, VeriSign, Inc.
Fayetteville, Arkansas Area
• 2 years CTO, web based e-learning company (Managed $1.3 million development budget)
• 2 years VP, Operations, networking consulting firm (Managed $500,000 budget)
• 2 years President/founder, network consulting firm (acquired)
• 8 years technology Venture Capital / M&A experience
• 9 years information security experience
• 10 years technology management and consulting experience
• Proven track record of creating and delivering, innovative, critical and secure technologies
• Technology startups and venture capital
• Security management and operations
• Securing large scale enterprise operations
(Public Company; 1001-5000 employees; VRSN; Computer & Network Security industry)
October 2006 — Present (2 years 10 months)
(Privately Held; Information Technology and Services industry)
November 2005 — August 2006 (10 months)
Served as subject matter expert in the areas of security, compliance, and IT Operations planning and implementation for investment portfolio companies. Managed multiple projects in various stages for multiple portfolio companies at any given point, many of which were business critical in nature.
• Responsible for creating a secure, scalable IT operations roll-out plan for a distributed digital sign business model with over 1,500 geographically disperse computing nodes
• Managed development, testing and implementation of hub and spoke vpn management network for digital signage nodes
• Architected, created and implemented a custom secure software license and authentication management gateway to manage client software licensing
• Served as PCI compliance project SME, spearheading security policy, process and technology enhancements
• Re-designed datacenter core switching infrastructure introducing redundant switching to the cabinet level
• Reported to the CEO of Stone Holdings
(Privately Held; 201-500 employees; Computer & Network Security industry)
June 2004 — November 2005 (1 year 6 months)
Responsible for all areas of security including operations, implementation, budgeting and certification/audit for a global network processing over $100million per day.
Created firewall implementation and management processes to provide for better quality, security and documentation for our 270 firewalls
Responsible for creating a patch management board that centralizes patch deployment decisions for all network and computing devices in the enterprise
Led the VISA CISP and PCI program initiatives and managed all remediation efforts achieving CISP Service Provider compliance for Data Return
Implemented the use of smart-token devices for 2-factor authentication for remote users
Implemented new security policy standards including Audit Policy, Password Policy, Document Sensitivity and Labeling Policy, Media Destruction and re-use Policy.
Architected and implemented a distributed Snort deployment for network IDS
Responsible for a staff of 4 security engineers
(Privately Held; 1-10 employees; Computer & Network Security industry)
August 2001 — December 2004 (3 years 5 months)
Provided the vision, plan and execution path for commercializing a product line around technologies built to assist various Stone companies with their risk management process. Responsible for $450,000 budget.
Responsible for market research (information security/perimeter vulnerability analysis specific), product plans and detailed revenue models
Developed centrally controlled scanning management platform designed to deliver perimeter vulnerability management for large, geographically diverse systems
Architected and managed development of remediation workflow management tool designed to assist companies in creating an audit and accountability record during network remediation for regulatory and best practice compliance
Designed vertical reporting system to assess multiple regulated verticals such as Gramm-Leach-Bliley Act (GLBA), Healthcare Information Portability and Accountability Act (HIPAA), Sarbanes/Oxley and California HB 1386
(Privately Held; 1-10 employees; Computer & Network Security industry)
August 2003 — June 2004 (11 months)
Provided information security and network management professional services on an independent consulting basis for multiple companies.
Served as an outsourced ISO17799 assessment consultant for NetDiligence, Inc. (a Stone Investments related company)
Provided ISO17799 assessment guidance for WebCE, LLC (a Stone Investments related company)
Served as subject matter expert advising on security and compliance impact of systems integration projects for multiple companies
Responsible for planning, architecting and leading phased relocation of production datacenters for multiple companies
Provided managed vulnerability services for multiple companies
Responsible for creating/managing systems/networks utilizing various technologies Nessus, Nmap, Nikto, PIX firewalls, Checkpoint firewalls, multiple VPN technologies, SSL, SSH, Apache, IIS, Microsoft SQL, PostgreSQL, and .NET
(Privately Held; 51-200 employees; Information Technology and Services industry)
August 1998 — August 2003 (5 years 1 month)
Provided guidance in virtually all areas of technology acquisition, planning, infrastructure, software, security, networking and application development for more than 10 portfolio companies.
Evaluated technical companies potential equity involvement and joint ventures
Ensured that all technology selection, planning, development and deployment were strategic to each investment
Interviewed possible CTO/CIO candidates for portfolio companies
Responsible for consolidation of critical infrastructure data centers
Advised portfolio companies on information security compliance efforts (GLBA/FDIC/OTS compliance efforts for a $4 billion financial institution)
Deployed and managed networks that included interoperable Microsoft and Linux platforms housing applications written in PHP, Perl, ASP and .NET using Microsoft SQL 7, mySQL and PostgreSQL relational databases and relying on Apache and IIS server technologies.
(Privately Held; 11-50 employees; Information Technology and Services industry)
August 1999 — January 2001 (1 year 6 months)
Led the technology team in growing a 100% paper-based local continuing education company with $200,000 in revenue to a nationwide online e-business with integrated call center management, content delivery and nationwide state approved online testing with $4 million in revenue.
Responsible for all phases of technology including security, application architecture, server architecture, data structure, data center, product management, documentation, quality assurance and configuration management
Architected secure process flow for managing sensitive data throughout the application (including social security numbers and credit card data)
Conceptualized and managed development of a business-to-business Private Labeling/Co-brand syndication system to create B2B market
Implemented and managed multi-platform technical environment which included Microsoft and Linux platforms delivering applications written in ASP, and PHP with Microsoft SQL and PostreSQL relational databases
(Privately Held; 1-10 employees; Information Technology and Services industry)
August 1998 — January 2001 (2 years 6 months)
Worked with various clients to successfully create, implement and manage internet commerce strategies and applications in the NetVitality secure networking environment. Responsible for creating all IT budgets, all IT department personnel decisions, security policy management, management of data center activities and daily operations. Responsible for $350,000 budget.
Led project for the National Fraud Center to provide a highly secure searchable database housing sensitive data (ss numbers, personal financial data, legal data, etc) for over 20 million people to law enforcement industry.
Led application development project for Sportsware Technologies an online nationally syndicated golf course database application serving Golf Digest, Golf.com, CNNSI.com and Lycos.com
Implemented and managed technologies which included Microsoft and Linux platforms delivering applications written in ASP and Perl with Microsoft SQL relational databases
(Privately Held; 1-10 employees; Information Technology and Services industry)
October 1996 — August 1998 (1 year 11 months)
Seeded and founded I-Net Solutions, Inc., a network consulting firm focused on network services for local ISPs and applications hosting. Responsible for creating all budgets, all personnel decisions, for all business strategies, marketing strategies and business development. Acquired by Stone Investments, Inc. August, 1998.
Responsible for all acquisition negotiations
Successfully created strategic partnerships with companies such as Nullsoft, Inc. (creators of Winamp), Susquehanna Radio Corp Dallas (KTCK, KPLX, KLIF) and Hays Internet Marketing (creators of e-kiss.com)
Responsible for maintaining core infrastructure technologies supporting a combined 25,000 ISP B2B and B2C clients
Managed numerous ISP core infrastructure technologies including high redundant network routing using BGP, security consulting and system administration for FreeBSD, BSDI, Linux, Solaris/Sun OS, Digital Unix, and Windows NT operating systems.
1994 — 1995
1991 — 1993