Summary
Highly accomplished IT Security Manager with over 10 years of progressive experience in designing, implementing, and managing comprehensive cybersecurity programs. Proven expertise in risk management, compliance adherence, and incident response, safeguarding critical information assets in dynamic technology environments. Adept at leading cross-functional teams and leveraging advanced security frameworks to achieve organizational resilience and maintain a strong security posture.
Experience
- Led a team of 5 security analysts, improving incident response time by 30% and reducing critical vulnerabilities by 25% across 500+ endpoints.
- Developed and implemented a new risk assessment framework, reducing identified high-risk vulnerabilities by 40% in the first year.
- Conducted over 150 penetration tests and vulnerability assessments, identifying and remediating 200+ high-severity vulnerabilities in core applications.
- Instrumental in achieving PCI DSS compliance, contributing to a 100% successful annual audit for payment processing systems handling $500M+ transactions.
- Monitored security events and alerts, analyzing over 10,000 logs daily to detect potential security breaches.
- Assisted in the implementation of an EDR solution, resulting in a 15% improvement in endpoint threat detection.
- Responded to 200+ security incidents, documenting findings and contributing to post-incident reviews.
Projects
- Developed a Python-based tool to automatically generate secure configuration policies for AWS and Azure based on industry best practices.
- Increased efficiency in policy deployment by 40% and reduced human error in manual configuration.
- Contributes to open-source community, receiving 50+ stars and forks, demonstrating practical scripting and cloud security expertise.
- Built a personal project using Python to aggregate multiple open-source threat intelligence feeds and integrate them with a local firewall.
- Improved proactive threat detection capabilities for home network by 20%, blocking known malicious IPs and domains.
- Showcased ability to integrate disparate security data sources and automate defensive actions.
- Designed and developed an interactive online security awareness training module focused on phishing and social engineering.
- Utilized engaging content and quizzes, resulting in a 15% increase in employee awareness test scores.
- Demonstrated pedagogical skills in making complex security concepts accessible to non-technical audiences.
Education
- Specialized in Enterprise Security and Information Assurance.
- Awarded Dean's List for academic excellence with a GPA of 3.9/4.0.
- Graduated Magna Cum Laude with a GPA of 3.8/4.0.
- Completed honors thesis on 'Advanced Cryptographic Techniques for Secure Data Transmission'.





