From: route@monster.com
Sent: Friday, May 06, 2016 1:33 PM
To: hg@apeironinc.com
Subject: Please review this candidate for: Cloud
This resume has been forwarded to
you at the request of Monster User xapeix03
|
|||||||
|
|||||||
|
|
|
||||||
|
||||||
|
chiadi obI Phone: 813.389.9777 e-mail:
chiadi.obi@contilaconsulting.com Clearable
US Citizen Career SUMMARY · Seasoned and pragmatic information security executive with
over 17 years of professional exposure enabling organizations understand
their risk profile and appetite through information security consultation and
advisory. Adept at marrying security strategy with business drivers to
produce solutions. Excellent consultative and client management skills across
multiple markets, technologies and sectors. · Cloud Adoption Strategist. Cloud Security Architect.
Proficient at developing bespoke cloud architectures, strategies and
solutions for both commercial and public sectors in compliance with
pre-established frameworks while establishing acceptable levels of cloud
risk. · Team Developer. Trust Advisor. Leader with a deep
understanding of customers, their respective markets and technology roadmaps.
Demonstrable effectiveness in developing security strategies and solutions
that solve business challenges and extend revenue generating
opportunities. Education
Master of Science,
Management (MSM-ISS) – Information System Security & Project Management,
6/2007 - Colorado Technical University (CTU) Bachelor of Science
(B.Sc.) – Management Information System, 12/1998 - University of South
Florida professional
development
§ CISM (Certified Information System Manager) § CISSP (Certified Information Systems Security
Professional) § CRISC (Certified in Risk and Information Systems Control) § CCNA (Cisco Certified Network Associate) § CCSK (Certified Cloud Security Knowledge) – 8/2015 Core
competences
§ Leadership, Management Consulting: Visionary leader. Excellent negotiator with
influential conflict resolution capabilities. Critical Thinker. Team
Developer. Proficient at disambiguating situations and environments to
produce impacting results. § Cloud: Cloud
strategy & evangelism, development of adoption & migration
architecture and strategies for both public and commercial sectors.
Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Cloud
Controls Matrix (CCM), Windows Azure, Azure Express Route, Office365,
Private/Public/Hybrid/Government Community Cloud deployment models,
Modernized Applications & large scale cloud enabled Datacenter build-out,
Cloud services orchestration, Hyper-V virtualization, Cloud OS Network (COSN),
CAPEX vs. OPEX considerations in deployment models § Security & Compliance, Government Framework &
Regulation: NIST 800-53 and other Special
Publications, FedRAMP, DISA, Cloud Security Alliance (CSA), UK Data Privacy
Act, GLBA § Framework Alignment:
PCI DSS, ISO 27001, FFIEC, GLBA, HIPAA, SOX § Threat Vulnerability Profiling and Management: Threats & Controls Catalog, Third-Party Risk
Assessments, Data Loss Prevention/Protection, Application Vulnerability
Assessments, Security Policies, Program & Awareness Development § RFP, Security Service Level Agreement (SSLA), Master
Security Service Agreement (MSSA):
Assessment, Development & Assessment Work
Experience
InfoReliance11/2014 – Present Responsible for the development of a cloud
security practice that enables business development of new cloud
opportunities within the public sector. Principal Cloud Security Architect
responsible for the cloud adoption and migration for public sector agencies
such as HHS, NTSB, etc. Deeply engaged with all facets of the business
helping drive security strategy and implementation for current public and
private sector clients in addition to generating new revenue streams. Cloud
Security Strategy Advisor · Principally responsible for designing the cloud security
and compliance framework used across the entire consulting practice · Engage with Chief Technology Officer (CTO) to drive cloud
computing strategy with a principal focus on architecture, security,
compliance and governance for public sector customers · Evangelize InfoReliance’s vast portfolio of cybersecurity
products and services whilst unifying its cybersecurity story across the
enterprise to include Sales, Business Development, Operations, etc. · Principal security SME brought in to address cloud
security related concerns & inquiries during the closure phase of new
business opportunities · Drive cloud strategy and security engagement for assigned
public sector clients seeking to adopt or migrate to the cloud · Develop FedRAMP strategies and packages designed to help
public sector clients obtain the Authority to Operate (ATO) required to
implement cloud technologies Microsoft Online Services Security &
Compliance | Cloud &
Enterprise 8/2012
– 7/2014* (*Brief employment period was
attributable to personal challenges that required my attention) Senior Engagement Manager (EM) and
Principal Security Advisor dedicated to the Windows Azure & O365 cloud
services’ and business groups [was the primary EM for both engineering groups
until an EM was hired for the O365 group]. Principally responsible for
driving the strategic and operational direction of the cloud online services
team in support of Microsoft’s cloud strategy and infrastructure services to
include security & compliance, privacy and governance. Overall
responsibility for envisioning, provisioning, supporting and delivering
security and compliance engagement services for over 200+
cloud services (Azure, Bing, O365, Xbox, Dynamics CRM online, etc.) to over 20
million businesses totally over 1B customers in 76 markets worldwide. Principal
advisor on the execution of online security & compliance’s strategy,
policies, engineering and build-out of the Azure Government Community Cloud.
Partner with business, marketing and legal teams to help develop and/or
understand Microsoft cloud offerings for adoption by both public sector
agencies and commercial enterprises all within a highly-matrixed environment
with an extensive global reach. Senior
Engagement Manager & Principal Cloud Adoption Strategist · Principally responsible for providing security, compliance
and strategic advisory in support of Microsoft’s business & engineering
groups’ cloud offerings · Developed and drove strategic direction and architecture
for emergent cloud, mobile and big data trends and technologies and provided
advisory to the Cloud & Enterprise senior management in alignment with
Microsoft’s Mobile First, Cloud First strategy. Delivered results by aligning
strategic direction with operational requirements through the prioritization
of initiatives and continual analysis of business needs · Direct line of reporting on progress readouts to senior
leadership teams comprising of Corporate VPs, General Managers and Senior
Directors in support of next generation cloud initiatives most notably the
Azure Government Community Cloud (GCC) § Led people within workstreams responsible for cultivating
relationships between Microsoft Public Sector, Sales, Business and
Engineering groups. Assisted in the generation new revenue streams from
government agencies looking to onboard onto the Windows Azure I/PaaS cloud
platform § Partnered with the Azure Security, Compliance &
Privacy team to develop strategies that helped build secure services for
Azure’s I/PaaS cloud offerings for both commercial and public sector
customers within Microsoft’s datacenters § Provided executive advisories on security risks and the
development of risk mitigation or acceptance strategies pertinent to the
implementation of I/PaaS environments § Leveraged industry trends, identified value generating
opportunities while executing strategic plans in support of Microsoft’s Cloud
First vision § Budgeted, forecasted and monitored capital (CAPEX) and
operational expense (OPEX) in consideration of cloud deployment models § Collaborated across multiple Microsoft
groups/organizations including product groups, business groups and other
internal Microsoft stakeholders to drive the adoption and deployment of
online security services, policies, frameworks and methodologies.
Stakeholders included Legal, compliance teams for the various business
groups, HR, security operations & engineering teams, Enterprise
Architects, Physical Security, etc. Selected Contributions/Achievements: § Planned, architected and
delivered a suite of cloud security & compliance services in support of
the Azure GCC I/PaaS build out. This suite of services were delivered ahead
of schedule which led to an earlier than planned private preview and General
Availability release of the Microsoft Azure GCC offering. § Led a diverse team with both
technical and business solution architects accountable for planning,
designing, implementing and delivering cloud solutions and services in
support of the Azure and O365 Cloud & Enterprise engineering groups.
§ Developed cloud adoption strategy
and penned its whitepaper for the Microsoft Consulting Services Public Sector
practice § Achieved FedRAMP Authority to
Operate (ATO) for 5 cloud enabled datacenters § Designed and developed the GFS Personnel Screening
Program used by the product groups for all personnel related screening
exercises. The Risk Assessment methodology built into the screening program
is based on the NIST Risk Management Framework (Special Publication 800-37),
was endorsed by the O365 online services group and is currently being used to
screen O365 support staff in support of its government community cloud
offerings. § Instrumental in the creation of a Microsoft Cloud Security
Service Provider Framework. Contila Consulting Services’ Engagements
12/2008 – 7/2012 Trusted Security Advisor for all lines of
business for a global distribution system (GDS), primarily responsible for
assessing the threat landscape and security posture of the enterprise,
developing and maintaining deep relationships with various business
units. Maintained compliance with business goals, corporate policy and
industry regulations with minimal impact to organizational profitability.
Managed a diverse team of Cyber Security Officers. Principal Security Consultant/Senior
Manager
§ Led engagement team responsible for conducting security
risk reviews & assessments, threat and vulnerability management,
penetration testing, security application (SDLC) and implementation services,
policy and program development § Led the development of information security strategies and
implemented security solutions to assist businesses with the assessment and
improvement of their security infrastructure. Developed & set information
security strategy and monitoring changes in legislation. Liaised with
management teams across the enterprise to ensure alignment of security with
key business drives § Built inter-organizational relationships and managed
internal and external customer expectations § Provided trusted information security advisory to all
senior leadership & executive team and strategic partners Selected Contributions/Achievements: § Built an information security program responsible for
managing the balance between information security and business risk appetite
through risk and impact management, data privacy, governance &
compliance, enterprise risk assessment, PCI remediation and certification,
application code review and the adoption of ISO 27001 framework as a security
standard. § Created an IT Risk Assessment framework and supporting
methodology. The program provided a top-down process to drive the
continuous identification, prioritization, and mitigation of critical risks
associated with high-value and regulated business information assets. § Provided executive level thought leadership to the
enterprise IT risk management and information security organizations
including the redefinition of the information security program to be more
adaptable and agile in addressing strategic business priorities and the
development of certification guidance for pursuing ISO/IEC 27001
certification. Principal Security Consultant
Led Centers for Disease Control and
Prevention (CDC) Compliance & Education (C&E) cyber security team
with 5 direct reports whose mission was to ensure security compliance of CDC
contracts and contractor network connections, manage and report yearly FISMA
privacy compliance of CDC information systems and public facing websites,
develop and implement security awareness, training and educational IT
security campaigns.
§ Provided leadership for C&E team of the Office of the
Chief Information Security Officer (OCISO) responsible for ensuring all CDC
public facing websites were Machine Readable Privacy Policy (MRPP) compliant
in accordance with yearly FISMA and OMB requirements and milestones.
Led team efforts to ensure Computer Security Plan (CSP) milestones and
deliverables were met ahead of yearly FISMA audit schedule § Provided security thought leadership and guidance to CDC
C&E Program Manager § Developed incident response standard operating procedures
(SOP) and provided guidance and fore thought for the implementation of CDC
PII Breach Incident Response requirements § Oversaw delivery of Risk and Privacy Impact Analysis (PIA)
reports to external auditors in compliance with OMB directives and timeline Selected Contributions/Achievements: § Achieved 98.41% MRPP compliance for 507 public facing CDC
websites within 2.5 months of assuming responsibility and 46 days ahead of
FISMA deadline § Developed and implemented security awareness and
educational IT campaigns across the enterprise in compliance with yearly
awareness and training requirements. Metrics that measured the
effectiveness of the security awareness and educational IT campaigns
exhibited a reduction of internal threats by 22% Sr. Global Director, Information
Security
Developed an
information protection & security program for a global travel management
company with operations in 90 countries, a combined workforce of 13,000
employees and generating $14 billion in total sales. Developed and deployed
global-wide security awareness & security policies in compliance with
overall corporate policy. Led and coordinated activities of team that enabled
client to increase efficacy of core security function.
§ Led team responsible for the development, management and
response to security based Response for Proposals (RFP) that generated up to
a $1 billion dollars in new client sales § Led the identification and delivery of a wide variety of
information systems security services that supported the corporate security
strategy. Services included security policy development, risk
assessments of key business platforms, network penetration testing, intrusion
detection and cyber crime response. Led the analysis and development of risk
assessment reports while providing guidance concerning compensating controls
and mitigating actions and assisted in the leveraging of internal
opportunities in accommodation of discovered gaps § Identified and implemented process changes &
efficiencies that aligned security functions with the client’s business
strategy and ensured compliance with PCI-DSS. These changes resulted in the
client obtaining its first ever PCI-DSS Report on Compliance (ROC)
attestation. §
Reviewed and signed off on all
client's Security Service Level Agreements (SSLA), security Request For
Proposals (RFP) and Master Service Agreements (MSA) for current and
prospective clients Selected Contributions/Achievements: § Implemented cost effective security controls that resulted
in reducing RFP turnaround time and increasing response time efficiency by
40%. § Provided vision & leadership that resulted in the
development of a global wide information security awareness program that
reduced internal threat vectors by 77% all within 90 days of assuming role. Accenture, LLC.
8/2007-12/2008 Senior Information Security Consultant
Disaster Recovery (DR) & incident
detection & response project for governmental agency running a 24x7
operation requiring high availability and geo-redundancy with 99%
uptime. Identified areas where project risks and opportunities existed,
facilitated communication between client and project groups and suggested
workable alternatives and mutually agreeable solutions. Client was the United
States Postal Services (USPS). § Led and managed Project Management Office (PMO) for
disaster recovery projects and other highly complex moving sub projects to
meet client deliverable deadlines § Coordinated disaster recovery testing efforts for Project
Management Office (PMO) for both project and various other client teams § Built relationships with application, environment and
portfolio owners as well as managed their respective DR testing efforts. § Led security management of client product portfolio which
included the development of threat and control catalogs, risk registers,
security control mapping to various security frameworks – NIST, ISO 27001/2,
PCI DSS, FFIEC, etc. Security Consultant /Senior Security
Architect – Infrastructure security design & architecture project for
emerging network service provider operating North America’s first 4G mobile
satellite & terrestrial communications network. § Managed the efforts of project resource in understanding
and accomplishing goals and objectives, project plan development and ensuring
deliverable timelines are met § Led project team in the development detailed design on RSA
Strong Authentication to be deployed in the client’s DR environment.
Client expectation was exceeded and deliverable was accepted without
modification. Security Consultant – Information risk
& vulnerability assessment project for high profile manufacturing plant
with $10 billion dollars in yearly sales. § Developed high level security risk assessment and
operational questionnaires for executive management and Information Security
Operations Team respectively § Assessed client’s security policies and procedures and
interviewed executive management, IT Operations group and Information
Security team and made actionable recommendations. § Identified and addressed client’s needs: built,
maintained, and utilized networks of client relationships; communicated value
propositions; managed resource requirements, Statement of Work (SOW), budgets
and prepared and/or wrote and verbal materials. Selected Contributions/Achievements: § Developed an enterprise risk management program with
supporting processes that integrated and optimized the information risk
activities of diverse clients, IT and support teams to deliver greater
consistency and compliance with lower risk acceptance levels. § Developed security governance strategy and information
security management system to support the evolution of client’s IT security
and compliance program. The resulting policy, process and control
framework was more proactive and able to effectively meet business requirements
related to regulatory, legislative, and pertinent mandates. EDS Inc.
4/2005 – 7/2007 Senior Consulting Manager (Veteran Affairs
Office of IT [VAIO])
Information Security executive primarily
responsible for overseeing professional services engagements and managing
client relationship whilst also responsible for the identification, planning
and delivery of a vast array of information security services. Implemented
cost effective security controls to meet client engagement security
requirements. Implemented strategies that consolidated various security
initiatives into one program to ensure uniformity in approach to risk
identification and management. § Responsible for aligning information security processes
with client’s overall business objectives and working closely with the CIO in
defining over-arching information security strategy and policies. Served as
an internal consultant to the various lines of business § Built positive team relationships amongst client’s lines of
business whilst implementing security technologies necessary to secure
client’s IT enterprise § Served as trusted advisor providing executive and
strategic counsel for key clients as well as overall client account
management and responsibility for professional services engagements |
|
|
||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|