Information Security System Analyst - St. Norbert College - De Pere, WI (Remote)
(2024-09)
- Designed, implemented, and managed cybersecurity awareness and phishing simulation programs using Mimecast, Defender and CISA resources; developed training matrices, KPIs, and performance dashboards to measure compliance, training effectiveness, phishing susceptibility, and overall organizational cyber resilience.
- Chair the PCI DSS Compliance Committee, aligning institutional policies, internal audits, vendor risk management, and continuous compliance initiatives.
- Serve as overall HIPAA Security lead, ensuring administrative, technical, and physical safeguards, risk assessments, and ongoing regulatory compliance across the organization.
- Author and maintain 10+ Information Security policies and standards aligned with NIST, PCI DSS, and HIPAA frameworks.
- Develop and maintain the enterprise Incident Response Playbook, defining procedures for detection, containment, eradication, recovery, and post-incident review.
- Lead enterprise endpoint security strategy using Microsoft Defender and Intune to secure 1,500+ endpoints under Zero Trust architecture.
- Conduct and oversee firewall governance, auditing 1,000+ rules, optimizing configurations, and reducing attack surface by 25%.
- Lead penetration testing initiatives (internal and third-party), coordinating remediation efforts and strengthening defensive controls.
- Perform monthly vulnerability scanning using Tenable, tracking remediation, validating patch effectiveness, and reporting risk trends.
- Implement and operationalize Arctic Wolf MDR, establishing incident escalation workflows and reducing mean-time-to-detect from day to minute.
- Coordinate internal and external security audits (including SECIT360), achieving 95% control coverage and delivering executive risk reporting.
- Perform comprehensive security auditing across infrastructure, applications, and vendors to validate compliance and control effectiveness.
- Develop and facilitate incident response tabletop exercises to test readiness, improve cross-functional coordination, and strengthen recovery procedures.
- Direct proactive threat hunting using FortiAnalyzer, Tenable, and Nmap, identifying and remediating 200+ anomalies.
- Deliver enterprise cybersecurity awareness and phishing training to 300+ employees, reducing phishing susceptibility by 90%.
Information Security System Analyst - St. Norbert College - De Pere, WI (Remote)
(2024-09)
Key Achievements
- Managed and secured 1,500+ endpoints through Defender and Intune with centralized policy enforcement.
- Reduced firewall rule set from 1,000+ to ~750, eliminating redundancies and improving security posture.
- Remediated 95% of critical vulnerabilities identified through ongoing Tenable scanning.
- Successfully passed PCI DSS audit with zero major findings.
- Built executive dashboards and board-level reporting to communicate risk, metrics, and program maturity.
- Strengthened HIPAA compliance program through continuous risk analysis and control improvements.
- Improved detection and response capabilities through MDR integration, incident playbook development, tabletop exercises, and threat-hunting operations.
Director of Development - Global IT Solutions (GiTS) - Nairobi, Kenya (Remote, Part-time)
(2022-01 - 2025-12)
- Lead a multidisciplinary team of 5 interns, 3 professional programmers, and 5 sales representatives in the development and commercialization of innovative software products.
- Spearheaded the design and deployment of: POS System: A scalable point-of-sale solution tailored for small and medium-sized businesses. BizMeets: A business networking and scheduling platform enhancing client engagement and meeting efficiency. TruckBiz Manager: A mobile and desktop application empowering truck drivers to manage logistics, finances, and compliance.
- Implemented agile methodologies to streamline development cycles and improve team collaboration.
- Coordinated with the sales team to align product features with market demand, resulting in a 30% increase in client acquisition.
- Mentored interns through structured training programs, fostering skill development and preparing them for full-time roles.
- Oversaw budget planning, resource allocation, and vendor negotiations to ensure cost-effective operations.
Information Security Analyst / Program Lead - Binghamton University - Binghamton, NY (Contract)
(2021-01 - 2024-08)
- Designed, implemented, and managed cybersecurity awareness and phishing simulation programs using KnowBe4 and CISA resources; developed training matrices, KPIs, and performance dashboards to measure compliance, training effectiveness, phishing susceptibility, and overall organizational cyber resilience.
- Lead penetration testing initiatives (internal and third-party), coordinating remediation efforts and strengthening defensive controls.
- Perform monthly vulnerability scanning using Tenable, tracking remediation, validating patch effectiveness, and reporting risk trends.
- Implement and operationalize Arctic Wolf MDR, establishing incident escalation workflows and reducing mean-time-to-detect from day to minute.
- Coordinate internal and external security audits (including SECIT360), achieving 95% control coverage and delivering executive risk reporting.
- Perform comprehensive security auditing across infrastructure, applications, and vendors to validate compliance and control effectiveness.
- Develop and facilitate incident response tabletop exercises to test readiness, improve cross-functional coordination, and strengthen recovery procedures.
- Direct proactive threat hunting using FortiAnalyzer, Tenable, and Nmap, identifying and remediating 200+ anomalies.
- Deliver enterprise cybersecurity awareness and phishing training to 300+ employees, reducing phishing susceptibility by 90%.
Information Security Analyst / Program Lead - Binghamton University - Binghamton, NY (Contract)
(2021-01 - 2024-08)
Key Achievements
- Reduced firewall rule base from 1,000+ to ~450, improving manageability and reducing exposure.
- Lowered phishing success rates by 85% through continuous simulation and training.
- Completed 20+ forensic cases with accurate documentation for compliance use.
- Supported multiple compliance audits with zero major deficiencies.
Adjunct Computer Instructor - Montclair State University - Montclair, NJ
(2013-09)
- Teach courses such as Computer Concepts, MS Office, Windows 7 & 10, Python, HTML, and IT Project Management.
- Evaluate student learning styles and create Academic Action Plans.
- Maintain weekly communication with students and support academic progress.
Computer Instructor Lecturer - Bergen Community College - Paramus, NJ
(2011-09 - 2024-08)
- Delivered courses from basic computer literacy to advanced cybersecurity topics.
- Taught certification-prep classes for CompTIA A+, Network+, Security+, and Cisco CCNA.
- Helped develop a Cybersecurity Degree Program.
Adjunct Computer Instructor - Raritan Valley Community College - Branchburg, NJ
(2010-09 - 2021-08)
- Taught Computer Literacy, Networking Essentials, Systems Analysis & Design, and SQL Server 2008.
- Designed labs covering LAN/WAN, TCP-IP/OSI, UML, JAD, and Agile.
- Delivered practical hands-on SQL Server programming and security modules.
Adjunct Computer Instructor - New Jersey Institute of Technology (NJIT) - Newark, NJ
(2016-01 - 2018-05)
- Taught Networking (Network+) courses on hardware, protocols, LAN/WAN, and OSI/TCP-IP models.
- Provided personalized mentoring and monitored student academic progress.