CTI CLOUD GOVERNANCE AUTHORITY – CLOUD QUALITY ASSURANCE & VALIDATION - TEKsystems onsite at Bank of America
(2025-05)
Highly skilled and certified cloud security professional with proven expertise in cloud architectures (IaaS, SaaS, PaaS), cloud governance, and compliance frameworks including CSA and NIST, aligned with Bank of America technology standards across Azure and AWS implementations.
- Assist in the interpretation and alignment of cloud controls with governance standards, control practices, and quality assurance requirements. Assist in the development and maintenance of evidence guidelines, evidence inventories, applicability matrices, and audit-ready documentation to support assurance activities.
- Perform pre-implementation quality assurance reviews of cloud deployments to validate control effectiveness and governance alignment. Confirm risk mitigation and regulatory compliance by gathering technical evidence and translating complex concepts into clear, business-focused language.
- Collaborate across lines of business, control practices, enterprise teams, and internal QA functions to deliver consistent, repeatable outcomes for controls and evidence requirements. Educate and train junior team members as needed.
- Execute effectively in fast-paced, matrixed environments, balancing competing priorities independently and as part of a team. Proactively identify and remove roadblocks, escalating risks and issues promptly to ensure timely resolution.
THIRD PARTY RISK MANAGEMENT - RISK ANALYST LEAD - USAA
(2021-01 - 2025-05)
Highly skilled and certified operational/third-party risk professional with over 20 years in information security and technology risk management. Team SME overseeing third and fourth-party risk, including IT, cybersecurity, privacy, fraud, business continuity, disaster recovery, incident management, issue management, emerging risks, RCSA, PRCI, and risk/performance metrics.
- Risk Leader and Advisor led complex cross-functional initiatives, targeted assessments, scenario analysis (cyber/quantum computing), governance, and board reporting, and ServiceNow issue management; provided second-line oversight of major cybersecurity and data incidents.
- Created issues in Issue Management Service Now (IMSN), reviewed actions plans, validated sustainability, and approved issues for closure. Participated in ECIO, CFO, Bank, Property & Casualty, and Life Company Issue Management Triage discussions. Provided second line advisory services to ETPRM, ECIO and CoSAs on high priority initiatives. Oversaw USAA's Disaster Recovery program.
- Oversaw third party (fourth party) cybersecurity, ransomware, data/privacy breach incidents from triage through resolution providing credible challenge to front line and third-party leadership and technology professionals.
ENTERPRISE INFORMATION SECURITY – BUSINESS RISK & CONTROL OFFICER - WELLS FARGO BANK
(2018 - 2021)
- Responsible for the design, implementation, and execution of a risk-based IS/IT monitoring and oversight program aligned to the corporate risk management framework. Lead a high-performing team of seven risk professionals responsible for oversight control testing.
- Trusted operational risk advisor to IS/IT business units, providing guidance on effective control design, remediation, and issue management. Delivered actionable oversight metrics and executive reporting to senior leadership while leveraging deep IS/IT governance, risk, and compliance expertise to address complex risk matters.
TECHNOLOGY RISK MGMT – OPERATIONAL RISK CONSULTANT 5 - WELLS FARGO BANK
(2015 - 2018)
- Experienced technical operation risk consultant that led multiple complex high-priority initiatives, including remediation of Network Perimeter Controls and Continuous Monitoring; IT Asset Management; GLBA data transmission services; Identity & Access Management (IAM) Oversight Committee activities; Privileged Access Advisory Board activities; and Security & Engineering Services.
- Provided exceptional credible challenge to IS/IT leadership and guided implementation of risk-mitigating controls that strengthened the organization's risk posture. Developed Network Security and Asset Management risk profiles utilized by risk management leadership to effectively challenge IS/IT risk-informed decisions.
IT AUDIT MANAGER - WELLS FARGO AUDIT SERVICES
(2013 - 2015)
- Led and executed multiple emerging-technology and project audits, including cloud computing, Salesforce.com, WF and Apple mobile wallets, EMV chip card technology, secure coding, IAM, and access certification. Defined audit programs and developed and executed test plans. Managed audit team strategic initiatives; supported recruiting, hiring, and onboarding; delivered interim performance feedback; and coached team members.
- Applied strong judgment to identify issues through credible challenge; vetted findings with business and technology partners; authored and distributed final audit reports, including Issues & Recommendations (I&Rs); and led audit closure meetings. Reviewed management corrective action plans (CAs) to confirm risk mitigation, validated remediation; and closed audit issues.
GLOBAL INFORMATION SECURITY – INFORMATION SECURITY CONSULTANT - TEK SYSTEMS onsite at BANK OF AMERICA MERRILL LYNCH
(2011 - 2013)
- Evaluated information security risks on LOB projects; provided security-related guidance to project teams, per the GIS Standards/Baselines and regulatory compliance programs (e.g., FFIEC, SOX, PCI-DSS, and GLBA). Identified control gaps and control design deficiencies.
- Worked directly with lines of business and technology risk partners to document information security control gaps and corresponding corrective action plans. Documented guidance given to project teams in the GIS Clearview Project Management & Reporting Tool.
- Worked collaboratively with other GIS partners (ADSF, DMZ COE, DTS, Access Management, Secure Data Governance, SSN Governance), as well as Enterprise Privacy, Operational Risk, and Supply Chain Management to document corrective action plans.
EIS CRYPTOGRAPHIC SERVICES – PROJECT MANAGER - CDI CORPORATION onsite at WELLS FARGO BANK
(2009 - 2011)
- Managed upgrade of secure file transmission implementations between Wells Fargo and various external/third party vendors. Developed project plans, assigned tasks, and led weekly team meetings from test thru production deployment. Worked with internal and external network engineers to establish and/or coordinate firewall rules updates and VPN updates on existing/ new secure proxy connections. Collaborated with Secure Proxy Service engineers to establish and coordinated secure file transmissions u
CORPORATE AUDIT – LEAD IT CONTROLS SPECIALIST - TIAA
(2006 - 2009)
- Consulted with leadership to design, define and implement the Sarbanes-Oxley 404 assessment program for the organization. Provided security & controls advisory services to IS, IT and business management. Assisted management with the development of control self-assessment programs for IT General Controls
- Managed staff of IT senior auditors and contractors that assessed the design, operating effectiveness and sustainability of IT General Controls, including System Security & Configuration, Network Security, Change Management, Promotion-to-Production, Application SDLC, Infrastructure SDLC, Problem Management, Incident Management, Project Management, User Account Management, Entitlement Review, Application Controls and Physical Security.
- Assessed secure data transmission/transfer controls of PII, PCI & NMPI including Secure Email, PGP, Secure FTP, Connect Direct, Secured FAX, VPN, HTTPS, SSL encryption, etc.
SARA LEE HANES BRANDS – IT AUDIT CONSULTANT / SOX 404 MANAGEMENT CONSULTANT - RESOURCES GLOBAL PROFESSIONALS
(2005 - 2006)
- Evaluated the Sara Lee Hanes Brand (SLBA) SOX 404 Q1/Q2 2006 test program; documented exceptions and facilitated timely remediation. Provided controls guidance to six SLBA IT application development divisions (SLBA IT) during the formation of ITGC narratives/process documentation. Assisted SLBA IT with SOX 404 program test plan development. Validated SLBA IT test results.
- Performed technical configuration review/audit of the UNIX operating environment (e.g., HP, AIX). Assessed UNIX system/security administration processes and procedures, backup and recovery, security monitoring, and physical security controls. Evaluated the Sara Lee Technology Support (SLTS) UNIX Baseline Security Standards and offered recommendations.
SOX 404 IT Compliance Manager - DAY INTERNATIONAL
- Developed SOX 404 IT compliance program for Day International, including identification & documentation of key risks and key controls, test program and test plans development, and test of design and effectiveness. Facilitator and analytical problem-solver for IT controls projects, developed statements of work to address control deficiencies, developed project plans, led projects to through remediation. Assisted management with the development and deployment of IT policies/standards. Facilitated
INFORMATION TECHNOLOGY - INFORMATION SECURITY BUSINESS CONSULTANT - COMPUTERNET RESOURCE GROUP onsite at WACHOVIA NATIONAL BANK
(2004 - 2006)
- Assessed enterprise information security residual risk assessment findings, recommended remediation strategies, defined statements of work and project plans to mitigate risks. Subject Matter Expert (SME) and liaison to three risk remediation teams, provided guidance to mitigate access control related risk exposures for Applications, Databases and Operating System environments. Liaison to the Sarbanes-Oxley integrated team.
- Conducted security assessments for SOX applications utilizing the COBIT framework. Identified and documented control gaps across applications, operating systems, and database environments.
MANAGING TEAM LEAD – CORPORATE INFORMATION SECURITY - CITIGROUP
(1999 - 2003)
- Established and maintained a Citigroup-compliant information security program throughout the various divisions of Primerica (i.e., U.S., Canada, Spain, and Ireland). Coordinated and managed various security initiatives in conjunction with business management. Managed staff of two responsible for security incident detection and response (SIRT).
- Led team that processed and reviewed log records, performed investigations of potential security incidents and communicated results to management. Established security log review processes for the network, distributed systems, mainframe systems, DBMS, and privileged users.
- Managed staff of five responsible for distributed systems and mainframe security administration, access control, account management for Windows, Active Directory, LDAP, AIX, PeopleSoft, web-based applications, CICS-based applications, RACF, DB2, and email services. Performed application security assessments, documented control deficiencies, and recommendations. Supported internal/external audits and business unit self-assessment testing and validated remediation.