Information Security professional with passion for aligning business goals with security standards while utilizing risk management principles to make cost-effective, risk-based decisions. Extensive experience in leading cross-functional teams to develop technology solutions.
Overview
20
20
years of professional experience
6
6
years of post-secondary education
2
2
Certifications
Work History
Information Security Analyst I - Lead
United Services Automobile Association, USAA
San Antonio, TX
07.2018 - Current
Serving as Security Risk Assessments Product Owner using Lean Agile to deliver products within enterprise project management standards, timeline and budget
Developed and implemented enterprise-wide Business Application Risk Ranking (BARR) process and tool on ServiceNow to enable business partners to assess the inherent risk of their applications. This effort included leading a cultural shift to require the business to take more accountability for the security of their applications.
Ported Application Security Risk Assessment to Archer, made process improvements and implemented automation to reduce numerous manual steps in the process
Conducting enterprise coordination with numerous stakeholders during development of products, change management, training across multiple lines of business, operations and reporting.
Assisting in responding to and closing issues identified by regulatory bodies (OCC, Fed), internal audit and management
Developed and implemented application security training for software developers using vendor content and a gamification platform
Supported USAA's bug bounty program by monitoring, triaging and managing payments for vulnerabilities reported by external researchers
Developing team communications including Confluence wikis, Asana projects and learning sessions for knowledge sharing among my team
Proved success working within tight deadlines in a fast-paced atmosphere with cross-functional teams
Information Security Advisor I - Senior
United Services Automobile Association, USAA
San Antonio, TX
02.2013 - 07.2018
Served on a two-person team to establish an Application Security program responsible for training developers, testing applications and managing application security vulnerabilities
Served as cloud domain advisor to create first risk assessments and guidance for cloud security based on Cloud Security Alliance materials and integrated Information Security into Information Technology and Procurement processes to enable secure cloud adoption
Served as mobile domain advisor to provide guidance on securing internal and member-facing mobile applications on iOS, Android and .com
Developed and implemented Data Access Reporting (DAR) application on Salesforce to enable third parties to supply data access reports
Conducted third party site visits to identify non-compliance with Information Security policy and standards
Software Developer and Integrator I - Senior
United Services Automobile Association, USAA
San Antonio, TX
01.2003 - 02.2013
Provided technical leadership of software development efforts through all stages of the software development lifecycle using both Agile and Waterfall methodologies
Worked closely with business partners to translate business requirements into technical requirements, use cases and design and lead developers and testers through the software development lifecycle to focus on satisfying business requirements
Participated in annual budget exercises and roadmap efforts to plan projects
Collaborated with project managers to develop solutions on time and under budget
Provided technical leadership for mobile projects, including USAA's first application for Android, development on iOS and mobile.usaa.com
Worked with cross-functional teams to establish mobile release processes and procedures
Integrated social media into usaa.com pages and new SMS vendor to reduce messaging costs
Lead beginning of Property Systems modernization to expose mainframe services and develop member-facing applications on usaa.com
Interviewed, hired and mentored junior developers and new hires
Documented technical workflows and knowledge to educate newly hired employees
Education
MBA - Information Assurance
The University of Texas At San Antonio
San Antonio, TX
08.2003 - 12.2005
BBA - Computer Information Systems
Texas State University
San Marcos, TX
08.1998 - 08.2002
Skills
Identifying existing and emerging risk
undefined
Certification
Certified in Risk and Information Systems Control (CRISC)
Interests
Executive Women's Forum (EWF)
San Antonio Women in Technology
Timeline
Targeting completion of Certified Information System Security Professional (CISSP)
12-2022
Certified in Risk and Information Systems Control (CRISC)
Business Support Analys Senior at United Services Automobile Association, USAABusiness Support Analys Senior at United Services Automobile Association, USAA
Insurance Sales Professional at United Services Automobile Association, USAAInsurance Sales Professional at United Services Automobile Association, USAA