Seasoned Information Security professional with law firm experience, accomplished in safeguarding data for national critical infrastructure, local government systems, and Fortune 500 companies. Poised expert at leading staff and enterprise-wide projects with geographically decentralized teams. Adept at presenting and articulating complex technical issues to audiences with diverse technical backgrounds. Critical thinker skilled at quickly developing solutions to complex challenges and driving continuous procedure improvement.
Overview
26
26
years of professional experience
1
1
Certification
Work History
Email Security Engineer
Los Angeles County via Trinus Corporation
Remote, FL
07.2022 - Current
Spearheaded and executed the implementation of DMARC protection for the largest county in the United States, ensuring email authentication and security across all departments
Served as the sole subject matter expert, educating and collaborating with C-level executives, external vendors, IT teams and end-users to align on project goals and deliverables
Developed and delivered detailed PowerPoint presentations and conducted regular progress meetings to communicate complex concepts like DMARC, DKIM, and SPF to diverse stakeholders
Coordinated the retrieval and deployment of DKIM records, ensuring accurate DNS configuration to authenticate third-party email services and enhance email security
Successfully led cross-functional teams, managed timelines, and mitigated risks, resulting in the seamless deployment of a countywide email security initiative
Planned, directed and implemented the County's advanced phishing implementation
Technical consultant and trainer to team members, internal customers and external partners on email delivery topics and issues
Manage on-premise appliances and cloud email security system in a complex multi-gateway environment with over 110,000 users, and internal and external SMTP relays
Key contact for email-related security incidents, collaborating with the incident management team to implement appropriate mitigation and identify root cause
Proactively analyze and optimize email flow to identify and resolve delivery or configuration issues, ensuring timely and secure messasge delivery across the County
Identified and resolved critical mail flow disruptions for three of LA County's highest-volume external email senders and internal Linux teams
Audited, isolated and facilitated configuration changes to Microsoft Defender in response to email scoring that negatively impacted email delivery
Develop and maintain documentation for email security protocols and procedures
Primary technical support contact for InfoSec IQ phishing simulation software, developing workarounds for Information Security Officers
Cyber Security Technologist
American Water
Voorhees/Cherry Hill/Camden, NJ
10.2010 - 04.2021
Developed solutions to protect company data from internal and external threats for national critical infrastructure
Remained current on latest threat vectors; analyzed risk level and collaborated with team to enact measures, if needed
Solely created and managed rules and policies for over 10,000 workstations in email security, web security, and remote access
Increased social engineering awareness by introducing, customizing and measuring email phishing simulations; decreased company click rate from 32% to 12% in 6 months
Solely built new cloud-based enterprise email and web replacement systems and filtering rules for 7,000+ users in parallel to existing on-premise systems, and conducted seamless migrations with zero issues
Created, planned and delivered quarterly cyber security best practices training sessions, leading to a 47% increase in security awareness
Introduced remote access soft tokens and mobile device OTP authentication as a resolution to an issue that prevented 300 special division end users from achieving consistent network connectivity
Investigated security incidents; collaborated with cyber team and other IT teams to investigate, isolate and mitigate threats
Planned, installed and configured alerts and alarms on the enterprise SIEM, connected to over 20,000 endpoints in the environment
Monitored and maintained the health of enterprise security tools and the landscape of security threats
Led monthly vulnerability and patch compliance scanning and reporting for enterprise endpoints; worked closely with respective client support teams to prioritize and manage mitigation tasks and patch deployment
Increased C-level executive cyber security awareness and participation by introducing visual dashboards and short presentations featuring weekly highlights
Participated in annual security audits and blue team tabletop exercises with the U.S. Department of Homeland Security (DHS)
Email Security:
Project and technical lead for all enterprise email security products and seamless migration to hybrid (on-prem + cloud protection) and integration with Microsoft O365
Configured email security feature enhancement and led POCs for Proof Point and Cisco Umbrella
Created and maintained email filters, policies and alarms
Blocked an average of 14,000-21,000 malicious emails daily; identified patterns and updated filtering rules for high-risk threats
Interpreted email headers and SPF, DKIM and DMARC standards; set safelist and blacklist thresholds for quarantined email
Integrated, normalized and reported on email security events with enterprise SIEM
Developed, maintained and tracked metrics of email security awareness program and identified areas of success as well as opportunities for improvement
Internet Security:
Project and technical lead for all software and hardware aspects of enterprise web filtering products
Created and maintained website security filters, policies and alarms
Responsible for all web security server maintenance including upgrades, patch deployment and hardware replacements if needed
Analyzed security risk level of inaccessible websites and pages and blocked/allowed as needed
Identified, analyzed and reported incidents of internet usage policy violations and worked with appropriate teams
Remote Access:
Project and technical lead for all software and hardware aspects of enterprise security remote access
Ensured 100% uptime for remote connectivity
Maintained token database and seed records; tracked and maintained physical and virtual tokens
Implemented usage policies and developed documentation for end users and 1st level technical support
Conducted server backups and upgrades. Resolved tickets escalated from first and second level support teams
Cyber Security Project Coordinator:
Headed cyber security projects and product implementations
Coordinated Statements of Work (SOWs), meetings and communication with vendors, IT teams and stakeholders
Monitored and facilitated project movement to ensure deliverables met requirements and deadlines
Researched and recommended cyber security solutions, including ROI comparisons
Tracked, negotiated and renewed cyber security enterprise software licenses
Paralegal
Nash Law Firm
Blackwood, NJ
04.2009 - 10.2009
Assisted attorneys in managing case files, including drafting and reviewing legal documents, preparing case summaries, and maintaining accurate and organized case records
Served as a primary point of contact for clients, providing updates on case status, answering general inquiries, and facilitating communication between clients and attorneys
Prepared and filed legal documents such as petitions, motions, and affidavits for family law and bankruptcy cases, ensuring compliance with court requirements and deadlines
Technical Team Lead, Information Security Management
Towers Perrin
Philadelphia, PA
01.2006 - 04.2008
Trained and provided technical guidance to a team of 14 administrators in information security policies, processes and procedures
Resolved complex issues escalated by other team members and first level support
Liaised communication amongst technical teams and external vendors
Reviewed access authorization to network resources and updated access policies
Maintained/troubleshot server login scripts and user account access
Technical support for network connectivity, user account access, external vendor connections via VPN and Citrix; controlled access authorization to network resources
Information Security Management Specialist
Towers Perrin
Philadelphia, PA
04.2001 - 12.2005
Maintained/troubleshot server login scripts and user account access.
Technical support for network connectivity, user account access, external vendor connections via VPN and Citrix; controlled access authorization to network resources.
Lead Help Desk Specialist
Towers Perrin
Philadelphia, PA
05.1999 - 04.2001
Consistently one of the top three of 12 specialists
First call resolution rate averaged 73%
Phone support and desktop troubleshooting for 20,000+ users across 80 offices worldwide, supporting laptop and desktop users
Scope of support ranged from network login and password resets, to configuration and troubleshooting of mainframe and LAN printers, in-house applications, various versions of Windows and Microsoft Office
Education
Paralegal Studies -
PJA School
Upper Darby, PA
Network Engineering Studies -
NetTrain
Cherry Hill, NJ
Rutgers University
Camden, NJ
Skills
Incident response and mitigation
Enterprise email security
Vulnerability management
Project management
Social engineering defense strategies
Staff management
Secure access and identity management
Certification
Google Analytics (GAIQ)
CompTIA Security+ (not current)
Certified Novell Administrator (CNA)
Timeline
Email Security Engineer
Los Angeles County via Trinus Corporation
07.2022 - Current
Cyber Security Technologist
American Water
10.2010 - 04.2021
Paralegal
Nash Law Firm
04.2009 - 10.2009
Technical Team Lead, Information Security Management
Towers Perrin
01.2006 - 04.2008
Information Security Management Specialist
Towers Perrin
04.2001 - 12.2005
Lead Help Desk Specialist
Towers Perrin
05.1999 - 04.2001
Paralegal Studies -
PJA School
Network Engineering Studies -
NetTrain
Rutgers University
Similar Profiles
Patricia Distefano, RNPatricia Distefano, RN
Relief RN Pre-Op, PACU & GI at County Of Los Angeles, Rancho Los AmigosRelief RN Pre-Op, PACU & GI at County Of Los Angeles, Rancho Los Amigos
Property Conveyance Examiner at Los Angeles County Registrar-Recorder / County ClerkProperty Conveyance Examiner at Los Angeles County Registrar-Recorder / County Clerk