Summary
Overview
Work History
Education
Skills
Certification
Accomplishments
Timeline
Generic
NANCY JORDAN

NANCY JORDAN

Roland,AR

Summary

25 year Information Technology leader with experience in Management, Security, and Strategic Planning. Adept in Problem Solving and communication skills. Proven experience with assessing individual talent and rebuilding teams to work as a cohesive unit. Transformational leader skilled in guiding navigation of modern technology. Accustomed to driving efficiency and effectiveness by developing, delivering, and supporting strategic plans. Demonstrated skill in translating technical requirements into business solutions. Successful record of building positive relationships with internal and external stakeholders. Proven ability to drive impactful security initiatives and collaborate across engineering, legal, and product teams.

Overview

26
26
years of professional experience
1
1
Certification

Work History

Director, Product Security, Enterprise Vuln Mgt

Johnson Controls
Milwaukee, Wisconsin
05.2024 - Current
  • Managed one-third of all cybersecurity personnel and multiple teams to lead the Global Product Security organization and served as the company contact for Product Security
  • Presented to the Executive Council on Product Risks.
  • Served as the Product CISO when interacting with other departments, including Engineering, Product, Legal, Privacy, etc.
  • Managed the Trust Center for customers' and partners' security inquiries, and documentation needs while offering white-glove service.
  • Identified and executed strategy, organizational realignment, capability gaps, and budget and technology opportunities while serving as the Security Transformation Leader.
  • Oversaw due diligence analysis of Mergers & Acquisitions.

Director of CyberSecurity

Blackbaud
Charleston, SC
12.2021 - 05.2024
  • Led multiple teams to provide Vulnerability Management, Application Security, Penetration Testing, and Red Team capabilities.
  • Re-platformed existing technologies to create a Risk-Based Vulnerability Management program focused on finding the most impactful risk reductions to infrastructure and applications.
  • Aided in creating a new Patch Management program within IT and educating on how that program and the Vulnerability Management program could be complementary to each other.
  • Presented risk-based findings to the CTO along with actions, serving as second line audit for Patch Management.
  • Led targeted red team campaigns to test Blue Team processes and alerting.
  • Grew the penetration testing coverage across the product inventory to include IT and cloud-based environments.

Manager of Information Security & GRC

Dillard's Store Services, Inc
Little Rock, AR
01.2015 - 12.2021
  • Transformed the Information Security department by analyzing and rebuilding the team with a talented group of individuals who worked well together, and newer, stronger technologies to better support the business.
  • Implemented NGFWs, EDR, and email security to better protect the organization.
  • Worked closely with other teams to advise on how to best implement new software in the most secure manner.
  • Managed all aspects of Information Security, including Data Protection, Network Security, Vulnerability Management, Threat & Incident Response, Architecture, and served as the Deputy CISO across the company and with affiliated organizations.
  • Built the Governance, Risk, and Compliance team to better align the individual departments with the Payment Card Industry framework and the privacy regulations.
  • Advised compliance, created policies and standards to communicate requirements and govern those procedures.
  • Established a Vendor Risk process to better advise on the security and privacy practices of external partnerships.
  • Folded the Project Management Office into the GRC team in order to better align the objectives and staff skills to better serve large-scale projects.

Manager of Integration/Infrastructure

Dillard's Store Services, Inc
Little Rock, AR
01.2010 - 01.2015

Lead of Web Administration

Dillards Store Services, Inc
Little Rock, AR
02.2007 - 12.2009

Web Administrator, Senior Web Administrator

Nuvell Financial Services LLC
Little Rock, AR
05.2004 - 02.2007

IT Technical Analyst I, IT Technical Analyst II

Alltel Information Services/Fidelity Information Services
Little Rock, AR
01.2000 - 05.2004

Education

Bachelor of Science - Computer Information Systems

Louisiana Tech University
Ruston, LA
01.1999

Bachelor of Science - Computer Information Systems, Marketing

Louisiana Tech University
Ruston, Louisiana
01.1998

Skills

  • Transformational Leadership
  • Risk Management
  • Program Management
  • CyberSecurity
  • Governance
  • PCI compliance, regulatory compliance

Certification

  • ISC2 Certified Information Systems Security Professional (CISSP)
  • GIAC Security Leadership Certification (GSLC)
  • GIAC Security Essentials Certification (GSEC)
  • ITC Women in Technology certification program
  • Payment Card Industry Professional (PCIP)
  • Louisiana Tech University Industry Advisory Board
  • Women in Technology (Central Arkansas)
  • Infragard
  • Walton Emerging Leaders Program

Accomplishments

  • Managed large-scale teams, including personnel issues, payroll, hiring & termination proceedings, performance evaluations, and mentoring.
  • Planned and maintained a separate product security budget, including capital, operating, and project budget, identifying opportunities for consolidation and cost-savings.
  • Increased department reputation and team communication skills by initiating a monthly touchpoint with other departments to discuss concerns.
  • Assessed individual talent and rebuilt teams to focus on the company's initiatives in a more efficient manner.
  • Revived or replaced existing technologies to improve the team's productivity and data value.
  • Improved Vulnerability Management effectiveness by doubling the number of assets scanned, adding credentials for a quicker, but more in-depth analysis, and presenting the data based on risk factors.
  • Revitalized Security Awareness by enriching the communications campaigns, content, and personalizing the context.
  • Expanded the use of NGFWs to more granularly restrict traffic by App-ID and user-ID/group-ID, instead of simple IP/port allowances/restrictions.
  • Implemented DDOS, origin cloaking, and an edge WAF to better protect the company's e-Commerce infrastructure.
  • Employed Managed Services for the Tier-1 response to our SIEM for troubleshooting and investigation.
  • Consolidated the organization's Application Whitelisting and File Integrity Monitoring solutions into one for a more streamlined and operations-friendly answer.
  • Revamped the Security Incident Response Team with a new policy, member agreement, playbooks, and team exercises.
  • Performed gap analyses, requirement updates, and coordination of external audits and attestations.
  • Established, and managed the eCommerce Performance Testing program which resulted in eliminating multiple bottlenecks and improving performance across all tiers of the architecture.

Timeline

Director, Product Security, Enterprise Vuln Mgt

Johnson Controls
05.2024 - Current

Director of CyberSecurity

Blackbaud
12.2021 - 05.2024

Manager of Information Security & GRC

Dillard's Store Services, Inc
01.2015 - 12.2021

Manager of Integration/Infrastructure

Dillard's Store Services, Inc
01.2010 - 01.2015

Lead of Web Administration

Dillards Store Services, Inc
02.2007 - 12.2009

Web Administrator, Senior Web Administrator

Nuvell Financial Services LLC
05.2004 - 02.2007

IT Technical Analyst I, IT Technical Analyst II

Alltel Information Services/Fidelity Information Services
01.2000 - 05.2004

Bachelor of Science - Computer Information Systems

Louisiana Tech University

Bachelor of Science - Computer Information Systems, Marketing

Louisiana Tech University