Encouraging manager and analytical problem-solver with talents for team building, leading and motivating, as well as excellent customer relations aptitude and relationship-building skills. Proficient in using independent decision-making skills and sound judgment to positively impact company success positively. Dedicated to applying training, monitoring, and morale-building abilities to enhance employee engagement and boost performance.
Overview
25
25
years of professional experience
1
1
Certification
Work History
Sr Mgr-Ntwk & Info Sec
Verizon
Richardson, TX, United States
11.2023 - Current
Oversee the shift threat monitoring operations of a Verizon SOC tasked with securing Verizon's global networks, and protecting strategic and intellectual assets
Ensure all relevant incident response detection, analysis, and response tasks to cyber security events are generated, cataloged, and retained.
Implement and enforce the incident response management processes and procedures, provide status updates to senior management as warranted.
Proactively drive compliance with industry standards such as NIST CSF, PCI & ISO 27K/9K.
Collaborate with other security organizations to promote mutual understanding of responsibilities and engagements throughout all incident response lifecycle during security incidents and driving remediation in vulnerability campaigns.
Serve as cross-functional support to Incident Commanders as appropriate
Serve as Backup to Associate Director and Shift Lead as appropriate
Review and approve shift coverage, include vacation in accordance with policy
Monitor analyst's individual & team performance and conduct evaluations
Conduct regular one-on-one discussions with analysts and monitor progress
Track and ensure analysts progression in training and career development
Support and mentor analysts to meet goals and expectations
Cross team engagements and escalations for incidents and vulnerability campaigns
Create and manage vulnerability campaigns
Support Shift Lead ticket escalations for incidents and vulnerability campaigns
Participate and support weekly Incident Reviews as appropriate
Review weekly Past Due Ticket Audit Summary tickets for any process or technical improvement and document any follow up actions and improvements recommended as part of the review
Support Incident Lessons Learned project engagements
Shift accountability, ensure all onboarding and offboarding actions are completed
Provide situational security awareness by gathering data from a variety of systems and normalizing/correlating the information.
Provide real-time (or near real-time) detection and reaction services for information security incidents within the organization's enterprise.
Set priorities and provide ongoing direction by hosting ad hoc team calls
Manage staff and response activities to maintain 100% closeout of all priority security events within mandated timeline metrics
Create and maintain Methods of Procedures, and other similar documentation in a standardized format
Monitor key performance indicators and metrics surrounding incident response, vulnerability management, and daily reporting of NCC activity
Make data driven decisions to improve the quality and responsiveness of the NCC
Collaborate with other internal security organizations and relevant parties to identify and assess security incidents, and serve as the focal point for the execution of the response process when an information security incident occurs
Attend and determine Verizon impact for any 3rd party/vendor vulnerability notification calls
Shift Lead
Verizon
Richardson
05.2016 - 11.2024
Monitor NCC dashboard ensuring pickup of any new security incidents and engagements
Monitor and ensure analysts adhere to targeted key performance indicators
Lead the NCC team continuous threat monitoring and response activities.
Mitigate risk to the business by ensuring incident response activities are complete.
Escalate to respective Day/Night Manager any critical issues and follow-up to ensure mitigation activities are completed and timely.
Assist management in setting priorities, provide ongoing direction by hosting ad hoc team calls.
Lead daily team calls; provide feedback and direction for ongoing incidents and engagements
Manage staff and response activities to maintain 100% closeout of all priority security events within mandated timeline metrics.
Implement new and develop existing threat monitoring dashboards.
Ensure the team follows and adheres to established MOP's.
Review weekly Near Due Ticket Audit Summary tickets for any process or technical improvement and document any follow up actions and improvements
Review results of ticket audit with respective Day/Night Manager for follow up actions and improvements
Participate in Weekly Incident Review meetings
Ensure all onboarding and offboarding actions are completed for new or departing shift analysts.
Activate participation in the cross-team collaboration calls/engagements, assist to identify use cases and create the process to go along with the investigation in working those alerts.
Technical mentor for Analysts, training on monitoring and response, identifying skills gaps, and assisting management with identifying training and development opportunities for individual Analysts, or the team as a whole.
Make improvements with existing MOP's as necessary.
Review, approve, and publish updates/new MOPs, in addition to mirrored in Confluence.
Participate and Support compliance standards for NSIT, CSF, PCI & ISO Audit recertifications
Oversee Annual Review for NCC Contacts and MOPs update process
Establish as required new MOPs for monitoring and response.
Secur Spec IV-Ntwk & Info Sec
Verizon
Richardson
02.2010 - 05.2015
Responsible for monitoring and engaging in a broad scope of cyber security-related events and incidents and taking ownership, investigating, and remediating alerts generated via NCC monitoring infrastructure.
Investigation and validation of alerts follow methods and procedures documentation outlined by the NCC of required steps that must be performed to ensure a thorough analysis is accomplished.
Analysts utilize a variety of security tools, and engage with system contacts, operations, and support teams to remediate alerts.
Analysts follow set workflows for higher severity issues and will escalate to a Shift Lead or Incident Commander accordingly for further guidance on incident handling.
Monitoring of NCC Dashboards for new tickets or alerts. This is the highest priority.
Actively monitoring NCC ticket Dashboards, and Splunk Dashboards for new events and tickets.
Reviewing of Shift Handover Log and Priority Events Report (PER) from the previous shift for any events, incidents, or projects that require follow-up.
Taking ownership of tickets in a timely manner in order of ticket severity.
Investigation of events in accordance with the process and procedure outlined in the NCC documentation.
Communicating to a Shift Lead or subject matter expert (SME) in the event of issues pertaining to alert tickets or ad-hoc issues.
Following all expectations outlined within the NCC Shift Procedures, and the shift hand-off process and thoroughly communicating to the next shift Shift Lead or highest-level Analyst on the incoming shift.
Checking NCC Hotline Voicemail immediately after each shift change.
Specialist Engineer
Incident Response
Richardson, TX
04.2000 - 07.2004
Monitor and respond to Intrusion Detection System (IDS) alerts
Perform IDS signature analysis
Review and analyze firewall and security logs
Review and respond to various incident sources
Review and resolve findings from penetration testing and security audits
Capture and analyze malicious software samples
Assist Team Leads and Management with major incidents
Document evidence and actions within incident tracking system
Review and analyze known malicious websites
Identify and implement egress filtering for known active threat sources
Develop and update process and procedure documents
Maintain departmental document repository
Compile and edit team reports
Track projects and performance measures
Update Disaster Recovery Plan
Coordinate Disaster Recovery Plan test
Manage assigned team projects
Assist with special projects as needed
Review and advise Management on new vulnerabilities or threats as needed
Review and update Incident Response Plan
Review and update Team presentations as needed
Perform Gap Analysis against current Incident Response standards
Provide evidence and documentation for audits as needed.
Education
Associate's Degree - Computer Networking
Collin County Community College - Preston Ridge
High School (HS) or General Equivalency Diploma (GED) or Secondary Level - Computer Technology
Antonelli College
High School (HS) or General Equivalency Diploma (GED) or Secondary Level - Computer Information Systems
Collin County Community College - Preston Ridge
Skills
Collaboration
Incident Analysis
Information Security
Leadership
Project Management
Decision Making
Strategic Thinking
Network Security Operations
Conflict resolution
Vulnerability Management
Audits
Problem Solving
Adaptability
Certification
Other, CIW Web Foundations Asso, Certification ID#: 653931, 2014-05-07