Summary
Overview
Work History
Education
Skills
Additional Information
Timeline
Generic

Stephen Costello

Uxbridge,MA

Summary

Detail-oriented IT Risk and Security Professional dedicated to creating and improving governance processes in order to meet a variety of ever changing business, policy, and audit requirements.

Overview

8
8
years of professional experience

Work History

IT Risk, Security & Business Continuity Consultant

MetLife
Cary, NC
09.2020 - Current
  • Implemented external SailPoint reporting system on SQL Server, resulting in improved compliance measures and enhanced data quality.
  • Designed, built, and implemented automated compliance testing for multiple applications, greatly increasing testing frequency from quarterly to daily.
  • Developed robust queries and processes to ensure the data integrity of critical platforms and systems.
  • Streamlined metrics reporting process for key governance team processes.
  • Developed Power BI dashboards presenting crucial data points to different departments within the organization.
  • Automated various time-consuming manual tasks using SQL, Powershell, VBA, and MS Access.
  • Assisted and guided team members at all levels in learning and executing application governance procedures.
  • Maintained oversight over multiple governance testing processes, implementing improvements for streamlined operations.

Information Security Risk Specialist

Middlesex Savings Bank
Westborough, MA
01.2020 - 09.2020
  • Made recommendations to improve security procedures and systems.
  • Performed reviews on various systems in order to ensure compliance.
  • Reviewed annual SOX/SOC-2 reports to ensure vendor compliance with the bank's controls.
  • Utilized KnowBe4 to manage company wide phishing and spearphishing simulations.
  • Processed and logged external vulnerability alerts, and tracked any required patching to completion.
  • Performed various social engineering and pretext call testing scenarios.

IT Risk and Security Analyst

MetLife
Cary, NC
07.2017 - 01.2020
  • Oversaw various data governance projects from conceptualization to completion
  • Conducted analysis to address potential security risks which led to a more secure IT environment
  • Designed, built, and carried out different IT governance processes in order to govern various platforms
  • Automated various existing governance processes in order to reduce time spent on manual data validation
  • Managed user access certification kickoff, reporting, and troubleshooting using SailPoint
  • Provided leadership and audit teams with detailed reports and metrics
  • Created dashboards for metric and progress reporting in Power BI.
  • Governed user access to Active Directory, and hundreds of applications in order to verify users only had access required for their job responsibilities and nothing more

Technical Intern

MetLife
Cary, NC
06.2016 - 08.2016

Learned many skills for operating in a corporate IT environment such as how to properly run meetings, send emails, plan projects, give presentations, and keep data safe.

Education

Bachelor in Computer And Digital Forensic Science - Information Technology (4 Years)

Champlain College
Burlington, VT
05.2017

Skills

  • Ability to learn quickly and adapt to new policies, procedures and a changing work environment
  • Scripting skills with experience in SQL, VBA, and Windows PowerShell and Power Query
  • Extensive knowledge of data reporting and process automation within SQL Server utilizing triggers, stored procedures, ect
  • Strong knowledge of Microsoft Office with Excel, Outlook, PowerPoint, Power BI, and Access skills
  • Strong knowledge of data governance in the Active Directory environment
  • Strong knowledge of the SailPoint database back end
  • Experience managing multiple access certifications from start to finish, including end to end revocation testing
  • Ability to adapt metrics from a variety of different data sources into concise dashboards in Power BI
  • Ability to communicate with other areas of the business in order to communicate IT security requirements and best practices
  • Excellent analytical ability and attention to detail
  • Excellent problem solving and troubleshooting skills with a commitment to thoroughness and quality
  • Able to work closely with teammates in order to problem solve, develop processes and transfer knowledge
  • IT Risk and Security mindset

Additional Information

GRC Certified

Served as a mentor for MetLife IT Interns

Timeline

IT Risk, Security & Business Continuity Consultant

MetLife
09.2020 - Current

Information Security Risk Specialist

Middlesex Savings Bank
01.2020 - 09.2020

IT Risk and Security Analyst

MetLife
07.2017 - 01.2020

Technical Intern

MetLife
06.2016 - 08.2016

Bachelor in Computer And Digital Forensic Science - Information Technology (4 Years)

Champlain College
Stephen Costello