Principal Consultant, Enterprise Operations
2017 - PRESENTCalWIN- Led oversight of all aspects of system security, including cybersecurity readiness, DR, security assessment, regulatory assessment, security incident reporting, and security training.
- Provided architectural review to ensure adherence to functional and non-functional requirements while minimizing costs for cloud migration projects, including SAAS and IAAS offerings in both the AWS and Azure environments.
- Managed the migration of on-premise applications to the AWS ecosystem utilizing rehosting, replatforming, and refactoring migration strategies. Supervised the development of native AWS applications to support new business functionality.
- Led oversight of general systems, including hardware, software, operating system, configuration management, data communications, networks, and applications to ensure adherence to requirements.
- Oversaw infrastructure-related and operational projects, including infrastructure upgrades, security remediation, ServiceNow, and cloud migration projects in AWS and Azure environments.
Technologies: Windows, HP-UX, Linux, Java, Oracle, Microsoft SQL Server, MySQLi, HTML5, Microsoft, COBOL, Disaster Recovery Plans (DRP), Disaster Recovery Consulting, Cloud Migration, System Migration, Architecture, IT Security, Cloud Security, Risk Management, Vulnerability Assessment, HIPAA Compliance, NIST, Threat Modeling, Network Security, Middleware, Software Architecture, Amazon Web Services (AWS), Project Planning, Project Management, Application Security, Security Testing, Penetration Testing, Consulting, CISSP, Program Management, Security Architecture, IT Management, IT Project Management, Technical Program Management, Web Project Management, Security Audits, Compliance, DevOps, DevSecOps, Risk Assessment, Information Security, Certified Information Systems Security Professional, Data Encryption, Database Security, Data Protection, Cybersecurity, SIEM, SAML, Security Policies & Procedures, Security Management, Vulnerability Identification, Information Security Management Systems (ISMS), ISO 27001, Business Services, Google Workspace, Gmail, VPN, Policy Development, Policies & Procedures Compliance, Data Security, Web Architecture, SOC 2, JavaScript, Networks, Transport Layer Security (TLS), OpenSSL, Amazon S3 (AWS S3), CI/CD Pipelines, Data Privacy, Privacy, International Data Privacy Regulations, Microsoft 365, SMTP, CISO, SoC, Web Applications, Cloud, Project Management Professional (PMP), IT Projects, IT Strategy, Request for Proposal (RFP)Security Roadmap Assessment
2022 - 2023Boston Children's Hospital - Trust- Performed NIST 800--53 Assessment for the Organization.
- Developed a plan to address the assessment findings while strengthening the overall security architecture of the organization.
- Developed a security roadmap to designed to ensure a sustained security architecture.
- Identified high-risk issues that required immediate attention.
- Presented assessment findings to senior management.
Technologies: IT Security, Security, CISSP, CISO, IT Projects, IT StrategySenior Technical and Enterprise Architect
2008 - 2015Georgia Department of Drivers Services- Spearheaded the design and development of technical solutions for modernization projects, including REAL ID and eCommerce projects.
- Managed the enterprise architectural design, development, and implementation of the Windows and web and mobile information systems.
- Led and mentored the project team from technical and functional perspectives, covering database development, data architecture, integration development, requirements identifications, testing, and project management.
- Designed architectural artifacts for external services, including Commercial Driver's License Information System (CDLIS), SR22/26, Problem Driver Pointer System (PDPS), and Digital Image Access and Exchange (DIAE).
- Improved architecture, provided design and integration solutions, and formulated methodologies to optimize object-oriented software and database development.
- Designed architectural artifacts for external services, including Commercial Skills Test Information Management System (CSTIMS), State-to-State (S2S) Verification Service, and Systematic Alien Verification for Entitlements (SAVE).
Technologies: Windows, SQL, Hyland OnBase, .NET 4, Mainframe Systems, Architecture, IT Security, Cloud Security, Vulnerability Assessment, HIPAA Compliance, NIST, Software Development Lifecycle (SDLC), Threat Modeling, Middleware, .NET, Software Architecture, Project Planning, Project Management, Application Security, Consulting, CISSP, Program Management, Security Architecture, IT Management, IT Project Management, Technical Program Management, Web Project Management, Compliance, Java, Mobile Security, OWASP, Octave, Risk Assessment, Certified Information Systems Security Professional, Visual Basic .NET (VB.NET), C#, Database Security, Data Protection, Cybersecurity, Security Policies & Procedures, Security Management, Vulnerability Identification, Information Security Management Systems (ISMS), ISO 27001, Business Services, Google Workspace, VPN, Policy Development, Policies & Procedures Compliance, Data Security, Web Architecture, SOC 2, Networks, Transport Layer Security (TLS), OpenSSL, Data Privacy, Privacy, Microsoft 365, SMTP, Web Applications, Project Management Professional (PMP), IT Projects, IT Strategy, Request for Proposal (RFP)Director of Information Technology
2005 - 2008Georgia Therapy Associates–Methadone Clinics- Managed all telecommunications, software, and computer support for four centers.
- Developed, built, and managed effective relationships with vendors and business partners and assisted with business issues and problem resolution while representing the company with integrity and professionalism.
- Managed, maintained, negotiated, and reviewed service agreements, leases, and other expense-related technology assets and services with favorable terms and contracts to the company and recommended and made changes as needed.
- Ensured all HIPAA and FDA requirements were met for all telecommunications, software, networking, and computers.
Technologies: Microsoft, Software QA, Disaster Recovery Consulting, Telecom Equipment & Solutions, HIPAA Compliance, Software Development Lifecycle (SDLC), Middleware, .NET, Software Architecture, Requirements Analysis, Project Planning, Healthcare IT, Application Security, Consulting, Security Architecture, IT Management, IT Project Management, Web Project Management, Java, Mobile Security, OWASP, Octave, TCP/IP, Visual Basic .NET (VB.NET), C#, Security Policies & Procedures, Security Management, Vulnerability Identification, Information Security Management Systems (ISMS), Business Services, VPN, Policy Development, Policies & Procedures Compliance, Data Security, Web Architecture, Transport Layer Security (TLS), Data Privacy, Privacy, Architecture, Microsoft 365, SMTP, Project Management Professional (PMP), IT Projects, IT StrategyChief Technical Architect | VP of Engineering
2004 - 2005DirectSellingLive- Directed and prioritized the workload of subordinate personnel. Implemented the enterprise architecture using TOGAF principles of the Windows and web systems.
- Developed disaster recovery plans. Established security policy for all locations, including physical and behavioral security. Led a team of seven local IT support personnel and 12 overseas resources.
- Directed technology research and recommended information technology strategies, policies, and development by evaluating the current environment, and anticipated organizational growth.
- Managed, maintained, negotiated, and reviewed service agreements, leases, and other expense-related technology assets and services with favorable terms and contracts to the company and recommended and made changes as needed.
Technologies: Linux, MySQLi, Web Security, Product Roadmaps, IT Projects, Software Development Lifecycle (SDLC), Middleware, Software Architecture, Requirements Analysis, Product Strategy, Application Security, Network Exploitation, Web Project Management, OWASP, Embedded C++, TCP/IP, MySQL, Business Services, Policy Development, Policies & Procedures Compliance, Web Architecture, JavaScript, Transport Layer Security (TLS), Data Privacy, Privacy, Architecture, Web Applications, IT StrategySenior Consultant and Architect
2000 - 2004Invesco- Developed the architectural design of logical and physical models. Developed and implemented a billing application and management information system (MIS) for the finance and accounting department, together with prototypes.
- Collaborated with directors and VPs to analyze business needs, write business requirements, create design documents for programmers, train users on the new system, and process reengineering.
- Designed and developed several decision support systems (DSS), including profitability, billing, and pricing application using Visual Basic 6.0, .NET, ASP, HTML, JavaScript, Microsoft SQL Server, and Oracle8i databases.
- Developed and maintained stored procedures, functions, triggers, cursors, and views using PL/SQL and T-SQL. Created and maintained business objection universes and reports using ActiveReports and BusinessObjects.
Technologies: Windows, .NET 3, Unix, Oracle, SQL, SQL Server Integration Services (SSIS), ETL Tools, Oracle Business Intelligence Enterprise Edition 11g (OBIEE), Architecture, Software Development Lifecycle (SDLC), C++, Requirements Analysis, Product Strategy, C, Embedded C++, TCP/IP, MySQL, Business Services, Policies & Procedures Compliance, Financial Services, Web Architecture, JavaScript, Microsoft 365, Web Applications, IT Projects