Michael Russell
Head of IT Security @Crane Worldwide Logistics
Signup · Get unlimited contacts
WORK HISTORY
Head of IT Security @Crane Worldwide Logistics
Houston, TX, US
Reporting to the CIO and responsible for IT security, while promoting best in class industry practices that includes all aspects of managing the development, implementation, and monitoring of the ISMS in support of on-prem, Azure, and AWS hosted systems. Managed the deployment of the Microsoft 365 security and compliance Center including Defender and Purview. Established annual and long-range security goals defining security strategies, KPI\'s, metrics, and reporting mechanisms. Managed the creation of a governance, risk, and compliance program. Performed security gap assessments for ISO 27001/17/18 and CMMC. Performed IT risk assessments based on ISO 27001/17/18. Managed the implementation of a control framework based on ISO, SOC, and NIST. Managed the development and publication of policies, standards, and procedures. Developed ISO 27001/17/18 compliance roadmap. Implemented privacy control compliance including GDPR, CCPA, PIPEDA, AU Privacy Act. Implemented the Managed Detection and Response (MDR) service. Managed the creation and oversight of the Security Operation Center (SOC). Managed the creation and oversight of a vulnerability management program. Managed the implementation of a log management and SIEM solution. Managed the implementation and oversight of vendor risk assessments and risk management activities. Managed security architects imbedded in infrastructure and software development teams. Ensured that security is embedded in delivery throughout the development life cycle (SDLC). Managed phishing and advanced social engineering testing and reporting. Implemented a penetration testing program for wireless, web apps, infrastructure, and ransomware. Collaborated on the annual BC/DR table-top test exercises for AWS and Azure based systems.
EDUCATION
Texas State University
Bachelor's degree, Computer Science
ABOUT MICHAEL RUSSELL
Accomplished Governance, Risk, and Compliance professional with over 20 years of comprehensive experience in Fortune 500, multi-site, multi-host, networked, and cloud environments. Extensive experience in coordinating information security activities to identify, evaluate, and reduce IT risks and vulnerabilities. Superb experience directing strategy, operations and the budget for the protection of the enterprise information assets. Exceptional ability to communicate and develop control requirements, and define security priorities in manufacturing, healthcare, and financial services industries. Seeking a senior-level cyber security position that allows for an immediate impact on the overall security posture, while providing opportunities for personal growth and advancement. Certifications include CISSP, CISA, CISM, ITIL and CRISC. CORE COMPETENCIES: Compliance Privacy Threat Protection Identify Access Management Configuration Management Risk Management Vulnerability Management Security Management Strategic Planning Data Loss Prevention Security Operations Sarbanes-Oxley (SOX) PCI-DSS FISMA/FedRAMP GDPR COSO COBIT ISO27001/17/18 NIST HIPAA HITRUST iRAP Archer Paisley RSAM SaaS IaaS Cloud AWS Azure TPRM CSA Audits Security & Risk Assessments IAM Okta Cisco Duo RSA DLP SASE SDLC CI/CD Pipeline Penetration Testing SAST DAST Systems Integration BC/DR Data Retention Agile Microsoft 365 Security and Compliance Center
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.