Paul McCarty
Cybersecurity Security Architect @Osumc James Cancer Hosptial
Signup · Get unlimited contacts
WORK HISTORY
Cybersecurity Security Architect @Osumc James Cancer Hosptial
Columbus, OH, US
Lead and support enterprise cybersecurity, compliance, and infrastructure programs across HospitalLead enterprise GRC programs aligned to NIST 800-53, NIST 800-171, ISO 27001, SOC 2, PCI-DSS, and HIPAA, ensuring continuous audit readiness across clinical, research, and enterprise systems. • Architect & Design: Lead the design and implementation of AWS-based network architectures (VPC, Subnets, Route Tables, Transit Gateway, Direct Connect, VPN, Peering, Gateway load balancing).• Infrastructure as Code (IaC): Develop and maintain automation scripts and IaC templates in Gitlab (CDK, CloudFormation) for provisioning and managing network resources.• Security & Compliance: Implement security best practices, including Network Access Control Lists (NACLs), Security Groups, and firewall configurations (Palo Alto).
EDUCATION
Morehouse College
Cybersecurity and AI
ABOUT PAUL MCCARTY
Experienced in PCI-DSS, ISO 27001/2, NIST 800-53, NIST 700-37 • Proficient in information security and compliance regulations (PCI, SOX, HIPAA, NERC) • Have worked with a computer emergency response team (CERT) for remediation.ts • Good technical experience managing products like Splunk enterprise security, Tenable Nessus, PaloAlto firewall, Cortex XSOAR • Experience with forensic tools, such as EnCase, X-Ways, Axiom, FTK, and Cellebrite [Physical Analyzer, UFED 4PC, • imaging and examinations of computer systems, digital media, network devices, and mobile devices. • Ability to analyze and forensically preserve information from social networking profiles and websites. • Strong understanding of operating systems such as Windows, MacOS, Linux and UNIX. • Strong understanding of ESI hardware such as laptops, desktops, servers, mobile devices and tablets. • Conducted regular vulnerability scans across enterprise systems using Qualys.Analyzed scan results to identify critical and high-risk vulnerabilities.Generated detailed reports to track findings and prioritize remediation.Collaborated with IT and security teams to implement corrective actions.Monitored remediation progress and validated fixes through follow-up scans.Applied CVSS scoring and risk-based approaches to focus on the most impactful vulnerabilities.Supported compliance initiatives by providing audit-ready vulnerability documentation.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.