Richard Horton
Sr Analyst, Security Risk Management @CVS Health
Signup · Get unlimited contacts
WORK HISTORY
Sr Analyst, Security Risk Management @CVS Health
RI, US
This role conducts thorough security risk assessments for new technologies before deployment and technologies post-deployment in the production environment. Identifies, assesses, analyzes security risks, scrutinizes potential vulnerabilities, and provides risk mitigation strategies to ensure compliance and adherence to information security standards for a seamless and secure integration. This role requires engagement with project managers, project management team members that include developers, architects, infrastructure engineers, and EIS stakeholders as applicable. Working knowledge of Information Security policies and procedures. Working knowledge of common security frameworks and regulations, including but not limited to NIST 800-53, ISO 27001/2, HIPAA/HITECH, HITRUST and PCI-DSS. Working knowledge of Information Technology including Cloud, access management, architecture, infrastructure, operating systems, application/software development, and endpoint security. Ability to comprehend implications of security risk (inherent risk, residual risks), compensating controls, etc. Operating in applications including Archer, Qualys, Checkmarx, and Prisma. Solid knowledge of regulatory (including Audit frameworks) standards, including but not limited to NIST 800-53, SOX, SOC1/SOC2 Type II audits, HIPPA/HITECH, HITRUST, and PCI-DSS. Execute on assigned tasks, providing timely feedback to customers/stakeholders/teammates related to security risk assessment outcomes. Collaborate across many teams in a large-scale environment. Communicate to non-technical and technical groups about security risk
EDUCATION
American InterContinental University
Bachelors, Information Technology
Strayer University
Masters of Science, Information Systems - Software Engineering
Harry S Truman
High School Diplomat
Monroe Community College
AOS, Accounting
ABOUT RICHARD HORTON
Over 12 years of Application, Production Support and Security Analyst experience. RSA Archer GRC subject matter expertCurrently -Provides technical expertise in development and ongoing support of program management functions within the Information Security team. Leads enterprise-wide definition, establishment, maintenance and reporting of metrics related to Information Security infrastructure, applications, and processes. Provides support to Information Security team members in governance functions such as finance and procurement management, SLA monitoring and reporting and remediation management. Reviews, develops, tests, and implements security process and control documentation. Provides material support, tracking and reporting for Information Security awareness and communications initiatives.A+ and Net+ certifiedBachelors in Information Technology 2003Masters Information System - Software Engineering 2012.6 month goal is to obtain my MCTS - Help develop and obtain the Senior Information Systems, Application Security Analyst position at TMX Finance12 - 18 month goal - obtain my CEH, GSSP-Java, GSSP.NET, and CISSP certifications - Junior Software EngineerSpecialties: I specialize in System Application support, in.NET and Unix/Linux based platforms. C#.NET, ASP.NET, T-SQL, Javascript, HTML, XML
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.