Zimbalist Walker

IT Security Compliance Officer @State of North Carolina

Raleigh, NC, US
MOBILE NUMBERS
+91 *********19

Signup · Get unlimited contacts

WORK HISTORY

Apr 2014 — Present

IT Security Compliance Officer @State of North Carolina

View department →

Raleigh-Durham, NC, US

Report directly to CISO and indirectly to N.C. Secretary of State.Assess and maintain PCI compliance activities for the agency. Managing vulnerabilities and threat environments under the purview of the Information Security Office including but not limited to PCI environments and agency facilities. Implementation and maintenance of an information security management system necessary to support PCI compliance. Stay abreast of and assess impact of constantly changing regulations, statutes, laws (federal and state) and regulations related to IT security and compliance (PCI, HIPAA, IRS Regulations, Agency, State & Federal Policies). Design and conduct monitoring reviews, risk assessments, and automated assessments to identify potential areas of compliance vulnerability and risk; develop/implement corrective action plans for resolution of problematic issues, and provide general guidance on how to avoid or deal with similar situations in the future. Review risk assessments, analyze the effectiveness of Agency IT compliance activities, and report (with recommendations) to the Chief Information Officer (CIO), Chief Information Security Officer (CISO), and appropriate IT leadership.Act as an advisor to Agency Business Units to relay the importance of the latest security threats, trends, technologies, and regulatory requirements. Follow up on deficiencies identified in monitoring reviews, risk assessments, automated assessments, and internal and external audits to ensure that appropriate remediation steps have been taken. Refine and improve the risk assessment process, Develop and publish documentation for internal education and compliance. Provide high quality security assessments of regulated data such as PII, PCI, PHI, ETC SSA data. Perform security risk assessments to identify and prioritize possible threats to IT systems. Provide expertise and assistance in the selection, implementation, and use of appropriate controls to protect critical information assets.

EDUCATION

2008 — 2011

SANS Institute

Certificate(s), Information Technology

2008 — 2010

McAfee University Classroom Training

McAfee Vulnerability Manager Administration

2010 — 2011

Global Knowledge Worldwide IT & Business Training Centers

Certificate(s), Information Technology Security

1985 — 1986

United States Marine Corps, 29 Palms, CA

Certificate, Advanced Communications Electronics

N/A

University of California, Los Angeles

Mathematics and Computer Science

1986 — 1987

Xerox Corporation

Certificate, Interpersonal Communications

2012 — 2012

NJ Security Officer Training Academy

Certificate, Physical Security (PhySec)

2011 — 2012

MicroTek Training Solutions

Certificate(s), Information Technology Security

2009 — 2012

Star12

Business Administration, Communication, and Management

N/A

Strayer University

Information Systems - Concentration in Homeland Security

2010 — 2012

United States Computer Emergency Readiness Team (CERT)

Certificate(s), Homeland Security

2012 — 2012

AMA - American Management Association

Certificate(s), Critical Thinking, Communication, and Management

SKILLS

Risk ManagementRisk AssessmentRisk IntelligenceHp OpenviewThreat AnalysisCritical Incident ResponseDisaster RecoveryNistNercRbacIso 27001Sox CompliancyHipaaCobitPci DssGlbaMetrics ReportingNagiosNessusMetasploitSharepointCvssWebsenseFfiecFismaCloud SecurityCipSolarwindsCore ImpactBluecoatSambaComputer SecurityHitech ActDodd-FrankTripwire Data Compliance and Integrity ManagerNimsMicrosoft SharepointArbor PeakflowxSymantec Enterprise - Antivirus/Client FirewallMcafee Enterprise Vulnerability Manager 7

ABOUT ZIMBALIST WALKER

Experienced professional with a developed focus on Governance, Risk Management, and Compliance (GRC). Successfully served in multiple roles of escalating responsibility and expertise during a 20+ year career working directly with Information Security Systems Technologies. For example; administration, support, engineering, architecture, analyst, and management teams. A hybrid acumen and heightened ability to identify, analyze, understand, communicate, and execute, while balancing technical complexities with business requirements. Strives to infuse added-value and is extremely accomplished in achieving both short-term objectives & long-term company goals through relationship building and strategic planning. A critical thinking, hands-on, Technologist, with detailed knowledge of related intricacies.CORE EXPERTISE • Audit and Compliance • Business Analysis • Change Control • Continuity and Disaster Planning • Dashboard and Metrics Creation • Identity and Access Control • Incident and Problem Handling • ITIL and SDLC Management • Patch and Vulnerability Analysis • Process-flow and Resource Analysis • Regulatory and Policy Governance • Risk Assessments and Management • Threat and Vulnerability Remediation • Vendor Assessment and ManagementOTHER AREAS OF FOCUSCapacity Planning, Contract Revision, Crisis/Emergency Management, Data Center Management, Investigations, IT Awareness Training, Personnel Development & Mentoring, Physical Security Management, Project Management, Resource/Quality Control, and Strategic Planning.Special note: A comprehensive curriculum vitae with supporting documentation (Licenses, References, Etc.) will be provided to potential for career opportunities (Speaking Engagements, Etc.) upon written request and mutual agreement. © 2013 ZIMBALIST WALKER. ALL RIGHTS RESERVED. UNAUTHORIZED REDISTRIBUTION / USE IN PROPOSALS, ETC. PROHIBITED.

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

Zimbalist Walker — IT Security Compliance Officer at State of North Carolina in Raleigh, NC, US | Unifers