aury Curbelo

aury Curbelo

About

Detail

Cyber Security Risk Manager
Oklahoma, United States

Contact aury regarding: 

work
Full-time jobs
Flexible work

Timeline


work
Job

Résumé


Jobs verified_user 0% verified
  • C
    Cyber Security Specialist- Oklahoma City
    Nov 2019 - Current (5 years 8 months)
    Cyber Security Risk Consultant: Provide IT risk management, information security, and compliance consulting services to clients in a variety of industries. Routinely perform risk assessments, audit systems for compliance, work with IT and business leaders to identify and properly mitigate risks, recommend improvements for administrative, technical and physical controls, help clarify compliance requirements and lead incident response activities. ◦ Conducted DFARS Compliance for Product Security ◦ Conducted EPCS (Electronic Prescribing for Controlled Substance) Gap Analysis for Client Certification. ◦ Implement Risk Management Framework (RMF) ◦ Lead and Implement the assessment and Authorization (A&A) Process under RFM. ◦ Facilitates dev
  • S
    Senior Information Security Executive
    2014 - 2019 (5 years 1 month)
    Oversee and/or assist in performing on-going security monitoring of organization information systems including: Assess information security risk periodically. Conduct functionality and gap analyses to determine the extent to which key business areas and infrastructure comply with statutory and regulatory requirements. ◦ Design and establish CP Corp Security Operation Center (SOC). ◦ Planning, buying, and rolling out security hardware and software, and making sure IT and network infrastructure is designed with best security practices in mind. ◦ Assist in developing, maintaining, reviewing and improving strategic organization wide information security and risk management plan. ◦ Issue alerts and advisories with respect to new vulnerabilit
  • S
    Information Security Consultant Directs
    SwitchRay inc. (former Aloe Systems inc.)
    2007 - 2014 (7 years 1 month)
    strategy, operations and the budget for the protection of the enterprise information assets and manages cybersecurity program. Moreover, provide leadership and guidance for the organization to manage the risks to the confidentiality, integrity and availability of the corporation digital assets. ◦ Develop Enterprise wide InfoSec Programs- Protecting corporate digital assets by managing cybersecurity. ◦ Identify, Report and Control Incidents- Determine the right tools and services implemented across the enterprise to detect and announce threats. ◦ Manage and Train Security Staff- Develop a comprehensive plan to attract, train and retain professionals ◦ Monitor Threats and Take Preventive Measures- monitors and explores threat sources.
Awards verified_user 0% verified
  • I
    ISC2-ISLAS (2012) Up-and-Coming Information Security Professional Award Nominee- ISC2-ISLAS (2012) Community Service S