Lutheran Life Communities
Corporate Director - IT • May 2007 - January 2021
Skills and Abilities
Information Security
• Disaster Recovery Solutions: Expert in initiating and establishing multiple disaster recovery solutions to ensure business continuity.
• Encryption Standards: Skilled in deploying and maintaining encryption standards across multiple organizations, including FIPS 140-2 compliance for data in transit and at rest.
IT Project Management
• IT Virtualization: Led full virtualization of an environment with 95+ physical servers, transitioning from Cisco UCS/VNX to a Scale Computing hyper-converged platform using VMware and Hyper-V.
• Cloud Conversion: Managed cloud conversion of a multi-site phone system and call center, replacing all handsets and analog adapters with new call center software.
Vendor Management
• MSP Management: Managed MSPs (Managed Service Providers) across multiple environments, including contract negotiation, SLAs, and creation of playbooks and documentation.
• HIPAA Compliance: As HIPAA Security Officer, reviewed Business Associate Agreements to ensure alignment with organizational policy and regulatory requirements.
Team Building and Leadership
• Team Development: Hired, coached, and developed multiple highly functional, cross-trained internal teams.
• Escalation Management: Served as the point of escalation for customers and team members, providing resolution regardless of complexity or timing.
Cybersecurity
• SIEM Implementation: Implemented multiple SIEM systems, building rule sets for reporting, alerting, and remediation across diverse environments.
• Email Security Solutions: Deployed email scanning/filtering solutions and configured DMARC, DKIM, and SPF to prevent phishing and spoofing.
Cloud Migration Projects
• EHR/ERP Migration: Led cloud migration of Electronic Health Record ERP systems, improving accessibility and healthcare regulatory compliance.
• Server Infrastructure: Managed server infrastructure migration to the cloud, optimizing performance, scalability, and cost-efficiency.
Strategic Planning
• Strategic Technology Planning: Led technology planning for a $200M greenfield campus and multiple remodel projects, integrating advanced systems to support growth.
• Market Trend Analysis: Used market trend and technology forecasts to implement one of the first failover DNS solutions before SD-WAN was viable.
Budgeting and Forecasting
• Strategic Financial Planning: Built a three-year plan that increased staffing and service capability while saving approximately $125,000 annually.
• Long-Term IT Roadmaps: Created multiple three- and five-year technology roadmaps addressing virtualization, cloud adoption, and regulatory change.
Network design and support
• Greenfield Campus Network Design: Led complete network design and implementation for a multi-building $200M greenfield campus in Naples, FL.
• Network Segmentation Strategies: Designed segmentation strategies to meet regulatory compliance, maintaining separation between trusted and untrusted networks.
Active Directory
• Active Directory Administration: Managed AD domains — user accounts, groups, and OUs — across on-premise, hybrid, and full cloud environments.
• Group Policy Management: Configured and maintained Group Policies to enforce security settings and manage network resources.
Policy and Procedure (creation and implementation)
• NIST SP 800-171 (CMMC) Guidelines: Established and enforced information security policies aligned with NIST SP 800-171 (CMMC) guidelines.
• HIPAA Compliance: Created and implemented IT security policies aligned with HIPAA regulations and NIST SP 800-53 standards.
Process Change and Improvement
• Onboarding and Offboarding Processes: Built processes ensuring new hires received correct access and departing employees were promptly deprovisioned.
• Technology Request Form (TRF): Introduced a standardized TRF process for staff to request resources, new tech, and access changes.
Risk Assessment and Mitigation
• Comprehensive Risk Assessments: Conducted internal risk assessments for HIPAA, CMMC, and PCI, managing third-party assessors to build mitigation plans.
• Incident Response Leadership: Led technical remediation for security incidents, serving as primary liaison to the DoD and Department of the Navy.