| Skills |
+ Product & Project Management
+ Personnel Management
+ Contract Management
+ Video Production
|
+ Security Engineering
+ Software Engineering
+ Information Systems Design
+ Audio Production
|
|
|
|
| Experience |
|
|
Co-founded AVP. Responsible for Marketing, Parnter, and Training programs for a cooperative venture of 35+ independently operated video studios across the U.S. AVP Web Site
|
|
|
Video Producer, specializing in a full range of Video, Photographic, and Audio production services. DeMello Video Web Site
|
|
|
Developed project strategy and roadmap with executive committee and
documented product strategy and roadmap. Implemented capture and
tracking process for new product features. Performed competitive
pricing analysis and developed new price structure for product line
for direct and various channels. Performed competitive technical
analysis. Managed beta tests for multiple releases. Chaired
cross-functional team meetings. Wrote technical white papers,
data sheets, Marketing Requirements Documents and Product Requirements
Documents. Wrote and maintained internal web site; provided content for
external web site. Managed government security certification process
for our products. Assisted sales team in proposal writing. Created
sales tools: Provided training on new product features for sales team,
developed PowerPoint slides, comparative pricing spreadsheets in Excel.
|
|
|
Responsible for development and
documentation of product plans and ongoing product
management of Company 51’s technology and product
offering. Worked with development team, partners, and
other cross-functional stakeholders to ensure that
Company 51 offers cutting-edge, high quality products,
and they meet strategy, timelines and business
objectives. Worked with engineering, design, QA,
marketing, customer support, and business development to
direct product and feature development through product
life cycle. Interpreted market trends, spot product
opportunities, and conducted competitive analysis and
traffic analysis. Translated research findings into
product plans. Researched product requirements through
customer and partner contact, industry analysts and
competitive product evaluation. Prepared and managed
product beta/launch and develop target pricing models for
different market segments. Provided technology, product
marketing and sales support and work with strategic
communications to generate product marketing/sales
collateral and related marketing materials.
|
|
|
|
Product Manager for HP’s Authentication/Access Control
product. Wrote Marketing and Product Requirements
documents (MRD/PRD). Responsible for defining HP’s
Value-Chain / End-to-End security at the corporate level,
and responsible for management of all OEM security
products.
|
|
|
|
Principal Project Manager leading development of Sun’s Security
Enterprise Access Authentication/Access Control architecture.
Wrote business requirements for justification of $30M
expenditure for revamping IT security infrastructure.
Participated in definition of overall Architecture. Wrote
system and component level technical requirements. Managed team
of 5 software engineers.
|
|
|
| Product Manager for all Database Security for both Oracle
and Trusted Oracle products. Duties include: writing
collateral, training, primary interface with customers and
partners, wrote feature specifications, managed release
cycle of products, product planning, beta-customer
management, developed internal and external web pages,
worked with legal to resolve export issues, developed
quality assurance goals for security, worked with
documentation group to include new features. Managed
security emergency bug fix processes. Worked database
integration issues with PKI and e-commerce groups.
|
|
|
|
Defined corporate goals and strategies for global product
security evaluations, specifically U.S. TCSEC B1/C2, U.K.
ITSEC E3, and International Common Criteria EAL-4
evaluation criteria. Wrote corporate policies for quality
assurance relating to security criteria. Updated
international sales model with respect to sales of
evaluated products. Defined corporate support for system
certification and accreditation. Defined, negotiated and
managed international subcontracts in support of product
security evaluations. Assisted in definition of security
requirements for Oracle8 and Trusted Oracle8. Represented
Oracle in Common Criteria and System Security
Engineering Capability Maturity Model standards
committees. Wrote internal Oracle web pages for Security
Evaluations. Reviewed all product documentation with
respect to correctness of implementation of security
functionality. Managed Security Evaluation team of up to
8 people.
|
|
|
|
Defined product requirements for a B2 MI Trusted Network
component accepted into the NSA TPEP process for the MISSI
program. Wrote final draft of the System Requirement
Specification for the NSA Dockmaster II procurement.
Assisted in writing System Specification for the BMDO
Trusted Software Engineering Environment Workstation.
Implemented Trusted Software Methodology at the T3 and T4
level of trust for multiple BMDO programs. Led winning
proposal effort for Arca’s largest contract. Wrote part
of NSA’s Certification and Accreditation guidelines. Personnel Manager, which included personnel reviews,
budgeting for division, procurement, subcontract
management.
|
ESL, Inc. -
Senior Systems Engineer
|
1990 - 1991 |
|
|
Led Certification and Accreditation effort for the U.S.
Army Guardrail system. Defined system security
requirements, wrote technical and cost chapters of
proposal for security effort. Managed security support
contractors. Defined software security requirements.
Chairperson of Government and Contractor Security
Accreditation Working Group. Received extensive training
in contract and project management.
|
|
|
|
Founder and original principle owner. Founded company with 5 others,
and built to a $1.5M per year company. Was responsible
for all Administration, Office Management, Legal, and
Benefits duties, as well as lead Site Coordinator for
contracting sites.
|
|
|
Lead Computer Security Engineer for the Tactical
Reconnaissance System Ground Segment (TRIGS). Contributed
to the TRIGS security policy modeling effort by defining
trusted processes and creating pre- and post-condition
semantics. Responsible for informal Code Verification
procedures, creating the Man Machine Interface for the
Information System Security Officer (ISSO) operational
position. Extensive support of Technical Interchange
Meetings with customers and accreditors. Assisted in
development of standards on How to Write Trusted Code
on VAX/SEVMS and delivered training to 200 software
engineers.
Member of a Research and
Development team for a Trusted A1 level Multi-Level Secure
Distributed Operating System.
Lead engineer writing the System
Security policy and Trusted File Server Security Policy. Contributed to formal modeling of the system in Gypsy on a Symbolics
processor, and implementation of proof-of-concept in the C
language (BSD UNIX) on Sun workstations.
Lead Software Engineer
responsible for initial and detail design of the B1 level Trusted Computing Base for TRIGS. Assisted in
writing and review of the Computer Security Policy and
Security Policy Model as per DoD specifications for
development of a TCB ("Orange Book", MITRE 9992).
Performed top level design of CPCI’s using Sun
workstations (UNIX) to produce Yourdon Data Flow Diagrams
using IDE tool package, writing B5 and C5 level
requirements, and producing detail design on MicroVax II’s
using Caine, Farber, & Gordon PDL/81.
|
ESL, Inc. -
Computer Security Engineer
(consultant)
|
1984 - 1986 |
|
|
Involved with production of a Signal Processing System and
solely responsible for the Design, Code, Test, and
Integration of the Post Processing phase of the project.
Helped design part of the Data Base Preparation CPC on the
Signal Routing phase. Assigned responsibility for
reviewing, rewriting, and performing System Test
Procedures. Work included design in PDL and implementation
in FORTRAN-77 on a VAX 11/780.
|
|
|
|
Responsible for Coding/Test and Integration of a Signal
Processing Control System. Delivered High Level Design
Review for the Man-Machine Interface component of the
System. Coded part of the Report Generation
capabilities. Additional responsibilities included cost
and schedule evaluation of Engineering Change Requests (ECR’s)
for the system.
|
|
|
|
For a Satellite Communications system, was the Responsible
System Engineer for Design, Implementation, Testing and
Documentation of a Custom Data Base Management System on a
network of VAX 11/780's. Directly responsible for
approximately 30,000 lines of code, and the supervision of
4 junior programmers.
|
|
|
Participated in the update of a computer controlled
Satellite Communications Control system. Responsible for
updating the Man-Machine Interface specifications.
Led the implementation of a state-of-the-art Multi-Tasking
Image Processing System with emphasis on custom device
interfacing and Man-Machine Interfaces. Responsible for
software development in the Image Processing R&D
Laboratory, and managed two R&D projects.
|
|
|
|
Board Member of the Concord Blue Devils, a $12M non-profit
performing arts organization for youth. President 3
years, Secretary 2 years.
|
|
|
|
Board Member of the Renegades Association of California, a non-profit
performing arts organization; President 1
years, Director 1 year, Musician 6 years.
|
|
| Publications |
|
Deploying eBusiness Portal Security with HP Domainguard,
RSA Conference 2001, San Jose, CA, April 2001.
Common Criteria Protection Profiles,
Panelist, National Information Systems Security
Conference, Crystal City, VA, October 1998.
National Information Assurance Partnership,
Panelist, National Information Systems Security
Conference, Baltimore, MD, October 1997.
Vendors Experience with Security Evaluations,
Panel Chair, National Information Systems Security
Conference, Baltimore, MD, October 1996.
The Trusted System Alphabet: P(Policy) Before
A(Architecture)?,
Plenary Panel, Computer Security Applications Conference,
Orlando, FL, December 1993.
Breaking in to Computer Security,
Association for Computing Machinery (ACM). Guest Lecturer
at California State University, Chico, November 1990.
Extending the Trusted Computing Base,
AIAA Computers in Aerospace VII Conference, Monterey, CA,
October 1989.
Extending the SEVMS TCB,
Digital Equipment Computer Users Symposium (DECUS),
Atlanta, GA, May 1989.
Presentations
-
Bay Area Trusted Systems Symposium (BATSS),
April 1989, San Jose, CA, and in August 1993, Redwood
City, CA. Co-chair of BATSS conference in February 1993. |
|
| Education |
|
|
Bachelor of Science in Computer Science/Systems, May 1978. |
|
|
Associate of Arts in Computer Science/Business, June 1976 |
| Corporate |
Oracle, Trusted Oracle, Oracle CASE tools, Subcontract
Management, Personnel Management, Interviewing Techniques;
Yourdon tools; RDD-100 design tools; DEC VMS Internals;
National Security Agency Certified Vendor Security Analyst. |
|
| Languages |
C, SQL (Oracle), HTML, FORTRAN, Pascal, Dbase, COBOL,
PL/1, BASIC, RPG-II, PDL. Assembly languages (IBM, DEC,
HP, CDC, Varian). Microcoding (various machines) |
|
| Systems |
SUN; HP; PC; Mac; DEC VAX Series (VMS, SEVMS, UNIX);
PDP 11 Series (RSX, IAS); HP 1000, 2000 Series, 3000 (RTE,
MPE); CDC 3150, CYBER 173, CYBER 18-30 (Nos, Kronos);
IBM 1130, 1401, System 3/10, 370/135 (MVS, VM), Varian
V72; Bendix G-15D. |
|
| Security Clearances |
LEVEL:
Top Secret/SCI, SBI & EBI (not current). Successful full
background and lifestyle polygraphs. |
|
| References |
|
Mary Ann
Davidson, Chief Security Officer & Vice President,
Oracle Corporation, 650.506.5464
David Gobuty,
Chief Security Officer,
Eastman Kodak Company Medical Imaging Division, 650.325.2533
Bill Wilson,
Vice President, Exodus Communications; President, Arca Systems, Inc. 408.725.0434
(more references available if required) |
|
|