Summary
Overview
Work History
Education
Skills
Accomplishments
Timeline
Generic
Rosauro F. Donato

Rosauro F. Donato

Information & Cyber Security Consultant
Taguig,Manila. NCR

Summary

INFORMATION SECURITY Manager / CYBER Security / Risk Consultant, AUDIT, GRC US FEDRAMP FISMA agencies Mix NIST, ISO27001, PCI, SOC2, HIPAA, Hi-TRUST Financials, Technology, Healthcare | United States (+63) 9472827334 | 09055701985 | renie.donato@gmail.com | Manila, NCR My Information Security, Cyber Security, IT Security hype: "In reality, we can’t improve what we can’t measure. We have to combine Both Business Strategies, Process, Technology Tools & People. Risk Assessment, Risk mitigation, business Impact Analysis BIA, Intelligence & Research, Deep Investigations, deployment, Setup Round d’ clock Threat Monitoring, Data Traffic, Prevention & Control, Incident response team Setup FW Firewall, IDS/IPS Intrusion Detection/Protection, AV Anti-Virus, WebSec, EmailSec, Train staff in Monitoring, threat Identification, Virus, Malware, APT’s, Impact mitigation, & visibility context on mission critical Systems. Creation & implementation of Standards, Guidelines & Policies to Educate people. Investigate on insider threats, IoT / BoT attacks, Privilege Abuse to prevent compromise attacks Meeting stakeholders, Aligning business requirements components to IT strategies Skills – Framework & methodologies, (reference NIST methods) Job role alignment, Business challenges, hands on Risk management & IT SECURITY skills, Prospect & opportunities. Why? There are two types of companies, 1 that is already Been hacked and 2 that still don’t know yet that they’ve been or being Attack. SKILLs Before an attack – Discover, enforce, harden Security During attack – Detect, block, defend After Attack – scope contain, re-mediate To truly protect against all possible attacks. Defenders must understand The attacker’s mindset, their motivations, and their methods before, during & after the attack. Hackers nowadays have replicated your network & got even more sophisticated, they even have their splunk & antivirus to test, penetrate, & take control of your network. The best is yet to come. I am readily available 24x7 over the sun mode! Flexible and Negotiable anytime. Should you need my attention, Please feel free to contact me anytime at your convenience. " Experience 23 years of total experience June 2016 – Present Consultant - INFORMATION SECURITY Manager / CYBER Security / Risk Consultant, AUDIT, GRC | US FEDRAMP FISMA agencies, Mix NIST, ISO27001, PCI, SOC2, HIPAA, Hi-TRUST | Financials, Technology, Healthcare etc | United States oThycotic PAM Software, all mix US FEDRAMP agencies underground || 6 years 5 months | BGC Makati US Global I am an IT Infrastructure Systems Engineer, Information Security (INFOSEC), AUDIT, GRC & CYBER SECURITY - my main objective is to provide management direction & support for Information Security in accordance w/ business requirements and relevant laws & regulations. Avoid penalties by Leading & implementing ISO 27001 / ISMS (Information Security Management Systems & NIST SP 800-53 (US National Institute for Standards & Technology - Special Publication 800-53), COBIT5, ITILv3, frameworks & methodologies, best practices, RISK driven standards. Securing Vulnerabilities of the Enterprise as we are the 1st & last line of defense. In lay man’s term, I catch the bad guys, (hackers) and keep them OFF the System. My main scope role aside from my JD is to deliver & Transition Organizations as follows: Assess readiness, for ISO27001 / ISMS, ISO27001 / ISMS Lead Implementer, Lead a team of Cyber Security CSIRT, GRV (Governance , Risk & Compliance), Risk Assessments, Plan Mitigation, Implement Control measures to reduce & mitigate risks, do GAP Analysis, assess PRIVACY & Business Impact Analysis (PIA / BIA), do AUDIT s, Organize & Implement IS Policies as per ISMS, ISO27K1, NIST SP 800-53, PCIDSS, COBIT5, SOX, ITIL, Train all IT Staffs, HR & all users, train White hackers on Penetration Techniques VAPT (Vulnerabilities Assessments & Pen Testing) , Plan implement BCP Business Continuity Planning & DR DISASTER RECOVERY. Setup round d' clock monitoring of incidents, resolving, reporting & documenting as well as measuring effectiveness of control sets for continues improvement. Please see my CV > Assess > remediate) as annual surveillance, maintenance & reviewed for continual improvement & management reporting as per ISMS / ISO 27001 standards. Lastly, getting ready for ISO 27001 certifications. Then continuously monitoring & improving process. Strong leader and problem-solver dedicated to streamlining operations to decrease costs and promote organizational efficiency. Uses independent decision-making skills and sound judgment to positively impact company success.

Overview

23
23
years of professional experience

Work History

Level Assistant Manager / Manager

  • Sourcing, compiling and interpreting key IT GRC data, providing analysis and recommendations for process improvement, and generating a variety of value-added reports for multiple levels of the organization
  • Ensuring the timely execution of quarterly
  • SOX evidence gathering and testing for infrastructure systems
  • Working on ISO 27001, 27002 & 20000 Audit for ITSM processes and proving my recommendations to ITSM process managers
  • Working for ITIL Project for different ITIL Processes like Incident,
  • Problem, Change, and Security Management and implementing according to ISO 27k & 20000 Standards
  • IT Security / INFOSEC Vulnerability Management VM.

Network/System Engineer

IT Systems Administrator

  • Responsible for Management & support Global Helpdesk / Technical Support on a 24x7
  • Operations utilizing both Windows, VMWARE, CITRIX, VEEAM, 6 VERISTOR SIMPANA 10,
  • BACKUPEXEC & Linux infrastructures comprised of 20+ remote locations throughout
  • North and South America, with several thousand of call-center and corporate users
  • Role involves managing member servers and domain controllers, monitoring DFS replication, automating deployment software and tasks, building software packages and supporting day to day maintenance operations
  • IT Security / INFOSEC Vulnerability Management
  • VM
  • Management of Helpdesk & Technical Support Team on 24x7 Global Operations

SYSTEMS Engineer

SUN
  • Level 3 (Enterprise Management Centre L3 Engineer)
  • Provides 24/7 over the, mode Global IT Infrastructure Support to Sonnet and

IT Audit & RISK Management Team Lead

OCWEN Financials
12.2015 - 04.2016
  • Industry Call Center / IT-Enabled Services / BPO
  • Specialization Finance - Corporate Finance/Investment/Merchant Banking
  • Role Enterprise Risk Management

SR SYSTEMS ENGINEER / ADMINISTRATOR

Results Manila Inc
06.2012 - 06.2015
  • Industry Call Center / IT-Enabled Services / BPO

IT MANAGER

WNS GLOBAL SERVICES PHILS
12.2009 - 05.2010
  • Industry Call Center / IT-Enabled Services / BPO
  • Responsible for ensuring the smooth operations of the company's Information
  • Technology Services
  • Reports directly to the AVP IT, VP Finance & Admin Director
  • Responsible for the administration of the company’s Datacenter hosting servers and related equipment’s
  • Maintain maximum availability in terms of hardware and application Provide support for backup and recovery, file backup and recovery and disaster recovery services prepare status reports on server utilization , hardware

SYSTEMS ENGINEER Level

EMC
06.2008 - 07.2009
  • Year 2 months)
  • Industry Call Center / IT-Enabled Services / BPO

HELPDESK, Network & Helpdesk Support Engineer II

SAUDI ARAMCO
12.1997 - 05.2002
  • Over the phone user queries utilizing REMEDY, Software & IBM TIVOLI Remote
  • Management Framework version 4.1 Software
  • Industry Oil / Gas / Petroleum
  • Specialization IT/Computer - Network/System/Database Admin
  • Providing Technical support over a LAN / WAN / INTERNET Enterprise Network of computers running Novell 4.11 NDS multi-context infrastructure and a multi-Master
  • Domain Windows NT on a Token Ring and Fast Ethernet Environment
  • Providing
  • Technical and System support to all levels of computer users on Hardware, Software and
  • Network installation over an Enterprise Networks of computers, which includes Helpdesk
  • Support to over 2,000 users of SAUDI ARAMCO Medical Services Organization (SAMSO) running Novell 4.11 NDS multi-context infrastructure and a Multi-Master Domain
  • Windows NT

Computer Hardware Engineer

DIGI SYSTEMS, INC
10.1993 - 01.1996
  • Hardware & Software: Responsible for the Assembly, Installations, Setup &
  • Configurations, Repairs and Maintenance of all Major products of the company
  • Takes care of all Clients/ Service calls and do Field works within Riyadh and Jeddah branches
  • I got around Two year’s valuable experience in the maintenance of all the systems products
  • The job involved installing computers & printers at the customer sites, imparting training and maintenance
  • Products: IBM 100% PC CLONES, Pentiums, 486,
  • Laptops & Notebooks, Printers & Laser Printers (Epson, Citizen, HP, Canon, Panasonic)
  • CREATIVE labs
  • Multimedia Products ranges from CD ROMS, Fax & Modems, Sound,
  • Video, Midi & Phone

Education

Bachelor's/College Degree - Computer Science/Information Technology, Computer Engineering

Adamson University, Philippines Technical Summary

ISO 27001 / ISO 31000, ISC2 /COBIT 5 / 4.x / ISACA / ISO/IEC 38500, TOGAF, PMP / PMBok, PRINCE2, ITIL V2/ V3/ ITSM / SLA Foundation. Windows 2012, 2008 R2, 2000, WIN2K Advanced Windows 2003 ACTIVE DIRECTORY / NT Management Administration and Troubleshooting, CITRIX / ESX VMWARE / UNIX / REDHAT-LINUX / NOVELL 4.11 INTRANETWARE / HP OPENVIEW, OPSMANAGER. Window Server AD System administration with acceptable knowledge of TCP/IP protocol, Web Services ( IIS), DNS & DHCP, RRAS, NAT, VPN, VoIP technologies. Good working knowledge in Remote access tools and console (Citrix, IBM TIVOLI,HP OVSD) & any - undefined

IT Security & INFOSEC Vulnerability Management - undefined

Excellent knowledge of Windows XP - undefined

REMEDY HELPDESK 6.0 and IBM TIVOLI Remote Management. Manage virus protection procedures on clients pc’s. Analyze work group systems and recommend Solutions. Sound understanding of network principles and Internet architecture Strong understanding of protocols TCP/IP, NetBEUI, IPX/SPX, Nwlink, SNA Network access methods including, dial-up, ISDN, Wired/ wireless, broadband (any) Network topologies and components such as: routers, switches, firewall etc. Understanding of VPN Technology, Firewalls, Security & RAID Technologies/ Excellent communication skills with customer service focus. Formulate and implement permanent solutions to recurring problems through investigations, root cause analysis and testing. Manage escalation and collaboration with 3rd party vendors for technical support problems and queries. Create, review and update technical documentation. Citrix Admin, iso 27001, iso auditor, IT Audit, IT Management, IT Security, ITIL Management Network IT Security, Risk Analyst, Risk Assessment, Risk Management Risk Management Consultant, Risk Mitigation, vmware esx - undefined

infrastructure vmware server, Windows Script, Citrix Administration, 27001, ISO auditor, IT Audit, IT Management, IT Security, ITIL Management, Network, IT Security, Risk Analyst, Risk Assessment, Risk Management Consultant, Risk Mitigation, vmware, esx vmware infrastructure, vmware server, Windows Script About Me Gender Male | Married | 3 dependents | Taguig NCR - undefined

Skills

My Information Security, Cyber Security hype: "People dont care how much you know till they know how much you care In reality, we can’t improve what we can’t measure We have to combine Both Business Strategies, Process, Technology Tools & People Risk Assessment, Risk mitigation, business Impact Analysis BIA, Intelligence & Research, Deep Investigations, deployment, Setup Round d’ clock Threat Monitoring, Data Traffic, Prevention & Control, Incident response team Setup FW Firewall, IDS/IPS Intrusion Detection/Protection, AV Anti-Virus, WebSec, EmailSec, Train staff in Monitoring, threat Identification, Virus, Malware, APT’s, Impact mitigation, & visibility context on mission critical Systems Creation & implementation of Standards, Guidelines & Policies to Educate people Investigate on insider threats, IoT / BoT attacks, Privilege Abuse to prevent compromise attacks Meeting stakeholders, Aligning business requirements components to IT strategies Skills – Framework & methodologies, (reference NIST methods) Job role alignment, Business challenges, hands on Risk management & IT SECURITY skills, Prospect & opportunities Why? There are two types of companies, 1 that is already Been hacked and 2 that still don’t know yet that they’ve been or being Attack SKILLs Before an attack – Discover, enforce, harden Security During attack – Detect, block, defend After Attack – scope contain, re-mediate To truly protect against all possible attacks Defenders must understand The attacker’s mindset, their motivations, and their methods before, during & after the attack Hackers nowadays have replicated your network & got even more sophisticated, they even have their splunk & antivirus to test, penetrate, & take control of your network The best is yet to come I am readily available 24x7 over the sun mode! Flexible and Negotiable anytime Should you need my attention, Please feel free to contact me anytime at your convenience "

undefined

Accomplishments

  • JETSTAR & QANTAS Airlines of Australia
  • Utilizing WINDOWS 2003 / WIN2K mixed mode server on multiple CITRIX Presentation Farm servers, EXCHANGE and ESX VM Virtual
  • Machines enterprise environment
  • IT Security / INFOSEC Vulnerability Management VM
  • May 2007 - Nov 2007 WINTEL Project Team Lead (8 months) Hewlett-Packard, Philippines AP
  • Industry Computer / Information Technology (Hardware)
  • Specialization IT/Computer - Network/System/Database Admin
  • Role Supervisor/Team Lead
  • Position Level Supervisor / 5 Years & Up Experienced Employee
  • Team Lead - HP ITO GCP RMC - WINTEL Tower /HP AsiaPacific Philippines
  • HP Infrastructure Technology Organization ITO / Global Center Philippines - GCP
  • Remote Management Center RMC
  • Project Name - P&G - Procter and Gamble NT
  • Infrastructure support Client - Hewlett-Packard, GCP- Global Center
  • P&G - Procter and Gamble NT Infrastructure support Project Description
  • Project involves managing of globally distributed NT Infrastructure of P&G (which includes 3 large Data Centers for NA/EMEA/AP region) at GCP, Philippines
  • This includes maintenance of Primary ERP Supply Chain Management and its DR site, RTCIS critical manufacturing sites and other critical Financial systems
  • Contribution to Project Supporting more than 9000 NT Boxes in 24x7 over the sun mode remote support environment
  • IT Security / INFOSEC Vulnerability Management VM
  • Around Six plus Years of Experience in the field of Windows
  • June 02 – Sept 2005 SR IT Helpdesk / Technical Support Engineer II (3 years 4 months) MARAFIQ | Saudi Arabia - Utilities / Power Industry
  • Providing Technical Support over a LAN / WAN / INTERNET Enterprise Network of computers utilizing Windows 2000 Servers on a Multiple Platform of Windows NT / 2000, ORACLE, SAP R/3 and AIX UNIX on a Fast Ether NET Environment
  • Promptly solves

Timeline

IT Audit & RISK Management Team Lead

OCWEN Financials
12.2015 - 04.2016

SR SYSTEMS ENGINEER / ADMINISTRATOR

Results Manila Inc
06.2012 - 06.2015

IT MANAGER

WNS GLOBAL SERVICES PHILS
12.2009 - 05.2010

SYSTEMS ENGINEER Level

EMC
06.2008 - 07.2009

HELPDESK, Network & Helpdesk Support Engineer II

SAUDI ARAMCO
12.1997 - 05.2002

Computer Hardware Engineer

DIGI SYSTEMS, INC
10.1993 - 01.1996

Level Assistant Manager / Manager

Network/System Engineer

IT Systems Administrator

SYSTEMS Engineer

SUN

Bachelor's/College Degree - Computer Science/Information Technology, Computer Engineering

Adamson University, Philippines Technical Summary

ISO 27001 / ISO 31000, ISC2 /COBIT 5 / 4.x / ISACA / ISO/IEC 38500, TOGAF, PMP / PMBok, PRINCE2, ITIL V2/ V3/ ITSM / SLA Foundation. Windows 2012, 2008 R2, 2000, WIN2K Advanced Windows 2003 ACTIVE DIRECTORY / NT Management Administration and Troubleshooting, CITRIX / ESX VMWARE / UNIX / REDHAT-LINUX / NOVELL 4.11 INTRANETWARE / HP OPENVIEW, OPSMANAGER. Window Server AD System administration with acceptable knowledge of TCP/IP protocol, Web Services ( IIS), DNS & DHCP, RRAS, NAT, VPN, VoIP technologies. Good working knowledge in Remote access tools and console (Citrix, IBM TIVOLI,HP OVSD) & any - undefined

IT Security & INFOSEC Vulnerability Management - undefined

Excellent knowledge of Windows XP - undefined

REMEDY HELPDESK 6.0 and IBM TIVOLI Remote Management. Manage virus protection procedures on clients pc’s. Analyze work group systems and recommend Solutions. Sound understanding of network principles and Internet architecture Strong understanding of protocols TCP/IP, NetBEUI, IPX/SPX, Nwlink, SNA Network access methods including, dial-up, ISDN, Wired/ wireless, broadband (any) Network topologies and components such as: routers, switches, firewall etc. Understanding of VPN Technology, Firewalls, Security & RAID Technologies/ Excellent communication skills with customer service focus. Formulate and implement permanent solutions to recurring problems through investigations, root cause analysis and testing. Manage escalation and collaboration with 3rd party vendors for technical support problems and queries. Create, review and update technical documentation. Citrix Admin, iso 27001, iso auditor, IT Audit, IT Management, IT Security, ITIL Management Network IT Security, Risk Analyst, Risk Assessment, Risk Management Risk Management Consultant, Risk Mitigation, vmware esx - undefined

infrastructure vmware server, Windows Script, Citrix Administration, 27001, ISO auditor, IT Audit, IT Management, IT Security, ITIL Management, Network, IT Security, Risk Analyst, Risk Assessment, Risk Management Consultant, Risk Mitigation, vmware, esx vmware infrastructure, vmware server, Windows Script About Me Gender Male | Married | 3 dependents | Taguig NCR - undefined

Rosauro F. DonatoInformation & Cyber Security Consultant