{"id":8,"date":"2015-04-27T18:26:13","date_gmt":"2015-04-27T18:26:13","guid":{"rendered":"http:\/\/devsec.smham2.org\/?page_id=8"},"modified":"2024-07-04T13:29:05","modified_gmt":"2024-07-04T17:29:05","slug":"resume","status":"publish","type":"page","link":"https:\/\/devsec.smham2.org\/?page_id=8","title":{"rendered":"Resume"},"content":{"rendered":"<p>Stanley M. Hammond<br \/>\nCape Cod, MA<\/p>\n<p><strong><u>Certification:<\/u><\/strong><\/p>\n<ul>\n<li>Network+ (CompTIA Certified Network Technician)<\/li>\n<li>CIW Security Analyst<\/li>\n<li>SANS GIAC (GSEC)<\/li>\n<li>SANS GIAC (GISP)<\/li>\n<li>SANS GIAC (GCCC)<\/li>\n<li>SANS GIAC (GEVA)<\/li>\n<li>SANS GIAC (GPEN)<\/li>\n<li>SANS Security Awareness Professional (SSAP)<\/li>\n<li>SANS GIAC (Computer and Network Security Awareness)<\/li>\n<li>SANS GIAC (Mastering Packet Analyst)<\/li>\n<li>CISSP (Certified Information Systems Security Professional)<\/li>\n<li>HCISPP (HealthCare Information Security and Privacy Practitioner)<\/li>\n<li>CISA (Certified Information Systems Auditor)<\/li>\n<li>CDPSE (Certified Data Privacy Solutions Engineer)<\/li>\n<li>ISACA CSX-P (Cybersecurity Practitioner)<\/li>\n<li>CCSK (Certificate of Cloud Security Knowledge &#8211; v4)<\/li>\n<li>CompTIA PenTest+<\/li>\n<li>AWS Certified Solutions Architect &#8211; Associate<\/li>\n<li>CISM (Certified Information Security Manager)<\/li>\n<li>CCSP (Certified Cloud Security Professional)<\/li>\n<\/ul>\n<p><strong><u>Experience:<\/u><\/strong><\/p>\n<p><strong>5\/2024 &#8211; present<\/strong><\/p>\n<p><strong>Mass General Brigham<\/strong><br \/>\n<strong>Somerville, MA<\/strong><\/p>\n<p><strong><u>Information Security Officer<\/u><\/strong><\/p>\n<ul>\n<li>More information to come. For specifics, please contact me.<\/li>\n<\/ul>\n<p><strong>6\/2016 \u2013 5\/2024<br \/>\n<\/strong><\/p>\n<p><strong>Cape Cod Healthcare<br \/>\n<\/strong><strong>Hyannis, MA<\/strong><\/p>\n<p><b><u>Information Security Engineer<\/u><\/b><\/p>\n<ul>\n<li><strong><u>Investigate security incidents including determining violations of internal and regulatory policies (HIPAA)<\/u><\/strong>. Regarding potential HIPAA violations, determine where, when and how the disclosure took place using workstation, server and application logs. Work with different IT groups that administer specific applications to retrieve logs and data. Compile a report and pass along to appropriate senior level staff (Director of Information Security, Director of Clinical and Research Compliance).<\/li>\n<li><strong><u>Perform regular risk assessments on servers and workstations.<\/u><\/strong> Assessments are done using vulnerability assessment tools (Nessus). Determine current state of PC and confirm that systems are complying based on the risk appetite of the organization and conforms to the patch management policy.<\/li>\n<li><strong><u>Implement new information security tools and applications to increase the security posture of the organization.<\/u><\/strong> Tools include desktop antivirus management, file analysis using virtual workstations, web content filtering, two-factor authentication (2FA) and cloud security measures in Microsoft 365.<\/li>\n<li><strong><u>Evaluate third-party vendors that are used for new technology implementations.<\/u><\/strong> Evaluate that third-party vendors comply with federal and state regulations. Evaluate that third-party vendors will comply with organization policies regarding information security.<\/li>\n<\/ul>\n<p><strong>5\/2010 \u2013 3\/2017<\/strong><\/p>\n<p><strong>Woods Hole Research Center<br \/>\nFalmouth, MA<\/strong><\/p>\n<p><strong><u>UNIX\/Linux System Administrator<\/u><\/strong><\/p>\n<ul>\n<li><strong><u>Manage Linux computing cluster environment:<\/u><\/strong> Support institution\u2019s UNIX\/Linux servers and data storage clusters running Red Hat Enterprise Linux, Sun Solaris, and Windows Server 2003.\u00a0 Perform user account management for the Linux servers, software maintenance and perform regular backups using Symantec Backup Exec and Retrospect.\u00a0 Maintain Raspberry Pi\u2019s that are used to monitor energy consumption.<\/li>\n<li><strong><u>Troubleshoot system issues:<\/u><\/strong> Monitor cluster usage and performance using open source tools (Ganglia, Sun Graphical Accounting Engine).\u00a0 Analyze user code written in different languages (Python, R) to determine performance issues and resolve compilation or run-time errors.<\/li>\n<li><strong><u>Provide technical support to scientific and administrative end users:<\/u><\/strong> Serve as systems administrator for Windows 2008 domain and VMWare ESX environment.\u00a0 Administer Windows Servers running versions 2003, 2008 and 2012.\u00a0 Provide technical support to end users running MacOS and Windows (XP, Windows 7 and 8).\u00a0 Manage Cisco backbone connecting computing cluster environment to company\u2019s main network.\u00a0 Manage internal HP backbone for network connectivity.<\/li>\n<li><strong><u>Manage cloud computing resources:<\/u><\/strong> Setup and create cloud computing instances within Amazon Web Services (AWS).\u00a0 Maintain access to instances and perform periodic updates to software packages contained within the instances.<\/li>\n<\/ul>\n<p><strong>1\/2010 \u2013 5\/2010<\/strong><\/p>\n<p><strong>Cape Cod Community College (Commonwealth of Massachusetts)<br \/>\nWest Barnstable, MA<\/strong><\/p>\n<p><strong><u>Adjunct Instructor<\/u><\/strong><\/p>\n<ul>\n<li>Serve as an instructor with the Business department teaching Operating Systems essentials in preparation for the CompTIA A+ Exam.<\/li>\n<\/ul>\n<p><strong>8\/2007 \u2013 5\/2010<\/strong><\/p>\n<p><strong>Cape Cod Community College (Commonwealth of Massachusetts)<br \/>\nWest Barnstable, MA<\/strong><\/p>\n<p><strong><u>Information Security Specialist<\/u><\/strong><\/p>\n<ul>\n<li><strong><u>Technical lead for heading up information security initiative:<\/u><\/strong> Served as the college\u2019s first Information Security Manager.\u00a0 First task was to analyze the existing infrastructure and determine what areas either already comply or needed to comply with federal, state and industry laws and regulations. Recommend any additions or changes that should be made to the Technical Director and CIO, and then implementing them.<\/li>\n<li><strong><u>Maintain the integrity of host and network resources:<\/u><\/strong> Implement a network intrusion detection using open source tools (Snort, Prelude IDS) for monitoring network traffic.\u00a0 Implement host intrusion detection system using open source tool, OSSEC, to monitor authorized and unauthorized access to critical servers housing student and staff data.\u00a0 Evaluate and implement Cisco ASA appliance to handle perimeter network monitoring for the main network entry point.\u00a0 Use IPCop to handle perimeter network monitoring on two segregated networks.<\/li>\n<li><strong><u>Maintain the confidentiality and availability of host resources:<\/u><\/strong> Administer the college\u2019s existing SSL VPN system (SSL Explorer).\u00a0 Evaluated, recommended and implemented a new SSL VPN solution for remote access.\u00a0 Working with the Technical Director, CIO and Vice President of Administration and Finance, managed the authorized user accounts for the VPN system.\u00a0 Maintain the tracking software solution that was used on the college issued laptops for the staff.\u00a0 Evaluate encryption software as a more cost effective solution for college issued laptops.\u00a0 Administer the college\u2019s Windows 2003 domain and virtual machines running in VMWare ESX.<\/li>\n<li><strong><u>Maintain system\/network infrastructure:<\/u><\/strong> Assist with administering, maintaining and troubleshooting network backbone comprised of Cisco routers, switches and access points. Serve as system administrator for Windows 2003 Active Directory domain and Exchange 2003 server.<\/li>\n<li><strong><u>Stay current with the latest developments in information security:<\/u><\/strong> Became familiar with federal (FERPA, HIPAA, FISMA), state (MGL chap. 93H, 93I, 201 CMR 17.00) and industry (PCI) regulations as they pertain to the college.\u00a0 Attend trade conferences to identify areas of interest that would apply to the college.\u00a0 Read articles (paper and internet posted) and blogs on information security topics that are affecting other institutions.\u00a0 Maintain contact on mailing list for information security issues that affected educational institutions.<\/li>\n<\/ul>\n<p><strong>4\/2007 \u2013 8\/2007<\/strong><\/p>\n<p><strong>VeriSign<br \/>\nProvidence, RI<\/strong><\/p>\n<p><strong><u>Security Analyst (third shift)<\/u><\/strong><\/p>\n<ul>\n<li><strong><u>Monitor and investigate customer systems for suspicious activity:<\/u><\/strong> Investigate security incident reports generated by deployed intrusion detection systems (IDS).\u00a0 Analyze contents retrieved from network devices using both open source (Tcpdump, Wireshark) and proprietary tools.\u00a0 Document incident analysis and steps taken in the investigation.\u00a0 Escalate confirmed security incidents to customers per service level agreement (SLA).\u00a0 Respond to customer\u2019s request for information on an incident via the telephone and\/or email.<\/li>\n<\/ul>\n<p><strong>12\/2006 \u2013 4\/2007<\/strong><\/p>\n<p><strong>Department of Revenue (Commonwealth of Massachusetts)<br \/>\nChelsea, MA<\/strong><\/p>\n<p><strong><u>Security Engineer<\/u><\/strong><\/p>\n<ul>\n<li><strong><u>Maintain the confidentiality and integrity of end user data:<\/u><\/strong> Provide support for tax filers using secure shell (SSH), including analyzing system logs to verify authorized logins and successful or failed file transfers.\u00a0 Update the existing SSH\/LDAP infrastructure used by the tax filers to authenticate their user accounts.<\/li>\n<li><strong><u>Maintain the existing infrastructure in accordance to DOR standards:<\/u><\/strong> Perform regular maintenance updates and upgrades on Symantec firewalls and Google search appliances.\u00a0 Setup new Linux servers for corporate applications, applying patches, hardening them using Bastille (including creating custom modules that comply with DOR and IRS standards) and integrating them into Active Directory.\u00a0 Wrote custom Perl scripts to perform account maintenance on Exchange server and transfer data between DOR and Massachusetts Information Technology Division (ITD).<\/li>\n<\/ul>\n<p><strong>4\/2002 \u2013 12\/2006<\/strong><\/p>\n<p><strong>Woods Hole Oceanographic Institution<br \/>\nWoods Hole, MA<\/strong><\/p>\n<p><strong><u>Information Systems Assistant III<\/u><\/strong><\/p>\n<ul>\n<li><strong><u>Maintain the availability of network resources:<\/u><\/strong> Monitor network traffic for suspicious activity using open source tools (Snort) for intrusion detection.\u00a0 Implement systems to analysis and audit network traffic using open source tools (IPAudit).\u00a0 Process firewall request for end users (including organizations that had network service provided by the institution) that need their systems to be accessible from outside the institution.<\/li>\n<li><strong><u>Investigate security incidents:<\/u><\/strong> Handle investigations for compromised Linux and Windows host, which included determining what files were compromised and preserving evidence for further analysis.\u00a0 Investigate RIAA and DMCA notices to determine if incidents occurred within the institution\u2019s address space and responded promptly to request with detailed information to assist in the investigation.<\/li>\n<li><strong><u>Educate end users on security best practices:<\/u><\/strong> Create and present content to educate end user community on security best practices for keeping their servers and data secure. <strong><u>\u00a0<\/u><\/strong><\/li>\n<li><strong><u>Provide support to both the end users and technicians:<\/u><\/strong> Provide first and second level telephone and email support for institution\u2019s end users (1000+ users) running Windows, Linux and Mac systems.\u00a0 Serve as lead help desk technician, assisting and mentoring new help desk personnel.\u00a0 Serve as systems administrator for issue tracking system (Footprints).\u00a0 Serve as secondary Windows support technician, setting up new user PC\u2019s according to department recommendations.\u00a0 Serve as Linux system administrator for Linux systems used in department\u2019s classroom.\u00a0 Research and procure equipment maintained by help desk (laptops).<\/li>\n<\/ul>\n<p><strong>4\/1998 \u2013 4\/2003<\/strong><\/p>\n<p><strong>Woods Hole, Martha\u2019s Vineyard &amp; Nantucket Steamship Authority<br \/>\nWoods Hole, MA<\/strong><\/p>\n<p><strong><u>Management Information Systems (MIS) Technician<\/u><\/strong><\/p>\n<ul>\n<li><strong><u>Provided end user technical support:<\/u><\/strong> Maintain the hardware and network infrastructure for the company\u2019s eight (8) locations and nine (9) ferries.\u00a0 Serve as system administrator for company\u2019s IBM AS400 mainframe and issue tracking system (Track-It). Setup PC\u2019s and laptop for new employees and existing end users in accord with what the user needed to accomplish their job (mandatory access controls).\u00a0 Perform user account management (creation and revocation) for domain access, email access and internet access.\u00a0 Work with external vendors to maintain telecommunication connectivity between the central office and remote offices.<\/li>\n<\/ul>\n<p><strong><u>Education:<\/u><\/strong><\/p>\n<p>University of Massachusetts &#8211; Lowell<br \/>\nAssociates of Science<br \/>\nMajor: Information Technology<\/p>\n<p>University of Illinois<br \/>\nCertificate of Professional Development: UNIX\/ Linux System Administration<\/p>\n<p><span style=\"text-decoration: underline;\"><strong>Conference Presentations:<\/strong><\/span><\/p>\n<p>&#8220;Did You Get Our Message? How to Maintain Email Availability&#8221;, SecureWorld Healthcare Virtual Conference, April 2023<br \/>\n&#8220;Leveraging AI to Create Your Organization\u2019s Security Policies&#8221;, SecureWorld Boston 2024, March 2024<\/p>\n<p><strong><u>Professional Development:<\/u><\/strong><\/p>\n<p>MGT433: Securing the Human: How to Build, Maintain and Measure a High-Impact Awareness Program<br \/>\nSEC580: Metasploit Kung Fu for Enterprise Pen Testing<br \/>\nSEC583: Crafting Packets<br \/>\nSEC541: Cloud Security Monitoring and Threat Detection<br \/>\nSEC474: Building A Healthcare Security &amp; Compliance Program<br \/>\nAIS247: AI Security Essentials for Business Leaders<br \/>\nNIST Cyber Security Professional (NCSP) Foundation<br \/>\nAZ-900 Azure Fundamentals Training<br \/>\nSC-900 Microsoft Security, Compliance, and Identity Fundamentals Training<br \/>\nAZ-500 Microsoft Azure Security Technologies Training<\/p>\n<p><strong><u>Professional Associations:<\/u><\/strong><\/p>\n<ul>\n<li>Member of ISACA \u2013 New England Chapter: 2009 and 2012 \u2013 2024<\/li>\n<li>Member of ISACA \u2013 Rhode Island Chapter: 2010 and 2011<\/li>\n<li>Member of ISSA &#8211; Information Systems Security Association: 2018 &#8211; 2021, 2023 &#8211; 2024<\/li>\n<li>Member of GIAC Advisory Board<\/li>\n<li>Member of IEEE Computer Society: 2014-2017<\/li>\n<li>Member of Project Management Institute: 2014, 2023 \u2013 2024<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Stanley M. Hammond Cape Cod, MA Certification: Network+ (CompTIA Certified Network Technician) CIW Security Analyst SANS GIAC (GSEC) SANS GIAC (GISP) SANS GIAC (GCCC) SANS GIAC (GEVA) SANS GIAC (GPEN) SANS Security Awareness Professional (SSAP) SANS GIAC (Computer and Network Security Awareness) SANS GIAC (Mastering Packet Analyst) CISSP (Certified Information Systems Security Professional) HCISPP (HealthCare [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":2,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-8","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/devsec.smham2.org\/index.php?rest_route=\/wp\/v2\/pages\/8","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devsec.smham2.org\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/devsec.smham2.org\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/devsec.smham2.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/devsec.smham2.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8"}],"version-history":[{"count":17,"href":"https:\/\/devsec.smham2.org\/index.php?rest_route=\/wp\/v2\/pages\/8\/revisions"}],"predecessor-version":[{"id":27781,"href":"https:\/\/devsec.smham2.org\/index.php?rest_route=\/wp\/v2\/pages\/8\/revisions\/27781"}],"wp:attachment":[{"href":"https:\/\/devsec.smham2.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}