7
Erwin (Chris) Louis Carrow Metro Atlanta, Georgia [email protected] 770-668-6971 (mobile); http://www.linkedin.com/in/ecarrow Skype: erwin.louis.carrow Summary: Obtain a challenging strategic leadership/SME security position utilizing my creative and innovative aptitudes, skills, and expertise in Information Technology. Develop strategic and operational IT security solutions for governance, compliance, assurance, forensics and operations with a comprehensive approach throughout an organization that is specific and sustainable for all business requirements. Be instrumental in implementing and maintaining IT security and compliance controls and constraints to advance digital footprint for both traditional and cloud- based service infrastructure environments. Ensure implementation, maintenance, and assurance efforts for sustaining information security industry standards and practices. Related Experience Vonage Essentials / Vonage Business Solutions / Vonage Holdings 3200 Windy Hill Road, Suite 200 East, Atlanta GA 30339 Nov 2014 to Oct 2015 Role and responsibilities: Senior Information Technology Security and Compliance Manager - developed long-term strategic security solutions and the establishment governance, compliance and operations for IT security strategy throughout the organization to implement and support operational requirements. Instrumental in implementing and maintaining IT security and compliance controls and constraints to advance digital footprint for both traditional and cloud-based service infrastructure environments with a focus upon open source solutions and the Amazon IaaS, PaaS and SaaS cloud-base service offerings. Ensure implementation and maintenance efforts for becoming and sustaining information security so as to achieve ISO/IEC 27001, SOX, SSAE16, SOC2-3, CALEA, and PCI-DSS certifications. Ensure compliance for PII, HIPAA, HITECH, Omnibus, and other privacy related regulatory requirements. Critical objectives and tasks include: Identify architect, implement, manage and support IT governance, assurance, compliance, operations, forensics, audit, change management and the SDLC application development efforts and process for information and information system security throughout the Vonage Business Solutions (VBS) infrastructure architecture. Establish a security and compliance framework for a telecommunication SMB corporate entity. Vendor and project manager for security and compliance contractual agreements. Select controls for both physical and cloud environments, assessment work, contract review, and exploit testing for development and vulnerability management. In addition, developed and documented a security framework with a plan to implement all required controls to enhance security. Worked with deployment, architecture, and production teams throughout the SDLC to production to ensure applications and cloud-based solutions and practices meet industry standards and provide effective security to manage and mitigate risk. Conducted static and dynamic applications vulnerability testing/security awareness for developers and supported public facing web presence. Have conducted assurance penetration testing with various commercial and open source tools e.g., BASH and python scripting, Veracode, Fortify, Checkmarx, Nexpose, Metasploit, WebInspect, AppScan, aircrack, nmap, wireshark, and Kali Linux suite of tools. Coordinate with legal, at as security and compliance liaison with senior leadership and other internal entities to ensure the VBS Security and Compliance Office (SCO) supports corporate risk and compliance interdependencies.

Erwin (Chris) Carrow resume Brief 10-23-2015

Embed Size (px)

Citation preview

Page 1: Erwin (Chris) Carrow resume Brief 10-23-2015

Erwin (Chris) Louis Carrow Metro Atlanta, Georgia

[email protected] 770-668-6971 (mobile);

http://www.linkedin.com/in/ecarrow Skype: erwin.louis.carrow

Summary: Obtain a challenging strategic leadership/SME security position utilizing my creative and innovative aptitudes, skills, and expertise in Information Technology. Develop strategic and operational IT security solutions for governance, compliance, assurance, forensics and operations with a comprehensive approach throughout an organization that is specific and sustainable for all business requirements. Be instrumental in implementing and maintaining IT security and compliance controls and constraints to advance digital footprint for both traditional and cloud-based service infrastructure environments. Ensure implementation, maintenance, and assurance efforts for sustaining information security industry standards and practices.

Related Experience Vonage Essentials / Vonage Business Solutions / Vonage Holdings 3200 Windy Hill Road, Suite 200 East, Atlanta GA 30339 – Nov 2014 to Oct 2015

Role and responsibilities:

Senior Information Technology Security and Compliance Manager - developed long-term strategic security solutions and the establishment governance, compliance and operations for IT security strategy throughout the organization to implement and support operational requirements. Instrumental in implementing and maintaining IT security and compliance controls and constraints to advance digital footprint for both traditional and cloud-based service infrastructure environments with a focus upon open source solutions and the Amazon IaaS, PaaS and SaaS cloud-base service offerings. Ensure implementation and maintenance efforts for becoming and sustaining information security so as to achieve ISO/IEC 27001, SOX, SSAE16, SOC2-3, CALEA, and PCI-DSS certifications. Ensure compliance for PII, HIPAA, HITECH, Omnibus, and other privacy related regulatory requirements.

Critical objectives and tasks include:

Identify architect, implement, manage and support IT governance, assurance, compliance, operations, forensics, audit, change management and the SDLC application development efforts and process for information and information system security throughout the Vonage Business Solutions (VBS) infrastructure architecture. Establish a security and compliance framework for a telecommunication SMB corporate entity. Vendor and project manager for security and compliance contractual agreements. Select controls for both physical and cloud environments, assessment work, contract review, and exploit testing for development and vulnerability management. In addition, developed and documented a security framework with a plan to implement all required controls to enhance security. Worked with deployment, architecture, and production teams throughout the SDLC to production to ensure applications and cloud-based solutions and practices meet industry standards and provide effective security to manage and mitigate risk. Conducted static and dynamic applications vulnerability testing/security awareness for developers and supported public facing web presence. Have conducted assurance penetration testing with various commercial and open source tools e.g., BASH and python scripting, Veracode, Fortify, Checkmarx, Nexpose, Metasploit, WebInspect, AppScan, aircrack, nmap, wireshark, and Kali Linux suite of tools. Coordinate with legal, at as security and compliance liaison with senior leadership and other internal entities to ensure the VBS Security and Compliance Office (SCO) supports corporate risk and compliance interdependencies.

Page 2: Erwin (Chris) Carrow resume Brief 10-23-2015

Erwin (Chris) Louis Carrow page 2

Recall Corporation Global, 180 Technology Parkway N.W., Norcross Ga. 30092 - Sept 2013 to Nov 2014.

Role and responsibilities:

Senior Information Technology Security Manager - established the governance, compliance and operations for IT security strategy and operations throughout the Recall global organization. Instrumental in implementing IT security controls and constraints to assist Recall in advancing their digital footprint for both traditional and cloud-based service infrastructure environments. Implement and maintain efforts for becoming the first SMB information management company to achieve global ISO/IEC 27001, SOC2, and PCI-DSS certifications. Ensures regionally compliance for PII, HIPAA and other privacy related regulatory requirements. Manages and supports IT governance, assurance, compliance, operations, forensics and audit efforts for information and information system security throughout the Recall global infrastructure architecture.

Critical objectives and tasks include: Creates and achieves operational, tactical, and strategic objectives that improve the corporate global IT security posture, minimize and mitigate risk, and support key business goals and objectives. Supports large complex projects and other initiatives to ensure technical relevancy and secure posture to service and support governance, operations, compliance and forensic requirements. Ensures business services technology and functionality enforces security policy compliance across all digital service lines. Presents complex compliance and security concepts and solutions, across all functional units, management, executives, and other constituents’ security related business requirements. Ensures timely delivery of security services with demonstrable accountability to business units for all security related troubleshooting, incident response, and problem resolution in accordance with agreed upon Service Levels covering Recall’s standard hardware, software platforms and approved application portfolio, outsourced SOC services.

Skill sets include:

Subject matter expertise includes a variety of security technologies in support of Windows/Linux OS, switching, routing, firewall, IDS/IPS, NAC, SIEM, event logging, SFTP, packet inspection (signature and anomaly based), proxies, SSO solutions (SAML), token authentication and session encryption, multi-factor authentication technologies, web application security, database application security, identity and access management controls, monitoring and measuring of events, vulnerability life-cycle management tools (Rapid7, Nessus, and various Open Source toolsets); in order to facilitate various infrastructure architecture security requirements for risk mitigation and regulatory compliance. These skill sets also include: DMZs design and architecture constructs, data encryption (at rest and in transmission), Data Loss Prevention, Mobile Device Management, integrity and change management monitoring and administration, RSA solutions, deployment of MPLS, IPSec, remote access technologies (VPNs, Site to Site VPN tunnels, SSL/VPN), DNS (DNSSEC, TSIG) and PKI Certificate of Authority services.

Strategic goals and outcomes include: Manage a team of highly skilled security engineers and administrators. Administrate and exchange with resources responsible for developing and maintaining customer-centric service and support focus that provides a global high-performing operations to consistently secure information and information system. Construct, plan, prioritize, and execute various project designs, diagrams, documentation, budgeting, and resolution requirements. Maintain relevancy regarding current security threat vectors, malware techniques and actively support appropriate countermeasures, configurations and constituency awareness. Construct and communicate IT security policy to support governance, compliance, and forensic requirements and initiatives. Support the maintenance and deployment of new security solutions in multiple data centers. Drive consistent IT security service management processes in each region globally. Analyse trends and recommend changes to current practices to achieve greater cost efficiency or improved customer satisfaction. Measure assigned objectives, standards, expectations, and outcomes against key performance indicators, so as to ensure constituent satisfaction globally per region. Own issue resolution / incident response throughout life-cycle of events. Monitor and measure for security event, unresolved issues and requests, and ensure prompt effective resolution and constituent support. Manage IT security capital expenditures. Create and monitor security service catalog and operations support levels and metrics. Ensure Recall Information Technology Security Office (RITSO) governance, management, and roles and responsibilities align with other IT operational entities and assist in optimizing resource allocation globally.

Page 3: Erwin (Chris) Carrow resume Brief 10-23-2015

Erwin (Chris) Louis Carrow page 3

Albany State University, University System of Georgia 504 College Drive, Albany Ga. 31705 - Mar 2012 to Sept 2013.

Role and responsibilities:

Vice President of Information Technology Services and Chief Information Officer - directed and drove deliberate information and information system objectives to align, sustain, improve, and innovate information solutions, tools, communications and support for higher education institutional objectives. Strategic context and mission is to lead, manage and administrate staff at various levels of responsibility (personnel population: 4200+ students, 600+ faculty and staff, and 30+ direct report personnel), demonstrate skills in strategic planning, enterprise risk management (ERM), fiscal management, communications, inventory, planning and logistics, physical and informational security management.

Critical objectives and tasks include: Advise and assist the president and other senior executives on IT acquisition and management; develop, maintain, and facilitate implementation of a sound, secure, and integrated IT architecture in support of academic and business requirements; promote effective and efficient design and operation of all major information resource management (IRM) processes for the institution, including improvements to academic and business work processes; assess requirements for personnel regarding knowledge and skills needed to achieve established performance goals; develop throughout the institution strategies and plans for personnel reorganization, hiring, and training in support of an effective and efficient IT governance; and represent the institution’s information technology innovations and integration interest when engaging with the industry, the local community, and other state and municipal agencies.

Strategic goals and outcomes include: Establish a “balanced score card” approach for critical resources and infrastructure to secure and safeguard the institution’s information and information systems to provide consistent and predictable application and communication services (this would include development of metrics, collect data, and analyze it relative to financial, internal academic/business process, constituency needs, and value benefit versus the needed resource optimization and risk mitigation). Implement and sustain a cost effective and relevant IT Cloud environment to support the institution and local communities’ extended service capability, economic growth and pedagogical mobility, flexibility and significance. Develop and implement strategic planning and management systems to support all academic and business information business intelligence requirements and map results to USG and institution’s strategic objectives.

University System of Georgia, Board of Regents 270 Washington St. SW, Atlanta Ga. 30334 - Nov 2009 to Mar 2012.

Role and responsibilities:

Director of Information Technology Auditing - performed the IT Audit function and to purposely provide assurance or identify and assists in the mitigate information and information system risk throughout the University System of Georgia. Support creation of the quarterly audit risk assessment and plan for the Office of Internal Audit and Compliance (OIAC). Assessed risk and assurance for USG IT value chain management (VCM) exposures for enterprise resource planning (ERP), supply chain management (SCM), and customer relationship management (CRM) systems. Recommended modifications to audit strategies to enable alignment and achievement of USG enterprise risk management (ERM) objectives. Communicate IT risk and/or assurance issues to the Associate Vice Chancellor for Internal Audit for corrective action. Directly managed and mentored staff, assists in the prioritization and allocation of internal personnel, budgeted resources, and balanced skill competencies and capabilities to ensure successful completion of assurance engagements. Coordinates, communicates, and schedules audit/consulting engagements with institution presidents. Directs, manages, and executes onsite institution engagements and creation of assurance report for Board of Regents, chancellor, and institution presidents. Ensures state and federal compliance and regulatory requirements are identified and assessed for USG information and information systems. Develops audit engagement programs and grant funding proposals. Assist in the development of USG IT policy, standards, procedures, and best practices. Managed OIAC office website content to ensure communications were effective. Investigated IT related incidents to include information and information technology systems hacking and malicious attacks. Direct, train, and oversee periodic training of all USG auditors. USG functional and technical lead for Wolters Kluwer’s CCH Teammate ERP application suite. Advisor for CCH Teammate suite to other audit education and industry corporations and users. USG IT audit representative to interface to various groups, e.g., USG CIOs, Committee on Information Technology (CIT), IT Audit committee, Security Advisory Group, and Risk Management Committee. Act as liaison and advisor regarding information and information technology systems issues, assurance, and best practices for controls to support internal and external agencies e.g., USG Vice Chancellor for Information

Page 4: Erwin (Chris) Carrow resume Brief 10-23-2015

Erwin (Chris) Louis Carrow page 4

Technology Support /Chief Information Officer, USG Chief Data Officer, USG Chief Information Security officer other USG senior leaders (vice-chancellors, presidents, vice-presidents, etc.), State IT Audit Director, Georgia Bureau of Investigations, State of Georgia Chief Information Security Officer, and other law enforcement agencies.

Google – Southern Polytechnic State University Mid-town Atlanta, Ga. – Nov 2010 to Dec 2012

Role and responsibilities:

Contracted instructor for Southern Polytechnic State University providing training to Google corporate employees. Advances Google system administrators’ & technicians’ knowledge and ability to conduct technical duties utilizing the Linux operating system, research associated challenges and present observations in a professional, clear and concise manner to both technical and non-technical audiences. Upon completion, students are able to successfully install, configure, and/or maintain Linux systems, and basic virtual machine instances. Perform basic system administration of the Linux operating systems and effectively communicate with other system administers and / or developers regarding the operational functionality and status of any Linux based operating system. Training encompasses industry standard Red Hat Certified System Administrator (RHCSA) and Red Hat Certified Engineer (RHCE) certification objectives. Training conducted from the Google Mid-Town Atlanta facility to 30-40 internationally dispersed cliental /students via video conferencing.

University System of Georgia, Board of Regents, 270 Washington St. SW, Atlanta Ga. 30334 - Mar 2007 to Nov 2009.

Role and responsibilities:

IT Auditor II, independently performed information system audit programs, project management, and lead audits of colleges and universities for the University Systems of Georgia. Assesses risk management; ensures Federal, State, Board of Regents and local compliance of policies, procedures, operational guidelines, and strategic initiatives. Evaluates USG and third party information system controls; and provide management with documented recommendations for improving and securing of IT related operations.

Competencies and capabilities: Performance of duties include: briefing university and college Presidents, Vice Presidents, CFOs, CBOs,

CIOs and CISOs on security audit risk and compliance issues. Research and investigate key security and compliance issues or problems. Mentor financial auditors on information systems audit fundamentals. Design, implement, and support departmental audit applications. Mentor and train entry-level information systems auditors, and interface with Board of Regents officers and staff to complete special projects and initiatives.

Audited database environments: Oracle 9.X-11X; Microsoft SQL, MySQL, Access 2003-7; which included Banner, PeopleSoft, BlackBaud Raizer’s Edge, and various other transactional database management systems and middleware platforms.

Certifications include: MCP+I, MCSE, CQS, CCNA, CCAI, CCNP, CCSP, INFOSEC, CISSP, LCP, LCI, ORACLE Master for DBA, and Lean Six Sigma Greenbelt. Current certification objectives are CISM.

Achievements: Audit –In-Charge for: USG Enterprise-wide Enterprise Resource Planning (ERP) audits (e.g., USG123 Data Marts, PeachNet); system office audits, research institution audits; and various other 4- year and 2-year university and college audits. Designed, coordinated, and implemented Wolters Kluwer’s CCH TeamMate ERP audit application suite to support 59 USG auditors and 35 university system campuses with audit life cycle process tools for consistency and continuity of audit work papers and reporting.

Chattahoochee Technical College 980 South Cobb Drive Marietta, Ga. 30060 - Jan 99 to Mar 07.

Role and responsibilities:

Instructor and Senior System Administrator / Engineer for computer communications networking security, database administration and network engineering. Primary task consisted of network management, data administration, and instruction to train students in industry standards for networking, security, and database administration.

Competencies and capabilities: Networking environments particulars: technologies Ethernet, Token Ring, Wireless, Analogue and Digital

Telephony and Broadband; all current OS technologies (Windows, Novell, Linux / UNIX) and associated services (DNS, SMTP, POP, DHCP, File and Print sharing, X500 directory services); CISCO routing [RIP, EIGRP, ISIS, OSPF

Page 5: Erwin (Chris) Carrow resume Brief 10-23-2015

Erwin (Chris) Louis Carrow page 5

(NSSA, Totally NSSA, Stub and Totally Stubby, Virtual links), BGP (internal and external – primarily single honed environment)], QOS, HRSP, Redistribution, Policies, Load Balancing, Multicasting ( PIM SM and DM, IGMP 1-2v), NAT, PAT, SNMP 1-3v, and IP version 6, switching [VTP, STP - IEEE (802.1Q, LACP, RSTP, MST) CISCO (ISL, PAgP, PVST+), CGMP, IGMP, QOS, and 802.11 a-g and 802.1x application integration], remote access [Frame Relay, HDLC, PPP (encapsulation, compression MLP fragmentation and interleaving), modem, Basic and Primary ISDN, various connection types (Point-to-point, Point-to-multipoint, NBMA), Traffic Shaping - QOS ]; CISCOWorks; security [Firewall appliances; ASA5500 series, IOS, PIX / Proxy /OS - software based (Windows/Linux) and various commercial applications Firewall and Intrusion Detection Systems” VPN, IPS/IDS]; and Voice over IP and analogue technologies integration, Video multicasting and Wireless.

Database environments: Oracle 8.X-10X; Microsoft SQL, MySQL, Access 97-XP, and 2003. Designed, implemented, and administered various database management systems to support a multi-tiered instructional environment.

Administration for: designing, purchasing, performance monitoring, fault tolerance strategies, troubleshooting, and disaster recovery of all classroom network assets and applications.

Languages include: Linux BASH, PERL, Python, Ruby scripting; various web / XML design/integration products; .Net -Visual Basic; C, SQL-PLSQL and various scripting applications.

Achievements: Novell Beta tester for various products, orchestrating and administering the Oracle Academic Initiative Academy providing the Atlanta corporate industry with many qualified and certified DBA’s and data administrators, SAIR/GNU LINUX Academy, submission and coaching of “Cyber Defense” team for Regional Competitions, Program Manager, Administrator and Certified Instructor for CISCO Regional Academy offerings for the CCNP, CCNA, CCSP, Wireless, VoIP curriculum. Introduced and managed the CISCO Academy locally and grew the schools resources to perform as a “Regional Academy” for Northwestern Georgia. Chattahoochee Technical College through my efforts CTC became responsible for training all instructors for the area supported “Local Academies.”

US Army (Active) and Air Force (Reserve) military duty;

FT Jackson, SC. – Robins ARB, Warner Robins, GA. Aug 87 to Mar 2016. Role and responsibilities:

Lead, manage and administration of staff at various levels of responsibility (30-200 personnel), demonstrated skills of fiscal management, communication, inventory, planning and logistics, physical and informational security management, counseled senior leadership (Field Grade and General Officer) and strategic deployment and support of military personnel and assets. Stationed in Germany (2 tours), South Carolina, and Georgia.

Competencies and capabilities: Positions of responsibility: Non-Commissioned and Commissioned Officer; Platoon Leader, Maintenance

Officer, Headquarters Executive Officer, Division Protocol Officer, Company Commander, Senior Protestant Chaplain, Wing Chaplain, along with various extra duties to include “physical” and “information” security management.

Credentials include: certified Crisis Intervention Stress Management (CISM) counselor, completed active duty Army 1992 in the grade of Captain / O-3; current active reserve commission station at the 78h Air Base Wing at Robins Air Force Base in the grade of Lt. Col. / O-5; active US Military “Secret” security clearance.

Achievements: Administrated and managed resources in excess of 18 million dollars. Planned and executed various live firing ranges and field exercises. Forecast and maintained a budget in excess of 1 million dollars. Coordinated training requirements at the platoon and company level for Battalion and Division support. Supported Division Command staff with managerial administration and technical support. Planned, organized, and led various public events. Organized and supported implementation of 8th Infantry Division event in excess of 1500 in attendance to include foreign and domestic dignitaries. Instituted and implemented an annual base-wide “Black Heritage Worship Celebration” event and multiple “National Day of Prayer” with renowned local and national speakers e.g., the former Governor Roy Barnes. Both series of events included all branches of the military service. Regularly manage, administrate, counsel, preach, train, and advise – often speak publicly to motivate and encourage various groups of people ranging from 5 to 1000 in number. Have supervised personnel ranging from 3 to 200.

Page 6: Erwin (Chris) Carrow resume Brief 10-23-2015

Erwin (Chris) Louis Carrow page 6

Chattahoochee Technical College 980 South Cobb Drive Marietta, Ga. 30060 - Jun 97 to Jan 99.

Role and responsibilities:

Network Engineer, Adjunct Instructor, project management, and staff and faculty support - serviced, supported, administered, trained, and maintained all computer desktop, databases, and network server systems.

Competencies and capabilities: Networking environments include: Cabletron / Enterasys, CISCO, and 3COM technologies for routing and

switching, Ethernet and Token Ring a 1000 + systems DOS, Windows 3.1, 95, NT, UNIX, and Novell 4.11. Supported website content management system.

Database environments: Oracle 7-8.X; Microsoft SQL, Access 97, and Banner. Achievements: Support the network development and technologies for administration of Information Systems

located on 4 campuses. Supported various equipment and software associated with the implementation and operations of enterprise telecommunications systems. Multimedia distribution and display system for video conferencing equipment based on H.320 and H.323 and CISCO standards.

Education Kennesaw State University, Kennesaw, Ga. - Jan 06 to May 09.

Graduated, Master of Science in Information Systems with an emphasis in Information Security- GPA 4.0.

CISCO Training, Florida Community College, Jacksonville Fla.; Lanier Technical College, Ga. - May 99 to Sep 05.

Successfully completed various “instructor” courses in order to offer and instruct Cisco CCNA, CCNP, and CCSP certificate programs at Chattahoochee Technical College.

Oracle Training Centers, Atlanta – Perimeter, Ga. - Jan 99 to May 04. Undertook various course work in preparation for Oracle programming and database administration (Database Administration, SQL/PLSQL, Backup & Recovery, Network Administration, Performance Tuning, Data Modeling and Relational Database Design, Designer, Distributed Systems and Advanced Replication, etc., Instituted and maintain the Oracle Academic Initiative (OIA) Program at Chattahoochee Technical College. Obtained a Oracle Master status for Oracle 8I Database Administration.

Kennesaw State Technical Education, Kennesaw, Ga. - Nov 97 to Jan 99. Undertook various courses in preparation for the MCSE for Windows NT, and CNE for Novell 4.11 requirements.

Regent University School of Divinity, Virginia Beach, Va. - Sep 92 to Aug 95. Graduated, Master of Divinity in Practical Theology; minor in Pastoral Counseling / Biblical Languages - GPA 3.92.

United States Army and Air Force Courses and Schools - Aug 87 to Present. Course work completed in Georgia, South Carolina, and Germany. Basic Training; Officer Candidate School; Officer Basic Course; Airborne Paratrooper School; Infantry Mortar Platoon Course; Motor Officer Supervisor Course; Chaplain Orientation Course; Chaplain Intermediate Course; Wing Chaplain Course; Squadron Officer School, Air Command and Staff College, and various computer hardware and software application courses.

L'Abri Fellowship; Chalet Les Me'lezes, Huemoz, Switzerland - May 85 to July 85. Studied Philosophy and Biblical Scriptural Apologetics and traveled throughout Western Europe.

University of Missouri Kansas City Conservatory of Music, Kansas City, Mo. – Aug 78 to May 84.

Graduated, Bachelor in Music Composition - GPA 3.45. Composer various works ranging from voice and instrumental solos to ballet, large orchestral and choral pieces. Composer with basic computer synthesizer interchange – early analog and digital wave signs to MIDI.

Professional Societies, Publications, Honors, & Awards Professional Memberships include: ISACA - Information Systems Audit and Control Association, www.isaca.org; ISC(2) – International Information Systems Security Certification Consortium, www.isc2.org; and InfraGard - www.infragard.net, [email protected]

Page 7: Erwin (Chris) Carrow resume Brief 10-23-2015

Erwin (Chris) Louis Carrow page 7

Journal Publications authored & Speaking Engagements: Speaker for Dell SecureWorks annual Sale Conference March 2015; Recall Corporation White Paper - Information Security - Governance & Practice, February 2014; “Puppetnets and Botnets: Information Technology Vulnerability Exploits that Threaten Basic Internet Use” and “InfoSec Technology Management of User Space and Services Through Security Threat Gateways” for the ‘Information Security Curriculum Development Conference’07, September 28-29, 2007, Kennesaw, Georgia, Copyright 2007 ACM 978-1-59593-909-8/00/0007. EDUCAUSE SEC09 Conference – April 20-23, 2009, Presented and chaired panel discussion for “IT Auditing in Higher Education.” ACUA National Conference Speaker [San Antonio, Texas] September 2012. ACUA Regional Conference Speaker [USG Board of Regents – Atlanta Ga.] August 2010. SecureWorld Expo Conference Speaker “A Framework for Effective Information Security in the Business World” 2011. Guest speaker for Georgia Bureau of Investigations. Frequent guest speaker for various University System of Georgia institutions security conferences and forums.

Certifications held: Microsoft Certified Professional plus Internet (MCP+I), Microsoft Certified Systems Engineer (MCSE), Cisco Certified network Associate (CCNA), Cisco Certified Network Professional (CCNP), Cisco Certified Security Professional (CCSP), Cisco Certified Academic Instructor (CCAI) -for the CCNP, CCSP and CCNA, Federal Government designation for Information Security Professional (INFOSEC), Linux Certified Professional (LCP), Certified SAIR /GNU LINUX Instructor (LCI), Oracle Certified Master for 8i with an emphasis in Distributed Database Replication (OCM), Certified Information Systems Security Professional (CISSP), and Lean Six Sigma Green-belt.

Military Awards: Meritorious Service Medal (3X); Army Commendation Medal; Air Force Achievement Medal; National Defense Service Medal (2X); Overseas Service Ribbon (2X); Army Service Ribbon, and various other recognitions.

Other Awards and Recognitions: Recipient of the 1st University System of Georgia Board of Regents “Accelerated Leadership Academy” for grooming senior executives, 2013-2014. Recipient and graduate of the University System of Georgia Board of Regents “Executive Leadership Institute” 2010-2011. Crisis Intervention Stress Management Certified Counselor. Recipient of the American Bible Society Award for Biblical language scholarship for the graduating class of 1994-1995. Awarded the Fred W. Beazley Graduate Scholarship 1994-1995 for academic achievement, leadership, and community involvement. Have appeared on various local Michigan TV Talk Shows, "Ask the Pastor," "The Voice of Fundamentalism," "Shiloh Tabernacle," and "Profiles on Pastors." Dean's list from 1982 to 1984. Placed 3rd, 1st, and 2nd in the Sigma Alpha Iota music composition contests in 1981, 1983, and 1984. Received honorable mention in the National Education of Music Society in 1983. Appointed as a voting member of the Undergraduate Curriculum Committee in 1980 during undergraduate school. UMKC Dean’s list recipient from 1981-1984. Member of the Composers Guild from 1980 to 1983. Ordained and licensed minister with the Southern Baptist and recognized through Calvary Ministries International. Reserve Chaplain (LtCol.) in the US Air Force Reserve Robins AFB Warner Robins GA, endorsement through Chaplaincy of Full Gospel Churches.