
Security Consultant, CISA, CISSP, ITIL
Madrid Area, Spain

Security Consultant, CISA, CISSP, ITIL
Madrid Area, Spain
Expertise on:
- Risk management:
· Managing compliance requirements -MiFID, LOPD, Basel, PCI-DSS-
· Risk analsys methodologies (Cobit 4.1, CRAMM, Octave, NIST 800-30)
· Enterprise risk management & communication transparency
- Information Security Management Systems elaboration:
· Based on ISO 27001(ISMS)
· Gap analysis & Road Map
- Business continuity, crisis and emergency plans deployment
· Based on BS 25999 (BCMS)
· Business Impact Analisys & business processes identification
· Business recovery strategies and approaches definition
- Enterprise IT strategic alignment:
· Linkage of business and IT plans
· Integrated balanced scorecard and KPI definition
· Enterprise architecture, rationalizing processes, organisation and IT
· Manage the IT value proposition;
· Business Process Analysis and Reengineering
- Business development, security services portfolio and customer management, presales, marketing experience
- Privacy related consulting
- Identity and Access Management solutions definition and deployment
· Digital evidence solutions
· Centralized User Management
· Federate identity (OASIS, Liberty Alliance standards)
· Identity provisioning workflow process design
· Versatile authentication systems (OATH, ESSO, PKI, biometrics, OTP)
- Hardware security designs
Information security lifecycle management. Risk managament. Secure systems design and integration. MiFID. Security law enforcement and regulation. PKI, Cryptography, IETF PKIX, CISSP, CISA, ITIL, digital signatures, training, planning, business development, business continuity, crisis management, business impact analysis
(Privately Held; Telecommunications industry)
May 2009 — Present (8 months)
Working in the Marketing and Business Development Area at Telefonica Empresas (TE) Security Division.
Main activities:
- Presales and portfolio management.
- Business Continuity Plans, contingency planning and crisis management.
- Information Security Management Systems (ISO 27001 based) deployments and certification.
- Security and compliance audits
(Legal Services industry)
March 2009 — Present (10 months)
Ecija Consulting is one of Spain’s leading business law firms (counting on the experience of over 230 professionals), with a pragmatic approach to its two main business lines: professional consultancy services in information security and Compliance solutions for businesses.
Conferences & interviews:
- https://www.ismsforum.es/img/a13/des73_CURSO_ANALISIS_RIESGOS_3.pdf
- http://www.diariojuridico.com/opinion/cisnes-negros-analisis-de-riesgos-en-tiempos-de-crisis.html
- http://www.conferenciasyformacion.com/conferencias/descargar_pdf/321
(Privately Held; Computer & Network Security industry)
April 2007 — March 2009 (2 years )
WISeKey is a leading information security and identity management company, and provides specialized security technologies for data protection, and effective identification and authentication of people and objects.Chosen as "100 New Champions" member by the World Economic Forum (WEF, 2007).
Conferences & Interviews:
- Infosecurity Caracas 2007 http://www.infosecurityonline.org/newsletter/diciembre2007/entrevista.htm
- Mundo Internet 2008 http://www.mundointernet.es/index.php?body=pon_article_ponencia&id_article=190&lang=es
-http://www.idg.es/computerworld/articulo.asp?id=192840
- Seminario de inducción TechBA v3
(Privately Held; 501-1000 employees; Defense & Space industry)
May 2006 — April 2007 (1 year )
- Project Manager "Seguridad 2020" (Spanish Government R+D project under PROFIT frame) www.seguridad2020.es
- Project and Security Manager in the EGNOS Data Server Project for the European Space Agency. www.egnos-edas.com
- Security Consultant for the ITEA R+D+i project "€-Confidential" (under FP6 contract) www.itea-econfidential.org
- Secure infrastructures engineer. Projects: C.S.I.C., Telecinco.
- Digital Identity sales consultant
- Safelayer Technical manager
(Privately Held; Banking industry)
2005 — 2006 (1 year )
- PKI integrations and viability deployment researchs (OpenCA, Windows 2003 CA, EJBCA, XCA)
- Security Manager in a Financial Fraud Detection system.
- Training courses elaboration: Cryptography; Plubic Key Infrastructures; Public Key Infrastructures Advanced Deployment and applications.
- Technical support on EMV migration
Computer Science Engineer (1 year) , Focused on IT security (cryptography, Data and Network security, Secure Infrastructures) , 2004 — 2005
ERASMUS
Computer Science Engineer , cryptography, network security, expert systems, Knowledge engineering , 2000 — 2005
- Certified Information Systems Security Professional, CISSP (ISC2) # 321898
- Certified Information Systems Auditor, CISA (ISACA)
- IT Service Management Foundation (ITIL). EXIN.
- Member of AENOR-ISO CTN7/SC7/GT-25 & GT-6 group, working on IT-Governance (ISO 38500) & process management standards (ISO 20.000).
- Founder Member "Comisión para el estudio y el desarrollo del Buen Gobierno Corporativo de las TIC, dentro de las organizaciones", ISACA Madrid-chapter.
- ITIL v2 and v3 Foundations course (60 h.). Sunion Gesfor.
- IT Governance advanced course (30 h). Sunion Gesfor.
- Security Principles and Models upper Course. ESNE. Madrid.
- Oracle 10g DataBase Administrator. Oracle University, Las Rozas. Madrid.
- Identity Management: Sun Identity Manager. Sun Microsystems. Madrid.
- Linux Advanced Development (Mono, C#, Java, .NET, LISP) .Universidad Autónoma de Madrid
- Teamwork and time management. Human.es. Madrid.
ISACA
EGNOS -E.D.A.S. (European Space Agency) :: www.egnos-edas.com
I.T.E.A. (Information Technology for European Advancement) :: www.itea-office.org
Free Software Promotion Association co-founder
Registered Linux User #295238