Rosemarie Lee, CISSP
Details
Criminal Justice/Safety Studies
American InterContinental University
AAS, Associate of Applied Science in Information Systems Technology
Community College of the Air Force
BlueCross BlueShield of Tennessee
VP Chief Information Security Officer
In this role, I oversee IS Security functions for this Fortune 100 health system comprising 15 hospitals, 300+ medical offices, 30,000+ users, and 90,000+ connected devices. I execute responses to security incidents, including phishing, internal threats, malware infections and other cyber risks. I lead threat intelligence, vulnerability management program, digital forensics, eDiscovery, and 24/7 incident response. I also perform as in-absentia Chief Information Security Officer (CISO) as needed.
2018 : 2022
BayCare Health System
Director, IS Security & Threat Management
During my tenure here, I led vision, strategy, and execution of information security functions for this $20B provider of managed care health plans with 4.4M members. I focused on safeguarding confidential, critical information and systems from unauthorized access. I also administered $10M+ annual budget. Additionally, I worked with teams in US, India, and UK; served as in-absentia Director of IT as needed.
***Value Added***
✔Secured Health Information Trust Alliance Certification, the highest security standard in the healthcare industry; answered audit inquiries relating to security infrastructure.
✔Architected cross-training program that empowered IT Security team with competencies to provide full 24/7 coverage.
✔Defined KPI metrics governing compliance and vulnerability management for millions of events each day; attained #1 highest Associate Opinion Survey score for infrastructure for 2 consecutive years.
2015 : 2018
WellCare Health Plans
Senior IT Security Manager
Here I was retained to manage IS at this financial services company that provides clearing and settlement services to financial markets. I identified suspicious activity and behavior across 20,000 desktop and laptop computers.
2012 : 2015
DTCC
Senior Security Engineer
2009 : 2012
SAIC
Senior Network Security Engineer
Skills
Active Directory, Analytical Skills, Auditing, budget management, Cisco Systems Products, Cisco Technologies, Computer Security, customer relationship management (crm), Data Center, Data Privacy, Disaster Recovery, Enterprise Architecture, Firewalls, Incident Response, Information Security, Information Security Awareness, Information Security Management, Information Technology, Integration, Intrusion Detection, ISO 27001, IT Executive Management, IT Security Best Practices, it security management, IT Security Operations, IT Service Management, Leadership, Network Security, Payment Card Industry Data Security Standard (PCI DSS), Penetration Testing, project management, resource management, risk analysis, Risk Analytics, Security, Security Audits, Security Information and Event Management (SIEM), Security Management, strategic communications, Threat & Vulnerability Management, U.S. Federal Information Security Management Act (FISMA), vendor negotiation, vendor partnerships, Virtualization, VMware, Vulnerability, Vulnerability Assessment, Vulnerability Management, Troubleshooting, information security audits
About
I am an accomplished, forward-thinking Chief Information Security Officer with a 20+-year portfolio of success delivering 24/7 security operations, functions, solutions, initiatives, engineering, and people management. I am experienced working in healthcare, financial services, insurance, and military environments. I offer a history of accomplishment ensuring compliance with laws, regulations, and policies to minimize or eliminate risk and audit findings. I am well-versed in coordinating penetration tests, directing remediation efforts to close identified vulnerabilities, and engaging in root cause analysis to deliver optimal security against in internal & external threats. My areas of expertise include::
✔Information Security Management
✔Security Architecture
✔IT Infrastructure Monitoring
✔Critical Data Protection
✔Security Audits
✔Risk Assessments
✔Vulnerability Testing
✔Internal Security Controls
✔Threat Management
✔Business Continuity
✔KPI Metrics
✔Compliance
✔Project Management
✔Team Leadership
✔Hiring & Training
✔Performance Management
✔Mentoring & Coaching
✔Root Cause Analysis
✔Relationship Building
✔Issue Resolution