James Pardonek
Details
Computer/Information Technology Administration and Management
Purdue University
2011 : 2013
Bachelor of Science (B.S.)
School of Technology
Purdue University
2006 : 2011
Loyola University Chicago
Associate Director and Chief Information Security Officer
Responsible for the oversight and ongoing management of the information security program, including policies, procedures, technical systems, training and project execution. Maintain the confidentiality, integrity, and availability of data within all information systems. Address electronic systems architecture and functionality as it affects the safeguards of all business information and regulated information assets while remaining in adherence to applicable regulations and law regarding such assets. Work closely with clients to fully understand their requirements, communicate information security needs and to identify solutions that meet both users' needs and information security compliance. Develop and implement plans to ensure institutional compliance with applicable laws, regulations and requirements, such as : FERPA, GLBA, HIPAA, PCI-DSS, DMCA, and IPIPA. Develop and promulgate effective and efficient institutional and divisional Information Security policies, procedures, standards and guidelines based on knowledge of best practices, compliance requirements and business objectives. Establish relevant security metrics. Coordinate response to any information security incidents. Keep abreast of information security threats and vulnerabilities, best practices and technologies. Facilitate the process for working with end users and various resources to ensure security expectations and controls can be met. Influence and persuade individuals and/or groups to identify common ground solutions. Identify, assess and work with the appropriate teams to mitigate known information security risks.
Regularly communicate in writing and in-person to end users about the state of information security, security expectations and on-going information risk status. Lead University-wide information security committee. Demonstrate a commitment to the mission and strategy by supporting the core values of service excellence for strategic initiatives and continuous improvement.
2012 :
Loyola University Chicago
Information Security Officer
Serve as expert advisor to PUC senior management in the development, implementation, and maintenance of an information security infrastructure. Identify key security program elements and determine which departments or offices must be involved in building a comprehensive information security program. Provide guidance and advocacy regarding prioritization of infrastructure investments that impact Security. Act as primary control point during significant information security incidents. Develop publish and maintain comprehensive university wide information privacy and security strategy, plans policies, procedures, and guidelines. Act as ombudsman for disputes, requests for exceptions, and complaints regarding university-wide information systems security policy, practices, and related issues. Advise the university administration on risk issues that are related to information security and recommend actions in support of the university’s wider risk management programs. Manage the development, implementation, and maintenance of information security policy, standards, and guidelines. Work with internal audit to ensure that departments consider information security risks in both ongoing and planned operations. Monitor information security trends internal and external to the university and keep university senior management informed about information security related issues and activities affecting the organization. Assist units as necessary to investigate security breaches and pursue associated disciplinary and legal matters. Direct the development and enforcement of information security and privacy policies in compliance with federal and state regulations and standards.
1992 : 2012
Purdue University Calumet
Assistant Director for Information Security and Assurance
Skills
CISSP, Computer Security, Disaster Recovery, Firewalls, Governance, Information Security, Information Security Management, Information Technology, IT Management, Linux, Microsoft Office, Network Administration, Network Security, Payment Card Industry Data Security Standard (PCI DSS), PCI DSS, Policy, Project Management, Security, System Administration, Troubleshooting, Vulnerability Management
About
Experienced Chief Information Security Officer with a demonstrated history of working in the higher education industry. Skilled in Payment Card Industry Data Security Standard (PCI DSS), Information Security, Linux, Troubleshooting, and Security. Strong information technology professional with a Master of Science (M.S.) focused in Computer/Information Technology Administration and Management from Purdue University.