Jasmine Hicks
Details
2021 : Present
CONFIDENTIAL
Manager, Information Security
Engaged by financial institutions, medical offices, hospitals, retail businesses, and government contractors to conduct and simulate attacks on systems within clients’ scope of work. Perform vulnerability assessment and validation, exploitation, and post-exploitation to identify weaknesses. Analyze and report on test results and remediation steps. Create, build, and train cybersecurity programs within budget and client requests.
✔ Bolstered financial institution’s cybersecurity posture by executing physical & social engineering penetration test. Prepared in-depth report on system and network vulnerabilities, recommending updates to security policies that saved millions in potential damages.
✔ Detected vulnerabilities in system and private data access before breaches to mitigate regulatory violations for higher education institution by analyzing their existing data privacy safeguards.
✔ Assessed cybersecurity posture and created new program for nonprofit medical clinic with 7 offices. Designed strategy to ensure data security with key policies for encryption, network / system administration, and password management. Rolled out new-hire and annual security awareness training.
✔ Evaluated retail business’s cybersecurity posture, discovering and reporting on significant vulnerabilities across their internet-facing systems.
✔ Saved client $3.5M through through advising them on integration of security throughout IT infrastructure, highlighting several regulatory violations, and providing insights to update their cybersecurity policies.
2009 :
Freelance
Business Security Consultant & Penetration Tester
Entrusted to remotely oversee all technical operations, including cybersecurity and network management for this furniture and flower retailer with 14 locations across military bases in Japan. Install, configure, and maintain computers and networks at 14 stores. Identify and resolve technical and customer service-related issues. Lead team of 7 and facilitate training on systems. Maintained PCI-DSS Level 2 compliance for 12+ years.
✔ Established comprehensive cybersecurity oversight for company, introducing formal policies and access controls for critical payment and order processing systems.
✔ Researched, purchased, and implemented highly secure payment processing and online web order systems to ensure strict PCI-DSS compliance.
✔ Streamlined product offering to include options for digital and phone orders and services for all stores across Okinawa and Mainland Japan, increasing revenue 35%.
✔ Led project to create product and service database, boosting revenue 27% within first year of implementation.
✔ Streamlined delivery processes, cut overhead costs, and increased number of daily deliveries by 20% through designing interactive map outlining order information, location, and customer contact data.
2008 :
Ebenezer Imports
Technical Operations Manager
2011 : 2016
University of Nevada Las Vegas
Research Assistant
2013 : 2014
UNLV CSUN Student Government
CSUN Senate President
About
I am a decisive and analytical IT leader with 14+ years of versatile experience, including success in cybersecurity consulting, operations, and technical management. I am dedicated to embedding proactive security strategies and rigorous policies to safeguard critical systems and data.
I am cognizant of the latest security trends, regulations, and threats to ensure a robust cybersecurity posture. I have built, trained, and led high-performing, service-oriented teams. I leverage sharp organizational, communication, and problem-solving skills to deliver timely, high-quality security projects and programs.
Specialties:
★ Cybersecurity Governance
★ Program Management
★ Incident Response & Recovery
★ NIST
★ CIS Critical Security Controls
★ Information Security & Risk Management (ISRM)
★ Project Management
★ ISO
★ COBIT
★ OWASP
★ HIPAA
★ Forensics
★ ITIL
★ Change Management
★ Policies & Procedures
★ Strategic Planning
★ Security Monitoring
★ Malware Analysis
★ Leadership
Technical Skills: Windows Server and Workstation, Linux, Mac OSX, Aircrack-ng, Nmap, Nessus, Wireshark, Metasploit, Kali, Burp Suite, Microsoft Office Suite / O365, Adobe Creative Suite, C++, Java, HTML, XML, CSS, JavaScript, PHP, SQL, Python