Contact Me|About Me

About Me

If you are interested in learning a bit more about me, this page is for you. Here I list some autobiographical facts and outline a several of my projects and accomplishments. After all, activity suggests a life filled with purpose.

Professional Background

My professional expertise spans business and technological functions in the areas of IT, information security, and risk management. In the recent years I contributed to security assurance efforts at several organizations in financial services and other compliance-focused industries.

I presently lead the New York security consulting team at SAVVIS, a premier provider of IT infrastructure and hosting services. I am also a member of the Board of Directors at SANS Technology Institute and a senior faculty member at SANS. I teach a number of courses at SANS, including the one that I authored on the topic of analyzing malicious software.

Academic Background

I hold a Master in Business Administration (MBA) degree from MIT Sloan and a Bachelor of Science in Engineering degree from the University of Pennsylvania. At MIT, I was one of the presidents of the MIT Innovation Club, which I helped get off the ground. Back at Penn, I was an active member of the Philomathean Society, the oldest continuously-existing literary society in the US. I also competed as part of the University's Ballroom Dance Team.

Publications

One of my most challenging and rewarding experiences was producing and co-authoring the book Inside Network Perimeter Security. Another exciting writing project in which I recently participated was contributing a few chapters to the book Malware: Fighting Malicious Code. I also contributed articles to publications such as the Information Security magazine, and presented to IT executives at conferences and private summits. I also authored a number of research papers, many of which are available throughout this website.

Professional Certifications

In addition to holding the CISSP certification, I am one of the few individuals in the world who have earned the GIAC Security Expert (GSE) designation. Earning GSE was a particularly challenging process, because it required obtaining several other subject-specific certifications as well as passing a 28-hour hands-on and written exam. In general, I find certifications useful motivators for keeping my skills current, as long as the cert's focus is in line with the real-world experience that I'm getting at the time.

Other Activities

I am an incident handler at SANS Internet Storm Center (ISC). ISC processes data from around the world, and acts as an early warning system for Internet-wide security problems. One of the handlers is on duty every day, analyzing data collected from automated sensors and messages that we receive from system administrators and computer users. At the end of each day, the handler-on-duty publishes a diary of that day's events, to let our readers know about recent security trends and occurrences. (See an article about ISC here.)

People I Know Who Have Websites

You are who you know, right? Or is it "you are what you eat"? In any case, here are links to several people's sites, which I'd like to offer for your consideration: