Avatar of Wayne Nordstrom.
ProfileResume
Posts
0Connections
Print
Avatar of the user.

Wayne Nordstrom

Manager
Wayne Nordstrom is a highly skilled and experienced: Penetration Tester, Vulnerability Analyst and Cybersecurity Specialist with a wide range of technical expertise including but not limited to: Ethical hacking, secure software coding, penetration testing, vulnerability assessments, and Linux systems administration. Wayne Nordstrom is adept at using technical acumen and strong communication skills to effectively drive discussions with all levels of staff and senior leadership. He is able to provide advocacy and strategic technical guidance to plan, build, and execute value added solutions using best practices to proactively keep technical environments operationally healthy and secure. In 2015, Wayne Nordstrom began working with Sanofi Pharmaceuticals as an industrial control systems (ICS) security engineer, a position he held for over a year and a half. While there, he collaborated with project managers across several countries developing network infrastructure, and applications security solutions. He developed and implemented highly secure network and firewall security solutions in order to meet international GxP and FDA compliance requirements for companies manufacturing life sciences products. He regularly performed risk assessments while proposing and implementing appropriate mitigation strategies. Following this, Mr. Nordstrom served as one of CVS Health’s Senior Network and Applications Security Engineers, where he regularly identified and addressed security threats and vulnerabilities across the firm’s infrastructure and applications across 70,000 retail network pharmacies. He secured network infrastructures and developed mitigation strategies to address security vulnerabilities found. Since 2017, Wayne Nordstrom has been a student at Cape Cod Community College, where he has undertaken an in depth study of Security Penetration Testing, Ethical Hacking, and Networking. He is pursuing an Associate of Science degree specifically in Cybersecurity, focusing on Security Penetration Testing, he expects to graduate in May of 2020, Cum Laude. Additional coursework in Linux Systems Administration prepared him well for the CompTIA Linux+ certification exam which he has passed earning him the title of Certified Linux+ Systems Administrator. His most recent college cousework includes but is not limited to: Penetration Testing, Ethical Hacking, Reverse Engineering, Networking, Wireless Networking, Cybercrime, Microcomputer Hardware, Windows and IOS Operating Systems. Alongside the degree, which he expects to earn by May of 2020, he holds numerous CompTIA, Cisco, GIAC, and EC Council certifications across a wide range of technical topics in addition to being certified in various Microsoft enterprise applications. Wayne Nordstrom's areas of expertise include but are not limited to: Penetration Testing, Ethical Hacking, Vulnerability Assessments, and Secure High Availability Network Design and Engineering, and secure Wayne Nordstrom is able to identify and document gaps/risks using the following - Tools: Kali Linux, Metasploit, Nmap, Wireshark, Burp Suite, Nessus, Qualys, SolarWinds, Rapid-7, QRadar, SolarWinds
Blue Cross Blue Shield Masachusetts
Champlain College
Boston, MA 02110, USA

Professional Background

  • Current status
  • Profession
  • Fields
  • Work experience
  • Management
  • Highest level of education
    Bachelor

Job search preferences

  • Desired job type
  • Desired positions
  • Desired work locations
  • Freelance

Work Experience

IT Security Vulnerability Manager

May 2020 - Present
• Manage and penetration testing engagements internally and externally. Execute daily ad-hoc and scheduled vulnerability assessments • Manage escalated threat cases throughout their entire lifecycle. This lifecycle includes information gathering, initial threat assessment, consultation with stakeholders, incorporation of mitigation strategies, continued monitoring and regular reviews of persons of concern • Utilize Rsam/Galvanize GRC integrated with Qualys API to track and assign vulnerabilities for remediation • Validate security configuration baselines and operational standards for security systems and applications including policy assessment, compliance tools, network security appliances and host-based security systems • Establish and deliver meaningful, actionable security metrics for remediation, compliance, and reporting

Principal Penetration Tester

Jan 2018 - May 2020
2 yrs 5 mos
• Executed web applications and infrastructure security penetration testing using tools such as Kali Linux, Metasploit, Burp suite, Core Impact, Cobalt Strike, Nessus, Web Inspect, and many more • Communicated clearly with clients to understand requirements related to penetration testing, vulnerability assessments, and cybersecurity, developed and agreed upon statement of work and rules of engagement • Performed a range of security assessments on infrastructure, including segmented networks, network devices, operating Systems (Windows and Linux), AD (malicious insider), Web/app servers and databases • Communicated clearly with stakeholders, to ensure successful security testing and closed loop remediation • Provided documentation of penetration tests to internal stakeholders to advance security of product lines

Cyber Threat Intelligence Analyst

Jan 2016 - May 2018
2 yrs 5 mos
• Lead the security assessment, vulnerability management and continuous monitoring programs tasked with identifying risks in the environment and managing mitigation initiatives • Leveraged internal and external resources to research threats, vulnerabilities and intelligence on various attackers and attack tools, techniques, and processes. Utilized Splunk, Threat Connect, Qualys, Crowd Strike, Carbon Black, Cylance, and SolarWinds • Supervised and lead the design and implementation of security solutions and detection logic, ensuring adequate support for threat prevention & detection, vulnerability management, incident response, and forensics activities • Created and automated a data analytics program reporting on vulnerabilities requiring remediation

Industrial Control Systems Security Engineer IV

Jan 2015 - Jul 2016
1 yr 7 mos
• Designed and integrated HA-AAA networks and VLANs for use with: NGFWs, SCADA, ICS, PLC, DCS, OT and IT systems for deployment within bio-pharmaceutical manufacturing environments • Enhanced the design of the wireless security architecture producing optimal performance and fewer security issues • Performed network security assessments, keeping network security viable with needed upgrades • Configured and managed: NGFWs, IDS/IPS/NIDS/HIDS/DLP systems. Served as security subject matter expert for security tools and platforms, including vulnerability management, endpoint security, identity, and access security monitoring • Responded to complex cyber-attacks and network intrusion attempts that threatened intellectual property, assets, networks, and computer systems • Delivered daily support of the functioning of routers, switches and network protocols while coordinating technical implementation with partners and vendors. Conducted network health and capacity planning. • Spearheaded team accountability ensuring smooth network operation and upgrades, ensuring high levels of reliability and maximum performance

Education

Bachelor of Science (BS)
Cyber Security
2018 - 2021
Activities and societies
ISACA
Associate’s Degree
Cyber Security - Penetration Testing
2018 - 2020
Activities and societies
ISACA