I am a seasoned IT Leader with extensive years of experience in Information Services and Technology in the areas of:
• Develop and implementation of IT Roadmaps
• Short and Long Term IT Strategies
• Information Security Management Programs for Corporate IT and Cloud Services
• SOX & FDA 21 CFR Part 11 Information Systems Audits
• FDA GMP, GLP; HIPAA Regulatory Compliance
• Sarbanes Oxley S404 Compliance
• Computer Validation Procedures (FDA 21CFR Part 11)
• ISO27001 and COBIT Standards
• SSAE 16, SOC 1, 2, 3 Attestation Reports Assessments
• ERP Systems, i.e.: SAP R3, BW Basis, Microsoft Great Plains/Dynamics
• LAN/WAN design and management
• Tele-Data Communications Management
• Active Directory
• Microsoft Exchange
• Data Center Management and Relocation
• Desktop Support Management
• Network Security/ Network Vulnerability/Penetration Tests
• Video Conferencing
• VMware Implementation
• Telephone & Voicemail Systems
• Systems Upgrades
• Call Center Management
• 24X7X365 Global & Local Operations Coverage
• Backups Automation, Data/Email Archiving Systems
• Help Desk Management
• E-Discovery, Search Compliance
• Systems Automation
• Business Applications
• Technical Procedures Documentation
• Change Management
• Disaster Recovery & Business Continuity Planning (BCP)
• Computer Programming
• System Performance & Capacity Planning
• Project Management
• E-Commerce
• NIST, COBIT, ISO 27001 Frameworks
Director of Information Technology @ From November 2015 to Present (1 month) Senior IT Director, Chief Information Security Officer (CISO) & Compliance Manager @ • Presided over Global IT support, Information Security and Compliance for Recommind, one of the top global eDiscovery leaders in the space
• Provided short and long term IT strategies in the areas of IT Infrastructure, Business Applications, Information Security Programs, and IT Support Services
• Managed the day to day IT Operations of a Global Organization including support for over 500 users in North America, Europe and Australia
• Ensured all Global IT Infrastructures, including datacenters, VMware clusters, servers, switches, firewalls, LAN, WAN, VPN, etc. performed seamlessly in the daily operations
• Created and implemented IT Policies and Procedures in the areas of Data Management, Change Management, Disaster Recovery, Business Continuity Planning, Emergency Notification Procedures, etc.
• Developed the Information Security Management System (ISMS – ISO 27001) Program for Corporate IT and Recommind’s Cloud Services, which included developing the charter for the Information Security Committee, writing Information Security Policies & Procedures in the areas of Data & Network Security, Logical & Physical Security, On-Off Boarding, Security Incident Management, Patch & Vulnerability, etc.
• Coordinated and scheduled third party info security audits including HIPAA, network scans, penetration tests and web application testing
• Performed Info Security assessments for new and existing cloud vendors
• Conducted Info Security audits and answered RFI/RFPs for new and existing Cloud/SaaS customers
• Designed the Information Security Awareness Program and ensured 100% company compliance through new employee orientations and annual trainings
• Aligned IT Security Policies and Procedures with ISO/IEC 27001, HIPAA, and PCI Standards
• Managed the IT CAPEX and OPEX budgets From July 2012 to September 2015 (3 years 3 months) Sr. Director, IT @ • Presided over the IT Department and provided IT Support and IT Governance for Medivation, one of the top oncology pharmaceutical companies in the world
• Built the IT Department from the ground up, including IT Infrastructure, Help Desk services, IT Policies & Procedures, and the Information Security Management Program
• Aligned IT Security Policies and Procedures with COBIT Standards
• Responsible for a complete strategic oversight for designing and implementing a technology infrastructure as business requirements change, including hardware, software, electronic security systems, vendor management, telephony, IT finance reconciliation/budget, technical support, wireless and wired networking for all offices and facilities company-wide
• Provided vision, leadership, and rapid deployment oversight to ensure the company's technology kept pace with evolving market and business demands
• Supported the organization with the on-going preparation, documentation, testing and monitoring of conformance to the requirements of Sarbanes-Oxley legislation and FDA 21 CFR Part 11 compliance
• Authored and maintained SOX IT computer controls documentation, such as IT Narratives, Risk Control Matrices, daily, monthly, quarterly and annual reports.
• Performed SOX IT computer controls audits twice a year resulting in a three consecutive years of successful results during my tenure at the organization
• Authored IT Policies and Standard Operating Procedures (SOPs) for Regulatory/Quality in the areas of Backup and Recovery, Disaster Recovery, Change Management, Network Security, Computer Validation, and Security
• Conducted annual IT/Quality audits resulting in two years of successful results during my tenure at the organization
• Managed the IT CAPEX and OPEX budgets
• Designed and coordinated the implementation of two network infrastructures for remote laboratories in India and Chile
• Created Disaster Recovery plans, procedures and emergency notification systems From October 2008 to May 2012 (3 years 8 months) Director, Information Technology & Information Security Officer @ • Presided over the IT Department and provided IT Support, Information Security and IT Governance programs for XDx, a leader in a non-invasion molecular diagnostics solutions for heart transplant patients.
• Managed the IT Department including IT infrastructure, data centers, networks, data-telecommunications systems
• Developed the Information Security Management Program for the IT Department and the Reference Lab
• Aligned IT Security Policies and Procedures with HIPAA and FDA regulations.
• Administered and supported company-wide financial systems
• Collaborated with the Software Development and Bioinformatics departments to provide technical support, monitoring and reporting for the Reference Lab, Customer Service, Clinical, Research and Development systems
• Provided Disaster Recovery and IT strategic planning
• Designed and built the IT infrastructure for the new office space in Brisbane, CA From October 2005 to October 2008 (3 years 1 month) Director, IT @ • Presided over the IT Department and provided IT Support and IT Governance programs for Kosan Biosciences, a cancer research organization
• Responsible for IS Strategic Planning and Budgets
• Responsible for all computerized systems including Accounting, Stock Options, Payroll, Project Management, Timesheets, Purchasing, Chemical & Biological System, Intellectual Property, Drug Safety, and Clinical Trials
• Managed and ran infrastructure systems such Help Desk, Active Directory, Network Security, E-mail, MS SQL, Citrix, Intranet, Backups, Cisco switching network, firewalls, Anti-Virus systems, Anti-Spam system, URL Blocking systems, Wireless E-mail solution
• Coordinated and built a VPN secured tunnel to Roche Pharmaceuticals
• Rebuilt most existing infrastructures including server rooms and servers
• Developed and implemented Disaster Recovery procedures, Sarbanes Oxley Computer Controls, IS Policies & Procedures and GLP Procedures
• Designed controls and tests which resulted in two successful years of Sarbanes Oxley annual IS audits during my tenure at the organization From October 2003 to August 2005 (1 year 11 months) Director, Global Information Services @ • Presided over the IT Department and provided Global IT Operations, including offices in Europe for SangStat Medical Corporation, a world leader in the anti-rejection drug manufacturer for organ transplant patients
• Responsible for IS Strategic Planning and Budgets
• Administered the ERP, Data Warehouse, and Life Science Systems
• Managed 4 SAP R3 systems, 2 SAP BW systems, MS Exchange 2000, Oracle Life Sciences servers, IIS Web servers, SQL Servers, Payroll systems, HRS, Stock Options systems
• Maintained network infrastructure including LAN, WAN (10 nodes), VPN, Firewall, Windows 2000 Active Directory, Norton Antivirus Corporate Edition, Trend Micro Scan Mail, E-manager (Anti-Spam), Websense (URL Blocking system), Enterprise Backups, Blackberry Server and Computer Systems Validation for FDA Requirements
• Designed and implemented Disaster Recovery Procedures
• Architected Global Network including U.S., Canada, and 6 European Cities
• Implemented Microsoft Windows 2000 Active Directory at a Global Level (North America and Europe)
• Upgraded Microsoft Exchange 5.5 to Exchange 2000
• Designed and implemented a backups automation solution
• Created IS Policies and Procedures
• Built Corporate Intranet from scratch From August 2000 to October 2003 (3 years 3 months) Director, Information Services @ • Presided over the Information Services Department for BabyCenter.com, a world leader in the parenting and pregnancy digital resource space, and on-line store
• Responsible for planning and building the Information Services infrastructure for a startup Internet company
• Managed Customer Services/Call Center Suite: Voice (ACD), Order Entry (MS Access-VB front-end, Oracle DB back-end), and e-mail (MS Exchange & Kana)
• Managed all aspects of telephony/voicemail including contracts
• Performed liaison duties with users and developers to design, test, perform quality assurance (QA) tasks, and troubleshoot of the e-Commerce or on-line store back-end system in the areas of Order Entry/Look-up, Inventory, Fulfillment, Finance, Sales, and Product/SKU Manager
• Worked with on-line Funds-Capture systems such as Cybercash and Paymentech.
• Designed and implemented Local/Wide Area Network.
• Designed and Implemented Help Desk services.
• Implemented NT Domain and MS Exchange environments.
• Implemented Desktops Standards.
• Designed and coordinated construction of the company’s server/infrastructure room
• Successfully coordinated all phases of the Y2K project
• Setup AS/400 and installed Mozart application (e-Commerce back-end system)
• Managed implementation of Shipping and Manifesting Systems (Evcor) for the Fulfillment/Distribution Centers
• Implemented installation of CRM Customer to Store e-mail system (KANA)
• Managed vendor contracts/relationships
• Managed Budgets for Information Services
• Documented procedures for users and systems configuration
• Analyzed business needs and recommend technical solutions From May 1999 to August 2000 (1 year 4 months) ICS Manager @ From 1998 to 1999 (1 year) Computer Operations Manager @ From 1992 to 1998 (6 years) Technical Account Manager @ From 1995 to 1996 (1 year)
Computer Science, Computer Programming @ Diablo Valley College From 1992 to 1994 Engineering, Industrial Engineering @ Universidad Jose Simeon Cañas From 1979 to 1980 High School, Physics & Math @ Externado de San Jose From 1974 to 1979 Gio Hernandez is skilled in: Technical Support, Enterprise Software, Integration, Biotechnology, Project Management, Information Security, Validation, Security, Information Technology, Start-ups, Business Intelligence, Document Management, Lifesciences, Pharmaceutical Industry, Sarbanes-Oxley Act