IT and Security Executive with 18+ years of significant contributions in helping envision, articulate, deploy, and manage business process and technology solutions across global organizations.
Chief Information Officer @ From June 2013 to Present (2 years 7 months) Director Application Security @ Responsible for overall risk management of Microsoft IT’s Application Portfolio. Responsibilities include but are not limited to the overall Application Security Strategy and execution, direct management of ten full time employees and indirect management of an additional 16 employees, oversight for technical standards and policies associated with Application Security, all Application Security Assessment activities, and Application Security guidance and oversight across Microsoft IT.
Highlights:
• Responsible for driving operation excellence within the Assessment, Consulting and Engineering Team with the establishment of an operational scorecard, building a culture of accountability and establishing a vision for application security that the team has embraced.
• Established a new Application Security Framework and established a security controls framework for application development teams.
• Evolved Microsoft Get Secure Program to enable a predictable and scalable model to advise and assess newly developed Microsoft applications
• Established a three year growth plan for each Application Security Analyst
• Increased overall customer satisfaction 25% in first full year
• Increased Workgroup Health Index +12 points in first year
• Increased Security Coverage of the MSIT portfolio by 70%
• Decreased the average severity one bug count by 50% From May 2011 to June 2013 (2 years 2 months) Director, Business Architect – Application Platform @ Responsible for defining and shaping Microsoft’s Enterprise Application Platform business and supporting model and tools as one of the top four company investment areas and objectives. Responsibilities include Application Platform Sales Strategy Development, Enterprise Application Platform Scorecard, Application Platform Sales Model and Tools and Global Cross Group Collaboration to ensure integration into various Microsoft Business Groups.
Highlights:
• Sales support responsibility for $2.5+ Billion Application Platform Revenue across Microsoft Global Enterprise Organization.
• Pioneered a new end-to-end enterprise selling strategy and business “architecture” of the Application Platform sales motion across Microsoft stakeholders that encompass the 6 customer centric platform capabilities of Data Warehousing, Reporting & Analytics, Platform, Application Integration, Custom Applications, and Web
• Built and lead the Global Application Platform field community for all selling roles and field leadership. Drive talent management of the App Plat Sales Leads in the sales team; strengthen and develop talent through involvement in hiring, development and succession planning.
• Led and managed a team 11 senior individuals consisting of three business architects, three program managers, one development manager and four developers.
• Accountable for worldwide Application Platform pre sales program by establishing an end-to-end engagement process, expectation setting and communication plan for customers resulting in a 38x return on investment
• Budget accountability of $40+ Million From February 2008 to May 2011 (3 years 4 months) Strategic Security Advisor @ Responsible for strategic security relationships with CIOs and CISOs in Microsoft’s largest customers headquartered in Minneapolis, St. Louis, Kansas City, Memphis, Des Moines and Omaha. Additional responsibilities included providing input into Microsoft Worldwide Security Strategy to include overall security investment strategy and product considerations.
Highlights:
• Increased FY05 and FY06 Security Net Customer Satisfaction (NSAT) by +14 and +12 respectively against a goal of +5.
• Increased customer confidence in Microsoft’s Security initiatives and products by conducting and developing strong relationships with approximately 50 CIOs, CISOs, and Security teams across the Midwest.
• Provided Security Leadership as “Chief Security Officer” of the North Central District by conducting educational sessions for non-security personnel, mentoring and increasing overall influence outside of a direct report structure to scale security messaging and achieve buy in from district constituents. These activities resulted in 200% increase in security activities performed by Microsoft Account Teams.
• Managed a virtual team of 15 personnel across four district offices From July 2004 to February 2008 (3 years 8 months) Managing Consultant @ Responsible for the day-to-day operation of Shavlik's Professional Security Services Division including the management of 10 consultants.
Highlights:
Grew the Shavlik Professional Services Division to one million in revenue the first year through the onboarding and management of 10 senior security professionals and development of overall consulting business strategy.
Developed and delivered service offerings related to:
Security Risk and Compliance
Identity Management (e.g., user management, authorization, authentication) technical architecture and strategy, detail design, and implementation projects.
Security architecture and policy development projects in line with ISO 17799.
Security technology (e.g., firewalls, intrusion detection systems) projects.
Grew a senior security professional team from a headcount of one consultant to ten consultants in less than 15 months. From March 2003 to June 2004 (1 year 4 months) Senior Security Engineer/Division Manager @ Responsible for the management and operations of an 85 person Naval Division as well as providing consultative support to build and execute information security strategy for US government entities worldwide.
Highlights:
Coordinated and directed several worldwide National Security Agency risk assessment teams for the assessment of various government agencies information security architecture.
Provided comprehensive security solutions to government agencies, including policy development, architecture hardening, physical security and data security.
Led and managed a team of 85 government personnel across multiple global locations
Edited, wrote and applied guidance for secure implementation of Microsoft Windows Operating Systems and applications for government and public utilization.
Designed and developed custom vulnerability scanning tools and tools to automate security configuration application, increasing the security posture of government networks.
Developed a comprehensive risk assessment training program and supervised the training of new NSA Network Security Engineers.
Researched and analyzed the security of Microsoft Windows NT, 2000, 2003 and XP operating systems.
Presented National Security Agency Guide to Microsoft Windows 2000 Security Recommendations at several conferences and provided network security demonstrations.
Co-authored NSA's "Guide to Securing Windows XP Professional." From August 2000 to March 2003 (2 years 8 months) Information Systems Manager/Operations Manager @ Responsible for the overall Operations of a Headquarters Level Communications center to include operational responsibility for critical Department of Defense missions. Supervised and trained 25 personnel to perform daily network administration functions, operation and maintenance of telecommunications circuits, cryptographic equipment, cryptographic keys and the overall operation of the information systems. From August 1996 to August 2000 (4 years 1 month) Information Systems Manager @ From July 1994 to July 1996 (2 years 1 month) Information Systems Manager @ From July 1994 to July 1996 (2 years 1 month)
BS, Information Technology @ University of Phoenix From 2001 to 2004 Tom Parker is skilled in: CISSP, Information Security Management, Information Security, Security, Network Security, Integration, Vulnerability Assessment, Enterprise Software, Computer Security, Firewalls, Risk Management, Pre-sales, Application Security, Identity Management, Risk Assessment