Thomas — Senior IT Project Manager
Thomas
Industries Served
Languages
Work History on Automate America
Secure & Personal Files
Verified documents on file. Only Thomas and Automate America admins can view or download them — except the background check, which is shared with a customer when they shortlist Thomas.
- Resume✓ On file
Programming Skills (6)
Developing and expanding the Ercot's Program and Project Management execution capabilities and managing significant risk in programs and projects in process. Managing an IAM Privileged Account management project under the direction of PMO and Governance. Following the PMP methodology and NIST, NERC and FSA guidance. Duties include reviewing policies and procedures, interviewing operations personnel and IT and collecting evidence. Deliverables include formal project planning and oversight, reporting to EPO management and the business unit management and project sponsors the status and compliance with industry standards, government rules and regulations and Ercot policies and procedures.
Specifically responsible for directing the implementation of CyberArk, a PIM (privileged identity management) solution implemented to control the passwords for the systems admin access for SunTrust Bank's Key Financial Applications Unix and Windows servers. The department managed all the user access for the Bank's applications for 25,000 employees and 10,000 contractors. Applications included CyberArk, Sailpoint, Centrify and Courion.
Database and Application
About Me
Project/Program and Audit, currently working in IAM and Privileged Access (CyberArk) and IT Audit.
Experience includes over 7 years of experience in IAM, analyzing data, implementing PAM solutions and auditing IAM systems. IAM experience includes analyzing and working with data from Active Directory, LDAP, and RACF / ZOS inclusive of request-based and policy-based Automated Account & Access Provisioning (RBAC & ABAC) and manually provisioned entitlement exceptions to On-Premise data stores Applications include CyberArk, Sailpoint IIQ, Courion, Forgerock and client developed applications. Scope included SIEM, API's, Data Integration, analytics, monitoring and reporting.
Professional Certifications/Licenses:- Certified Information Systems Auditor (CISA)
Project Management Professional (PMP):- Certified Inventory and Production Manager (CIPM)
Software Competencies (3)
Professional Competencies (11)
Applications (2)
Bank of Montreal, Toronto, Ontario, Canada – IAM Program & Techinical project manager leading a direct team of 3 engineers and a matrixed team of 12, installing and implementing CyberArk at the infrastructure and database level for non-personal priviledged access. Responsibility including directing the infrastructure build for 3 environments, installation of the CyberArk modules in the environments, integration of Remedy ticketing system and onboarding of the accounts, CyberArk applications infrastructure (Vaults, Safes, OU's Groups and Accounts), creating build and operating documentation, user guides and FAQ's under a accelerated timeline.
Applications include CyberArk, Sailpoint IIQ, Courion, Forgerock and client developed applications. Scope included SIEM, API's, Data Integration, analytics, monitoring and reporting.
Work Experience(10)
The Electric Reliability Council of Texas (ERCOT) manages the flow of electric power to 24 million Texas customers -- representing about 90 percent of the state's electric load. Developing and expanding the Ercot's Program and Project Management execution capabilities and managing significant risk in programs and projects in process. Managing an IAM Privileged Account management project under the direction of PMO and Governance. Following the PMP methodology and NIST, NERC and FSA guidance. Duties include reviewing policies and procedures, interviewing operations personnel and IT and collecting evidence. Deliverables include formal project planning and oversight, reporting to EPO management and the business unit management and project sponsors the status and compliance with industry standards, government rules and regulations and Ercot policies and procedures.
Program/Project Manager Identity and Access Management department under the Technology Risk and Compliance group for SunTrust Bank. Activities included working with the team developing the information technology strategy to build out the operationalization of the current GRC and Information security tools, policies and procedures to comply with current risks, regulations and future state goals. Specifically responsible for directing the implementation of CyberArk, a PIM (privileged identity management) solution implemented to control the passwords for the systems admin access for SunTrust Bank's Key Financial Applications Unix and Windows servers. The department managed all the user access for the Bank's applications for 25,000 employees and 10,000 contractors. Applications included CyberArk, Sailpoint, Centrify and Courion. Program/Project Director responsibilities included project oversight and leadership for Process ID access remediation, Data Base access remediation, Attestation (SailPoint), Generic and default ID remediation of System Admins at the server level. Additional director level oversight included project plan creation and management, daily status calls, vendor 2 and resource identification, timing, task assignment and review, forecasting and budgeting (Ecosys), status reporting, heatmap (scorecard) reporting including senior management reporting/presentation.
Internal Audit IT Director responsible for all aspects of IT testing for SOX compliance. Activities included GRC and IT Risk compliance with procedures and controls, interim and roll forward testing, all communications with the business units and KPMG, developing evidence PBC lists for each location, finalizing testing formats and workbooks, updating the KPMG workpaper site, developing and meeting deliverable timelines and due dates. Worked with the VP of Internal Audit after identifying deficiencies to develop remediation plans. Worked with the business units to address and implement process improvements related to remediation. Was responsible for all reporting and communication with client and KPMG on status and results
Internal Audit IT Director responsible for complete compliance and SOX attestation project. Projects included Entity level through remediation of business and IT processes and controls. Worked with the Board of Directors and senior management to define entity level control environment, enterprise risks and risk assessment, business and IT controls and control environment. Worked with external auditors in the SOX attestation. Helped develop and direct the policies and procedures requirements. Developed internal templates, testing procedures and plans. Worked with management and users to document, test and remediate deficiencies
Senior IT Project Manager and member of the PMO creation team focusing on SOX, ITGC, User Access Management and audit findings resolution. Responsible for template and audit checklist creation, audit planning and user assessment program rollout, action items identification and remediation planning and follow-up for SOX applications, OS and databases in scope. Member of the User Access Management resolution team resolving user ID and password issues including system and mech ID's in the application, database and operation system layers
Senior Project Manager engaged to help plan and launch the Internal Audit Department and inComm's initial SAS70 Type II audit of IT and operations (also setting the foundation for SOX certification) focusing on transaction processing and settlement for stored value and green card departments. Managed the IT portion of the internal audit activities directing several resources in addition to executing portions of the audit plan and testing. Worked with all levels of management and operations, remediating gaps and reengineering the processes to enhance efficiency while staying in compliance with key IT and operational controls
Senior Manager with IT audit responsibility for the internal and external RSM McGladrey and McGladrey and Pullen audit clients. Provided IT-related audit and consulting deliverables in client engagements. Responsible for planning, project management, staffing, client communication, deliverables and reporting to client and firm partners. Coordinated risk assessment and application control identification testing with the audit team on external audit clients. Coordinated and delivered IT consulting and internal auditing for internal audit clients. Reduced fees year over year on continuing IT engagements by instituting RCSA methods and audit planning with the IT Department and educating the users on evidence and control requirements. Minimized external IT audit fees for internal audit clients by coordinated planning of IT audit scope and consistent and standardized templates and evidence methodology and execution.
Working with PHEAA's Program Management (EPO) and internal audit department on management and reviews of agency wide projects and leading internal audits of agency wide high risk IAM and related focus areas. Leading advisory audit reviews of high risk projects covering the areas of Governance, Project Management, SDLC and Project Specific controls. Advisory activities include client meetings and walkthroughs, reviewing project deliverables and application controls, documenting processes and adherence to policies, procedures and alignment to end strategy and user goals. Audit activities include audit planning and scoping, budgeting and resource planning, findings remediation and review, workpaper and evidence requests, testing and results documentation and audit report preparation and review
Working with CME's internal audit department on a time sensitive Privileged Account and user access audit for the firm's regulator. Reviewing internal policies and controls, designing workpapers, key controls and test steps for the audit. Defining the evidence request lists and working with the process and account owners to test the CyberArk accounts and the controls, automated and manual. Testing the evidence, documenting the results and creating observation and possible remediation steps for deficiencies going forward
IAM Program & Techinical project manager leading a direct team of 3 engineers and a matrixed team of 12, installing and implementing CyberArk at the infrastructure and database level for non-personal priviledged access. Responsibility including directing the infrastructure build for 3 environments, installation of the CyberArk modules in the environments, integration of Remedy ticketing system and onboarding of the accounts, CyberArk applications infrastructure (Vaults, Safes, OU's Groups and Accounts), creating build and operating documentation, user guides and FAQ's under a accelerated timeline
Education / Training / Certificates(5)
Active
Active
Frequently Asked Questions
- What does Thomas do?
- Thomas is a Senior IT Project Manager on Automate America, the global professional marketplace for skilled talent across industrial, commercial, and residential work.
- Where is Thomas located?
- Thomas is based in Fernandina Beach, Florida.
- What does Thomas specialize in?
- Thomas works with SQL - review, Quest, CyberArk, Oracle, PMP as a Senior IT Project Manager on Automate America, the global professional marketplace for skilled talent across industrial, commercial, and residential work.
- Is Thomas available for work?
- Availability unknown. Thomas has not marked it recently.
- How do I connect with or hire Thomas?
- Create a free profile on Automate America and send a connection or contract request from this profile. Thomas can then respond and coordinate the work directly through the platform.















