Warren Reid, MS
Director of Cybersecurity @ Atlanticus
About
Resourceful, strategic Information Security Leader with extensive experience in security architecture, risk management, and compliance across diverse sectors, including government and commercial clients. Adept at engaging with stakeholders to align security goals with business objectives, providing strategic guidance on compliance requirements, and enhancing organizational awareness through tailored training programs. Expert in developing and executing incident response and disaster recovery plans, ensuring readiness and resilience in dynamic IT environments. Certifications: CRISC, CEH, CCNA Security, CCENT, Security+, Network+, A+
United States
Atlanta Metropolitan Area
Computer Software
Data Governance, Cybersecurity Tools, Vulnerability, Security Automation, IT Risk Management, Digital Authentication, Data Privacy, Manufacturing Systems, Cyber-security, Decision-Making, Presentations, Auditing, Networking, Cybersecurity, Small and Medium-Sized Enterprises (SME), Technical Leadership, Mitigation, IT Audit, Threat & Vulnerability Management, IT Security Operations
Experience

Director of Cybersecurity
Atlanta, Georgia, United States
• Led the development and execution of a cybersecurity strategy in alignment with industry regulations and business objectives • Oversaw day-to-day operations of the security operations and threat intelligence, including enhancing threat detection and response capabilities in a highly regulated FinTech environment • Managed security department, mentored a instilling a culture of continuous learning, monitoring, and regulatory readiness based on threat intelligence and email security, governance, risk, & compliance, provisioning, vendor relationships, and privacy. • Ensured governance, risk, and compliance with PCI DSS, SOX, and NIST frameworks critical for securing operations • Partnered with internal audit and external compliance stakeholders to meet regulatory standards and optimize control environments • Completed client security assessments to maintain alignment with compliance and business objectives • Supported vulnerability management tailored to FinTech infrastructure and customer-facing systems to meet remediation and SLA requirements • Collaborated with Network and Infrastructure teams to maintain architecture across perimeter, endpoint, and platforms to safeguard data and customer trust • Promoted enterprise-wide security awareness campaigns, policy review, and updates to establish security best practices to organization Key Skills & Achievements: • Leadership experience in cybersecurity operations and incident response, utilizing tools for DLP, integrity checking, monitoring, detection, prevention, and alerting of anomalies, phishing, ransomware, data spillage, and other vulnerabilities. • In-depth knowledge of risk management, compliance, security architecture, and data protection specific to FinTech • Expertise in cloud security implementations (AWS, Azure) and zero-trust architecture models supporting secure digital finance • Maintained security policy reviews, updates, and collaboration with IT teams for IR and BCP & DR initiatives.

Senior Security Engineer Lead
Atlanta, GA
Serve as the primary point of contact for technical deliveries, initiatives, change management board, security impact analysis, and project implementations, coordinating efforts to meet security and organizational objectives. Security Architecture & Design Create and maintain comprehensive architectural diagrams, service dependencies, and the service catalog, ensuring integration of security considerations within the IT infrastructure. Mentor and empower team members, including the Service Desk, to adopt and implement a security-focused approach across their work processes. Manage, maintain, and monitor the traditional security stack, including antivirus, configuration control, vulnerability management, and endpoint security; escalate issues as necessary and assist with remediation efforts. Used Microsoft Azure, Active Directory, Barracuda, Cisco Umbrella, Sentinel One, Rapid 7 IDR, Abnormal, Tanium for incident response, investigation, remediation, and continuous monitoring, for account takeover, vendor fraud, phishing, ransomware, and related risks. Performed due diligence on 3rd party vendors for pen testing, disaster recovery metrics, incident history, and SLA compliance. Led external audits and maintained compliance under best practices for SOC 2, pen testing, security awareness training, ensuring secure processing systems. Guide IT management on security requirements for technical proposals and specification documents, ensuring adherence to security controls and compliance standards. Assist in developing technical designs and solutions that align with corporate security policies and meet external standards. Coordinate with external partners to deliver security support and consultancy services across a dynamic and diverse IT environment. Provide technical support for vulnerability remediation efforts and actively manage security incidents to ensure effective resolution.

Senior Director of Security (CISO)
• Responsible for maintaining and optimizing GRC security program including responsibility for ensuring the security and data privacy of FM:Systems’ suite of cloud products and services nationally and internationally. Manage GRC security responsibilities based on security, governance, compliance, integrity, and confidentiality affecting customers, business partners, and employees. • Review and update all System Security Plans, throughout the company to ensure alignment between security and privacy practices, and act as a liaison to individuals, legal, the Infosec committee and the CTO on all security matters • Maintain, and audit System Security Plan(s), vulnerability remediation, and POAM mitigation addressing of collected, processed, or stored information. • Responsible for GDPR compliance for EU operations for FM:Systems’ role as a legal processor of its clients’ Protected Information. • Ensure company processing systems have appropriate policies, procedures, personnel, and equipment in place to ensure the integrity and confidentiality of all information residing on those systems, and leads the external audits and certifications through programs like SOC 2, FedRamp, NIST, GDPR, and others. • Conduct data security due diligence on third party service providers including disaster recovery policies, details of incidents or breaches, and work with legal counsel to include specific requirements or SLAs. • Collaborated with cloud service partners (AWS) regarding leveraging of operational controls, availability of services, and maintenance for FedRAMP environment. • Ensure that business unit security programs appropriately address security across various departments (e.g., Hosting, Engineering, Human Resources, IT Support, etc.)

Information Security Manager
• Develop and maintain company Infosec program based on company community-cloud SaaS services. • Led status meetings and presentation with executives regarding company security posture, client relationships, vendor partners, metrics, current challenges, and future goals. • Collaboration with vendor management partners based on external penetration testing, datacenters, business continuity, disaster recovery, and backups. • Led meetings with Sales teams to discuss customer prospects and client security assessments • Maintain system controls for security frameworks based on NIST, SOC 2, FedRAMP, and ISO 27001. • Led audit efforts and collaborated with internal departments (i.e., Operations, Support, HR) during external audits. • Participated in Production Change Control Board with Operations, Security and Support departments to discuss and track production changes, IT maintenance (i.e., tickets, risk management, configuration changes) and elevated requests. • Maintained information security policies, standards, and procedures, and System Security Plans • Coordinated with government clients for plan of action and milestones (POAM) to resolve remaining risk management vulnerabilities. • Conducted job interviews for potential company candidates. • Utilized Remedy, Jira Service Desk, CSAM, and Salesforce ticketing systems to track vulnerabilities, access requests/termination, security assessments, and troubleshooting status.

Cybersecurity Manager
Wise Enteprises
Washington DC-Baltimore Area
• Oversaw security tasks for client support including security engineering, penetration testing, security assessments, and audits for commercial and government agencies. • Supported the CDC under Merlin International Inc. and continued under Cybersecurity Manager for Wise Enterprises, extensively managing teams in aspects of security, networking, operations, incident response, and configuration management in business continuance. • Presented kickoffs and debriefings with both commercial and government agencies regarding security posture, methodology, compliance strategy, vulnerability and risk management, plan of action and milestones (POAM), and authorization to operate (ATO) remediation recommendations. • Managed budget and scheduling, and providing security awareness training on best practices, risk management framework and baselines security tools. Utilized security tools such as Tenable Nessus, Security Center, WebInspect, Burp Suite, AppScan, AppDetective, Wireshark, Nipper Studio, Nmap, Core Impact, McAfee Mobile Security, Lookout Mobile Security, and Net Surveyor. • Identified existing and/or potential organizational security weaknesses, including personnel controls, training, incident response, configuration management, technical controls, physical controls, operational security and integrity of system security posture for ATO approval, with understanding of NIST, RMF, CSF, ISO, DISA STIGs, PCI, SOX, FISMA, and FedRAMP standards. • Assessed security control baselines, procedures, cloud architecture, network diagrams, mobile security devices, system inventory, and security plans for compliance. Analyzed architecture and design based on connectivity, data flows and network devices (routers, firewalls, switches, etc.). • Conducted vulnerability testing on mobile devices, servers, databases, web applications, routers, firewalls, switches, wireless access points, and tracked vulnerabilities for scheduling and remediation to meet SLAs.

Security Assessment Lead (contract at CDC)
Merlin International
Washington D.C. Metro Area
• Conducted assessments for security control baselines, procedures, cloud architecture, network diagrams, mobile security devices, system inventory, and security plans for compliance. Analyzed architecture and design based on connectivity, data flows and network devices (routers, switches, etc.). • Identified security control weaknesses based on risk management, personnel controls, awareness training, incident response, configuration management, technical controls, physical controls, operational security and integrity of system security posture. Interviewed clients on security controls based on NIST, STIGs, PCI-DSS, SOX, Risk Management Framework, and FedRAMP standards. • Tested OS’s, databases, applications, network devices, and wireless access points for vulnerabilities. Coordinated vulnerability management with clients for annual assessments and continuous monitoring. • Performed pen testing via Nessus, Tenable Security Center, WebInspect, Burp Suite, AppScan, AppDetective, Wireshark, Nipper Studio, Nmap, Core Impact, McAfee Mobile Security, Lookout Mobile Security, and Net Surveyor.

Senior Information Security Analyst
Washington D.C. Metro Area
• Assessed government systems through all phases of certification and accreditation (C&A) assessment lifecycle and risk management framework, performing information assurance under FISMA, FIPs, FedRAMP, DIACAP, NIST and other standards. • Evaluated and tested mobile operating systems (i.e. Android, IOS, Blackberry) devices to identify mobile security threats and vulnerabilities such as infected files, malware, spyware and viruses. Verified mobile security compliance based on technical and physical security controls. • Developed policies and procedures for investigation and response to malware, mobile threats and other threats to network security. Provided vulnerability testing and analysis via security tools using Nessus, WebInspect, AppScan, AppDetective and WebSense. • Managed projects with engineers and developers on vulnerability findings and mitigation strategies using Cybersecurity Assessment and Management (CSAM) for POAM management. • Analyzed incidents, threats, logs, continuous monitoring and configurations via IDS to determine operational impact, intent and advisory capability. Produced briefings, findings, deliverables and recommendations based on policy and best practices. • Partnered with client and cloud services provider on security assessments, systems security plan and design, and security documentation for FedRAMP compliance to obtain ATO accreditation. • Provided training for incident response and business continuity planning, and contributed to deliverables such as SSPs, contingency testing, assessments, and continuous monitoring for risk management.

Security Architect Lead
Herndon, VA
• Managed proposal effort as solutions lead for security architecture tasks, model design, and security frameworks for DISA, DHS and Air Force proposals. Provided firewall rule change configurations, RFCs, and performed risk assessment and POAM management. Created firewall rule change requests including ports, protocols, and source/destination IP addresses to allow connectivity throughout DHS network. • Presented and voted in Configuration Management and Architectural Review Boards for approval on business cases, cost/benefit analysis, technology issues, requirements and architecture. • Provided IA services to d multiple clients based on ISO, RMF, NIST, SOX, PCI-DSS, DISA STIGs, FedRAMP, mobile device security controls, testing and evaluation for technical, operations and management security controls, security architecture, risk and threat assessment engagements, firewall rules, operational security (configuration, vulnerability, patch management), and contract RFP proposals. • Applied change control management based on NIST security requirements, supporting log database, artifacts, PKI certificate updates, content and media maintenance for SOX and PCI-DSS audits for compliance. • Troubleshot operational tasks involving PKI web certificates, virtualization, patch management, IDS/IPS for continuous monitoring for detection and mitigation, Cisco ASA 8500 firewall appliances, Wireshark, McAfee Mobile security for IOS and Android mobile devices, and Remedy ticket system. Performed vulnerability scans based on Nessus, AppScan and WebInspect.

Senior Security Engineer (contract)
L-1 Identity Solutions AG
• Assessed customer’s IA needs from enterprise perspective, reviewing and determining applicable IA requirements, and developing enterprise-level IA technical solutions and trades. Reviewed security documents and provided input for POAM, architecture design, RFC requests, and C&A. • Analyzed and/or created work deliverables such as security reviews, security architecture diagrams, security requirements traceability matrices (SRTM), project security milestones and other related security documents. Analyzed change, release and configuration management practices to ensure that all modifications made were adequately controlled. • Evaluated network infrastructure to ensure confidentiality, integrity, availability and authorization of network and information transmitted. Performed independent research using analytical skills to provide mitigation strategies, and input to baseline development. • Created governance compliance database for NIST 800-53, 800-37, FIPS-199, FISMA, DIACAP, ICD 503, ISOs and contingency plan testing. Provided daily operational reports on trouble tickets and escalations, and performed assessments based on NIST, HIPAA and service level metrics.

Cross Domain Security Engineer
• Provided security support using IA knowledge, implementation and technical operation of DISA cross domain solutions. Presented status presentations based on charts, scheduling and dependencies on DISA operations and enterprise architecture. Applied customer needs into security requirements based on security policy and DISA STIG guidelines. • Led security status meetings with management, clients and engineers regarding client connectivity, network monitoring, firewalls, security testing and evaluation, and upgrading migration. • Implemented security tools such as Retina scanner, Syslog and Wireshark, for continuous monitoring mitigate IA vulnerabilities. • Oversaw project management regarding field clients, configuration management, security of Data At Rest and Data in Transit, and network operations for establishing infrastructure solutions. • Worked in lab environment to create client accounts, perform metric tests, configure port settings, and control data flow traffic to network using single point access server. Provided guidance to customer liaisons, program/technical managers, and operations engineers regarding service connectivity, troubleshooting and security requirements. • Supported transition of client network connections for rollout migration upgrade, and performed audit and filter functions for data parsing using TDX and Radiant Mercury Guards. • Resolved RFCs and IAVA alerts for vulnerabilities and risks, applying equipment security patches and upgrades to ensure integrity.
Warren Reid, MS's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.



