
Ming Chan
IT Security Analyst

Connect with Ming Chan to Send Message
Connect
Connect with Ming Chan to Send Message
ConnectTimeline
About me
Manager of Governance & Engineering at Exostar
Education

University of Maryland
2010 - 2013M.S. Computer and Information Systems Security/Information Assurance
George Mason University
2007 - 2010BA Government and International PoliticsActivities and Societies: Phi Alpha Delta
Experience

Technology Associates
Jan 2012 - Jan 2012IT Security AnalystManaged the C&A for new IT infrastructure & Integrated Audio/Video systemsDeveloped the Risk Assessment (RA), System Security Plans (SSP), Contingency Plan (CP), Privacy Impact Assessment (PIA), E-Authentication for mission critical communication systems in the Operations CenterResponsible for implementing and maintaining Symantec Antivirus and Symantec Backup Exec within the corporate and production environments

DrFirst
Oct 2012 - Jun 2014Security AnalystManaged requirements outlined by the HITECH security rule and worked with various groups in the organization to establish and maintain complianceMaintained NIST SP 800-53, SOC2, ISO27001, and ISO27002 standardsResponsible for handling security risk assessments from clientsImplemented a company-wide HIPAA training program Formulated metrics compiled from multiple IT-related departments for senior management briefingsWorked closely with Operations, System Operations, and legal managers to resolve security related issuesWorked closely with Human Resources, Sales, and Legal team to ensure information security protections were in place with suppliers, vendors, partners, etc. Show less

Federated IT
Jul 2014 - May 2017Spearhead internal preparation of and external audit for the organization's ISO 27001 certification to win a multi-year, multi-billion-dollar IT contracts. Guided leadership efforts, coordinated between with multiple department heads, and oversaw multiple project priorities while maintaining IT operational responsibilities. Develop risk assessment and treatment, threat prevention/mitigation strategy, security compliance, and technical protections for the corporate offices and as a SME for others supporting customer-facing engagements.Managed incident response efforts including root cause analysis, evidence preservation, and compiled forensics/legal report. Establish and presented a company-wide information security awareness programImplemented Operating System hardening security configurationsMaintained company DNS configuration to increase interoperability with Office 365 functionalitiesMaintain company headquarters IT infrastructure and provided support for hardware, software, and networking issuesCultivate situational awareness for the various operational processes within Federated IT in order to proactively provide solutions Show less
IT Manager
Dec 2015 - May 2017Microsoft Office 365 Consultant
Mar 2015 - May 2017Information Assurance Specialist Level III
Sept 2015 - Dec 2015Systems Administrator/Infrastructure Engineer
Jul 2014 - Sept 2015

Exostar
May 2017 - nowManager of Governance & EngineeringServe as the information security department’s lead for integrating security initiatives into Product, Development, Technical Operations, Operations, HR, and Legal interests.Manage the security engineering and risk assessment program that to align identified risks with the organization’s risk tolerance.Work with product, development, and technical teams to establish plans to address information security risks and mitigate future occurrences.Provide security engineering support to customer-facing initiatives while taking into account the business, technical, financial, and legal perspectives when architecting a solution.Manage customer and supplier security assessments, maintain customer flow downs, and standardize requirements for suppliers. Align the information security program with frameworks such as ISO 27001, ISO27002, NIST SP800-53, NIST SP800-171, GDPR, etc.Lead internal and external audits including ISO27001, SOC 2 Type 2, FBPKI, Kantara, etc. These efforts include coordinating audit responses, driving findings to closure, and maintaining an audit playbook to increase preparedness for internal stakeholders.Attend industry working group sessions to monitor for compliance and regulatory changes; then translate the impact of potential changes to operations, security, or audit interests.Maintain standing meetings with the CISO and with each team member. Establish metrics throughout this vertical to highlight performance, risks, and quantifiable progress towards security initiatives and map advancement towards departmental goals. Develop an information security awareness program including new hire training, annual courses, phish email testing, newsletters, etc.Standardize processes and cross-train to promote functional resiliency within the team.Coach team members to lead their part of the security organization. Coach team members to build working relationships with others while supporting the projects and initiatives of other groups. Show less
Licenses & Certifications

Certified Data Privacy Solutions Engineer (CDPSE)
ISACA
Certified Information Security Manager (CISM)
ISACA%C2%B2.webp)
Certified Cloud Security Professional (CCSP)
(ISC)²
Certified ScrumMaster (CSM)
Scrum Alliance%C2%B2.webp)
Certified Information Systems Security Professional (CISSP)
(ISC)²
Recommendations

Johanny trujillo
Sales manager| Trade Marketing | B2C |Power BI | Retail | Consumo masivo | SAP| SalesProvincia de Santiago, Región Metropolitana de Santiago, Chile
Jess heredia
Audiovisual Content Creator | Production Sound MixerMadrid, Community of Madrid, Spain
Falegan oluwatosin
ADMINISTRATIVE OFFICER AT VOE INDUSTRY&EQUIPMENT LIMITEDNigeria
Caroline christie fcipd
Head of HR at SCVOEdinburgh, Scotland, United Kingdom
Antonija jurič
Digital Marketing Manager at Bijeli Svijet - Bright World #brightworldZagreb Metropolitan Area
Alix rosset
Élève avocate | Lexcab Avocats | Diplômée du Master Droit du Commerce InternationalGreater Paris Metropolitan Region
Massimo iansig, pmp®, phd
Project Engineer at MARINE INTERIORS S.P.A.Trieste, Friuli-Venezia Giulia, Italy
Sarath athukorala
Manager - FinanceSri Lanka
Fabienne könig
Spezialistin Finanzen Clearing bei SBB CFF FFS | Dipl. Betriebswirtschaft HFZofingen, Aargau, Schweiz
Edmore mucheni
|Fund Administrator|Middle Office Operations| Pursuing MSc Financial Engineering|Cape Town, Western Cape, South Africa
Brooklyn mccue
👩🏻💻💡Building positive brand association through tangible goodsColumbus e Região
Niraj verma
Founder at The Prelude Of TomorrowKolkata, West Bengal, India
Nic swaner
NOC Technician | CybersecurityFort Collins, Colorado, United States
Pablo refoyo álvarez
Asesor Técnico Ayuntamiento de Madrid.Greater Madrid Metropolitan Area
Christian aucane
Étudiant Bachelor IT spécialité Intelligence Artificielle - 1ère année - Recherche une alternance po...Marseille, Provence-Alpes-Côte d'Azur, France
Ned van roi bautil
Solutions Engineer LeadQuezon City, National Capital Region, Philippines
Pamela rabelo
Technical director Medical Coordinator of Clinical Emergency Care DoctorUberlândia, Minas Gerais, Brazil
Jessica morrish
Ambitious Neuroscience graduate with focus on neurodegenerative disease | Centre of the Cell Public ...London, England, United Kingdom
박찬욱
도전의 미학.South Korea
Mahwish moiz
Co-Founder @ MedicoTech Solutions/Helped Business Owners Generate more than $15M in Sales/Podcast & ...Karāchi, Sindh, Pakistan
...