Michael DeBiase, CISSP

Cyber Security Professional



Accomplished cyber security professional with 10+ years of progressively responsible experience leading teams in minimizing security risk by architecting, maintaining, and managing secure IT solutions. Personable and respected leader of both office and virtual teams; skilled at collaboration and clear communication. Well-prepared to assume executive-level role. Backed by 4-year degree and CISSP certification.

* Project Management
* Risk Management
* Compliance Assessment
* Penetration Testing / Hacking
* Vulnerability Assessment
* Disaster Recovery


* Team Leadership
* Security Policy Creation
* Security Testing
* Reverse Engineering
* Cryptography
* Secure Software Development


* Application Architecture
* Data Analytics
* Log Analysis & Correlation
* SEO / Website Security
* Complex Project Resolution
* Auditing


Career Profile / Summary

* Selected to lead 30+ developers, team leads and other IT professionals as Chairman of the Westchester County Information Technology Architecture Committee; developed and shared best practices.
* Use subject matter expertise and team leadership to guide organizations in the development, maintenance, and continuous improvement of information security policies and projects.
* Solid background in Systems Development Life Cycle (SDLC) from needs analysis, design, and testing to implementation and post production maintenance.
* Business acumen to develop and manage budgets, recruit and supervise staff, and collaborate well across organizational levels and lines of business.
* Articulate and persuasive; can convey technical information to stakeholders at all levels of understanding.


Professional Experience

WESTCHESTER COUNTY GOVERNMENT – White Plains, NY 2006 - Present

Manager / Technical Lead of Information Technology Team
Lead teams in developing and maintaining cutting-edge software architecture solutions that minimize risk and ensure information safety for this public organization serving approximately 1M residents. * Provided guidance on the creation of policies, procedures, and training curriculum regarding information security and compliance for all departments.
* Led the vision, architecture, engineering, implementation, and support of several internal and external applications for government programs and departments, including the one-stop employment center, DOT, warrant watch, sewage water response systems, Facebook economic development portal, and content management systems.
* Developed and led the Technical Operations and Support Division as business volume increased.
* Reduced team budget by 80% through implementation of open source technologies.
* Increased external web application page views by 500%.
* Implemented organization-wide best practices including penetration testing of all applications, secure software development policy, and ongoing training to identify and mitigate risk. * Worked nights and weekends when necessary to meet otherwise unattainable deadlines.


Education (Currently Enrolled), Masters of Cyber Security, Mercy College NSA Center of Academic Excellence, Dobbs Ferry, NY, expected graduation date 2017
Bachelor of Arts, Information Technology and Informatics, Rutgers University, New Brunswick, NJ, 2006
Professional Writing Certificate, Rutgers University, New Brunswick, NJ, 2006


Certifications / Training

Certified Information Systems Security Professional (CISSP), (ISC)2, 2015
Project Management +, CompTIA, 2015
Python Programming Certification, Career Academy, 2015


Technical Tools

OS / Servers: Windows, Linux (Red Hat, CentOS, Ubuntu), Unix, OSX
Programming: Node.js, Javascript(JQUERY), Angular JS, Python, C/C++, SQL, No-SQL, Java, .Net, PHP, Objective-C, Facebook Open Graph
Compliance: FIPS, FISMA, PCI-DSS, HIPAA, GLBA, SOX, CJIS, 501c3
Infrastructure: AWS, Reverse Proxy Servers, Citrix NetScaler, Kerberos, Firewalls, WAF, Lyris
Security Frameworks: ISO 27001, COBIT, COSO, ITIL, NIST SP 800-53, 800-30, 800-37r1
Security Tools: Wireshark, CyberArk, IDS/IPS, Norton, Kali Linux, Arduino Open Hardware, OWASP, Vulnerability Scanners (Qualys, Nessus, Acunetix), Cloud Security
IoT: Rasberry Pi, Arduino
Physical Security: USBJJ Certified Brazilian Jiu-jitsu Black Belt, Defend University Women's Self Defense Instructor Certified