Lee Forrest

Principal Cyber Security Architect, Security Architecture | ISA Standards | ISO Standards | Supply Chain | OT/IT Cyber-Security

Spring City, Pennsylvania, United States

About

Specialties: CISSP® - Certified Information Systems Security Professional ITIL Microsoft Certified Professional Microsoft Certified Systems Engineer Microsoft Certified Database Administrator Industrial Control System Security, ISA/IEC 62443 Series of Standards, ISO Standards, Emerson DeltaV, PCS7, Distributed Control Systems, SCADA Security , Pi, VPx, AWS, Windows Server, SharePoint Portal Server, Microsoft SQL Server, VMware, MS Content Management Server, Internet Information Server (IIS), Microsoft Internet Security Acceleration Server (ISA), MSCS Clustering Services.

Experience

  • Johnson & Johnson (20 yrs 6 mos)
    • Cyber Security Principal Architect, Security Architecture
      Jan 2025 - Present · 1 yr 6 mos

      Primarily responsible for development and maintenance of the enterprise (cross-technology) security technology architecture and near-term roadmap pertinent to significant business facing initiatives and core programs as well as providing key consulting expertise. Identifies future acceleration opportunities. Constantly monitoring and evaluating emerging security technologies and trends, staying up to date with the latest advancements in the field. Identify potential opportunities for future improvement and contribute to the long-term strategic planning of security technology within sector initiatives. Accountable for gathering input from key stakeholders including sector architects and business facing Information Security Risk Management teams and provide extensive insights and actionable consulting and direction through knowledge of current technology solution products and capabilities roadmap. Have in-depth knowledge of key solution roadmaps and schedules across other technology areas to build a living roadmap updated quarterly that prioritizes remediation of risk gaps. Provide expert input and consulting expertise to key strategic sector initiatives/programs understanding current security technology and product sets and future acceleration opportunities to meet needs, · Partner to maintain and publish a holistic and integrated enterprise security technology architecture, · Partner to support the detailed short term and near-term technical & functional roadmaps across all products and technologies in use across the security technology teams, · Maintains industry connection across peer groups and research teams to understand new and emerging security technologies and solutions that maybe disruptive and significant velocity enablers for addressing and mitigating the threat/risk landscape at JNJ · Partners with Service lifecycle team to ensure customer facing technology solutions have an integrated service definition, service blueprint and operating model.

    • Cyber Security Manager
      Jan 2019 - Jan 2025 · 6 yrs 1 mo

      I Provide cybersecurity consulting and assurance to the Pharmaceutical and Medical Device Supply Chain (SC) and Plan/ERP Product Line Organizations. I lead all aspects of Security Consulting and Assurance for the Corporate ERP applications to be located in Raritan, NJ, will consider JNJ sites within NJ, PA, and EMEA. My responsibilities are, manage and inspire a team of 8-10 through authentic leadership, driving results. • Responsible for advancing cybersecurity of Pharmaceutical and Medical Device SC systems, applications and integrations across product lines and regions by identifying key risks and controls • Engage with the Plan/ERP Technology Product Line within SC and Corporate to present holistic metrics, risks, trends, and pragmatic mitigations across the area. • Understand and promote risk management activities associated with external regulations and internal Johnson & Johnson policies such as IAPP, SOX, GxP and GDPR • Bridge the gap between traditional Information Technology (IT), Operational Technology (OT) and Pharmaceutical SC business functions by relating cyber threats and vulnerabilities to business imperatives and communicating them to key business leaders • Orchestrate and deliver cybersecurity risk assessments of Pharmaceutical and Medical Device SC projects, applications and the technologies that run them while maintaining awareness of the changing threat landscape • Maintain connections across peer groups to continuously understand emerging security solutions that are ground-breaking enablers for mitigating supply chain risk at J&J • Constantly strive to shape the administrative controls for cybersecurity through advisory and assurance services • Work both collaboratively and independently, globally across cultures is important

    • Lead IT Analyst
      Jan 2006 - Dec 2018 · 13 yrs

      Responsible as an IT Security Generalist and design IT infrastructure.

  • Owner/ President at Delaware Valley Laser Skirmish
    Mar 2007 - Dec 2017 · 10 yrs 10 mos

    Plan and run Laser Skirmish in the Delaware Valley area. We run a fully mobile business with open play located at various parks in the area. After a very successful summer we are looking to expand our venues.

  • System Administrator at Centocor (part of Johnson & Johnson)
    Jun 2001 - Jan 2006 · 4 yrs 8 mos

    Systems administrator for all R&D servers and networks. Performed security analysis and upgrades. Developed new environments and troubleshoot high end issues with R&D servers, clusters and SAN.

  • Analyst at Robert Half Technology
    2001 - 2002 · 1 yr

    Lead Systems Analyst

  • Analyst at Host Pro
    Jan 1999 - May 2001 · 2 yrs 5 mos

    A division of Micro, started working for Hostpro in technical support.