Thomas Lam CISSP, CISA, CRISC, CDPSE, ITIL

Principal Cloud Security Architect at NTT DATA, Inc.

San Diego, California, United States

About

Thomas is self-motivated security professional with diverse technical experience and business sense who specializes in cloud security controls and GRC with agile software development experiences, a team player who brings positive energy and value to the business.

Experience

  • NTT DATA, Inc. (9 yrs 1 mo)
    • Principal Cloud Security Architect
      Apr 2022 - Present · 4 yrs 3 mos

    • Information Security Engineer
      Jun 2017 - Apr 2022 · 4 yrs 11 mos

      ♦ Hands-on skills with CrowdStrike, Qualys, Splunk, CyberArk, Cisco/IDS, DUO, OpenDNS, Syslog, NXLog, OSSEC, Trend. ♦ Monitor and respond to CrowdStrike detected incidents on Indicators of Attack (IOA) using MITRE ATT&CK framework. ♦ Deployed CyberArk (IAM) solution, enabled privileged access management (PAM) for the organization. ♦ Architected and deployed Splunk SIEM security control, supporting SecOps functions. ♦ Implemented Cisco FirePower IDS solution at each data center, populating intrusion events into Splunk. ♦ MSFT Azure platform migration Architecture Review Board member for the InfoSec team. ♦ Developed Python scripts via REST API/OAuth 2.0, pulling data from various controls, such as Qualys and CrowdStrike. ♦ Developed MySQL/Python-based Webservices provisioning analytical metrics published via REST API. ♦ Lead products and network vulnerabilities penetration tests based on industry best practices, including OWASP guidelines. ♦ Address vulnerabilities by collaborating with cross-functional teams through software development Agile sprints. ♦ Cross-team collaboration on Network, VMWare, Storage, Applications, and Kubernetes containers platforms.

  • Sr. Information Security Compliance Analyst at ServiceNow
    Oct 2012 - May 2017 · 4 yrs 8 mos

    ♦ Perform risk and gap analysis on laws, regulations and standards, such as, NIST 800-53, ISO27001/27002/27018, GDPR, PCI, HIPAA, CFR Part 11, against cloud and IT controls. ♦ Lead SSAE 16 SOC 1 and SOC 2 audits, including testing controls effectiveness, remediating deficiencies and reviewing final reports. ♦ Develop and implement ISO27001/MTCS based controls within Information Security Management System (ISMS) framework. ♦ Perform ISMS audits and compile results and recommendations for C-staffs review and approval. ♦ Drive remediations of gaps from internal/external/customer audits and cloud scans by directly engaging IT, Legal, Finance, HR, Security, Network and Development. ♦ Review vulnerability and OWASP penetration test reports prior to distributing to customers. ♦ Led data confidentiality enhancement projects through role-based access controls LDAP and IAM solutions. ♦ Lead IT GRC enhancement effort, encompassing JavaScript and mapping authoritative sources to unified control framework. ♦ Produce monthly operations KPI cadences, covering, GRC, FedRAMP, vulnerabilities and training. ♦ Led SQL database access monitoring project, leveraging cross-functional team resources. ♦ Led PCI Level 2 SAQ-D and SAQ-A assessment and remediation projects.

  • Motorola Solutions (15 yrs 3 mos)
    • Information Security, Corporate IT
      2004 - Sep 2012 · 8 yrs 9 mos

      ♦ Responsible for protecting company's intellectual properties and assets by designing and implementing security controls from corporate to operations levels ♦ Provide leadership and hands-on vulnerabilities management, cyber attack/defense (APT), incident responses management; Governance, Risk Management, and Compliance (GRC), and internal & external ISO27001/27002/SOX/SSAE16/PCI audits.

    • Information Security, Operations IT
      2002 - 2004 · 2 yrs

      ♦ Managed Information Security operation for main business units at Headquarter campus to ensure minimal network vulnerability risks and disaster impacts to IT and business operations.

    • IT Account Management
      2001 - 2002 · 1 yr

      ♦ Managed computing environments projects from systems specification, resources planning to deployment.