Director of Information Security
Washington, District Of Columbia
Director of Information Security @ Arent Fox Washington D.C. Metro AreaIT Security Specialist @ U.S. Department of Health and Human Services From November 2015 to March 2016 (5 months) Washington D.C. Metro AreaSr. IT Security Architect @ Open System Sciences Expert consultant related to information technology security, information assurance, risk management, governance and compliance. - Serves and...
Director of Information Security @ Arent Fox Washington D.C. Metro AreaIT Security Specialist @ U.S. Department of Health and Human Services From November 2015 to March 2016 (5 months) Washington D.C. Metro AreaSr. IT Security Architect @ Open System Sciences Expert consultant related to information technology security, information assurance, risk management, governance and compliance. - Serves and assists as a senior adviser to IT security leadership in executive departments of the US Federal Government. - Provides technical knowledge and analysis of highly specialized IT applications and operational environments, system analysis, design, integration, documentation and implementation advice on exceptionally complex problems. From February 2015 to June 2015 (5 months) Washington D.C. Metro AreaInformation Systems Security Manager @ United States Department of Health and Human Services Senior Information Security Officer for the Office of the Secretary of Health and Human Services reporting to the Deputy Chief Information Security Officer on all matters related to the information security of systems and the initiatives of the agencies security program. Serves as a primary point of contact for governance risk and compliance. Acts as a steward of information security practices and policies while fostering an environment of communication and collaboration with organizational entities, intergovernmental teams, working groups, and direct support of IT security strategic and tactical initiatives. Implements and administers programs to protect the information resources of the agency by assuring compliance with Risk Management Framework, Federal legislation, FISMA, NIST standards, executive orders, directives of the Office of Management and Budget. - Leads a large group of System Owners and Information Security Officers in the completion of IT Security related task and the security authorization process.- Accounts for tracking and reporting the risk profile of a large number of information systems and actively driving the mitigation of threats and vulnerabilities though customer communication and system security team management.- Serves as the representative the office of the HHS Chief Information Security Officer liaison and the Enterprise Information System Security Manager for IT Projects and CTO initiatives that span the operating divisions of the Department. - Maintains an IT Systems FISMA inventory of over 100 systems, security compliance, Plan of Action and Milestone Management with risk mitigation progress tracking and reporting systems raising the Office of the Secretary’s security authorization compliance from a 68% to 92%. - Serves as the lead liaison and POC for all IG requests, reviews and audits of organizational IT Security systems. From November 2010 to February 2015 (4 years 4 months) Washington D.C. Metro AreaIT Specialist (INFOSEC); Assistant Project Leader – Certification Program Office @ United States Department of Veterans Affairs Project leader in the Office of Cyber Security, Certification Program Office responsible for the development and operation of department-wide IT systems testing and certification programs. Insured independent verification and validation of security control assessments and accurate reporting of risks and vulnerabilities in IT inventory management tools. Responsible for the management of special projects related to certification and accreditation with team members, customers and contract staff, to help VA achieve the goals of the Federal Information Security Management Act. - Managed certification testing as Ex Officio/Certification Agent for the department and evaluated the findings of all assessments to determine risk profiles and the effectiveness of IT security control implementations. - Provided oversight for all VA security programs. Prepared and presented recommendation for program and policy changes for the department level security control assessments and security control selections to the Deputy CISO and other senior information security officials. - Ensured that enterprise security policies, procedures and standards were in compliance with regulatory requirements and legislated mandates governing information security. - Prepared statements of work, independent government cost estimates and cost benefit analyses and other documentation necessary for the procurement of IT and telecommunication equipment, goods and services. From January 2010 to November 2010 (11 months) Washington D.C. Metro AreaIT Specialist (INFOSEC); Aide to the Chief Information Security Officer - Office of Cyber Security @ United States Department of Veterans Affairs Specialist of information security in the Offices of Cyber Security identifying, developing, and recommending information protection and risk management solutions for the VA enterprise. Reported directly to the CISO/ADAS of Information Protection and Risk Management. Provided support on technical security matters to CIO, DAS, CISO, ISO’s, engineering, enterprise architecture, system administrators, software developers and other personnel involved in the implementation of security technologies and IS systems. - Investigated sources of Federal security requirements and best practices including, existing policy, guidelines, standards, legislation, mandates and advised leadership in the development and maintenance of departmental policy as it relates to cyber security, information protection, privacy and risk management. - Represented OCS and communicated management’s interests to VA stakeholders, OIT customers, staff members, external elements, and identified specific project goals and objectives to determine the effort, resources, and methodology necessary to complete the project. From June 2009 to January 2010 (8 months) Washington D.C. Metro AreaIT Specialist (INFOSEC); Emerging Technology Specialist – Field Security Operations @ United States Department of Veterans Affairs Responsible for the recommendation and evaluation of emerging technologies for the modernization and innovation of the agencies enterprise information technology systems. Served as a Senior IT Specialist of information protection and risk management. Performed work that involved a wide range of IT security services that extend and apply to the Office of Information & Technology (OI&T) and or the VA enterprise in general. Evaluated technologies for their ability to meet the VA’s existing cyber security standards and requirements. - Conducted product evaluations and proof-of-concepts to determine functional and technical ability to meet VA security requirements. - Oversaw and managed research to address practical application of existing and emerging information systems technologies. - Advised senior leadership on system and application planning, design, development, and procurement processes to ensure security integrity and compliance with policy. From February 2008 to May 2009 (1 year 4 months) Senior Integration Specialist @ Hargray Communications • Responsible for complete design, installation and maintenance of business IT networks and communication systems. Generated revenue and retained customers though account management and project planning while providing pre and post sales support. • Duties included determining scope and technical needs of project, implementation requirements, design, planning, installation and oversight of technicians, other vendors and contractors, product delivery and documentation along with initial customer training.• Accountable for qualifying customer needs and delivering optimal solutions over IP (LAN and WAN), DBN, WI-FI, IPCentrex, VoIP, P2P and copper telecom. • Managed support staff and contract employees performing facility work at customer sites and provisioning work within the telecom infrastructure. From December 2005 to October 2007 (1 year 11 months) Data Systems Technician @ Hargray Communications Designed, installed and maintained business IT networks and communication systems. Generated revenue and retained customers though account management and project planning while providing pre and post sales support. Duties included determining scope and technical needs of project, implementation requirements, design, planning, installation and oversight of technicians, other vendors and contractors, product delivery and documentation along with initial customer training. From June 2001 to December 2005 (4 years 7 months) Hilton Head, South Carolina
Arent Fox
Director of Information Security
Washington D.C. Metro Area
U.S. Department of Health and Human Services
IT Security Specialist
November 2015 to March 2016
Washington D.C. Metro Area
Open System Sciences
Sr. IT Security Architect
February 2015 to June 2015
Washington D.C. Metro Area
United States Department of Health and Human Services
Information Systems Security Manager
November 2010 to February 2015
Washington D.C. Metro Area
United States Department of Veterans Affairs
IT Specialist (INFOSEC); Assistant Project Leader – Certification Program Office
January 2010 to November 2010
Washington D.C. Metro Area
United States Department of Veterans Affairs
IT Specialist (INFOSEC); Aide to the Chief Information Security Officer - Office of Cyber Security
June 2009 to January 2010
Washington D.C. Metro Area
United States Department of Veterans Affairs
IT Specialist (INFOSEC); Emerging Technology Specialist – Field Security Operations
February 2008 to May 2009
Hargray Communications
Senior Integration Specialist
December 2005 to October 2007
Hargray Communications
Data Systems Technician
June 2001 to December 2005
Hilton Head, South Carolina
What company does John Hartmann work for?
John Hartmann works for Arent Fox
What is John Hartmann's role at Arent Fox?
John Hartmann is Director of Information Security
What industry does John Hartmann work in?
John Hartmann works in the Computer & Network Security industry.
Enjoy unlimited access and discover candidates outside of LinkedIn
One billion email addresses and counting
Everything you need to engage with more prospects.
ContactOut is used by
76% of Fortune 500 companies
John Hartmann's Social Media Links
/company/a... /school/un...