Você está na página 1de 2

Michael T.

Kibbe, TOGAF 8
Phoenix, AZ 85086
Cell: (602) 697-7376

e-mail: Michael.Kibbe@outlook.com
Skype:Michael.Kibbe@outlook.com
Linkedin:www.linkedin.com/in/MichaelKibbe1

Twenty plus years experience in architecting governance processes, designing secure


information systems, reference architectures, information security.
Professional Experience
American Express Technologies
Lead Technical Architect Enterprise Architecture and Services;1996-2016
Lead of the IRP (Incident Response Team)
o Built the first IRP process.
o Lead the team responsible for responding to security incidents.
Coordinated the appropriate groups, when appropriate, to identify and
remediate a threat.
o Liaison with senior management when verified incident occurred.
o Assisted with IDS team on fine tuning of IDS systems when an incident arose but
turned out to be false positive.
Lead the team that launched first Governance process @ AET, ECRB (E-Commerce
Review Board).
o Reviewed the Security of any e-commerce application before launch into
production. Ensured application was secure and in compliance to standards.
o Was par to the C level review of applications before launch.
Built the first security standard, the MSB (Minimum Security Baseline).
Lead the team that built the tool to support the ECRB process.
o Tool was originally built in Lotus Notes.
Built the PGB (Project Governance Board) process.
o Expanded ECRB to include more than e-commerce projects. Process was rebuilt and re-architected to include all distributed applications.
o Also added other groups around AET that had standards to be enforced.
This required alignment with those groups on when they would be
included in a review, what they needed asked in our up front forms, and
where else they would come into the PGB process; including but not
limited to RMP (Risk Management Plans), signatories on various project
artifacts (i.e., RMP, Executive review deck preparation and review, etc.).
Lead the team that re-branded the tool to support the PGB process (Lotus Notes
application).
Built and launched SAR (Solution Architecture Review)
o Complete rewrite of the governance process. Became Architecture and Security
focused.
o SAR processes now included business owners to agree and accept risk for their
application.
o Added support to review mainframe applications into the SAR process.

30-Nov-2016

AXP Internal

Page 1 of 2

Lead the team that built GEM (Governance Engagement Manager). .Net solution that
replaced the Lotus Notes governance application.
Created the AOC (Architecture Oversight Council). AOC takes input from reviewers
(those who conduct the reviews in the governance process) and projects. Takes the
inputs, prioritizes them for improvements to either process or tools. Also looks at
requests for groups that wish to be added as a reviewer group (someone who owns a
standard and wants to utilize the SAR process for reviewing).
Lead the JADR (Joint Architecture Design Review, one of the review process in PGB
and SAR).
o JADR consisted of looking at the security and architecture of an application.
o Check for standards compliance among other possible issues an application
would/could have.
o I covered only Java and .Net.
o Conducted and reviewed applications for both enterprise security and
architecture compliance, regulatory compliance, industry standards, principles
and guidelines.
Launched the Application Development Security program.
o Assisted developers in writing secure code by:
Education
Component development
Implemented Code scanning in SVN repository.
o Scans code in the SVN repository every night for security gaps.
Implemented the wireless LAN project.
o Gave employees access to the local LAN.
o Gave guests ability access the internet without getting access to resources on
the LAN.
Lead the design team (security and architecture) for the implementation of OpenShift.
o Open source cloud platform.
Lead the design team (security and architecture) for the integration of Microsoft Azure
cloud services with internal and Azure hosted applications.
Lead the design team (security and architecture) for the implementation of Vsphere.
o VMWare cloud offering.

30-Nov-2016

AXP Internal

Page 2 of 2

Você também pode gostar