Summary
Overview
Work History
Education
Skills
Timeline
Career Highlights
Generic

Michael Conner

Charlotte

Summary

Dynamic and results-driven professional with over 20 years of experience delivering complex processes and projects within tight deadlines and budgets. Expertise in spearheading project portfolios from conception to full operational status, leveraging motivating leadership alongside meticulous strategic and tactical planning. Proven ability to foster collaboration among diverse teams across various business lines, driving cohesion and enhancing overall project outcomes. Committed to achieving excellence through innovative solutions and a steadfast focus on stakeholder satisfaction.

Overview

25
25
years of professional experience

Work History

Senior Information Technology Analyst (TEK Systems)

First Citizens Bank
Raleigh, NC
07.2024 - 01.2026
  • Created and populated an application release calendar to track changes with potential to impact the regulator-mandated ISO-20022 implementation.
  • Reviewed and monitored all documentation supporting the five workstreams within Wires Transfers for compliance with internal and regulatory requirements.
  • Served as the primary liaison with Internal Audit, ensuring all requests from Audit were fulfilled in a timely manner and all deliveries to Audit were accurate and verifiable.
  • Monitor team meetings and metrics for opportunities to improve the overall Audit and Governance posture.

IAM Senior Analyst – Governance

State Employee’s Credit Union (SECU)
Raleigh, NC
06.2023 - 07.2024
  • Established an Identity and Access Management (IAM) Governance capability aimed at demonstrating controls were effective through the development and publication of Key Performance Metrics.
  • Created over 25 target metrics to include in a monthly package called the “Domain Capability Report” which summarized the performance of IAM Operations for internal stakeholders and leadership.
  • Orchestrated a monthly Steering Committee to share IAM plans and progress in implementing controls to ensure key business leaders were kept apprised of the status and potential impact of IAM activities on their respective teams.
  • Initiated manual controls around Local Admin Access processing, Group Policy Object updates, and access certification of privileged accounts while awaiting automation of those controls in our IAM tool suite.
  • Demonstrated the effectiveness and efficiency of several IAM processes by calculating the time saved for users when applications use our Single Sign On (SSO) and automated provisioning capabilities.

Information Security Process Engineer, Process, Risk, and Controls (PRC) Team Lead

United Services Automobile Association (USAA)
San Antonio, TX
05.2022 - 06.2023
  • As the senior process owner for the Authorization Domain, oversaw procedures and controls to ensure compliance with established enterprise and regulatory requirements.
  • Recommended the consolidation of control owners into a single, focused team then as team lead, developed a structured and repeatable process to ideate, justify, present, and secure approvals for control changes that improved the overall security posture of the Identity and Access Management function.
  • Produced a daily analysis of access termination data intended to support business and control requirements. This analysis enabled the team to identify and correct instances of inappropriate access management practices within various business entities, further improving the overall security posture.

Information Security Governance Leader/Business Support Consultant

Wells Fargo Corporation
Charlotte, NC
01.2018 - 01.2022
  • Built upon the successes established in a viable Enterprise Access Management Governance function, sustaining the oversight this function provided and “right sizing” the organization and structure of associated Governance Committees.
  • Coordinate all evidence collection and storage in support of the Identity and Access Management response to Audit and Regulatory information requirements.
  • Managed the intake, review, and decisioning of all policy exception requests against Identity and Access Management Control Requirements.
  • Solely responsible for the identification and escalation of Information Security out-of-compliance conditions that could impact the overall security posture of the company.

Information Security Governance Leader (TEKSystems)

Wells Fargo Corporation
Charlotte, NC
01.2016 - 01.2018
  • Established and implemented governance framework and supporting structure around Identity and Access Management policy and controls.
  • Created governance standard operating procedures and identified appropriate committee protocols for execution and maintenance of the governance process.

Senior Program Manager, Information Security (TEKSystems and EttainGroup)

Bank of America
Charlotte, NC
01.2011 - 01.2016
  • Managed execution of CTO-mandated acceleration initiative to consolidate access controls and review processes for all 6,500 applications enterprise-wide into two Identity & Access Management tools.
  • Developed, scheduled, and delivered targeted training for a cadre of Control Specialists who form core of an Adoption Factory approach to provide direct assistance in meeting extremely aggressive timeline
  • Addressed chronic audit issues by managing targets and deliverables for seven work streams focused on correcting those issues in the Identity & Access Management space.
  • Created efficiencies in budget and hardware while reducing risk and expense exposures by providing program delivery services to the organization’s Infrastructure & Engineering branch.
  • Spearheaded Business Case Development of 26 individual efforts within Identity & Access Management, all aimed at reducing risk while improving the employee on-boarding experience.
  • Provided Program Management oversight of 14 initiative-funded projects, including QA/QC of all project documentation and supervision of personnel, budgets, and timelines.
  • Ensured high-risk IT processes were appropriately assessed, monitored, and reported by Technology Governance and Operational and Compliance Risk groups.
  • Validated sustainability, clearly defined ownership, and accountability of IT Management processes.

Senior Technology Project Manager, Identity and Access Management, (Signature Consultants)

Wells Fargo Corporation/Wachovia Corporation
Charlotte, NC
01.2001 - 01.2011
  • Managed all aspects of traditional waterfall project methodology supporting three distinct efforts with a common focus of minimizing risk while maintaining operational functionality and efficiency.
  • Implemented Virtual Clustered Services solution; identified and remediated Out of Band Console Access in a pool of 6,200 disparate devices; eliminated Windows Server Local Accounts across 1,500 servers.
  • Drove reduction in overall cost of business as part of Workforce Location Optimization project, supporting Wealth, Brokerage, and Retirement leadership.
  • Supported confidential decisions on non-domestic support opportunities by researching, collecting, and presenting IT data on process dependencies.
  • Executed project management and status/metrics reporting for major reissue of Remote Access Security Tokens to over 62,000 enterprise users in a 70-day period.
  • Led geographically dispersed team of “first-responder” security analysts and engineers tasked with monitoring computer security health of Wells Fargo domestic and international footprints.
  • Managed continuous vulnerability scanning data, extracting actionable events and transitioning those events to responsible support teams for effective remediation.
  • Revitalized company’s Computer Security Incident Response (CSIR) process to ensure consistent, rapid, and accurate responses to security events to provide containment and minimize impact.

Education

Master of Information Systems Management -

DeVry University
12.2004

Bachelor of Science - Computer Information Systems

Strayer University
03.1998

Skills

  • IT asset management
  • IT infrastructure
  • Data analysis
  • IT governance
  • Statistical analysis

Timeline

Senior Information Technology Analyst (TEK Systems)

First Citizens Bank
07.2024 - 01.2026

IAM Senior Analyst – Governance

State Employee’s Credit Union (SECU)
06.2023 - 07.2024

Information Security Process Engineer, Process, Risk, and Controls (PRC) Team Lead

United Services Automobile Association (USAA)
05.2022 - 06.2023

Information Security Governance Leader/Business Support Consultant

Wells Fargo Corporation
01.2018 - 01.2022

Information Security Governance Leader (TEKSystems)

Wells Fargo Corporation
01.2016 - 01.2018

Senior Program Manager, Information Security (TEKSystems and EttainGroup)

Bank of America
01.2011 - 01.2016

Senior Technology Project Manager, Identity and Access Management, (Signature Consultants)

Wells Fargo Corporation/Wachovia Corporation
01.2001 - 01.2011

Bachelor of Science - Computer Information Systems

Strayer University

Master of Information Systems Management -

DeVry University

Career Highlights

  • Centralized, standardized, and fully documented procedures and processes to manage all Identity and Access Management security controls ensuring they were regularly and effectively reviewed and updated.
  • Established a process to record participation, actions, and decisions in key Identity and Access Management routines, providing a complete inventory and traceability of all proposals, presentations, discussions, and decisions regarding the IAM Operations and Control.
  • Built a successful and transportable Identity and Access Management Governance Program, from the ground up that was lauded by Audit as a “best practice” and has been used as the model for other similar programs.
  • Ensured Identity and Access Management program decisions were participative and transparent, with clear documentation of the process from conception to implementation.
  • Ensured threats to global infrastructure were evaluated and escalated within 15 minutes of discovery, 24/7/365, resulting in quicker identification of, and response to threats.
  • Overhauled Computer Security Incident Response Team process that detailed team’s activities during major security-related events.
Michael Conner