Vanguard Security & Compliance 2012 Vanguard Website Home IBM Logo CA Tech
   

Instructors

Learn from the world´s leading IT and cyber security subject matter experts. Vanguard Security & Compliance speakers and instructors are the best in the security industry, representing industry leaders including: Vanguard Integrity Professionals, IBM Corporation, CA Technologies, NIST, Department of Defense, Acxiom Corporation, AHIMA, Terra Verde Systems, NMI, Key Resources, Experis ManpowerGroup, RSH Consulting, Technology Law Consulting, and Tata Consultancy Services. Learn the most advanced automated security methods, Best Practices and advanced techniques to enable you to secure System z and increase enterprise security.

Doug Behrends - Vanguard Integrity Professionals
Scott Blackmer - Founding Partner of InfoLaw Group LLP
Mike Buzzetti - IBM Design Center
Gayathiri Chandran - IBM Corporation
Wai Choi - IBM Corporation
John Connors - Vanguard Integrity Professionals
Thomas Cosenza - IBM Systems and Technology Group Lab Services
Brian Cummings - Tata Consultancy Services
Phil Emrich - Vanguard Integrity Professionals
Carla Flores - CA Technologies
Albert Ganley - CA Technologies
Edward M. Glagola Jr. - Glagola Consulting LLC.
Robert S. Hansel - RSH Consulting
John Hilman - Vanguard Integrity Professionals
Dave Hrycewicz - CA Technologies
Hoyt L. Kesterson II- Terra Verde Services
Bob Kleamovich - CA Technologies
Brian Marshall - Vanguard Integrity Professionals
Jim McNeill - Vanguard Integrity Professionals
Ernest Nachtigall - IBM Canada
Mark Nelson - IBM Corporation
Ray Overby- Key Resources, Inc.
Steven Ringelberg - Vanguard Integrity Professionals
Andrew T. Robinson - NMI LLC.
Ron Ross - National Institute of Standards and Technology (NIST)
Bill Rowehl - CA Technologies
Paul Rozek - Experis ManpowerGroup
Mitch Rozonkiewiecz - CA Technologies
David Schipper - CA Technologies
Barry Schrager - Xbridge Systems, Inc.
Bob Ubert - Vanguard Integrity Professionals
Bill Valyo - CA Technologies
Lou Ann Wiedemann - American Health Information Management Association (AHIMA)
Jim Yurek - Vanguard Integrity Professionals

Doug Behrends
Senior Professional Services Consultant
Vanguard Integrity Professionals


Doug Behrends Doug Behrends joined the Vanguard Professional Services team with over 30 years of information systems experience in 2003. Doug is currently focusing on remediation work to assist Fortune 500 companies in improving their security environment. Major activities related to this have included evaluating and implementing role-based security access structures and converting production batch processes from a single user ID to unique user IDs by line of business.  Prior to joining Vanguard, he performed multiple IT functions such as Operations Manager, Office Systems, Application and Systems programming and DB Management. His breadth of knowledge spans across numerous verticals including manufacturing, insurance and financial services where his expertise lent itself to MVS system installation and maintenance, productivity improvement/automation, security assessment and product design. Since 1997 Doug has focused his career solely on information security for z/OS and RACF. Before joining Vanguard as a full-time member of the Professional Services team, he contributed as a Beta tester for the Vanguard product suite. Today, in addition to his security activities, he continues to provide insight into streamlining and automating processes.

back to top

Scott Blackmer 
Founding Partner of InfoLaw Group LLP


Scott Blackmer W. Scott Blackmer is one of the Founding Partners of InfoLawGroup LLP. He has practiced information technology law since 1982. Scott has been listed in several peer-reviewed directories of prominent IT lawyers, including the Legal Media Group´s "Guide to the World´s Leading Technology, Media & Telecommunications Lawyers." Formerly a partner in the Washington, DC and Brussels offices of the firm now known as WilmerHale, Scott is a founding partner of InformationLawGroup and serves on the executive management team of the First Law International legal network (Brussels). He also consults on privacy, data protection, and security issues in association with HR Privacy Solutions (New York) and Jeitosa Group International (San Francisco). Scott is currently based in Salt Lake. A frequent speaker and writer on IT law and information privacy and security issues, Scott blogs at www.infolawgroup.com and contributed to the 2011 edition of "Information Security and Privacy" published by the American Bar Association. He has made presentations or taught seminars on these subjects at numerous industry and professional conferences, such as Vanguard, RSA, and Catalyst, at the University of Chicago, Johns Hopkins University, Carnegie-Mellon University, George Washington University, the University of London, the University of Toulouse, and the Catholic University of Buenos Aires, and at the US State Department (Washington, Berlin, Brussels, and Shanghai), the European Commission, the Council of Europe, the International Monetary Fund, the Multilateral Investment Fund, and the Electronic Commerce Promotion Council of Japan. Scott acts as general counsel to the Trusted Computing Group and XDI.org, and he counsels other industry associations as well as corporations and individual entrepreneurs. He has advised US federal and state agencies and the European Commission on privacy and security issues, and he has served as a privacy advisor to the US Social Security Administration. Scott also arbitrates Internet domain name disputes brought before the World Intellectual Property Organization (WIPO) in Geneva. Scott has worked on transactions and licensing, compliance issues, litigation, and arbitration matters in over 100 countries.

back to top

Mike Buzzetti
IT Architect IBM Design Center


Mike BuzzettiMike Buzzetti is an IT Architect at the IBM Design Center with worldwide focus on client enterprise infrastructures. He began his IBM career in 2003 at the Test and Integration Center for Linux. In 2006 Mike joined the Design Center, where he helps customers architect and design optimized IT infrastructures. He designed a number of infrastructures that featured Linux on the mainframe and has had extensive experience helping clients leverage virtualization in complex environments. More recently, Mike has been a leader in implementing cloud computing. Mr. Buzzetti has authored a book on J2EE on z/OS®, Deploying a Cloud on System z, Deploying Cloud Components on Power, and many white papers.


back to top

Gayathiri Chandran
Advisory Software Engineer
IBM


Gayathiri ChandranGayathiri Chandran is an Advisory Software Engineer at IBM Silicon Valley Laboratory. She has 11 years of experience in DB2 for z/OS development. She is currently the team lead for DB2 for z/OS security and her responsibilities include design and development of security functions in DB2 for z/OS. She has led many security-related projects such as network trusted contexts, roles and new DB2 authorities.




back to top

Wai Choi
Senior Software Engineer, IBM


Wai Choi Wai Choi is a Senior Software Engineer for IBM in Poughkeepsie, NY where she has worked for over 14 years. Wai spent her early years with the company in Function Test and Development and now works in design for digital certificate supporting RACF and PKI services since z/OS V1R7. Her extensive expertise focuses on Digital Certificate support for multiple components of z/OS: RACF (RACDCERT, callable services), PKI services and System SSL. Wai is an industry expert, active educator and speaker whose engagements have included SHARE, where she received a Best Session award, Vanguard Security & Compliance, RACF User Groups and multiple IBM hosted events like System z Security Conference and zExpo. She also actively participates in the RACF-L Forum answering certificate-related questions.

back to top

John Connors
Senior Professional Services Consultant
Vanguard Integrity Professionals


John Connors John Connors has more than 8 years of z/OS experience in RACF, TCPIP, LDAP, PICC and DB2 subsystems. His technical expertise and certifications include Microsoft Certified Systems Engineer (MCP, MCP+I, MCSE - 1357178), Cryptographic System Repairman, Computer Languages including .NET, C#, C++, ADA, PHP, Visual Basic, HTML, SQL, Perl, Dbase III, ACCESS; CISCO Firewalls, Switches, Routers, Frame Relay, ATM, Microsoft Information Server, Microsoft SQL Server, Microsoft Site Server, VTEL Video Communications Systems, TC2000, Multi-point Conference units, AT&T Switches, Dimension 400, 2000, System 75/85 and G3. Prior to joining Vanguard, John served for over 24 years in the United States Air Force where he was the Secure Communication Specialist/Superintendent of Network Operations. After a long, successful career with the service, he retired as Chief of Special Projects responsible for managing command control communication and computer systems. John's wide-ranging knowledge base spans Microsoft, IBM, SUN, Cisco, Novell, and Nortel technologies. John's background and integral roles include Operations Manager and Chief Architect for a large ASP and Senior Systems Engineer for a major network integrator. John Connors joined Vanguard´s Professional Services Team as a Senior Professional Services Consultant in April 2002. Today, John guides and aids clients with various z/OS issues including RACF security assessments, z/OS TCPIP/UNIX implementation evaluations and network-based assessments.

back to top

Thomas Cosenza
Security Architect for z/OS, z/VM, and Linux on System z
IBM Systems and Technology Group Lab Services


Thomas CosenzaThomas Cosenza is a Networking and Security Solutions Architect with IBM Systems and Technology Group Lab Services. Thomas has worked in System z after graduating from the University of Florida in 1998 and has built a career around providing solutions to customers for their enterprise environments. Thomas is a certified IT Specialist and CISSP certified in good standing.




back to top

Brian Cummings
North American Lead for Information Risk Management Advisory Services
Tata Consultancy Services


Brain CummingsBrian Cummings is the North American lead for Information Risk Management Advisory services at Tata Consultancy Services (TCS). Prior to TCS, Brian was a Director at LECG, an expert services firm; and before that served nearly nine years as a Sr. Manager/Director at KPMG in Risk Advisory Services/Information Risk Management. He has been an information security, risk management, audit, and business continuity professional since 1977 with a diversity of industry experience. Considering the current threat, risk, and regulatory environment, Brian fosters more than thinking outside of the box. Instead, we need to blow the box up, examine our premises, refocus our vision and effort on what is important, and make the most of automated, repeatable, and sustainable solutions and overcome an unbalanced focus on administrative activities, manual processes, misaligned responsibilities, and unfocused effort.

back to top

Phil Emrich
Senior Professional Services Consultant
Vanguard Integrity Professionals


Phil Emrich Phil Emrich has nearly 40 years of experience in the information technology field. Phil spent 31 years with IBM where he held a number of crucial roles and responsibilities that included technical consulting to customers, technical product support to sales engineers and guidance to IBM´s software development laboratories. Throughout his remarkable career Phil garnered expertise that spans IBM z/OS Security Server (RACF), security for multiple versions of the IBM Customer Information Control System (CICS®), IBM´s cross-platform messaging software, WebSphere® MQ (formerly MQSeries), IBM Information Management System (IMS™) and IBM DB/2 relational database software. Phil is a member of the IBM Gold Team of Independent Consultants and holds certifications in IBM smA2Rt CA ACF2™ to RACF Migration Tools, CA TopSecret® (TSS) to RACF Migration Tools, and has been certified to instruct CICS, RACF, and DB2 courses for IBM. Additionally, he is also an integral member of Vanguard´s Professional Service team where he consults with clients on all facets of z/OS and RACF security. As a premier subject matter expert Phil is an active educator and speaker in the U.S., UK, and Europe. His engagements include SHARE, GSE, numerous IBM sponsored conferences and Vanguard’s own annual Security Conference for 25 years. Phil holds a Bachelors of Science in Mathematics from Purdue University.

back to top

Carla Flores
Principal Product Marketing Manager, Mainframe Security
CA Technologies


Carla FloresCarla Flores is responsible for building market awareness and brand growth for the CA Technologies mainframe solutions. She has over 15 years of experience in mainframe security and compliance as related to product management, pre-sales, consulting, system analysis and business process reengineering. Carla also serves as a volunteer on the Security and Compliance Project with SHARE.
back to top



Albert Ganley
Director, Pre-Sales
CA Technologies


Albert GanleyAlbert Ganley has over 25 years of experience in mainframe computing environments. Getting his start in the business with General Dynamics in operations in the 1980s, Albert moved on to Maxima managing operations for the Naval Military Command Post. In the late 1980's Albert began his career supporting CA software products for DISA out of Hill Air Force Base working for Aries Systems as a consultant supporting the production control products. In 1991, Albert Joined CA Technologies in federal services and moved into project management and over to his current role as a pre-sales director within the Mainframe Global Pre-sales Group. back to top


Edward M. Glagola Jr.,
Glagola Consulting LLC.


Ed Glagola recently retired from the US Government Accountability Office (GAO) and has 40 years of government experience in Information Technology Security and Information Technology Operations. Ed spent his early years at GAO as an Information Technology Auditor and Computer Specialist. He left the GAO to take the position of Director of Information Technology (CIO) at the Department of Transportation, Office of Inspector General (OIG), where he managed the OIG's technical EDP audit group and internal IT support functions. Ed rejoined GAO in March 1997 and was the Senior Assistant Director in GAO's eSecurity Lab. The eSecLab provides GAO with the capability to conduct technical Information Security Assessments at Government Department and Agencies and provides GAO's mainframe data center. Ed's specialties include enterprise systems, networking and integration technologies.
back to top

Robert S. Hansel
Lead RACF Specialist and Founder
RSH Consulting


Robert HanselRobert S. Hansel is Lead RACF Specialist and founder of RSH Consulting, Inc., a firm he established in 1992 that is dedicated to helping clients strengthen their IBM z/OS mainframe access controls by fully exploiting all the capabilities and latest innovations in RACF. He has worked with IBM mainframes since 1976 and in information systems security since 1981. Mr. Hansel began working with RACF in 1986 and has been a RACF administrator, manager, auditor, instructor, developer, and consultant. He has reviewed, implemented, and enhanced RACF controls for insurance firms, financial institutions, utilities, manufacturers, payment card processors, universities, hospitals, and international retailers. Mr. Hansel is especially skilled at redesigning and refining large-scale implementations of RACF using role-based access control concepts. He has created elaborate automated tools to assist clients with RACF administration, database merging, identity management, and quality assurance. Mr. Hansel has also developed and presented training on nearly all aspects of RACF implementation, administration, and auditing. back to top

John Hilman
Senior Professional Services Consultant
Vanguard Integrity Professionals


John Hilman John Hilman brought over 25 years of information systems experience when he joined Vanguard´s Professional Services team in 2005. Leveraging his technical background and expertise, John aids clients with security assessments, remediation projects, DB2 internal security migration and training for security administrators. Prior to joining Vanguard, John spent 20 years with IBM, the last five as a Certified Technical Trainer for RACF security. Throughout his extensive career, he has held numerous IT positions in Computer Operations, Systems Programming, Security Audit and Security Administration. After his tenure at IBM, John accepted the role of Training Director at EKC, Inc. where he was responsible for training security administrators and auditors on using the CA ACF2 and RACF security subsystems. John´s expertise has made him a highly sought after speaker and educator. His engagements include CA World, IBM Secure World and Vanguard´s own Security Conferences, where he has been awarded the Top Gun Award three times. Vanguard´s prestigious Top Gun Award is reserved for the instructor that receives the highest rating from students following the conference.

back to top

Dave Hrycewicz
Software Architect, Mainframe Security
CA Technologies


David HrycewiczDave Hrycewicz has over 30 years of mainframe applications programming, systems programming, IT security/auditing, and software development experience. For the past 27 years at CA Technologies, Dave has worked for the mainframe security product development team and is responsible for numerous enhancements to CA ACF2, CA Top Secret, CA Auditor (formerly CA Examine), CA Compliance Manager for z/OS, and many other products. Dave is a seasoned speaker and has delivered many presentations at CA conferences, SHARE conferences, as well as at numerous user group meetings, customer meetings, and internal training opportunities. back to top



Hoyt L. Kesterson II
Senior Security Architect
Terra Verde Services


Hoyt L Kesterson llHoyt L. Kesterson II is a Senior Security Architect with Terra Verde Services in Scottsdale, Arizona. He has more than 40 years of experience in information security and related technologies. For 21 years he chaired the international standards group that created the X.509 digital signature certificate, a fundamental component in digital signature and securing web transactions. He is a founding member and vice-chair of the American Bar Association's eDiscovery and Digital Evidence Committee and a founding member of the Information Security Committee. He is a testifying expert. He is a frequent and top-rated speaker at the RSA Conference. He has participated on ALI-ABA and ABA CLE web-casts on a variety of topics and lectured on data breach at the ABA 2008 Annual meeting. He is an acknowledged contributor to a book on e-discovery and a book on digital data and the rules of evidence, both published by the ABA. back to top

Bob Kleamovich
Sr. Consultant, Pre-Sales, Mainframe Security
CA Technologies


Bob KleamovichBob Kleamovich has over 25 years of experience in mainframe computing environments. Bob got his start in Information Technology with the US Air Force, both working in and managing data processing facilities in both the Pacific and European theaters. Entering the private sector in the early 1990's, Bob worked primarily for larger financial institutions, managing their mainframe security programs. Bob has extensive experience converting between the three mainframe security products. Bob also created a mainframe-centric Identity Manager for one of his employers; before Identity Management was an industry standard. back to top



Brian Marshall
Vice President of Research and Development
Vanguard Integrity Professionals


Brian Marshall Brian Marshall joined Vanguard in 2006, serving initially as Director of Research & Development until 2010. Brian was the primary architect and visionary behind Vanguard Configuration Manager, and is an expert on NIST security standards. Prior to joining Vanguard, Brian served 11 years in software development management at Computer Associates and Innovative DP Designs, Inc. He holds one shared patent on a method of reorganizing IMS databases online. Brian has been a Professor of Computer Science at Solano College in California. He holds a B.S. Degree in Computer Science and an M.B.A, both from Sonoma State University. Brian is a frequent speaker at RUGS on various z/OS security and compliance topics, and is the Vanguard representative for OASIS, where he is helping to define communication protocols that will be applicable for cloud computing in the future.

back to top

Jim McNeill
Senior Professional Services Consultant
Vanguard Integrity Professionals


Jim McNeill With more than 40 years of experience in Information Technology and Systems Programming, Jim McNeill leverages his extensive knowledge base and expertise to assist with ACF2/TSS migrations to RACF, DB2 internal security to RACF, z/OS and RACF assessments, RACF remediation projects, RACF basic and advanced training along with Vanguard security software implementations. Before joining Vanguard´s elite Professional Services team, Jim worked in the company´s research and development labs as Director of Research & Development where he was responsible for the first three releases of Vanguard´s flagship software – Vanguard Administrator. In addition to these accomplishments, Jim served as the Lead Architect and Team Leader for both the Advisor and Analyzer products. Jim´s notable accomplishments include performing multiple large ACF2 and CA Top Secret to RACF migrations for Fortune 500 companies and leveraging his expertise in assembler language to code User Exits and convert ACF2 calls to RACROUTE calls for RACF. His certifications include IBM ACF2/TopSecret to RACF Migration Engineer, IBM RACF Instructor and Vanguard Product Instructor. Jim is an active educator and speaker on information security. His engagements have included GUIDE, SHARE and Vanguard Security & Compliance.

back to top

Ernie Nachtigall, CISSP, CISA
Certified IT Consultant and Open Group Master Certified IT Specialist
IBM Canada


Ernie NachtigallErnie Nachtigall, CISSP®, CISA, is a Certified IT Consultant and Open Group Master Certified IT Specialist for IBM where he has worked since 1969. Ernie began in operations and system programming eventually transitioning to application programming ("C", PL/1, PL/X, PASCAL, BASIC, COBOL, FORTRAN, FCL and ASSEMBLER). In 1971, he was the first at IBM Canada to become involved in the burgeoning discipline of z/OS cryptography and its associated implementations. Ernie actively participated in authoring code for ATM, teller, PIN and 3270 emulation solutions and assisted in the design of IBM´s 475. Ernie is an active educator and speaker whose engagements include SHARE, IBM Secure World, IBM zExpo, Vanguard Security & Compliance and multiple user groups such as CMG. His highly sought after cryptography expertise has led him to conduct classes across the globe including Australia, Germany, The Netherlands, France, Denmark, South Africa, Singapore, Hong Kong, New Zealand, China, Brazil, Canada and the US. back to top

Mark Nelson, CISSP®, CSSLP
Senior Software Engineer, IBM, z/OS Security Design & Development


Mark Nelson Mark Nelson, CISSP®, CSSLP™ has been a long-standing featured expert and educator at the Vanguard Security & Compliance. As an enthusiastic mentor and presenter, Mark has secured the Vanguard "Top Gun" award four times, an honor reserved for the instructor that receives the highest rating from attendees following the event. In addition to this tribute, Mark was the recipient of the 1999 Vanguard "Chairman´s Award" and has received several SHARE "Best Session" awards and continues to be an active speaker on RACF. Mark is a co-author of the book Mainframe Security for Security Experts: An Introduction to RACF, has helped write several Redbooks, and has published articles in NaSPA´s Technical Support, z/Journal, and IBM´s Hot Topics. Mark is a Senior Software Engineer with IBM´s z/OS Security Server Design and Development Team in Poughkeepsie, NY where he has devoted the past 23 years working on RACF auditing and data analysis (IRRDBU00, IRRADU00, and RACFICE), RACF´s Health Checks, RACF/DB2, and RACF´s support for digital certificates.

back to top

Ray Overby
President
Key Resources, Inc.


Ray Overby began his career as an MVS Security guru in 1981 when he joined SKK, Inc. as an ACF2 software developer. ACF2, for many years, was the leading mainframe software security product. Ray was responsible for maintaining and enhancing the security interface code (SVC A and SVC S), the ACF2 MVS intercepts, and the main ACF2 task. Ray was responsible for designing and implementing the first distributed database for security data propagation across networks.

Ray has been published in a number of computer magazines, including z/Journal and Technical Support Magazine. He has also presented at regional and national computer Security Groups, as well as SHARE, and at a variety of security conferences.

Ray left SKK in 1988 during the acquisition by CA Technologies. He formed a software and consulting company, Key Resources, Inc (KRI). KRI does security software development, security consulting, security assessments, security system conversions, and z/OS penetration testing. Ray's latest achievement is the development of the zAssure™ software product which performs automated penetration testing in z/OS for integrity based vulnerabilities. This penetration testing is required by all major compliance standards such as PCI-DSS, NIST 800-53, ISO 27001, HIPPA, and SOX. back to top

Steven Ringelberg 
Chief Global Strategist,
Vanguard Integrity Professionals


Steven Ringelberg Steven Ringelberg is the Chief Global Strategist of Vanguard Integrity Professionals. Ringelberg joined Vanguard in 2007 serving initially as General Counsel. He has also served as Vice President of Business Development, Director of International Operations, Director of Professional Services, Vice President of Worldwide Sales and Marketing, and Chief of Staff to the CEO. He was appointed Chief Operating Officer in 2009 and Chief Global Strategist in 2012. Ringelberg is responsible for the strategic and operational leadership of the company´s Worldwide Sales, Professional Services, Customer Support, Quality Assurance, IT, Human Resources, Training, Marketing and International Operations organizations. Prior to Vanguard, Ringelberg served as Chief Administrative Officer for Exstream Software, an enterprise document automation software vendor, now an HP company, where he provided oversight to Human Resources, Finance, IT, Legal and Administration.

Before joining Exstream Software, he held positions as Director and General Counsel for Honkworm International, an online media company based in Seattle, Washington; Director and General Counsel for Agile Equity, a technology-focused boutique investment bank headquartered in Paris, France and New York City; and Corporate Counsel for Microsoft in Paris, France. Before joining Microsoft, Ringelberg was in private practice with Webster & Sheffield in New York City and Curtis, Mallet-Prevost, Colt & Mosle in Washington DC. In addition to his current responsibilities, Ringelberg is an active educator and speaker. His engagements have included SHARE, ISSA, Vanguard Security & Compliance, the Forum for Incident Response and Security Teams conference and other events throughout the years. Ringelberg holds a BA in History from Oberlin College and a JD from New York University School of Law. back to top

Andrew T. Robinson
Founder and President
NMI LLC


Andrew T RobinsonAndrew T. Robinson (Andy) is the founder of the EGRC and EITC conference series, and the founder and President of NMI LLC. Andy has over 30 years of professional experience in enterprise architecture, security architecture, governance, risk management, compliance, information technology, and software engineering. Andy created one of the first processes for enterprise, security, and enterprise IT architecture (RAPID), the RSK quantitative risk assessment process, The Martial Art of Security, Governance, Risk Management & Compliance Training Program, and the STORM enterprise risk management (ERM) process and methodology.
back to top


Ron Ross
National Institute of Standards and Technology (NIST)
Senior Computer Scientist and Information Security Researcher


Jim YurekRon Ross is a Fellow at the National Institute of Standards and Technology (NIST). His current areas of specialization include information security and risk management. Dr. Ross leads the Federal Information Security Management Act (FISMA) Implementation Project, which includes the development of security standards and guidelines for the federal government, contractors, and the United States critical information infrastructure. His recent publications include Federal Information Processing Standards (FIPS) Publication 199 (security categorization standard), FIPS Publication 200 (security requirements standard), NIST Special Publication (SP) 800-53 (security controls guideline), NIST SP 800-53A (security assessment guideline), NIST SP 800-37 (security authorization guideline), NIST SP 800-39 (risk management guideline), and NIST SP 800-30 (risk assessment guideline). Dr. Ross is the principal architect of the Risk Management Framework and multi-tiered approach that provides a disciplined and structured methodology for integrating the suite of FISMA standards and guidelines into a comprehensive enterprise-wide information security program. Dr. Ross also leads the Joint Task Force Transformation Initiative, a partnership with NIST, the Department of Defense, the Intelligence Community, the Office of the Director National Intelligence, and the Committee on National Security Systems to develop a unified information security framework for the federal government.

In addition to his responsibilities at NIST, Dr. Ross supports the U.S. State Department in the international outreach program for information security and critical infrastructure protection. Dr. Ross previously served as the Director of the National Information Assurance Partnership, a joint activity of NIST and the National Security Agency. A graduate of the United States Military Academy at West Point, Dr. Ross served in a variety of leadership and technical positions during his over twenty-year career in the United States Army. While assigned to the National Security Agency, he received the Scientific Achievement Award for his work on an inter-agency national security project and was awarded the Defense Superior Service Medal upon his departure from the agency. Dr. Ross is a three-time recipient of the Federal 100 award for his leadership and technical contributions to critical information security projects affecting the federal government and is a recipient of the Department of Commerce Gold and Silver Medal Awards. Dr. Ross has been inducted into the Information Systems Security Association (ISSA) Hall of Fame and given its highest honor of ISSA Distinguished Fellow. Dr. Ross has also received several private sector cyber security awards and recognition including the Vanguard Chairman's Award, the Symantec Cyber 7 Award, InformationWeek's Government CIO 50 Award, Best of GTRA Award, and the ISACA National Capital Area Conyers Award. During his military career, Dr. Ross served as a White House aide and as a senior technical advisor to the Department of the Army. Dr. Ross is a graduate of the Defense Systems Management College and holds Masters and Ph.D. degrees in Computer Science from the U.S. Naval Postgraduate School specializing in artificial intelligence and robotics.

back to top

Bill Rowehl
Principal Consultant, Pre-Sales, Mainframe Security
CA Technologies


Bill RowehlBill has over 25 years of experience in mainframe computing environments, Operations, programming, Systems Programming and Technical Support Management. Bill has worked on numerous operating system and mainframe installations over the years and has been involved with the operation, support and security on z/OS, Linux on System z, AS/400 and UNIX systems. Bill has worked for CA Technologies for the last two years in a pre-sales capacity for the security and compliance solutions. back to top



Paul Rozek, CGEIT™ 
Engagement Manager, Experis ManpowerGroup


Paul Rozek Paul Rozek is a subject matter expert in the Risk Advisory Services practice for Experis (formerly Jefferson Wells). With over 30 years of professional expertise, Paul has also held positions as CISO for a major financial services' service bureau and IT Audit Officer for a large bank holding company. In his current role, Paul supports sales and delivery of information security, privacy, regulatory compliance, and IT control services for his firm´s global client base. He is an active member of ISACA, IIA, and ISSA. Additionally as a recognized subject matter expert, Paul regularly presents at numerous security, audit, and control conferences.

back to top

Mitch Rozonkiewiecz
Sr. Director, Software Engineering, Mainframe Security
CA Technologies


Mitchell RozonkiewieczMitchell Rozonkiewiecz is a 26-year IT industry veteran and for the last 20 years he has held various positions of increasing responsibility within the CA Technologies mainframe security research and development organization. In his current role, Mitchell is responsible for the CA Compliance Manager for z/OS solution as well as the technology that facilitates integration between CA ACF2 and CA Top Secret for z/OS with other platforms. The integration includes the distributed security line such as CA IdentityMinder, CA SiteMinder, CA ControlMinder and CA ELM as well as user authentication integration of Linux on System z. back to top


David Schipper
Senior Advisor, Product Management
CA Technologies


David SchipperDavid Schipper is the Product Manager for the CA Technologies mainframe security products, including CA Mainframe Chorus for Security and Compliance Management, CA ACF2™, CA Auditor for z/OS, CA Cleanup, CA Compliance Manager for z/OS and CA Top Secret®. David has over 35 years of experience in the IT industry in both IBM mainframe and distributed environments. He has held positions in applications development, systems programming, sales, sales management, product management and management. back to top



Barry Schrager
President and COO
Xbridge Systems, Inc.


Barry SchragerBarry Schrager has an unquestioned history of design and development in mainframe software and security. He is honored to be a member of the Mainframe Executive Magazine's Mainframe Hall of Fame along with such luminaries as Thomas J. Watson, Jr., Gene Amdahl and Admiral Grace Hopper. Barry was the designer and primary author of the ACF2 mainframe security product in 1978 which has now generated more than $1 billion in revenues. He also developed software to improve the RACF and ACF2 security system reporting by access analysis and categorization of resources, developed other data security products and contributed to the development of the Shadow SOA product (now from DataDirect). Barry is also an experienced company developer -- started SKK in 1978 with 3 employees and built it to 160 employees in five countries and revenues of $26 million in 1986. back to top

Bob Ubert
Senior Professional Services Consultant
Vanguard Integrity Professionals


Bob Ubert Bob Ubert has over 30 years of mainframe experience and is a 21 year veteran of IBM specializing in IBM Security Server (RACF®). Before joining IBM, he was a mainframe systems programmer for three Fortune 500 companies. His career with IBM began as a consultant in the Heartland Services Center where his projects spanned from system programming in the VM and MVS areas to coding a major assembler Object Access Method Application. In 1993, he transferred to the IBM Education Company as an instructor where he taught security (RACF) and storage curriculum. In 2005, Bob joined the IBM Software Migration Project Office (SMPO) where he assisted customers migrating to RACF and provided technical sales support for Vanguard and zSecure products.  Today, Bob is a member of the Vanguard Professional Services team where his expertise is leveraged by providing RACF security assessments and remediation, CA ACF2 and CA TopSecret migration assessments and migration services. Additionally, he remains an active educator providing training to customers utilizing RACF and the Vanguard product suite.

back to top

Bill Valyo
Sr. Consultant, Pre-Sales, Mainframe Security
CA Technologies


Bill ValyoBill Valyo was raised on the IBM mainframe, starting his career as a computer operator, then moving to systems programming and ultimately IT Manager of a mainframe shop. Bill worked as a consultant for 18 years on projects all over the world until taking a job with CA Technologies as a mainframe security specialist. In this capacity, he has worked with customers all over North America, helping guide them through their compliance woes.
back to top



Lou Ann Wiedemann, MS, RHIA, FAHIMA, CPEHR
Director of Professional Practice Resources
American Health Information Management Association (AHIMA)


Lou Ann WiedemannLou Ann Wiedemann, MS, RHIA, FAHIMA, CPEHR is the Director of Professional Practice Resources at the American Health Information Management Association (AHIMA). In her role, Wiedemann provides professional expertise on health information management (HIM) practice issues. Her areas of expertise include the management and implementation of electronic health records, and privacy. She provides AHIMA members, the media and outside organizations expertise through articles publications and presentations. Prior to joining AHIMA in 2006, Wiedemann was employed as director of HIM at a large metropolitan academic medical facility. In this position she oversaw all HIM functions, including campus-wide record storage, reference lab billing, trauma registry functions, coding and abstracting. Before this, Wiedemann served in various HIM roles, ranging from Assistant Director of HIM to Director of Utilization Review. back to top

Jim Yurek, CISSP®
Senior Professional Services Consultant
Vanguard Integrity Professionals


Jim Yurek Jim Yurek, CISSP®, joined the Vanguard Professional Services team as a Professional Services Consultant in 2009. Bringing more than 30 years of Security Server (RACF) experience, his current focus is on PCI-DSS compliance and remediation projects, and technical sales support and training for Vanguard Policy Manager and Vanguard Configuration Manager. Prior to joining Vanguard, Jim spent 20 years working as an information security manager with several financial services enterprises. Throughout his extensive career, he has had multiple IT responsibilities including applications programming, system programming, security administration, RACF consulting, business recovery, product management, PCI compliance and information security management. back to top

Sessions, instructors and speakers are subject to change.