
Matthew Denis
@matthewdenis
I drive enterprise vulnerability remediation, access control, and security audit readiness.
What I'm looking for
At Bank of America, I lead application vulnerability closure for Global Markets Technology Risk & Regulatory Management, reducing open ADSF-related vulnerabilities by 42%.
I coordinate remediation plans, audit engagements, targeted risk assessments, evidence collection, RFIs, and executive reporting with technology, BISO, and leadership teams.
Previously at Truist, I implemented role-based access control for databases and servers, transitioned non-compliant access, and supported privileged access management with CyberArk, Okta, and SailPoint.
My work at Wells Fargo, DDB Worldwide, and First Data spans SAST/DAST, penetration testing, vulnerability remediation, intrusion detection deployment across 50+ global offices, and security standards including NIST, ISO 27001, GDPR, and PCI DSS.
Experience
Work history, roles, and key accomplishments
Led application vulnerability closure efforts on the Global Markets Technology Risk & Regulatory Management team. Collaborated with application managers to devise and track remediation plans, achieving a 42% reduction in open ADSF vulnerabilities.
Led the implementation of the Truist Role Based Access Control Model for databases and servers. Utilized CyberArk, Okta, and Sailpoint to enforce least privilege and manage privileged access.
Performed dynamic and static application security testing using HCL AppScan. Ensured IAM and PAM project deliverables were tracked and met, and processed Jira tickets for IT security issues.
Global IT Security Analyst
DDB Worldwide
Oct 2017 - Mar 2019 (1 year 5 months)
Led and coordinated the deployment of a host-based intrusion detection system to 50+ global offices. Enforced security standards including NIST, ISO 27001, and GDPR, and managed security awareness.
Information Security Analyst
First Data
May 2014 - Oct 2014 (5 months)
Performed manual and automated penetration testing on web applications to detect PCI DSS vulnerabilities. Analyzed security issues and provided remediation documentation to developers and management.
Education
Degrees, certifications, and relevant coursework
(ISC)²
CISSP, Information Security
Actively studying for the CISSP certification, with expected completion in Q1 2027.
New York Institute of Technology
Master of Science, Cyber Security
Grade: 3.60
Master of Science in Cyber Security from New York Institute of Technology, graduated with a GPA of 3.60 and Cum Laude honors.
CompTIA
CompTIA Security+, Information Security
2012 - 2015
CompTIA Security+ certification, valid from December 2012 to December 2015.
St. John's University
Bachelor of Science, Cyber Security
Grade: 3.69
Bachelor of Science in Cyber Security from St. John's University, graduated with a GPA of 3.69 and Cum Laude honors.
Availability
Location
Authorized to work in
Salary expectations
Social media
Job categories
Skills
Interested in hiring Matthew?
You can contact Matthew and 90k+ other talented remote workers on Himalayas.
Message MatthewGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
