Job Title: Director – Global Security & Safety

TAL Global, an international security consulting firm, is seeking applications for the position of Director – Global Security & Safety, for a Palo Alto, California-based client. The client is a global leader in virtualization and cloud infrastructure, two areas that consistently rank as top priorities among CIOs. The company employs more than 9,000 employees in 40+ locations worldwide.

Job Description:

This is a leadership role, reporting directly to the VP of Real Estate & Workplace, and responsible for developing a holistic, global strategy for Corporate Security & Safety. The successful candidate would develop and implement a program aimed at mitigating physical risk and safeguarding people and assets, all in line with the company culture. This position is responsible for providing regional REW teams globally with the necessary standards, processes and guidance to ensure consistent implementation under an outsource model.

Key Responsibilities:

  • Create and document a clear, global Corporate Security & Safety strategy aimed at protecting employees, clients, and assets
  • Analyze business and global trends to determine and plan for both short-term and long-term security operational goals
  • Develop organizational policies and procedures that mitigate known risks to employees, clients, and assets related to workplace violence, travel, and emergency response
  • Partner with HR and Legal to ensure that the standards and procedures meet corporate goals and culture
  • Provide the regional REW teams with the tools, processes and training to manage security and safety proactively
  • Establish guidelines and procedures for crisis management and disaster response
  • Guide the regional REW teams in building emergency response teams and contingency plans
  • Provide leadership during a time of crisis
  • Establish a professional outsourced network globally to ensure best practices and measured results
  • Develop an ecosystem of best-in-class service providers in this field
  • Set standards and negotiate contracts with major outside providers
  • Develop security plans for corporate events globally
  • Lead a security technology roadmap for access control and monitoring facilities
  • Guide local REW teams to ensure compliance with local laws and safety regulations
  • Proactively develop safety programs for risk reduction and response to local, regional and global threats
  • Actively participate in the company Business Continuity Plan and Emergency Management Team
  • Lead and maintain an effective enterprise wide incident management tracking & response system
  • Serve as the central point of contact for global Security & Safety
  • Be an active member of the Real Estate & Workplace leadership and participate in the implementation of REW programs
  • Develop proficiencies in our company’s business style, planning cycle, real estate portfolio, and growth projections.

Required Qualifications:

  • 12 years minimum experience in corporate Security & Safety management in a high tech environment
  • World class understanding of Corporate Security & Safety best practices
  • Strong strategic, analytical and decision making skills
  • Ability to communicate complex concepts clearly
  • Ability to plan, coordinate and lead the work of others
  • Strong knowledge of the protective service industry, including best practices in physical, technical, personnel, information, legal, and administrative security disciplines
  • Experience in creating tools and processes and leading change in a high tech corporate environment
  • Knowledge of current and emerging security technology and integrated security systems
  • Knowledge of investigative techniques and best practices.
  • Proven leadership and organizational skills with a practical, operational sense
  • Ability to develop, administer and evaluate technical training related to protective services and employee security awareness
  • International experience in high tech corporate environment

Education Required:

  • A Bachelor of Science in Security Administration, Homeland Security, Criminal Justice or other Justice and Public Safety related field
  • Masters degree desirable

Location: Palo Alto, CA, US

Is this a remote or multiple location position? No

Job Segments: Cloud, Corporate Security, Criminal Justice, Emergency Management, Government, Homeland Security, Management, Manager, Real Estate, Safety, Sales, Security, Service, Technology, Virtualization

Please send CV and cover letter to: info@talglobal.net.

The Challenge – Proactive Hospital Security

Proactive hospital security

Proactive hospital securityMedical Centers and other healthcare facilities face a growing need to manage a spectrum of security issues ranging from workplace violence, through crimes against assets and people, to cyber incidents and even terrorist threats.

These very same facilities also face a unique “dual mission” dilemma: on the one hand they must provide an unrestricted environment for patients, staff, visitors and contractors while on the other hand, they must provide for a threat free environment to minimize all risks and ensure the safety and well being of patients, staff and visitors – and their property.

Preparedness, practiced action plans, and proper access control are a healthcare facility’s first “line of defense”. This can only be accomplished with an effective Environment of Care Security Management Plan and Risk Assessment Process. But a truly successful security strategy cannot remain passive; it must take into account the special needs of the facility, both during routine and emergency periods, the public nature of the facility, and the threats posed to the facility and its users from the outside and from within. In short, a successful strategy must be proactive and multi-layered. It must be able to constantly evaluate and present solutions to dynamically evolving risks.

To Learn More about Proactive Hospital Security, please download this white paper.

Contracting Tips – Prepare to Negotiate with IT Vendors

TAL Global’s General Counsel, Lawrence Dietz, Esq. was selected to present a Vendor Contract Workshop at the prestigious RSA Security Conference (www.rsaconference.com) held annually in San Francisco. This conference is the major information security event in the US. Competition for presenting slots is quite keen and normally only 1 in 11 are selected.

Mr. Dietz’s Peer to Peer session focused on vendor contracts and how customers can best position themselves during the negotiation. Neither than session or these notes are intended as legal advice. Legal advice can only be rendered by competent, licensed professionals.

The following comments and tips should be helpful to customers as they prepare to negotiate with IT vendors, especially with cloud services vendors. TAL Global does not provide legal advice, but we are delighted to work with your General Counsel to assist in the process or help with vendor contract problems.

Contracting Tips

  • The process is just as important as the substance.
    • Legal Perspective
    • Customer Perspective
  • Just about everything is negotiable.
  • You want to apply the law of your State and have any legal matters adjudicated in your home court. (no pun intended)
  • Know the authority level of the person or people on the other side. Just how much can they decide before going to someone else.
  • Does the penalty fit the crime? Merely refunding your monthly payment may not be enough compensation in many cases.
  • Cloud, shmoud – you need to know who are the subcontractors and where they are located. It is vitally important to know where the servers containing your data reside.
    • Legal reasons
    • Security Reasons
  • Benchmark/Milestone payments are a good approach as long as they are quantifiable.
  • Make sure you understand the escalation procedure.
  • Talk to at least three references – preferably about the same size you are, ideally same business, but not competitors.
  • Need to insure the honesty of vendor (and subcontractor) personnel working with your data. Vendors must certify that they have done a background check.
  • Bonding is probably only a remedy in the event of a reported crime.
  • If hardware or software is being supplied, make sure you have documentation of what it is and assurance of legal ownership.
  • Vendor should describe the physical and information security controls.
  • Primary contact needs to be vetted for technical and customer support skills.
  • Third parties: As with any third party, the vendor must identify the third party, describe what services the third party will be performing, and the qualifications of the third party. You should have the right to approve or disapprove. Disapproval should also include the right to terminate the contract without any of the stated penalties for early termination.
  • As with any third party, the vendor must identify the third party, describe what services the third party will be performing, and the qualifications of the third party. You should have the right to approve or disapprove. Disapproval should also include the right to terminate the contract without any of the stated penalties for early termination.
  • Document how or if your information will be used.
  • Decide if you want an automatic renewal or not.
  • Make certain all legal terms are defined to your satisfaction – especially key ones like material breach.
  • Prohibit the use of your organization’s name, logo, etc. without your written permission.

TAL Global Leading Edge InfoSec Presentations at RSA Conference 2012

Mr. Johnathan Tal, TAL Global’s President and CEO, and the company’s General Counsel and Managing Director, Information Security, Mr. Larry Dietz will both lead Peer2Peer Sessions at the upcoming RSA Conference 2012, February 27 to March 2 the Moscone Center, San Francisco, CA.

RSA, the Security Division of EMC, is the premier provider of security, risk and compliance solutions, helping the world’s leading organizations succeed by solving their most complex and sensitive security challenges. It was founded by (and named after) the inventors of public key cryptography: Ron Rivest, Adi Shamir and Leonard Adleman.

Mr. Tal’s session (Thursday, 3/1, 10:40am) is titled: Getting To The Why – A New Approach In Managing Risk. This session will explore and demonstrate how training and anticipating the human element is the path to innovative solutions that may help us fight the next battle not the last one.

Mr. Dietz will lead the Vendor Contract Workshop (Wednesday, 2/29, 9:30am). Participants will work with a practicing attorney to review sample contracts, and are encouraged to bring their own contracts for analysis as well. The workshop will examine and provide practical advice on issues concerning authority to contract, damages, arbitration and penalties. Think of it as Judge Judy meets Information Security vendors.

RSA Conference is helping drive the information security agenda worldwide with annual industry events in the U.S., Europe and Asia. Throughout its history, RSA Conference has consistently attracted the world’s best and brightest in the field, creating opportunities for conference attendees to learn about IT security’s most important issues through first-hand interactions with peers, luminaries and emerging and established companies. As the IT security field continues to grow in importance and influence, RSA Conference plays an integral role in keeping security professionals across the globe connected and educated.
More information can be found at: www.rsaconference.com.

TAL Global – Disaster Simulation Service

Enhanced Exercise Experience – combining modern simulation technology with the latest emergency preparedness and functional exercises practices.

Helping organizations address the challenges of:

  • Teams with little or no experience in real life events
  • The need for a more effective way to identify gaps of knowledge and experience on the teams
  • Facing an evolving set of threats which drives the need to run more complex exercises, with the same allocation of resources.

The solution includes:

  • Simulation technology to run functional exercises
  • Immersive experience for participants (they get involved, they love it)
  • Enhanced after-action (play-by-play) capabilities
  • “As real as it gets”; a fast paced environment  (where you inject distractions, escalations and confusion)

TSA Pre✓™ Pilot to Expand to Busiest U.S. Airports

Department of Homeland Security (DHS) Secretary Janet Napolitano and Transportation Security Administration (TSA) Administrator John S. Pistole today announced the expansion of TSA Pre✓™, a passenger pre-screening initiative, to some of the busiest airports across the country following the program’s success at seven pilot locations.

When implemented, the program will free TSA resources to enable better screening of “unknown” passengers, and expedite the screening of pre-vetted passengers – a win-win for security, civil aviation and passengers alike. This is a program the TAL Global has advocated for the past several years.

TSA Release:

Department of Homeland Security (DHS) Secretary Janet Napolitano and Transportation Security Administration (TSA) Administrator John S. Pistole today announced the expansion of TSA Pre✓™, a passenger pre-screening initiative, to additional airports across the country following the program’s success at seven pilot locations.

With more than 336,000 passengers screened to date through TSA Pre✓™ lanes, this screening concept enhances security by enabling TSA to focus its efforts on passengers the agency knows less about while providing expedited screening for travelers who volunteer information about themselves prior to flying.

“Good, thoughtful, sensible security by its very nature facilitates lawful travel and legitimate commerce,” said Secretary Janet Napolitano. “The expansion of TSA Pre✓™ to the nation’s busiest airports will increase our security capabilities and expedite the screening process for travelers we consider our trusted partners.”

“TSA Pre✓™ moves us closer to our goal of delivering the most effective and efficient screening by recognizing that most passengers do not pose a threat to security,” said TSA Administrator John S. Pistole. “We are pleased to expand this important effort, in collaboration with our airline and airport partners, as we move away from a one-size-fits-all approach to a more intelligence-driven, risk-based transportation security system.”

TSA Pre✓™ is currently operating with American Airlines at airports in Dallas, Miami, Las Vegas, Minneapolis and Los Angeles, and with Delta Air Lines at airports in Atlanta, Detroit, Las Vegas, and Minneapolis. US Airways, United Airlines and Alaska Airlines are all opting in new passengers and will begin operations later this year.

As part of the initiative’s expansion, TSA Pre✓™ will be implemented at the following airport locations throughout 2012:

· Baltimore/Washington International Thurgood Marshall Airport (BWI)

· Boston Logan International Airport (BOS)

· Charlotte Douglas International Airport (CLT)

· Cincinnati/Northern Kentucky International Airport (CVG)

· Denver International Airport (DEN)

· Fort Lauderdale-Hollywood International Airport (FLL)

· George Bush Intercontinental Airport (IAH)

· Honolulu International Airport (HNL)

· Indianapolis International Airport (IND)

· John F. Kennedy International Airport (JFK)

· LaGuardia Airport (LGA)

· Lambert-St. Louis International Airport (STL)

· Louis Armstrong New Orleans International Airport (MSY)

· Luis Muñoz Marín International Airport (SJU)

· Newark Liberty International Airport (EWR)

· O’Hare International Airport (ORD)

· Orlando International Airport (MCO)

· Philadelphia International Airport (PHL)

· Phoenix Sky Harbor International Airport (PHX)

· Pittsburgh International Airport (PIT)

· Portland International Airport (PDX)

· Ronald Reagan Washington National Airport (DCA)

· Salt Lake City International Airport (SLC)

· San Francisco International Airport (SFO)

· Seattle-Tacoma International Airport (SEA)

· Tampa International Airport (TPA)

· Ted Stevens Anchorage International Airport (ANC)

· Washington Dulles International Airport (IAD)

TSA will continue expanding TSA Pre✓™ to additional airlines and airports once they are operationally ready.

Eligible participants include certain frequent flyers from participating airlines as well as members of Customs and Border Protection’s (CBP) Trusted Traveler programs (Global Entry, SENTRI, and NEXUS) who are U.S. citizens and fly on a participating airline.

If TSA determines a passenger is eligible for expedited screening following the TSA Pre✓™ vetting process, information will be embedded in the barcode of the passenger’s boarding pass. TSA will read the barcode at the security checkpoint and then may refer the passenger to a TSA Pre✓™ lane, where they will undergo expedited screening, which could include no longer removing the following items:

· Shoes

· 3-1-1 compliant bag from carry-on

· Laptop from bag

· Light outerwear/jacket

· Belt

TSA will always incorporate random and unpredictable security measures throughout the airport and no individual will be guaranteed expedited screening. As part of the agency’s risk-based security initiative, TSA is currently testing several other screening initiatives, including initiatives designed to provide positive ID verification for airline pilots and the use of expanded behavior detection techniques.

Erroll Southers – Keynote Speaker at European-American Sheriff’s Advisory Council Event

Erroll Southers, TAL Global’s Managing Director for Counter-Terrorism and Infrastructure Protection was the keynote speaker at the 8th European-American Sheriff’s Advisory Council (EASAC) and European Consular Corps event.

Southers’ remarks entitled, “Counter-Terrorism: The Human Element” focused on the importance of understanding Terrorist Decision Making (TDM) in developing counter-terrorism and counter-radicalization strategies.

EASAC is comprised of representatives from many of the 49 national communities of Europe present in Los Angeles County. This council meets regularly with Sheriff Baca and other leaders of the Los Angeles Sheriff’s Department in an effort to foster strong communication and good relations between the Sheriff’s Department and the European American communities.

New Book: “Security and Game Theory”

Game Theory in the Service of Aviation Security

Dr. Milind Tambe’s new book, includes a chapter by Erroll Southers, Managing Director of  TAL Global’s Counter-Terrorism & Infrastructure Protection Division. The chapter: “LAX Terror Target: the History, the Reason, the Countermeasure” describes the pilot project leading to the innovative research transition program known as ARMOR (Assistant for Randomized Monitoring Over Routes).

ARMOR  is a game theoretic model developed at LAX and since deployed to protect infrastructure across the nation. This is a return on investment for Congress and the American people, demonstrating the value of interdisciplinary responses to the threat of terrorism.

The book is available on Amazon: http://www.amazon.com/Security-Game-Theory-Algorithms-Deployed/dp/1107096421

About the book:
Game theory provides a sound mathematical approach to deploy limited security resources to maximize their effectiveness. This book distills the forefront of this research to provide the first and only study of long-term deployed applications of game theory for security for key organizations such as the Los Angeles International Airport police and the U.S. Federal Air Marshals Service.

Larry Dietz on IT Security: Shady Rat Revisited

In August we published a commentary on Project Shady Rat, a research project orchestrated by McAfee (now part of Intel). We recently attended a meeting of the Silicon Valley Information Security Association, hosted by McAfee and where the features speaker was Vincent Weather, Sr VP of Engineering & McAfee Labs who previously was a senior research with Symantec.
Vincent had some interesting things to say which I would like to pass along.

First of all, he felt that hacking has gone through three stages: Fun, Profit and Espionage. Our view is that all of these activities are still going on. However, only recently has the extent of cyber espionage, at least by suspected nation states, been publicized. We believe, as do other experts, that nation states constitute the greatest threat simply because they have the most resources. Furthermore, in today’s economic climate, mere military secrets are not the only targets. Any information or clues that can provide an economic advantage by saving research time or optimizing production is fair game.

Another possibility for the increase in espionage, perhaps not by nation states, but by commercial entities or individuals is the new change to US patent law which gives deference to the “first to file” rather than the “first to invent”. Conceptually if an individual can steal enough info about your confidential project, he or she could file a patent application which would prevent you from benefiting from your own invention.

We have also seen several other examples of hostile activity that were specifically aimed at non military targets. There was Project Aurora (check out: http://www.youtube.com/watch?v=8Y5Vbp6qQRI) which was the name given to the suspected Chinese attacks against Google and Night Dragon which were targeted attacks against the Petrochemical Industry (see http://www.networkworld.com/news/2011/021011-night-dragon-attacks-from-china.html).

The cyber defense game will always be one of cat and mouse, moves and counter moves. Some new attack vectors include Skype calls and JPEGs to deliver malicious code. There is also a great deal of concern about an adversary’s ability to exploit a vulnerability before the vulnerability is generally known and/or to come up with novel attack vectors that were never used before and for which there is no proven defense.

Weafer believed that the commercial sector and government organizations are shifting their emphasis from concentrating on the ways and means of the technical features of the attack to determining the identity of the attack and perhaps exploring their motives.

In addition to Best Practices, to increase Global Awareness, the following are recommended:
• Logging
• Application Whitelisting
• Review and Monitor Internal Access Control (Insider threat or insider non-compliance with policy)
• DLP (Data Leak Protection) for exfiltration prevention and monitoring
• Rely on Partnerships with trusted organizations for information sharing.

TALGlobal is available to help those organizations wrestling with what the possibility of nation state or industrial espionage means to them and how to best thwart these attempts. We can provide a wealth of talent and experience to help you in these efforts.