John
Monaghan, CISSP, CISA, Security Assurance, Empire BlueCross BlueShield
John Monaghan is currently responsible for technical security
compliance at Empire BlueCross BlueShield where his responsibilities
include project management of the organization’s HIPAA Security
initiative, performing security due diligence reviews of prospective
business associates, and the monitoring of technical audit trails.
Prior to this position, Mr. Monaghan’s previous assignments
at Empire included project management of the organization’s
Gramm-Leach-Bliley Security initiative, support of the HIPAA Privacy
initiative, development of privacy compliance workflows, and helping
to ensure that the organization’s e-Business applications
are in compliance with privacy and security best practices. His
work with the e-Business applications included the development of
workflow requirements and in supervising privacy and security-related
system testing, Prior to Empire BlueCross BlueShield, Mr. Monaghan
worked in the Human Resources Outsourcing division of PricewaterhouseCoopers
(subsequently divested and sold to Mellon Financial Corporation)
as an internal Risk Management Consultant. At PricewaterhouseCoopers,
Mr. Monaghan assisted senior management in defining SAS 70 review
objectives, and the business units in defining the control objectives
and activities embedded in processes. He edited and updated narratives
that explained the business processes, for use in the SAS 70 reports.
Prior to that position, Mr. Monaghan was an Information Technology
auditor at IBJ Whitehall Financial Group and at the New York Power
Authority. At both organizations, he assessed the internal controls
of Information Technology areas including applications, Local Area
Networks (LANs), data security and contingency plans. He has also
held various applications development and computer operations positions.
Mr. Monaghan received his MBA in Finance/Information Technology
and his BS in Marketing/Finance from Fordham University. He has
earned the Certified Information Systems Security Professional (CISSP)
and the Certified Information Systems Auditor (CISA) certifications.
|