About Chris Carpinello
I create solutions to optimize security operations in order to:
* Maintain business system availability
* Protect intellectual property
* Limit corporate liability
* Safeguard the corporate brand
* Ensure compliance
I achieve those business goals by embracing these security fundamentals:
* Confidentiality, Integrity and Availability
* Defense-in-depth
* Least Privilege
* Simplicity
* Education
* Information Assurance Vulnerability Management (IAVM)
* Network behavior analysis (NBA)
* Network intrusion prevention systems (IPS)
* Host and network intrusion detection systems (IDS)
Contents at a Glance
Social Networking
Connect with me!
Experience
Where I've made a difference
Focusing on military, civilian government and commercial organizations, this public 21,000 person company with $4B in revenue is a global leader in creating satellite-based network solutions that solve the toughest communication challenges. Worked with a team of seven to deliver solutions to Army and Marine Corps customers adherent to Department of Defense Information Assurance Certification and Accreditation Process (DIACAP), Army Regulations (AR25-2) and DoD 8500 directives on Windows and Solaris platforms.
* Rearchitected security update service to allow scaling with new business opportunities, significantly increasing quality and streamlining testing.
* Provided security architecture guidance during software development lifecycle to meet federal regulations and reduce vulnerabilities.
Senior Software Engineer at Lancope, Atlanta GA, 2002 - 2008
Focusing on Fortune 500 customers, this privately held 60 person company consistently outperformed competitors to remain on the network behavior analysis short list of industry analysts. Researched and developed enterprise security products with the Founder and Chief Research Officer using C and Perl on Linux and Cisco platforms.
* Architected new security product with Cisco to bring their threat mitigation Adaptive Control Technology to market.
* Increased revenue through prototype development and productization of NetFlow technology into StealthWatch, the company's flagship product.
* Enabled business by providing security expertise during request for proposals and Common Criteria evaluation.
* Optimized testing and manufacturing processes through creation of custom Linux platform, increasing quality and reducing time from hours to minutes.
Software Engineer at Internet Security Systems, Atlanta GA, 1997 - 2001
As a public company with 1,500 employees and $250M revenue, ISS dominated the vulnerability prevention enterprise market. Produced high quality deliverables for host and network information prevention products with application development teams of five to twelve engineers using C/C++, Tcl and Perl on Unix platforms.
* Awarded Product of the Year in 1999 and 2000 by Network Magazine for RealSecure (IDS).
* Engineered Nokia OEM partnership solution, porting RealSecure from Solaris to FreeBSD.
* Applied highly effective problem solving skills to become a valued asset to the team and company, through commitment to quality and consistently good development habits.
Software Engineer at Nortel Networks, Atlanta GA, 1995 - 1997
Nortel Networks is a publicly owned telecomm giant catering to the enterprise and carrier markets with $15B revenue and 70,000 employees. Provided services to engineers and quality assurance teams totaling 300 people as one of two configuration management developers using Perl and Tcl on Unix and VMS platforms.
* Lead critical migration project with a $600K project deadline penalty, delivering three weeks ahead of schedule.
* Exceeded performance ratings as recognized by 18 "thank you" emails, 1 peer award and 1 management award in a one-year period.
System Administrator at NASA Langley Research Center, Hampton VA, 1993 - 1994
Aerospace pioneering and atmospheric sciences are the core disciplines amongst NASA LaRC's 3,300 civil service and contract employees. Administered 100 Unix workstations in the Fluid Mechanics division, working with two IT operations personnel.
* Improved customer service satisfaction level resulted in a full-time job offer at the end of this internship position.
System Administrator at Old Dominion University, Norfolk VA, 1991 - 1994
The academic computing network at this 60-year old state institution brought together 3,000 faculty, undergraduate and post-graduate students. Cooperatively administered 300 Unix workstations with eleven other undergraduate students.
* Awarded highly competitive internship at NASA Langley Research Center after reducing helpdesk turnaround time and increasing uptime of computing resources.
Affiliations
Infragard, specifically the Atlanta chapter.
LinkedIn Answers
Career Management
I have a 4+ years of Technology experience as a Software Engineer in Wireless domain and now I am pursuing MBA. What kinds of opportunities I should be targetting once I complete MBA (three years from now)?
5 Secrets to Strengthen Your Brand
Computer Networking
Surviving a denial-of-service attack, what are your options?
Where can someone volunteer to do computer networking in the NY/NJ area to gain CCNA experience?
What are some of the more important and recognized IT certifications at present (MCSE, CCNA, etc...)?
Education and Schools
What subject do you think should be added to the school/college curriculum?
What changes would you like to see in entrepreneurship education?
Enterprise Software
With Sun's OpenOffice, Google Apps, and IBM's Lotus Symphony being free, does this pose a threat to MS office dominance?
Job Search
Tough times for commuters
Do services like LinkedIn prove the adage: 'it's not what you know but who you know' thats gets you ahead in your career, in life?
Should your boss be surprised to find that you have an account with Monster.com, Dice.com or the likes?
What are people's thoughts on the privacy issues surrounding Facebook profiles potentially appearing on Google results? What effect do you think this will have on the growing number of people, and organisations, using the site for recruitment purposes?
Information Security
What are the top 10 required features when selecting a network security product?
Intrusive testing professional tools
What is the biggest problem a CIO/CTO faces?
Anti-virus testing
Intellectual Property
How do you best contact a 'domainer' about a domain name that you believe infringes or is confusingly similar to your brand name?
Professional Networking
Credibility of members on social networking sites. How much do you consider that?
Resume Writing
Are IT resumes different?
Does earned LinkedIn "Expertise" belong on a resume?
Software Quality
How do you measure software quality?
Software Security
What does the phrase secure coding practices mean to you?
Wireless
Online course on Wireless LAN fundamentals: I'm looking for a good provider that can provide training on wave theory and antenna / radio application.
Networking and Security
Optimizing security and network operations is what I've done for almost a decade. These are the best technical titles I've come across.
Network Warrior by Gary Donahue
One of the best technical books I've ever read.0 points
The Tao of Network Security Monitoring: Beyond Intrusion Detection by Richard Bejtlich
Definitive work on why network behavioral analysis more...0 points
TCP/IP Illustrated Volumes 1-3 Boxed Set (Addison-Wesley Professional Computing Series) by W. Richard Stevens
The legend lives on.0 points
Software Security
Building Security In!
Put software security into practice with these excellent books.
Writing Secure Code, Second Edition by Michael Howard
Keep black-hat hackers at bay with the tips and te more...0 points
Unix Software Development
POSIX is your friend!
Invaluable technical references for all things POSIX and Unix.
The Zone
Music to code by
Mostly trance, techno, industrial and dance with high beats per minute and few lyrics.
Career Management
It's not who you know or what you know, but who knows what you know.
I highly recommend all of these books!
Challenge the way you think!
Productivity, Organization, Simplicity and Interaction
Fundamental books that have changed the way I think.













































