-
Jc Consulting Service
Distance: 2.3 Mi65 S C St
95376-4538 Tracy -
R.L. Johnson & Associates
Distance: 3.7 Mi1241 Citadelle St Tracy
95304 Banta -
Beyond the Box
Distance: 14.6 Mi5455 Keeler Ct
94550-7135 Livermore -
WSI Internet Consulting & Education
Distance: 15.2 Mi4435 1st St
94551-4915 Livermore -
Digital Media Advocates
Distance: 15.5 Mi4049 First Street, Suite 235
94551 Livermore
Website Links
Description
Edward Frye is an Information Security Technologist with over 15 years experience in Linux Systems administration, network engineering, information security architectures, compliance, and policy management. Edward is well versed in many aspects of IT from hardcore hands on PERL and PHP coding, SQL scripting, Systems Administration (both windows and linux), to big business concepts of enterprise architecture, business requirements, cost-benefit analysis, risk management, and so on. Edward is also an amateur photographer, and motorcycle enthusiast. Both of which are hobbies he developed after being well established in the information technology and security arena. This website will encompass many aspects of Edward's life in regards to Information Security, Photography, Motorcycles, and anything else that suits his fancy. Below is an abridged auto biography of Edward's career path into information security. You could say my information security career started even before I joined the global workforce. In high school, I was interested in computers and computer security. I started taking computer programming classes in my senior year. While there, rather than learning how to draw flow charts, or writing BASIC code on paper, I was more interested in finding out the different security levels and how easy it was to perform privilege escalation. Directly out of high school, I joined the U.S. Air Force and enrolled in a program to become a "Computer Communications Systems Control Specialist", where they taught us about analog and digital communications, frequency division multiplexing (not used much for standard voice, but still used in DSL lines, Radio communications, etc); time division multiplexing (currently used today in T1, ISDN, SONET, etc); Phase-shift Keying; Radio frequency communication; basic IP networking; basics about cryptography; mandatory access control methodology; and so much more. After training, I was stationed at McChord Air Force Base in Tacoma Washington, where I was a member of the 62nd Communications Squadron (62CS). We were responsible for all the data communication on the base. Setting up Ethernet networks, making sure the long haul data lines were operational. Most of these lines were 4-wire 56k modem lines because it was too far between buildings for Ethernet or T1 lines, and when I was there, the entire base hard wired digital communications ran through a single T1 line. The base had its own telephone switch, and many of the buildings had their own Meridian PBX systems. I continued to learn layer 2 and layer 3 network troubleshooting; segregation of duties and its importance in Mandatory Access Control (MAC) environments; and other basic troubleshooting skills. My next technical job after separating from the Air Force was with a technical support outsourcing company, called "Stream" where I was hired to support a new product called "Netscape" which was about to be released. During my time supporting Netscape, I learned a lot about how to deal with all different types and levels of people, from the highly technical, to your average end user, to your not so average end user. This was a wonderful learning experience. After five or six months, the management team asked for volunteers to support Netscape on the Macintosh and on UNIX. I raised my hand and said "I have a little Mac experience, and I'll try this UNIX thing." Having no experience in UNIX, or even knowing what it was. I think this was the best thing I ever could have done. Later that week they handed me a spare computer and stack of floppy disks (remember those) and said "Figure it out". So I did, and thus began my career as a Linux Systems Administrator, almost. It took several more months of playing with Linux, re-installing, supporting Netscape on Linux, starting services on the Linux box, including setting up my first web server, and IRC server. I was exposed to SunOS 4 and SGI Irix during this time as well. After a while, it got to the point where I wasn't answering the phones as much, but rather working on the Linux system and asking and answering questions internally. By this time, I felt I was a pretty good systems administrator, so I started looking for jobs in that field and came across a small company in Beaverton that was in the starting phases or providing LAN Party style gaming, internet cafe, as well as providing dial-up services. When I started, they had a single T1 hooked up to a Livingston Portmaster 2er with a stack of modems sitting next to it but not connected. They had two Slackware Linux boxes one for Web, DNS, etc. the other was used for email. The company name was VR-Net.com, and I took over the administration of the Linux and network services, got the modems all setup and configured and basically started running all technical aspects of this small company. While here I learned about OSPF, BGP, subnetting, super netting and even intrusion detection and prevention. We didn't have firewalls at the time, and our ACLs weren't great. After about a year we had added a second T1, setup BGP, grown the server count to 8 servers. Had a full NIS/YP setup using RADIUS and had begun implementing Livingston Portmaster 3 access servers. After a couple more years of running the, a coworker had moved on to another company that was attempting to startup its own ISP for business customers, and they looked to me for guidance and over the lunch meeting basically offered me a job building this new ISP from scratch. This new company was CMS and they provided international FAX services and wanted to offer internet services to their business customers. So I made recommendations on all the equipment that was needed and began building a new ISP from the ground up. After about six months of running this new ISP called Coho.net, the owner of VR-Net.com offered to sell his customer base and equipment to us as he was unable to find someone to properly address the customers' needs. I ran Coho.net for another two years before deciding to look for something a bit more challenging and a bit more pay. By this time, Coho.net was in cruise mode, we weren't growing too much, and the systems basically ran themselves. I was contacted by a professional services company with an office in the San Francisco Bay Area called Net Daemon Associates, which had recently been purchased by Interliant. This was a fun gig, I got to visit many companies throughout the Bay Area and perform professional services consulting for companies like Apple, Palo Alto Internet eXchange (PAIX), Berkeley National Labs (DoE) and many others. I was sent to Checkpoint Firewall training and became a Checkpoint Certified Security Engineer (CCSE). I worked on Information Security Audits. Managed network infrastructure on many different platforms such as Juniper, Foundry, Nortel, Cisco. Worked with NAS devices such as NetApp, and so on. The amount of experience gained during this time was immense. I saw so many different types of environments, and dealt with so many different problems, working with many levels of personnel from the Junior systems administrators to the CEOs of companies. I was really hoping to stay with this company, but they were hit hard with fallout from the dot.com bust, 9/11, and the Enron scandal. It was all too much and Interliant closed its Bay Area offices on 10/15/2001, laying off all but two windows systems administrators who were currently working on projects and two managers who had been planning on moving back to the East Coast. I was out of work for six weeks, and found a company called "ConXion" who was a managed service provider looking for a Sr. Security Engineer to join the team and manage the security infrastructure for the hosted customers. We managed the firewalls and intrusion detection systems for companies like Symantec, Seagate, Oracle, and many other smaller companies. From my previous hosting background, this was a good fit. Although, the economy still in a bad place, and with the invention of Akamai, ConXion was losing a bit of ground in the hosting industry. We had three datacenters located in Santa Clara, CA; Herndon VA; and Chicago IL. After about 18 months with the company, many lay-offs, etc. the owner decided to sell the company to Navisite, another hosting company which had a datacenter in San Jose. I was the only Security Engineer who made it through the acquisition and continued to work for Navisite for another 6 months or so. After the data-center move from Santa Clara to San Jose, it was a different company, run out of the East Coast Datacenter now. Almost all of the former ConXion folks were gone, and those who were left were looking. Three of us left Navisite the same day, two security engineers, and a network engineer. Two other network engineers had left the week prior. I started working for a company called PaymentOne as a Senior Security Engineer. I also worked on their Linux and Solaris environment. PaymentOne setup a process to pay for services on your telephone bill. We setup a brand new Solaris Oracle cluster for a new micro payment solution they were getting ready to offer. Also with the assistance of Deliotte, I was the primary point of contact for getting PaymentOne through a SAS70 type 1 and type 2 audit. This was my first introduction into compliance initiatives. I had to work on SAS70, CISP which is now PCI complaince and had to do research on many others. Our human resources team looked to me for guidence on HIPAA compliance. The company was getting ready to be acquired, but at the last minute, the purchasing company backed out of the deal. P1 spent a large amount of money in preparation for the acquisition which now wasn't going to happen so they began laying off people. Once again I made it through un-scaved but things weren't the same. At the time, things didn't look well for the company, so I decided it was time to move on before the company went under or I was forced to. more to come More to come...