- Academic and Education History
- Professional and Employment History
- Sun Microsystems, Inc. (Various Roles)
- Global Systems Engineering, Chief Security Architect
- Global Systems Engineering, Leader, High Performance Computing Tiger Team
- Global Systems Engineering, Chief Architect and Director, Global Security Office
- Client Solutions, Chief Security Architect
- Sun Professional Services, Chief Security Architect (Americas/United States)
- Sun Professional Services, Sr. Security Architect (USA/Financial Services Area)
- Sun Professional Services, Sr. Security Architect (USA/North East Area)
- St. Joseph's University, Adjunct Professor of Computer Science
- Continental Resources, Inc., Unix Engineering Manager
- Lockheed Martin ATL, Artificial Intelligence Lab, Member of Engineering Staff
- Saint Joseph's University, Office of Network Services, Asst. Network Manager
- Awards and Honors
- Media Exposure
- Patents
- Publications
- Software and Tools
- Conferences and Events
- Selected Industry Working Groups and Committees
- Member, National Cyber Security Summit, Technical Standards and Common Criteria Task Force.
- Member, Center for Internet Security (CIS), Unix Security Benchmark Team.
- Working Group Lead, Common Criteria User's Forum
- Vice-Chair, Enterprise Grid Alliance Security Working Group
- Community Leader, OpenSolaris Security Community
- Community Member, Cloud Security Alliance
- Selected Customer Security Activities
- Selected Sun Working Groups and Projects
- Mentoring
- Professional Associations
- Additional Resources
Academic and Education History
Academic and University Education
Glenn has earned the following academic degrees:
- St. Joseph's University (Philadelphia, PA)
Degree: M.S., Computer Science (May 1999) GPA: 4.00 Awards: Graduate Computer Science (Gold Medal) Award Recipient
- St. Joseph's University (Philadelphia, PA)
Degree: B.S., Computer Science (May 1993) GPA: 3.38 Minor: Mathematics Awards: Departmental Honors (Networking)
Professional Certifications
Glenn holds the following certifications and designations in good standing:
- Sun Certified Security Administrator (10/2007) (Exam Co-Developer)
- Sun Certified Network Administrator (10/2007)
- Sun Certified System Administrator (10/2007)
- CompTIA Security+ (01/2003) (Exam Beta Tester)
- SunU Trademark Certification (03/2003)
- Prince 2 Foundation Certification (04/2003)
- National Security Agency INFOSEC Assessment Methodology (04/2002)
- Certified Information Systems Security Professional (CISSP) (12/2000)
Professional and Employment History
Sun Microsystems, Inc. (Various Roles)
Global Systems Engineering, Chief Security Architect
|
present- |
As a member of Sun's Chief Architect's Office, Glenn leads Sun's security initiatives for Cloud Computing and other highly-scalable and dynamic architectures. Realizing that Cloud Computing models have the real potential to raise the bar for IT security, Glenn has created architectures, patterns, recommended practices, and tools to drive improved security for Cloud Computing environments. Many of these works have been integrated into Sun's Cloud Computing initiatives and made publicly available. Glenn is responsible for developing Sun's Cloud Computing security strategy and evangelizing it at both Sun and industry events, and he represents Sun's perspectives as a member of industry groups such as the Cloud Security Alliance. Glenn is the security liaison to the Cloud Computing product group and the security lead for Sun's Cloud Architecture Group, an internal governance team chartered with defining standards and practices for Sun's public Cloud Computing offerings. Further, Glenn works with customers from around the world to help them better understand and apply Cloud Computing security concepts and practices. |
Global Systems Engineering, Leader, High Performance Computing Tiger Team
|
2009- |
In parallel with his duties as Director and Chief Architect of the Global Security Office, Glenn led a global, virtual team focused on driving awareness and growth in the area of high performance computing (HPC). Focusing on both traditional and commercial HPC opportunities, Glenn and his team have supported over $175M in global customer wins and opportunities. This Tiger Team has captured architectural artifacts and lessons learned to improve our products, services and sales processes, developed HPC-related training for the Global Systems Engineering community, and worked with leaders from across Sun to ensure alignment across various HPC-related activities in order to promote greater efficiency and effectiveness across the field organizations. |
Global Systems Engineering, Chief Architect and Director, Global Security Office
|
2009- |
Leads a team of principal security architects and professionals on the development and execution of the corporate and divisional security strategy. Works in concert with executive security leadership throughout Sun on key cross-organizational strategic security initiatives and architectures including Sun Systemic Security. Works to define and promote a consistent and comprehensive security vision and architectural model for Sun's entire portfolio of products and services. Provides both strategic and tactical subject matter expertise in the field of information security to groups across Sun and throughout the industry. Drives the development and integration of "security as a systemic quality" into Sun's products, services and customer solutions. Evangelizes and leads architectural and technical security solutions in open-source and Internet forums, at conferences and customer workshops, and through publication of recommended practices. |
Client Solutions, Chief Security Architect
|
2005- |
Works as a member of both the Global Data Center CTO and the Global Security Team. In these roles, Glenn worked to define and evangelize the security strategy and vision for Client Solutions as well as to design security into Client Solutions training, solutions and offerings. Provided both strategic and tactical subject matter expertise in the field of information security to groups throughout Sun to help improve the overall consistency, quality and security of Sun's products and services. Drove the development of security recommended practices, architectures, training, services, and tools used both by Sun, its partners and its customers. Provides executive and tactical engineering, sales and delivery support to teams throughout the United States and globally. |
Sun Professional Services, Chief Security Architect (Americas/United States)
|
2004- |
Lead the development and execution of the region's information security strategy. Responsible for raising the baseline security awareness and skills of the SunPS US field organization through the development of the Security Everywhere! program. Provided both strategic and tactical subject matter expertise in the field of security to groups throughout Sun to help improve the overall consistency, quality and security of Sun's products and services. Drove the development of security recommended practices, training, services, and tools used both by Sun, its partners and its customers. Provided engineering, pre-sales and delivery support to Sun teams throughout the United States. |
Sun Professional Services, Sr. Security Architect (USA/Financial Services Area)
|
2002- |
Same responsibilities as below. |
Sun Professional Services, Sr. Security Architect (USA/North East Area)
|
2000- |
Lead the development and execution of layered security solutions for Sun Professional Services in the region. Responsible for comprehensive security service delivery in the areas of assessment, architecture, implementation and management. Provided both strategic and tactical guidance to clients in matters of information security with a special focus on platform and network security, security architecture and management. Assisted clients in designing and deploying secure, highly available, and scalable mission critical environments. Customers have included major financial services firms, service providers, new media and life sciences, academic and government organizations. In addition to contact services, responsibilities include the development of security methodologies, best practices, training and tools through close cooperation with the Engineering, Enterprise Services, Marketing and Computer Systems divisions. Participated on two security-focused teams whose goals were to identify and recommend security-related improvements for Sun's products and services. Managed a highly utilized team of security architects and engineers. |
St. Joseph's University, Adjunct Professor of Computer Science
|
1999- |
Responsible for developing and teaching an advanced computer programming course using the C++ programming language. In addition, this course offered students an overview of object-oriented analysis and design techniques. |
Continental Resources, Inc., Unix Engineering Manager
|
1999- |
Lead technical contact for Sun Microsystems hardware and software products, Unix, and system and network security for the Mid-Atlantic region (Boston, MA to Washington, D.C.). Develop structure to drive Sun and related (Veritas, Legato, Netscape, Checkpoint, etc.) product sales and services for offices in the Northeast U.S. corridor. Design, install and support heterogeneous network infrastructures for Fortune 1000 clients, from desktops to mission/business critical database and compute servers. Provide performance, redundancy, reliability and security recommendations to clients in order to increase overall network availability. Render pre-sales configuration in addition to availability and capacity planning to customers. Develop and present general and customized presentations that cater to individual client's requirements. Complete sales cycle by providing post-sales consulting and maintenance for all facets of Unix-based solutions. Manage and execute regional trade show including the coordination of literature, equipment and personnel from multiple vendor sources. Integrate solutions into a cohesive demonstration suitable for general audiences. Provide custom technical and business training for clients, as well as CRI internal sales and support staff. Specialize in operating systems, networking, Unix/PC Interoperability (especially Unix/NT Interoperability), in addition to system and network security. |
Lockheed Martin ATL, Artificial Intelligence Lab, Member of Engineering Staff
|
1997- |
Installed, diagnosed and maintained a network of 50 Sun/HP/SGI workstations and servers. Provided secondary support for over 140 Sun/HP/SGI workstations and servers. Planned, budgeted and installed network, server and desktop upgrades, while managing and training junior level administrators. Responsibilities also included software engineering. Designed and developed advanced concept systems for distributed Command and Control (C2) environments, satellite test systems and sensor emulation tools using the C, C++ and Java programming languages. Responsibilities included project management (>150K budgets, 5+ software engineers), knowledge acquisition, system architecture design and development, and portable multi-platform development, integration, and deployment for government, military and commercial customers. Special responsibilities included management of classified computer processing servers, porting of applications between computing environments, in addition to performing security administration on the non-classified network. |
Saint Joseph's University, Office of Network Services, Asst. Network Manager
|
1993- |
Designed, installed and supported a campus-wide network management system based on SNMP; designed and developed departmental and campus-wide database systems using the Ingres RDBMS. Managed hardware and software installation and support for over 50 networked desktops and servers (DOS, MS Windows, Macintosh, UNIX, Terminals) in the one of the country's first networked dormitories. Provided direct hardware, software, network, and security support for 500+ nodes on the campus academic network. |
Awards and Honors
Glenn has received the following awards and honors (organized chronologically by organization):
Sun Microsystems, Inc.
- SunRise 2008 Award (09/2008)
- Sun Innovation Award (formerly the Chairman's Award, 07/2008)
- Sun Global Sales and Service Leadership Institute (03/2007)
- Awarded by Don Grantham, EVP, GSS, Sun Microsystems, Inc.
- Sun Stars Around the Globe (01/2007)
- Sun BluePrints Award for Prolific Contributions to the Program (04/2006)
- Awarded by Jonathan Schwartz, President/CEO, Sun Microsystems, Inc.
- Sun Grid Security Challenge - Grand Prize Winner (01/2006)
- Sun Distinguished Engineer Promotion (06/2004)
- Sun Principal Engineer Promotion (04/2002)
- Sun Top Achievement Recognition Summit (STARS) FY01
- SunPS North East Area, 400 Club Award (Q1FY01, Q2, FY01)
- Sun Top Achievement Recognition Summit (STARS) FY00
- SunPS North East Area, 400 Club Award (Q1FY00, Q2FY00, Q4FY00)
- SunPS North East Area, Most Billable Hours (Q2FY00)
- SunPS North East Area, Area Excellence Award (Q1FY00, Q2FY00)
Lockheed Martin (and Martin Marietta)
- Lockheed Martin Advanced Technology Lab, General Manager's Award (12/1996)
- Lockheed Martin Advanced Technology Lab, Manager's Award (01/1996)
- Lockheed Martin Advanced Technology Lab, Employee of the Month (06/1995)
- Lockheed Martin Advanced Technology Lab, Manager's Award (12/1994)
St. Joseph's University
- Upsilon Pi Epsilon (UPE) Distinguished Alumnus Recipient (2008)
- Graduate Computer Science Award Recipient (1999)
- Departmental Honors Recipient (1993)
- Sigma Xi, National Research Honor Society (1993-present)
- Who's Who Among American College Students (1990-1993)
- Saint Joseph's University Dean's List (Spring and Fall 1992)
- Saint Joseph's University Presidential Scholarship Recipient (1989-1993)
Other
- Society for Technical Communication (STC) Award of Excellence
- STC 2004-2005 Southern California Technical Communication Competition awarded for the entry of "Securing Systems with the Solaris Security Toolkit". (2005)
Media Exposure
Glenn has been interviewed by a number of industry analysts and organizations including but not limited to:
- Immutable Service Containers - Addressing Security in a World of Changing Deployment. Sun Microsystems, Inc. (Innovating@Sun)
- Panel Discussion: Is Cloud Computing More or Less Secure than On-Premises IT?. The Open Group's 23rd Enterprise Architecture Practitioners Conference. July 2009 (Podcast Panel Session).
- Immutable Service Containers. HELDENFunk Folge 30 vom 3. April 2009 (Podcast Interview).
- Managing the Top Five Security Threats to Web Scale Success. Sun Microsystems, Inc. (Inner Circle Magazine).
- In the Boardroom with Sun Microsystems. Security Stock Watch.
- Shining a Light on Enterprise Grid Security. GRIDtoday.
- A Different View of Security. Sun Microsystems, Inc. (Innovating@Sun).
- A Closer Look at Solaris 10 Security. Sun Microsystems, Inc. (Innovating@Sun).
- Securing the Mobile Workforce - Common Sense & Sound Network Architectures Can Protect Your Data. Processor Magazine.
- Responding to Risk: Invisible Enemies. Industry Week.
- Systemic Security: Building Blocks for the Secure Enterprise. Sun Microsystems, Inc. (Inner Circle Magazine).
Patents
Glenn is named as one of the co-inventors for the following patent applications:
- System and Methods for the Construction, Fusion, Prosecution and Maintenance of Minimised Operating Environments in Static and Dynamic Infrastructures
G. Brunette, D. Walker, and B. Blanquart. Sun Patent #SUN041051. Status: Pending (04/06/2005).
- System and Method for the Construction of Tailored Security Profiles and their Fusion and Prosecution in Dynamic Computing Environments
G. Brunette and D. Walker. Sun Patent #SUN040048. Status: Pending (04/2004).
Publications
Author, Co-author, Significant Contributor
Glenn is an author or significant content contributor to the following publications. Note that both Sun internal and public documents are listed below. References are provided only for external publications. Note that since 2004, Glenn has also published many articles, not referenced below, in his Sun Blog.
Books
- Solaris Security Essentials
Sun Microsystems Security Engineers. Prentice Hall PTR. ISBN: 978-0-13-701233-6. (11/2009).
- Enterprise Information Security and Privacy
W. Axelrod (Editor). Artech House Publishers. ISBN: 978-1-59693190-9 (02/2009)
- Securing Systems with the Solaris Security Toolkit
A. Noordergraaf and G. Brunette. Sun Microsystems Press. ISBN 0-13-141071-7. (07/2003).
- Enterprise Security: Solaris Operating Environment
A. Noordergraaf. Prentice Hall. ISBN: 978-0-13-100092-6 (06/2002).
Articles
- Introduction to Cloud Computing Architecture (SunWIN #564162)
J. Carolan, S. Gaede, et al. Sun White Paper (06/2009).
- Understanding the Security Capabilities of Solaris 10 Zones Software
G. Brunette, J. Victor. Sun BluePrints Article (12/2008).
- Security Architecture and Adaptive Security
J. Weise, G. Brunette, R. Alvi, S. Nelson. Information Systems Security Association (ISSA) Journal (07/2008).
- An Overview of Solaris 10 Security Controls
G. Brunette. Sun White Paper (09/2007).
- Using Solaris Operating System Security to Address PCI DSS Compliance - A Systemic Approach to Security
G. Brunette, M. Thacker, J. Weise. Sun White Paper (07/2007).
- Rules of Engagement for the Support of Reduced or Minimal Configurations
G. Brunette. Sun White Paper (11/2006).
- Privilege Bracketing in the Solaris 10 OS
G. Brunette. Sun BluePrints Cookbook (04/2006).
- The Solaris Fingerprint Database - A Security Validation Tool for Solaris Environment System Files (Updated for Solaris 10)
V. Dasan, A. Noordergraaf, L. Ordorica, G. Brunette. Sun BluePrints Article (03/2006).
- Privilege Debugging in the Solaris 10 OS
G. Brunette, D. Moffat. Sun BluePrints Cookbook (02/2006).
- Toward Systemically Secure IT Architectures
G. Brunette. Sun BluePrints Article (02/2006).
- Enforcing the Two-Person Rule Via Role-Based Access Control in the Solaris 10 OS
G. Brunette. Sun BluePrints Cookbook (08/2005).
- Restricting Service Administration in the Solaris 10 OS
G. Brunette. Sun BluePrints Cookbook (06/2005).
- Limiting Service Privileges in the Solaris 10 OS
G. Brunette. Sun BluePrints Cookbook (05/2005).
- Enabling TCP Wrappers in the Solaris 10 OS
G. Brunette. Sun BigAdmin (04/2005). Republished from an internal Technocrat article and external blog article.
- Managing Non-Login and Locked Solaris 10 Accounts
G. Brunette. SecurityDocs.com (10/2004). Republished from an external blog article.
- Solaris 10 Account Lockout ("Three Strikes!")
G. Brunette. SecurityDocs.com (10/2004). Republished from an external blog article.
- How to Limit Display of Other User's Processes in Solaris 10
G. Brunette. SecurityDocs.com (10/2004). Republished from an external blog article.
- Foundation for Minimal Solaris 10 Systems
G. Brunette. SecurityDocs.com (10/2004). Republished from an external blog article.
- Solaris 10 Password History
G. Brunette. SecurityDocs.com (10/2004). Republished from an external blog article.
- Automating Solaris 10 File Integrity Checks
G. Brunette. SecurityDocs.com (10/2004). Republished as a Sun BluePrints Cookbook (03/2005).
- Integrating Solaris 10 BART and the Solaris Fingerprint Database
G. Brunette. SecurityDocs.com (11/2004). Republished as a Sun BluePrints Cookbook (04/2005).
- Adaptive Security for Dynamic Computing Environments
G. Brunette. SUPerG Conference White Paper. (04/2004). Internal paper.
- Common Configuration Working Group Recommendations Report.
DHS National Cybersecurity Summit Technical Standards and Common Criteria Task Force. Glenn Brunette et al. (Version 1.0, 02/2004).
- Hiding within the Trees
G. Brunette. USENIX ;login Article, Volume 29, Number 1. (02/2004).
- Securing Sun Linux Systems: Parts I and II
- Part I: Local Access and File Systems
G. Brunette, M. Hullhorst, and Ge Weijers. Sun BluePrints Article (07/2003). - Part II: Network Security
G. Brunette, M. Hullhorst, and Ge Weijers. Sun BluePrints Article. (07/2003).
- Part I: Local Access and File Systems
- Auditing System Security
A. Noordergraaf and G. Brunette. Sun BluePrints Article. (05/2003).
- Using NTP to Control and Synchronize System Clocks: Parts I, II, and III
- Part I: Introduction to NTP.
D. Deeths and G. Brunette. Sun BluePrints Article. (07/2001). - Part II: Basic NTP Administration and Architecture.
D. Deeths and G. Brunette. Sun BluePrints Article. (07/2001). - Part III: NTP Monitoring and Troubleshooting.
D. Deeths and G. Brunette. Sun BluePrints Article. (09/2001).
- Part I: Introduction to NTP.
- SunCluster/Annex Terminal Server Security
G. Brunette. Sun Internal Article. (09/2001).
- Solaris Security Toolkit (Version 0.3)
- Quick Start
A. Noordergraaf and G. Brunette. Sun BluePrints Article. (06/2001). - Release Notes
A. Noordergraaf and G. Brunette. Sun BluePrints Article. (06/2001). - Installation and Configuration
A. Noordergraaf and G. Brunette. Sun BluePrints Article. (06/2001). - Internals
A. Noordergraaf and G. Brunette. Sun BluePrints Article. (06/2001).
- Quick Start
- JumpStart Architecture and Security Scripts for the Solaris OS: Parts I, II, and III (Version 0.2)
- JumpStart Architecture and Security Scripts for the Solaris OS (Version 0.1)
Subject Matter Expert, Technical Reviewer
In addition to his publications, Glenn has actively participated as a subject matter expert and technical reviewer for a wide array of Sun and industry publications including articles and books such as:
Books
- Operating System Security
T. Jaeger. Morgan & Claypool. ISBN: 978-1-59-829212-1 (10/2008).
- Core Security Patterns: Best Practices and Strategies for J2EE™, Web Services, and Identity Management
C. Steel, R. Nagappan, and R. Lai. Prentice Hall. ISBN: 978-0-13-146307-3 (10/2005).
- Building N1™ Grid Solutions Preparing, Architecting, and Implementing Service-Centric Data Centers
J. Carolan, S. Radeztsky, P. Strong, and E. Turner. Prentice Hall. ISBN: 978-0-13-148201-2 (09/2004).
- Secure Shell in the Enterprise
J. Reid. Prentice Hall. ISBN: 978-0-13-142900-0 (06/2003).
- JumpStart™ Technology: Effective Use in the Solaris™ Operating Environment
J. Howard and A. Noordergraaf. Prentice Hall. ISBN: 978-0-13-062154-2 (10/2001).
Articles
- Security Guidance for Critical Areas of Focus in Cloud Computing. Cloud Security Alliance. (04/2009).
- Many Sun BluePrints articles on security and other topics.
Software and Tools
Glenn is an author or significant content contributor to the following published software tools. Sun internal tools are not listed.
- OpenSolaris Immutable Service Container Construction Kit (Preview)
G. Brunette. A Kenai Project. Downloads not calculated.
- Cloud Safety Box (s3-crypto.ksh)
G. Brunette. A Kenai Project. Downloads not calculated.
- JumpStart Architecture and Security Scripts / Solaris Security Toolkit
A. Noordergraaf and G. Brunette. (Versions 0.1 through 4.1). As of version 4.2, this project was made into an official Sun product. As of version 5.0, an OpenSolaris SST Project. Downloaded over 100,000 times.
- OpenSolaris Encrypted Scratch Space SMF Service (isc-encrypted-scratch)
G. Brunette. An open-source project. Downloads not calculated.
- OpenSolaris Encrypted Swap SMF Service (isc-encrypted-swap)
G. Brunette. An open-source project. Downloads not calculated.
- Solaris Fingerprint Companion
G. Brunette. (Versions 0.1 through 0.5). An OpenSolaris Forensics Project. Downloads not calculated.
- Solaris Interesting File Discovery Tool (ifd.sh)
G. Brunette. (Versions 0.1 through 0.4). An OpenSolaris Forensics Project. Downloaded over 2,300 times.
- Solaris Package Companion (spc.ksh)
G. Brunette. (Versions 0.1 through 0.9). An OpenSolaris SVR4 Packaging Project. Downloaded over 6,000 times.
- Solaris Privilege Debugging Tool (privdebug.pl)
G. Brunette and D. Moffat. An OpenSolaris Security Community Project. Downloads not calculated.
- ZFS Encrypted Backup to the Cloud (zfs-backup-to-s3.sh)
G. Brunette. A Kenai Project. Downloads not calculated.
Conferences and Events
Glenn has been a speaker or co-speaker at the following industry and Sun conferences and events:
Industry and External Sun Events
| Event | Date | Topic |
|---|---|---|
| Cloud Computing Expo (West) | 11/2009 | Cloud Computing Security Bootcamp Session |
| Cloud Computing Expo (West) | 11/2009 | Cloud Security - It's Nothing New; It Changes Everything! |
| OpenSolaris Developer's Conference | 10/2009 | Immutable Service Containers |
| BrightTalk Cloud Security Summit | 09/2009 | Decision Tree: Key questions to ask your Cloud Service Provider (Webinar) |
| Sun Cloud Computing Security Webinar | 09/2009 | Safety First: Protecting Your Services in the Cloud (Webinar) |
| Cloud Security Alliance Federal Symposium | 08/2009 | Virtualization Security |
| Cloud Security Alliance Federal Symposium | 08/2009 | Cloud Computing Threats (Panelist) |
| Cloud Camp Toronto 2009 | 07/2009 | IaaS Security (Working Group Leader) |
| 3rd Open Group Security Practitioner's Conference | 07/2009 | Is Cloud Computing More or Less Secure than Traditional In-house IT? (Panelist) |
| Cloud Computing Expo (East) | 03/2009 | Enhanced Security Models for Machine Image Deployments |
| Sun HPC Consortium Conference | 03/2009 | HPC and Cloud Computing |
| Solaris Campus in SecondLife | 02/2009 | Solaris Security Expert Chat: Top 5 Solaris Security Features |
| NJEdge Conference 2008 | 11/2008 | What's old is new again: HPC and Cloud Computing |
| 4th Annual NIST Security Automation Conference | 09/2008 | IT Product Security Configuration (Panelist) |
| St. Joseph's University, Upsilon Pi Epsilon Induction Ceremony | 03/2008 | Building at Network Scale: Future Information Factories |
| NSA Red/Blue Security Symposium | 02/2008 | A Building Block Approach to Solaris Security |
| RSA Security Conference (USA) | 02/2007 | What Can You Trust? A Platform Security Update. (Panelist) |
| United Nations 3rd Web for Development Conference | 11/2006 | Securing the Multimedia Web Experience (Panelist) |
| NSA Red/Blue Security Symposium | 10/2006 | Applied Solaris 10 Security |
| NIST Security Automation Conference | 09/2006 | Improved Security through Participation - A Solaris Security Story |
| Corporate and Channel Computing Expo | 06/2006 | Systemically Secure Architectures (Plenary Session) |
| RSA Security Conference (Europe) | 10/2005 | Systemically Secure and Dynamically Adaptive Computing Strategies |
| Sun Data Center and Storage Symposium | 08/2005 | Sun Systemic Security |
| NY State Cyber Security Conference | 06/2005 | Lessons from the Trenches: Solaris Security Best Practices |
| Gartner Security Conference | 05/2005 | Systemically Secure Architectures: Lessons from the Trenches |
| EDUCAUSE Security Professionals Conference | 04/2005 | Systemically Secure Architectures: Lessons from the Trenches |
| RSA Security Conference | 02/2005 | Adaptive Security for Dynamic Computing Environments |
| NIST Security Configuration Workshop | 11/2004 | Role of Software Vendors in Security Checklist Development (Panelist) |
| Sun OEM Forum | 10/2004 | "Designing In" Security |
| St. Joseph's University, Invited Talk | 02/2004 | Secure Software Design and Development |
| Upper MidWest Technology Conference | 10/2003 | Practical Minimalism |
| SunNetwork, San Francisco | 09/2003 | Practical Minimalism |
| Kentucky Executive Leadership Conference | 04/2003 | Designing Secure Architecture |
| Storage Network Industry Association Security Summit | 09/2002 | Layered Security Architecture |
| New York State OIT Security Conference | 04/2002 | Layered Security Architecture |
| Sun Net Talk "Unplugged": Minimization and Hardening | 02/2002 | Solaris Platform Minimization and Hardening Practices/Recommendations (with Alec Muffett) |
| Solaris Security Toolkit On-line Discussion | 04/2001 | Solaris Security Toolkit (with Alex Noordergraaf) |
| GEAC Advance User's Group Conference | 04/2001 | Solaris Platform Security, Solaris Security Toolkit |
Internal Sun Events
| Event | Date | Topic |
|---|---|---|
| Customer Engineering Conference | 11/2008 | Hack-Fu Part Deux: Immutable Service Containers |
| Customer Engineering Conference | 11/2008 | Solaris 10 Security Deep Dive 2-Hour Training |
| Innovation@Sun 2008 | 10/2008 | Immutable Service Containers (Poster Session) |
| Customer Engineering Conference | 10/2007 | Hack-Fu: Deconstructing the Security of the Solaris Operating System |
| Customer Engineering Conference | 10/2006 | Security Patterns for IT Architecture |
| Customer Engineering Conference | 10/2006 | Enhancing Security Awareness and Control with DTrace (with Jon Haslam). This talk was awarded "Best of Day" for Day 2 of this conference from nearly a hundred talks given that day. |
| Global Technology Leadership Conference (India Engineering Center) |
07/2006 | Grid and Utility Computing (Panelist) |
| Global Technology Leadership Conference (India Engineering Center) |
07/2006 | Identity Management (Panelist) |
| Security Ambassadors Conference | 02/2006 | Sun Systemic Security |
| Immersion Week | 11/2005 | Sun Systemic Security, Solaris 10 Technical Security Deep Dive |
| SUPerG | 05/2004 | Adaptive Security for Dynamic Computing Environments |
| Customer Engineering Conference | 03/2004 | Adaptive Security for Dynamic and Consolidated Environments (with Dave Walker) |
| Customer Engineering Conference | 03/2004 | Designing Secure Architectures (Updated, with Joel Weise) |
| SMI Security Summit | 03/2003 | Designing Secure Architecture |
| Customer Engineering Conference | 02/2003 | How We Let Hackers Do It |
Other Conference Participation
In addition, Glenn has served as a submission reviewer for the following conferences:
- Annual Computer Security Applications Conference (ACSAC'05)
- Annual Computer Security Applications Conference (ACSAC'06)
- Technology @ Sun (Fall 2007)
Selected Industry Working Groups and Committees
Member, National Cyber Security Summit, Technical Standards and Common Criteria Task Force.
|
Champion of the "Common Security Configurations" Working Group. On December 3rd, 2003, the Technical Standards and Common Criteria Task Force was formed by members of academia, industry and government at the first National Cyber Security Summit in Santa Clara, CA. This Task Force along with four others chartered that day by the National Cyber Security Partnership in conjunction with the U.S. Department of Homeland Security ("DHS") was directed to identify gaps and develop recommendations to promote the adoption and implementation of the President's National Strategy to Secure Cyberspace. These recommendations will be presented to the DHS, various U.S. Congressional subcommittees focusing on cyber-security and other stakeholders for consideration in planning next steps. This Task Force was co-chaired by:
As a member of this team, Glenn led the Common Security Configurations working group, a team comprised of academia, industry, government and other consortia. This working group was formed to meet the challenge of responding to risks identified by the lack of common, baseline security capabilities, settings and documentation in all information technology (IT) infrastructure components and to develop and document recommendations for the collection and promotion of these common capabilities. The result of this effort was a report highlighting 28 specific recommendations across 6 core focus areas. The recommendations include a range of actions to encourage better security recommendation development and maintenance, to increase industry and government coordination and collaboration, and to promote the development and management of more secure product configurations by default and in deployment. The final Technical Standards and Common Criteria Task Force recommendations report (which includes this working group's report) is available at: http://www.cyberpartnership.org/. |
Member, Center for Internet Security (CIS), Unix Security Benchmark Team.
|
As a member of the Center for Internet Security's Unix Security Benchmark Team, Glenn works to develop consensus-based security recommendations for Unix-based platforms. Glenn is a driving force behind aligning the Solaris Security Benchmark published by CIS with the Sun BluePrints recommendations for Solaris security as well as security recommendations published by the U.S. National Security Agency and Department of Defense. The result of this multi-year-long effort is a more consistent and stronger set of security recommendations that are supported officially by Sun worldwide. Sun, CIS and all of our users benefit from this work through the publication and use of common security recommendations. A version of the recommendations targeting the Solaris 10 OS was published in August 2005 and a new version was published in September 2007. This new version was co-developed with support from the CIS, NSA, DISA and NIST - a clear demonstration of what is possible when the public and private sectors work well together. More information on the Center for Internet Security can be found at http://www.cisecurity.org/. Glenn is recognized as a contributor to the CIS Benchmark effort. In 2007, Glenn negotiated a contract between Sun and CIS to more easily facilitate sharing and (re-)publication of information developed by the two companies. This work enables both organizations to more readily share content developed by the other to reach even more communities and customers. In 2009, Glenn worked with the Center for Internet Security to develop the first vendor-provided, CIS compliant virtual machine image for Amazon EC2. |
Working Group Lead, Common Criteria User's Forum
|
As the workshop chair for "Setting Requirements for Commercial Users" team, Glenn lead a team that developed a number of ideas focused on making the Common Criteria more relevant and useful for commercial end-users. These recommendations were shared with DHS, NIST, NSA as well as industry organizations such as CSIA and TechNet who were the event organizers. Glenn presented these recommendations to the entire Forum audience and provided content in support of the Forum's final recommendations report. |
Vice-Chair, Enterprise Grid Alliance Security Working Group
|
As the vice-chair of the EGA's Security Working Group, Glenn has helped to set the technical direction and charter for the group. The group identified security risks, threats and use cases that are specific to enterprise grid architectures. Working with members of the group as well as other EGA working groups, Glenn has helped to craft a report outlining the issues uncovered as well as recommendations for vendors and customers to better secure their enterprise grid products and architectures. More information on the Enterprise Grid Alliance can be found at http://www.gridalliance.org/. Glenn was interviewed by GRIDtoday regarding the work published by this team. |
Community Leader, OpenSolaris Security Community
|
As one of the OpenSolaris Security Community Leaders, Glenn has worked to promote a greater understanding of Solaris 10 and OpenSolaris security controls and technologies. In addition to his Sun BluePrints publications on this topic, Glenn has also developed and enhanced a number of tools made available from the OpenSolaris Security and Install Communities. In addition, Glenn has also contributed to the community extensions to the Solaris Security Toolkit that enable over 30 new and different Solaris OS auditing checks not previously available. Finally, Glenn maintains the Security Community Library and Presentation pages to provide up to date references on Solaris and OpenSolaris security related books, articles, white papers, presentations, etc. Glenn has also conducted security testing of the Solaris operating system and has logged hundreds of bug reports and requests for enhancement that have directly contributed to significant improvements in the operating system in terms of functionality, security and integrity. |
Community Member, Cloud Security Alliance
|
As one of the founding members of the Cloud Security Alliance, Glenn has worked to drive security recommendations and best practices for Cloud Computing environments. Glenn supported the initial release of the group's publication, "Guidance for Critical Areas of Focus in Cloud Computing" by providing subject matter expertise in the review of the group's 15 strategy security domains. Since the initial publication, Glenn has taken on a leadership position as co-leader of the Editorial Working Group chartered with the publication of an updated set of cloud computing security issues, opportunities and recommendations. Further, Glenn is often requested by the CSA to present on a variety of cloud computing security topics including architecture, virtualization, and other areas. |
Selected Customer Security Activities
Available upon request for approved uses. Glenn has been involved in a wide array of information security and assurance activities for customers and industry around the world. The types of activities have included executive briefings, security workshops, strategy and policy development, assessments, architecture design and vetting, implementation and integration support, as well as forensic analysis.
Selected Sun Working Groups and Projects
During his tenure at Sun, Glenn has taken leadership positions across a wide array of internal projects, working groups, and other efforts. Included below is a representative sample of several activities:
|
In addition, Glenn has often been requested to join engineering teams in support of new architecture, product, or technology development:
|
Mentoring
Glenn has been a very active mentor to members of Sun's worldwide technical staff in both software and customer engineering disciplines. In addition, Glenn has been a guide for three engineers who have been promoted to the rank of Principal Field Technologist, one who has been promoted to the rank of SMI Principal Engineer, and two who have been promoted to the rank of Sun Distinguished Engineer. Glenn is consistently one of the most highly requested mentors in the Sun Engineering Enrichment and Development (SEED) program.
Reaching out to both high school and university students, Glenn has delivered talks on a variety of technical and professional development topics. For example, he has been at speaker at Sun's New Jersey Governor's School of Engineering and Technology event three of the last four years speaking on topics such as information security, cloud computing and professional technical career development.
Professional Associations
Glenn is or has been a recent member of the following professional organizations:
- Association for Computing Machinery (ACM)
- Certified Information System Security Professionals (CISSP)
- International Association of Privacy Professionals (IAPP)
- Institute of Electrical and Electronics Engineers (IEEE)
- Information Security Forum (ISF)
- Sigma Xi
- Upsilon Pi Epsilon (UPE)
- USENIX
Additional Resources
Glenn also has a presence on: