Ids Analyst Resume
5.00/5 (Submit Your Rating)
WashingtoN
WORK HISTORY/EXPERIENCE:
Confidential
IDS Analyst
Responsibilities:
- Analyzed all relevant cyber security event data and other data sources for attack indicators and potential security breaches; produce report.
- Assisted in coordination during incidents; and coordinate with the engineering team to maintain all security monitoring systems are on - line, up to date, and fully operational.
- Monitored intrusion detection and prevention systems and other security event data sources on 24x7x365 basis. Determined if security events monitored should be escalated to incidents and follow all applicable incident response and reporting processes and procedures.
- Correlated data from intrusion detection and prevention systems with data from other sources such as firewall, web server, and DNS logs.
- Provided support for the Bureau eSOC Hotline and appropriately document each call in an existing tracking database for this purpose.
- Worked with management to establish procedures for handling each security event detected.
- Utilized Remedy “Case Management” processes for incident and resolution tracking.
- Identified misuse, malware, or unauthorized activity on monitored networks. Reported the activity. appropriately as determined by eSOC Management.
- Monitored and responded to eSOC e-mail addresses.
Confidential
Information Security Systems Officer (ISSO)
Responsibilities:
- Served as an advisor to the Chief Information Security Officer (CISO) on all matters relating to security vulnerabilities and threats to CDC computer systems.
- Provided Cyber Security and Certification and Accreditation (C&A) support to the Department of Justice’ US Marshals Service (USMS).
- Conducted comprehensive IT security assessments of all operational USMS Information Systems leveraging DOJ Policy and Guidance, in conjunction with USMS Policy.
- Performed IT security assessments based on National Institute of Standards and Technology (NIST) Special Publications 800-37, Rev. 1, 800-53, Rev. 3, as well as Federal Information Security Management Act (FISMA) of 2002, OMB Circular A-130, and Federal Information System Controls Audit Manual (FISCAM) requirements using CSAM.
- Provided Program Management support to CISO and Deputy CISO using comprehensive reporting features of CSAM, to ensure USMS compliance with Federal laws and regulations, DOJ policies and IT Security Standards, IT system tracking, inventory, maintenance, and FISMA reporting.
- Conducted Risk Assessments and Security Impact Analysis for various Integrated Project Teams (IPTs) in support of the Change Control Board (CCB) and Functional Control Board (FCB).
- Performed security testing and evaluation using Cyber Security Assessment & Management (CSAM).
- Developed and updated System Security Plans using CSAM.
- Utilized CSAM to manage all aspects of the Risk Management Framework (RMF), to include Plans of Action & Milestones (POA&M) Management, Reporting features, and other aspects of the System Development Life Cycle (SDLC).
- Served as CSAM subject matter expert for application and process-related functions.
- Used enterprise-level Splunk dashboards and data connectors and correlations to analyze audit logs for System Owners and DBAs.
- Used Splunk search language (SPL) to create and optimize complex big data correlations.
- Performed detailed incident detect reports for USMS identified anomalous events.
- Created custom channels, and queries within ArcSight and Splunk to correlate malicious events occurring at the application and host level.
Confidential
Sr. Security Engineer
Responsibilities:
- Developed and executed various levels and types of certification and accreditation documentation for systems requiring Certificates to Field and Authorization to Operate.
- Performed automated vulnerability scans such as ACAS, NESSUS, and NMAP.
- Captured and analyzed system vulnerabilities and work with developers to mitigate or correct security risks.
- Developed security test plans and test reports.
- Produced sound solutions and processes to ensure program/mission accomplishment.
- Evaluated DoD-enterprise enclave security products for compliance.
- Provided Government POCs with guidance based on industry standards and policy.
Confidential
Cyber Incident Response Analyst
Responsibilities:
- Performed detailed incident detect reports for CAT 1-9 events.
- Reviewed open sources for emerging cyber threats and implement the appropriate countermeasures.
- Monitored and analyzed Netflow data streams for anomalous sessions.
- Created custom channels, and queries within ArcSight to correlate malicious events occurring at the network and host level.
- Used custom Perl and Python scripts to parse through Netflow data to identify target criteria based sessions.
- Conducted packet analysis within Wireshark.
- Created custom Sourcefire signatures from emerging Cyber threats, push approved Signature sets to IDS sensors.
- Isolated infected host and begin remediation actions.
- Triaged malware using static and dynamic analysis techniques.
- Created enterprise-level Splunk dashboards and data connectors and correlations for clients.
- Used Splunk search language (SPL) to create and optimize complex big data correlations.
Confidential
Information Security Network Engineer
Responsibilities:
- Researched, captured and processed security, technical, policy information to develop DIACAP packages for multiple networking solutions.
- Assisted in the transition of DIACAP to Risk Management Framework (RMF) for the Joint Regional Security Stack (JRSS)
- Analyzed network protocols and associated network logs
- Implemented and tested applicable IA controls, conducting testing activities, recording compliance status, maintaining IT security POA&Ms, and performing scheduled reviews.
- Conducted audit scans, and provided analysis of results. Communicated scan results with System Administrators, as well as provide direction as needed to facilitate remediation.
- Researched Confidential STIGs and provided guidance based on STIGs requirements
- Performed vulnerability scanning and analyzed results. Coordinated actions to correct deficiencies
- Created Implementation Plans, Installation Guides and Acceptance Test Plans for project deployment
- Conducted Security Test and Evaluation (ST&E) reviews including system security reviews (SRR) to ensure that systems conform to all applicable Security Technical Implementation Guides (STIGS) and write System Security Authorization Agreements (SSAA)
Confidential
Junior Cyber Engineer (Penetration Tester)
Responsibilities:
- Performed network and system penetration testing.
- Researched and analyzed known hacker methodology, system exploits and vulnerabilities to support Red Team Assessment activities.
- Created written reports, detailing assessment findings and recommendations.
- Provided oral briefings to leadership and technical staff, as necessary.
- Provided occasional, assistance with the development and maintenance of internal Red Team methodology, to include training program.
Confidential
Certifying Authority Representative (CAR)
Responsibilities:
- Supported Army Headquarters in the Certification and Accreditation of all Army systems.
- Coordinated and trained users on registration of systems in the IACORA database for Army systems.
- Worked with clients to communicate the proper procedure on how to get systems accredited through the Army, using AR 25-2 as a guideline.
- Provided concurrence on MAC/CL levels to ensure the proper level of security for Army systems.
- Conducted technical reviews to ensure that Network Diagrams accurately reflect the security posture and explain the overall level of security for the system.
- Analyzed reports from ACA teams to assess the security posture as documented after third party validation.
- Tasked with drafting, updating and presenting recommendation packages that are reviewed by the Certifying Authority for release to system owners upon completion of C&A process.
- Tasked with making assessments on packages that are both granted and denied ATO/IATO on behalf of the CA.
- Briefed CA, government leadership and other CAR’s on status of high priority packages.
- Conducted training presentations on various aspects of the CAR process to strengthen team understanding on direction that is given to “the field”.
- Was responsible for as many as 200 systems at any given time that must be categorized, prioritized and managed in a customer centered manner.
Confidential, Laboratory D.C.
Network Security Engineer
Responsibilities:
- Member of the central Information Assurance Team, supporting NRL.
- Experience working in a RDT&E environment on time sensitive accreditations.
- Experience in hardening systems by way of STIGs, checklist, Gold Disk and Retina.
- Prepared and generated Risk Analysis and Risk Assessment reports necessary to support NRL.
- Isolate and diagnose IT equipment, systems, networks and software problems.
- Provide IA and IA-related technical support to NRL customers; this support extends to geographically separated NRL sites.
- Was responsible for the composition of DIACAP packages.
- Validator/Certifier for the Certification and Accreditation (C&A) process.
- Prepared and coordinated Authority to Operate modifications (ATO MOD), by requesting documentation of any/all security changes per enclave.
- Analyzed and designed system security plans, documents, and requirements.
- Provided IS testing and support while ensuring quality assurance to NRL Division Heads.
- Wrote, edited, and updated policy as necessary; compose and update templates for Information Assurance (IA) Team.
Confidential, Washington
Security Compliance Specialist
Responsibilities:
- Supported the Washington Headquarters IT Services (WITS) contract as a Certification and Accreditation Task Manager for the C&A Team.
- Created, maintained and edited all Certification and Accreditation documentation based on DoD Information Assurance Certification & Accreditation Process (DIACAP) requirements.
- Served as the subject matter expert on DIACAP policies.
- Reviewed customer policies and procedure documentation against written DoD guidelines; responsible for conducting on-site physical security assessments in accordance with DoD guidelines.
- Conducted regularly scheduled DoD security reviews
Confidential
Security Analyst
Responsibilities:
- Responsible for the researching, composing and editing Certification and Accreditation (C&A) documentation based on DoD requirements.
- Assisted in system consolidations, software upgrades and internal information security investigations; present presentations of findings to senior managers and IT staff with the intent to assists clients in attaining highly secure enterprise networks.
- Analyzed basic customer security requirements; assist with contingency management groups in planning and executing disaster recovery procedures.
- Responsible for creating, maintaining and editing all Certification and Accreditation documentation based on DoD Information Assurance Certification & Accreditation Process (DIACAP) requirements.
- Served as the subject matter expert on DIACAP policies.
- Reviewed customer policies and procedure documentation against written DoD guidelines; responsible for conducting on-site physical security assessments in accordance with DoD guidelines.
