Senior Security Analyst Resume
2.00/5 (Submit Your Rating)
Baltimore, MD
SUMMARY:
- A hardworking and driven Senior Security Analyst with over 8 years of experience in information technology, with over 5 years of experience as a Security Analyst specifically.
- I have a great deal of experience with FISMA standards, security control assessments, and the Risk Management Framework.
- In addition, I have a multitude of experience creating and updating various security documents, such as the SSP, POA&M, SAP, and SAR.
- Before making the transition into the security field, I worked as an Epic systems analyst, where I also developed and maintained detailed records for system configurations, among other tasks.
- I am a reliable team player who possesses excellent communication skills and is a very adept writer.
- Furthermore, I thrive in challenging settings where accuracy and productivity are of the utmost importance.
SKILL:
Risk Management Framework (6 years), Risk Assessments/ A (6 years), FISMA (6 years), POA&M Management (6 years), System Security Plan (6 years), Gap analysis (6 years), Continuous monitoring/ (6 years), Microsoft Office 365 (6 years), Epic (3 years), R (3 years), MySQL/SQL (3 years), JIRA (3 years), Sharepoint (3 years), Microsoft Office 365 (6 years), Tableau (2 years), Citrix (2 years)
RELEVANT EXPERIENCE:
Senior Security Analyst
Confidential, Baltimore, MD
Responsibilities:
- Oversee and direct a team of information security professionals to conduct Security Authorization packages based on Confidential standards
- Prepare reports on IT weaknesses and recommendations for noted exceptions
- Work with system owners to maintain the system’s required security controls and environment
- Examine, interview and test security controls using Confidential A as a guide
- Utilize FIPS 199 and Confidential SP to aid in information system identification and categorization
- Conduct meetings with the IT team to gather documentation and evidence about their control environment
- Work with business process owners to ensure timely identification and remediation of jointly owned risk related issues and action plans
- Conduct Risk Assessment utilizing Confidential , in order to obtain Authorization to Operate (ATO)
- Document and review System Security Plan (SSP), Security Assessment Report (SAR) and Plan Of Action and Milestone (POA&M)
- Review Privacy Impact assessment (PIA) document after a positive Privacy Threshold Assessment (PTA) is created to ensure PII findings are recorded in the System of Record Notice (SORN)
- Provide continuous monitoring support for control systems in accordance with FISMA guidelines and recommendations
Information Security Assessor
Confidential, MD
Responsibilities:
- Performed information systems security audits and and Accreditation (C&A) tests in compliance with the Confidential standards
- Provided support for all assessment and authorization phases
- Reviewed authorization documents to ensure accuracy and completeness
- Ensured that policies in place were reflective of current standards in place, in regards to FISMA compliance
- Validated system security plans (SSP) to ensure Confidential control requirements were met
- Supported client in creating findings as part of POA&M remediation efforts through the utilization of CSAM
- Assisted with the accurate categorization of information systems through the use of FIPS 199 and Confidential SP
- Provided continuous monitoring of systems in compliance with FISMA standards
Epic Systems Analyst
Confidential, Baltimore, MD
Responsibilities:
- Developed and maintained detailed documentation on system configurations and technical components
- Provided support for go - live events, as well as other organizational implementations
- Maintained regular communication and collaborated with end users, as well as business owners
- Utilized technical build, testing, and configuration to resolve end user issues
- Identified and participated in the development of new content
