We provide IT Staff Augmentation Services!

Senior Security Analyst Resume

2.00/5 (Submit Your Rating)

Baltimore, MD

SUMMARY:

  • A hardworking and driven Senior Security Analyst with over 8 years of experience in information technology, with over 5 years of experience as a Security Analyst specifically.
  • I have a great deal of experience with FISMA standards, security control assessments, and the Risk Management Framework.
  • In addition, I have a multitude of experience creating and updating various security documents, such as the SSP, POA&M, SAP, and SAR.
  • Before making the transition into the security field, I worked as an Epic systems analyst, where I also developed and maintained detailed records for system configurations, among other tasks.
  • I am a reliable team player who possesses excellent communication skills and is a very adept writer.
  • Furthermore, I thrive in challenging settings where accuracy and productivity are of the utmost importance.

SKILL:

Risk Management Framework (6 years), Risk Assessments/ A (6 years), FISMA (6 years), POA&M Management (6 years), System Security Plan (6 years), Gap analysis (6 years), Continuous monitoring/ (6 years), Microsoft Office 365 (6 years), Epic (3 years), R (3 years), MySQL/SQL (3 years), JIRA (3 years), Sharepoint (3 years), Microsoft Office 365 (6 years), Tableau (2 years), Citrix (2 years)

RELEVANT EXPERIENCE:

Senior Security Analyst

Confidential, Baltimore, MD

Responsibilities:

  • Oversee and direct a team of information security professionals to conduct Security Authorization packages based on Confidential standards
  • Prepare reports on IT weaknesses and recommendations for noted exceptions
  • Work with system owners to maintain the system’s required security controls and environment
  • Examine, interview and test security controls using Confidential A as a guide
  • Utilize FIPS 199 and Confidential SP to aid in information system identification and categorization
  • Conduct meetings with the IT team to gather documentation and evidence about their control environment
  • Work with business process owners to ensure timely identification and remediation of jointly owned risk related issues and action plans
  • Conduct Risk Assessment utilizing Confidential , in order to obtain Authorization to Operate (ATO)
  • Document and review System Security Plan (SSP), Security Assessment Report (SAR) and Plan Of Action and Milestone (POA&M)
  • Review Privacy Impact assessment (PIA) document after a positive Privacy Threshold Assessment (PTA) is created to ensure PII findings are recorded in the System of Record Notice (SORN)
  • Provide continuous monitoring support for control systems in accordance with FISMA guidelines and recommendations

Information Security Assessor

Confidential, MD

Responsibilities:

  • Performed information systems security audits and and Accreditation (C&A) tests in compliance with the Confidential standards
  • Provided support for all assessment and authorization phases
  • Reviewed authorization documents to ensure accuracy and completeness
  • Ensured that policies in place were reflective of current standards in place, in regards to FISMA compliance
  • Validated system security plans (SSP) to ensure Confidential control requirements were met
  • Supported client in creating findings as part of POA&M remediation efforts through the utilization of CSAM
  • Assisted with the accurate categorization of information systems through the use of FIPS 199 and Confidential SP
  • Provided continuous monitoring of systems in compliance with FISMA standards

Epic Systems Analyst

Confidential, Baltimore, MD

Responsibilities:

  • Developed and maintained detailed documentation on system configurations and technical components
  • Provided support for go - live events, as well as other organizational implementations
  • Maintained regular communication and collaborated with end users, as well as business owners
  • Utilized technical build, testing, and configuration to resolve end user issues
  • Identified and participated in the development of new content

We'd love your feedback!