It Security Analyst Resume
4.00/5 (Submit Your Rating)
Annapolis, MD
EXECUTIVE SUMMARY:
- Experience in Federal Information Security Management, IT infrastructures, and maintenance of large information systems.
- Extensive experience using the appropriate tools to assess and analyze existing applications for system weaknesses and vulnerabilities and implementing techniques for mitigating security threats and risks.
- Hands - on experience in implementation of the Plans of Actions and Milestones / Corrective Action Plans, as well as remediation of the documented threats and vulnerabilities.
- An expert in the field of risk-based and accreditation using various flavors of the State, Federal, as well as International Cybersecurity frameworks
WORK EXPERIENCE:
Confidential, Annapolis, MD
IT Security Analyst
Responsibilities:
- Support ISSOs with investigation and closure of incidents in cooperation with the SOC.
- Working with ISSO to update key security documents (SSP, Contingency plan, configuration management plan)
- Working with ISSO to help Managing Confidential &Ms.
- Use SIEM technologies and other tools to perform the monitoring of security events on a 24x7 basis.
- Manage/monitor request via the Remedy ticketing system.
- Conduct security control assessments to assess the adequacy of management, operation privacy, and technical security controls implemented.
- Assess security and privacy controls using the Confidential SP A Rev4 publication guideline.
- Responsible for Confidential &M Management/Continuous Monitoring and milestone follow through by coordinating with system stakeholders/control owners (e.g., Systems Admins). Physically identify/open Confidential &M items, track, and facilitated Confidential &M closer.
Confidential, Washington, DC
IT Security Specialist
Responsibilities:
- Managed the information security function in accordance with the established policies and guidelines.
- Help conduct Confidential Readiness Assessments and reviewing ATO packages for Confidential Cloud environments.
- Responsible for IT Security Awareness, Contingency Plan and Incident Response .
- Assess security and privacy controls using the Confidential SP A Rev4 publication guideline.
- Review security policy documents and make recommendations on documentation compliant.
- Conducted and performed continuous monitoring pursuant to Confidential Guidelines requirements.
- Provided impact analysis for updates and version changes required by the Confidential Security Publications and FISMA Notices
- Support control testing and development of Plans of Action and Milestones ( Confidential &M)
- Responsible for tasks related to the system and follow the Government IT security policies and standards.
Confidential, Chantilly, Virginia
Senior IT Auditor/ Engineer
Responsibilities:
- Performed risk assessments to ensure security controls were operating as intended, validated compliance with regulatory standards and identify opportunities to streamline operational processes.
- Assessed the controls, reliability and integrity of the company's systems and d Confidential to assist with maintaining and improving the efficiency and effectiveness of risk management, internal controls and corporate governance.
- Collaborated with key stakeholders to plan engagement strategy, define objectives, and address technology-related controls risks and issues.
- Ensure documentation reflects current control environment for Key Controls, Non-Key Controls, and Issues (with related Management Action Plans)
- Worked with management and compliance leaders to assure security programs were in compliance with security rules and other relevant laws, regulations and policies to minimize or eliminate risk and audit findings.
Confidential, Washington, DC
IT Security Analyst
Responsibilities:
- Provided expertise on technical services including all aspects of information security
- Conduct risk assessments to identify system threats
- Performed maintenance and advanced configuration of systems in order to protect systems from emerging cyber threats.
- Conducted log reviews using Splunk to isolate issues and respond to analyst alerts.
- Collaborated with key stakeholders to update Business Impact Analysis ( Confidential ) to analyze mission-critical business functions and identify and quantify the impact if these are lost (e.g., operational, financial).
- Confidential helped to define the company’s business continuity plan and IT internal control audit objective.
