Information Security Officer Resume
3.00/5 (Submit Your Rating)
Baltimore City, MD
EXPERIENCE SUMMARY:
Information Technology professional with 8+ years’ experience in information security, cloud security, IT risk. Management, Governance and Compliance
KEY SKILL AREAS:
- Cloud Computing Security
- Experience with security frameworks
- Access Control Mapping
- ISO 27001/NIST 800 - 53
- Cyber Security Policy and Governance
- Project and Team Management
- Risk Assessment and Vulnerability Management
- Information Assurance/Certification and Accreditation
PROFESSIONAL EXPERIENCE:
Confidential, Baltimore City, MD
Information Security Officer
Responsibilities:
- Conducting meetings with the client to discuss client’s material weaknesses identified in an audit to gain an understanding and develop mitigation strategies for the findings.
- Conduct POA&M management by tracking and addressing weaknesses, as needed.
- Coordinate with POCs to request artifacts to close out POA&Ms.
- Meet with system point of contacts to discuss and provide guidance on remediation strategies.
- Communicate complex technology and security concepts and methodologies to senior leadership to support development of enterprise security strategy implementation.
- Serve as a subject matter expert in governance and leadership by reviewing and developing effective structure for communicating, decision making and responding to security threats across an organization
- Update secure configurations by routinely reviewing vendor sites, bulletins, and notifications for security information.
- Provide technical advice on access control, security models, disaster recovery, business continuity planning, and security awareness training.
- Plan, implement and monitor internal information technology security policies, application security, access control, and corporate data safeguards
- Discuss and develop security strategies with CIO after weekly review of network vulnerability assessment results.
Confidential, MD
Information Security Analyst
Responsibilities:
- Initiated and established a Role Base Access Control (RBAC) method for finance divisions to define controls for managing access and reducing risk.
- Managing role certification campaigns to confirm access controls and ownership.
- Co-ordinate meetings with senior officers of Confidential to determine privileges and access requirements relating to their departments.
- Developed materials to educate staff on the benefit of Role Based Access Control policy for the firm.
- Trained junior analyst on the daily tasks associated with provisioning appropriate access.
- Processed user access requests, modifications, terminations.
- Communicating status across the firm charting progress against the Identity Access Management program roadmap.
- Assist Project/Audit Lead with Semi Annual Access Review process for financial divisions.
- Work with various business and IT application owners in order to define Role-based access templates for implementing RBAC for multiple applications.
Confidential, MD
Information Security Analyst
Responsibilities:
- Install, configure and maintain IPS/IDS, Firewall, Anti-Virus, Anti-Spam, Anti-Malware, SIEM, etc. for maximum internal network protection.
- Research suspected or confirmed malware infection.
- Perform firewall vulnerability assessments and penetration tests assessments and remediate issues that arise.
- Helps to conduct internal and external security scans to identify vulnerabilities on the network or attached systems.
- Helps to conduct the training of client staff to recognize, respond to, and report to IT department, any unauthorized or fraudulent attempts to obtain client information.
- Investigates new information security technologies and makes recommendations on the best use of technology for a particular application.
- Works with other Information Technology staff to standardize the access and security privileges provided on these systems to ensure that access given to users is appropriate, and is in the interest of the client.
- Provides assistance and direction to other Information Technology staff on information security matters.
