Snr. Information Security Analyst Resume
2.00/5 (Submit Your Rating)
SUMMARY
- Exceptionally focused and skilled Information Security Analyst. Diligent and proficient with a thorough understanding of ascertaining security threats and vulnerability, formulating plan of action and milestone to prioritize, remediate, and monitoring corrective actions., testing, IT security risk and compliance.
- Vast in knowledge of NIST publication series, FISMA, Security Control Assessment, Vulnerability Management.
- Proficient in developing Authorization Packages - SSP, SAR, POAM. Able to multitask effectively and seeking to work in a professional environment where my skills in analyzing and problem solving can be fully utilized.
PROFESSIONAL EXPERIENCE
Snr. Information Security Analyst
Confidential
Responsibilities:
- Apply appropriate information security control for Federal Information System based on NIST 800-37 rev1, SP 800-53 rev4.
- Review and update some of the system categorization using FIPS 199.
- Create and update Contingency plan and Disaster recovery plans for infor. systems using NIST SP 800 -34.
- Categorize information systems in accordance to FIPS 199, NIST 800-60.
- Select and assign appropriate security controls to Federal information systems.
- Conduct security control assessment in accordance with NIST 800-53A Rev4.
- Conduct continuous monitoring after authorization (ATO) to ensure continuous compliance with the security requirements
- Develop, review and update Information Security System Policies, System Security Plans (SSP), and Security baselines in accordance with NIST, FISMA, OMB Ap. III A-130, NIST SP 800-18 and industry best security practices.
- Performed risk assessments; developed and review system security plan (SSP), Plans of Action and milestones (POA&M), Security Control Assessments, Configuration Management Plans (CMP), Contingency Plans (CP), Incident Response Plans (IRP) and other tasks and specific security documentation
- Performed assessment of IT internal controls as part of financial statement audit.
- Planned and performed review of IT general and Application controls.
- Maintained a good working relationship to enhance customer satisfaction.
- Implemented log and event management with the use of Arc Sight SIEM, Splunk
SAP/GRC Security Consultant
Confidential
Responsibilities:
- Created and modifying Single, Derived and Composite Roles using Profile Generator.
- Performed user administration (creating, changing, maintaining, deleting user accounts) using SU01, SU10
- Lock/unlock users and reset user passwords.
- Transported all approved roles through the landscape from Development to QA and Production
- Trouble shoot missing access or additional access for the user using SU53, ST01.
- Worked extensively with user information system (SUIM).
- Provided Detailed Reports of Users, User Status, Roles, Activity Groups, T-Codes and Objects when required.
- Reviewed and act on daily monitoring/change reports.
- Assigned/Changed org level values to derived roles.
- Assigning /removing roles from users and end dating roles validity date.
- Worked with CUA (Central User Administration) for creating/changing/deleting users/roles in the CUA landscape system (Dev, QAS, Prod)
- Provided SAP audit remediation to resolve segregation of duties violations (SOD) in end user roles.
- Identify missing authorizations by using SU53 and maintain them manually in PFCG
Information Security Analyst
Confidential
Responsibilities:
- Worked under general supervision to plan and conduct security related assignments for one or more programs/customers.
- Conduct compliance assessments with key business partners and creates the necessary documentation for evidence in PCI DSS, for areas of concern such as threats, vulnerabilities, processes, controls and impacts on critical assets.
- Trusted advisor to program manager and development team to ensure adherence to security architecture and development standards.
- Acted as one of several primary points of contact for the customer relative to matters of information security.
- Provided guidance to our Program Managers and Program Directors regarding internal security strategy.
- Helped implement selected program components for our internal security department/posture as well.
