We provide IT Staff Augmentation Services!

Sr. Security Analyst Resume

4.00/5 (Submit Your Rating)

TECHNICAL SKILLS

Audit, Standards, & GRC: ISO 27001 / 27002/ 9001, SOX, PCI - DSS, GDPR, Shared Assessments Standardized Information Gathering (SIG), Secure SDLC Life-cycle (Agile / Dev Ops), ServiceNow, BMC Remedy, One Trust, RSA Archer, rSam, cSAM, EITDR, eMASS, Amazon AWS, Microsoft Azure, Salesforce, HIPAA, Global Decision Support System (GDSSII)

Security Tools: Netwitness, Snort, Splunk, Identity Finder, Wireshark, Force Point, Check Point, ArcSight, Sourcefire, Nessus, DISA STIG, Host Base Security System (HBSS), Nessus, Analysis Console for Intrusion Databases (ACID), Department of Defense Government off-the-shelf (GOTS) IT Service Management BMC Remedy, JIRA, Microsoft System Center Configuration Manager

Operating Systems: UNIX / Linux, Windows

Network / Devices: Firewalls, IDS / IPS

PROFESSIONAL EXPERIENCE

Confidential

Sr. Security Analyst

Responsibilities:

  • Performed all aspects of risk assessments for third - party vendors
  • Analyzed supporting documentation (SIG, CAIQ, and SOC reports)
  • Worked with privacy. legal, HR, to identify and document adherence to control requirements
  • Created and maintained the risk register to track identified risk, risk owners and action plans
  • Facilitated the creation of policy exceptions for deviations from baseline security controls
  • Provided risk and compliance guidance to internal and external stakeholders
  • Assisted in establishing and implementing global risk and compliance oversight
  • Assisted with the implementation of globally aligned operational controls, manuals and methods across all business units
  • Performed security solutions as part of the scrum team using web, mobile, IoT and cloud technologies

Confidential

Sr. Analyst

Responsibilities:

  • Performed attestation of security controls used within the organization by reviewing SOC reports
  • Provided service delivery of related functions to vendor management team
  • Identified gaps or issues and documented evidence in RSA Archer
  • Led risk response including analysis, assessments, monitoring, remediation, and reporting
  • Collaborated with IT and business to provide guidance on compliance and standards
  • Monitored and tracked trouble tickets, using BMC Remedy through remediation
  • Served as a team lead within the Risk team and provide mentoring for Jr. analysts
  • Functioned as a project coordinator for planning and scheduling for disaster recovery
  • Assisted development teams to understand features and capabilities of approved web, mobile, IoT and cloud technologies, served as escalation for issue resolution
  • Participated in the enterprise risk management program ensuring compliance with the information security policy and associated procedures

Confidential

Sr. Analyst

Responsibilities:

  • Performed third-Party vendor evaluations and risk assessments for PCI compliance
  • Conducted privacy impact assessments to identify areas of non-compliance
  • Led PCI Governance and related committees
  • Provided supporting activities around the third-party vendor compliance program
  • Assisted in the deployment and sustainment of solutions to meet PCI DSS requirements
  • Provided PCI Remediation Consulting
  • Assisted with Disaster Recovery plan creation, testing, and remediation where needed
  • Assisted in managing, monitoring and reporting enterprise business operational risk Assisted with installation, configuration, and customization of role-based access control tools
  • Performed research on emerging products, services, protocols, and standards in support of security enhancement and development efforts

Confidential

Information Systems Security Officer

Responsibilities:

  • Led risk function for third-party risk on regulatory requirements in relation to third-party risk
  • Monitored security controls and performed third-party risk assessments
  • Built and business relationships with BCP, Legal, Compliance, Audit and Training
  • Ensured risk management activities conformed to best practices, regulations and local procedures
  • Coordinated with the third-party program officer to maintain the third-party inventory
  • Identified areas of Third-party risk, worked to reduce, mitigate or eliminate residual risk
  • Created, revising, and reviewed System Security Plans, Security Assessment Plans, Plan of Action & Milestones (POA&M), Security Assessment Reports for low, moderate and high government systems

We'd love your feedback!