Sr. Security Analyst Resume
TECHNICAL SKILLS
Audit, Standards, & GRC: ISO 27001 / 27002/ 9001, SOX, PCI - DSS, GDPR, Shared Assessments Standardized Information Gathering (SIG), Secure SDLC Life-cycle (Agile / Dev Ops), ServiceNow, BMC Remedy, One Trust, RSA Archer, rSam, cSAM, EITDR, eMASS, Amazon AWS, Microsoft Azure, Salesforce, HIPAA, Global Decision Support System (GDSSII)
Security Tools: Netwitness, Snort, Splunk, Identity Finder, Wireshark, Force Point, Check Point, ArcSight, Sourcefire, Nessus, DISA STIG, Host Base Security System (HBSS), Nessus, Analysis Console for Intrusion Databases (ACID), Department of Defense Government off-the-shelf (GOTS) IT Service Management BMC Remedy, JIRA, Microsoft System Center Configuration Manager
Operating Systems: UNIX / Linux, Windows
Network / Devices: Firewalls, IDS / IPS
PROFESSIONAL EXPERIENCE
Confidential
Sr. Security Analyst
Responsibilities:
- Performed all aspects of risk assessments for third - party vendors
- Analyzed supporting documentation (SIG, CAIQ, and SOC reports)
- Worked with privacy. legal, HR, to identify and document adherence to control requirements
- Created and maintained the risk register to track identified risk, risk owners and action plans
- Facilitated the creation of policy exceptions for deviations from baseline security controls
- Provided risk and compliance guidance to internal and external stakeholders
- Assisted in establishing and implementing global risk and compliance oversight
- Assisted with the implementation of globally aligned operational controls, manuals and methods across all business units
- Performed security solutions as part of the scrum team using web, mobile, IoT and cloud technologies
Confidential
Sr. Analyst
Responsibilities:
- Performed attestation of security controls used within the organization by reviewing SOC reports
- Provided service delivery of related functions to vendor management team
- Identified gaps or issues and documented evidence in RSA Archer
- Led risk response including analysis, assessments, monitoring, remediation, and reporting
- Collaborated with IT and business to provide guidance on compliance and standards
- Monitored and tracked trouble tickets, using BMC Remedy through remediation
- Served as a team lead within the Risk team and provide mentoring for Jr. analysts
- Functioned as a project coordinator for planning and scheduling for disaster recovery
- Assisted development teams to understand features and capabilities of approved web, mobile, IoT and cloud technologies, served as escalation for issue resolution
- Participated in the enterprise risk management program ensuring compliance with the information security policy and associated procedures
Confidential
Sr. Analyst
Responsibilities:
- Performed third-Party vendor evaluations and risk assessments for PCI compliance
- Conducted privacy impact assessments to identify areas of non-compliance
- Led PCI Governance and related committees
- Provided supporting activities around the third-party vendor compliance program
- Assisted in the deployment and sustainment of solutions to meet PCI DSS requirements
- Provided PCI Remediation Consulting
- Assisted with Disaster Recovery plan creation, testing, and remediation where needed
- Assisted in managing, monitoring and reporting enterprise business operational risk Assisted with installation, configuration, and customization of role-based access control tools
- Performed research on emerging products, services, protocols, and standards in support of security enhancement and development efforts
Confidential
Information Systems Security Officer
Responsibilities:
- Led risk function for third-party risk on regulatory requirements in relation to third-party risk
- Monitored security controls and performed third-party risk assessments
- Built and business relationships with BCP, Legal, Compliance, Audit and Training
- Ensured risk management activities conformed to best practices, regulations and local procedures
- Coordinated with the third-party program officer to maintain the third-party inventory
- Identified areas of Third-party risk, worked to reduce, mitigate or eliminate residual risk
- Created, revising, and reviewed System Security Plans, Security Assessment Plans, Plan of Action & Milestones (POA&M), Security Assessment Reports for low, moderate and high government systems
