Security Consultant Resume Profile
SUMMARY
- NIST 800-30/61 with federal Gov. security regulations, NIST SP 800-53, NISPOM, DoD PKI LDAP etc. Working with the Department of Energy Nuclear/DOE - Department of Energy/DOD: NERC CIP regulations version 3 5. Responsible for assisting Power Generation in the development, implementation, and communication of the information security practices, policies, and procedures NEI 08-09/NAP14-1.D which promote a secure and uninterrupted operation of Power Generation Industrial Control and SCADA systems., Working with the various Operating Systems e.g. WindRiver, Linux, UNIX, SQL Oracle databases. Implementing IA Cyber Security via Operating Security Centers OSC such as Emerson, and Honeywell.
- Overseeing the Key Management Infrastructure KMI with the development of a Software Application KMI2 to transfer Black Keys from KMI-MGC to flow into an existing ACES workstation down to the Brigade level.
Confidential
Sr. Information Ass. Cyber Security Consultant
- Leading the IA Security team at Eglin Air Force base, FL for the DIACAP Certification Accreditation of the Air Combat Training Systems. The architecture involves air to ground radios, Aircraft processors, NSA Crypto devices e.g. KG-250X HAIPE devices and Cross Domain Solutions CDSs . Also includes simulated weapons processors so the pilot can do training in a LIVE and SIMULATED environment up in the air. The training involves F-15s, F-18s, JSFs F-35 and other NATO aircraft. This is a Multilevel Security domain Air Combat Training exercises. Expertise in security of multiple operating systems, especially: HPUX, Linux, Windows, other OSs Expertise in access control, authorization and authentication technologies: PAM, Active Directory, LDAP. Securing fundamental networking protocols: DNS, HTTP, TCP, UDP, TLS, IPSEC, 802.1x, NFS. Encryption fundamentals techniques symmetric/asymmetric, ECB/CBC operations, AES, etc. Vulnerability assessment process and tools experience a strong plus: OWASP, Burp Suite, SpiDynamics, etc.
- Also leading the IA Security of a Hand held device for an R D Army/Marines project. Involved in the HW SW architecture of the whole Hand-held and particularly in the Cyber Security architecture. Involved in customer and NSA meetings to further develop the DIACAP Certification Accreditation of the system. The system involves an Android smart phone, a Crypto SUITE B engine and a Tactical Rifleman radio. The Android phone will run an ARMY application called FBCB2. This App is running in a secure OS environment. The smart phone provides user authentication via 2 factors and user roles. All messages back forth to the Android are encrypted via a Type 2 FIPS 140-2 crypto engine. The Black side of the Crypto is connected via a 3 foot cable to a Rifleman radio for reach back to major classified/unclassified networks.
Confidential
As a Senior Information Security Engineer, Confidential was the team lead for the United States Air Force Reserve Command W. Robins, GA support Department of Defense Information Assurance DIACAP Certification and Accreditation activities of the Video Teleconference System the Information Warning System IWS , and various Telephone Switches. Responsibilities included registering DoD IS with Enterprise Information Technology Database Repository EITDR/eMASS developing DIACAP comprehensive and executive packages, support documentation and artifacts conducting security hardening using DISA STIGs, SRRs, and security checklists Conducted independent verification and validation IV V , and security test and evaluation ST E testing activities conduct risk and vulnerability assessments, document, mitigate, and remediate deficiencies. Vulnerability assessment process and tools experience a strong plus: OWASP, Burp Suite, SpiDynamics, etc.
Confidential
- As a Senior Information Security Consultant, Mr. Georgoulis provided certification and accreditation support to the Spacelift Range System Contract SLRSC for the Vandenberg Air Force Base Telemetry Receiver Site VTRS . Responsibilities include reworking DIACAP C A packages to include SSP, and ST E. Conducting ST E testing and reviewing raw test data. Developing the Security, Test and Evaluation ST E plan, test cases and generating reports. Develop DIACAP Comprehensive Executive packages support documentation and artifacts. Make recommendations and comments to improve the success rate for project documentation. Identify, review, document, verify, test, and validate IA controls, safeguards, and countermeasures. Develop SSP, ST E test cases, report , RMP, DIP, SIP, POA M and Scorecard.
- Conduct peer reviews. Provide expert technical guidance, interpretation, and implementation oversight of applicable information security policies, processes, and practices to support continued operational availability and integrity for DOD information systems and IT processes e.g. security of multiple operating systems, especially: HPUX, Linux, Windows, other OSs access control, authorization and authentication technologies:
- Implementing IA Cyber Security via Operating Security Centers OSC such as Emerson, and Honeywell. DSPs, PLCs, PAM, Active Directory, LDAP. Securing fundamental networking protocols: DNS, HTTP, TCP, UDP, TLS, IPSEC, 802.1x, NFS.Encryption fundamentals techniques symmetric/asymmetric, ECB/CBC operations, AES, etc.
Confidential
Sr. Information Ass Cyber Security Consultant
As a Senior Information Assurance Engineer Team Lead , Confidential supported the GDLS/GDC4S JTRS-HMS Project. He conducted Department of Defense Information Technology Security Certification and Accreditation Process DITSCAP/DIACAP Vulnerability assessment process and tools experience a strong plus: OWASP, Burp Suite, SpiDynamics, etc. Understanding of risk modeling concepts and frameworks e.g. STRIDE, DREAD, FAIR. Strong background in data driven information security decision making and prioritization Strong understanding of the attacker kill chain activities for several platforms to include the JTRS-HMS radios e.g. Rifleman Type 2 , Type 1 radios and the R D HAIPE Type 1 Vehicle Radio NSA Type 1 Certification Accreditation Also supported the Future Combat Systems FCS , Abrams New Evolution Tank, Stryker Family of Vehicles, Joint Light Tactical Vehicles JLTV and MUOS waveform. Responsibilities include developing DITSCAP C A packages, support documentation and artifacts identifying and documenting security requirements conducting security hardening activities using DISA and NSA Type 1 security technical implementation guides STIGs , security readiness reviews SRRs and security checklists, and industry best practices. Conduct risk and vulnerability assessments IAW DISA PSSM/CAP policies and procedures conduct independent verification and validation activities conduct risk management activities assessment, mitigation and remediation . Confidential was the subject matter expert for several Cross Domain Solutions CDS , and for HAIPE Type 1 devices.
Confidential
Information Ass. Security Consultant
As a Senior Information Assurance Engineer Team Lead , Confidential supported the JTRS Ground Mobile Radio GMR , Airborne Marine Fixed AMF , and Future Combat Systems FCS project. Responsibilities included conducting NSA, NIACAP, NISCAP, DITSCAP/ DIACAP certification accreditation packages. Conduct DITSCAP to DIACAP transitioning Expertise in security of multiple operating systems, especially: HPUX, Linux, Windows, other OSs access control, authorization and authentication technologies: PAM, Active Directory, LDAP. Securing fundamental networking protocols: DNS, HTTP, TCP, UDP, TLS, IPSEC, 802.1x, NFS. Encryption fundamentals techniques symmetric/asymmetric, ECB/CBC operations, AES, etc. Vulnerability assessment process and tools experience a strong plus: OWASP, Burp Suite, SpiDynamics, etc. Understanding of risk modeling concepts and frameworks e.g. STRIDE. Strong background in data driven information security decision making and prioritization Strong understanding of the attacker kill chain. Conduct security test and evaluation, ST E , configuration, test and evaluation CT E , and independent verification and validation IV V activities. Conduct risk and vulnerability assessments. Conduct risk management activities assessment, mitigation and remediation . Conduct security hardening activities using DISA STIGs, SRRs, and security checklists. Develop C A packages, support documentation and artifacts. Map security requirements to system requirements. Develop security test and evaluation test cases. Evaluate defense in-depth architecture and designs and made recommendations for improvements.
Confidential
Sr. Information Security Lead
As an Information Assurance Engineer Team Lead , Confidential supported the Multi-sensor Command and Control Aircraft platform MC2A with C4ISR Intelligence, Surveillance and Reconnaissance sensors and associated subsystems for the United States Air Force. Enter security requirements into the DOORS database. Develop DITSCAP certification and accreditation packages, support documentation and artifacts. Conduct security test and evaluation ST E activities, and developed ST E test cases. Conduct risk and vulnerability assessments. Conduct risk management activities assessment, mitigation and remediation . Configure system components, and employ DISA/NSA STIGs.
Confidential
Information Security Consultant
As an Information Assurance Engineer Team Lead , Mr. Georgoulis supported the FAA/NASA Aeronautical Telecommunication Network ATN . Responsibilities included installing and configuring the public key infrastructure PKI . Supervise a team of 10 IA engineers. Develop the Air to ground digital protocol VDL M2 IAW OSI methodology utilizing ICAO VDL M2 and SARPS. Develop DITSCAP C A packages, support documentation and artifacts. Develop ST E plan, test cases, and conduct testing activities.
Confidential
Sr. Systems Consultant
As a Senior System Engineer, Confidential supported the Air Traffic Control Division/Software Integration. Responsibilities included develop system design and architecture, and documentation. Defining system requirements and mapping requirements to system architecture. Conduct system and networking activities. Conduct network modeling and simulation activities, and coordinate and schedule system integration activities.
Confidential
FL Senior Systems Engineer
As a Senior System Engineer Team Lead , Mr. Georgoulis Manage testing activities to Design with a team effort various test stations for DOD projects. The Test stations will test various LRUs, such as radars, radios, antennas, etc
