We provide IT Staff Augmentation Services!

Malware Agent, Business Agent, Software Developer Resume

2.00/5 (Submit Your Rating)

San Diego, CaliforniA

SUMMARY:

  • Confidential is an IT Security Engineer with over 25 years of experience ranging from research and development (R&D), quality assurance (QA), customer support, penetration testing, and security administration.
  • He has assisted in the development and QA of dozens of software products for the enterprise, engineering, and consumer segments.
  • He has extensive experience as a liaison between QA, R&D, engineering, and support teams bringing teams together to resolve complex issues.
  • On the Confidential Internet Security Systems X - Force team, he combatted malware and dissembled the code red virus.
  • Recently, he is focused on product implementation and support for Business clients to include identification future enhancements.
  • He has presented at security conferences, established security policies, and mentored colleagues and student.

TECHNICAL SKILLS:

Known/Used Software, Hardware, Computer Languages: Access; Adobe PhotoShop; AMP; AMP 1.0-9.2; Apache; Arcsight SIEM; Blue Coat Proxy; Bomgar; BSD (Open 2.8 and Free 4.3); Centos 6.x and 7.x; CheckPoint; Checkpoint Firewall-1 3.0-4.1-NG; CheckPoint Nokia IP440 NG R55; Cisco Pix 535 Firewall; Compaq Servers; Content Vectoring Protocol with Symantec Norton Antivirus; Corporate Exchange; Cybercop Scanner; Dell Servers; desktop defense; DevInspect; DOS; Dragon IDS; Dragon NFR; Eeye Retina; Confidential Business Products EndPoint EEA/EES 4.x, 5.x, 6.x; Confidential Mail Security and File Security 4.x and 6.x; Confidential Remote Administrator 5.x and 6.x; Exchange 5.5-2003; FileMon; Firewall-1; Confidential SCA 4.x; FTP; Ghost; Hayes/USR/ISDN Modems; HP Servers; Hyena; IIS; Internet Security Systems (ISS) Internet Scanner; IP tools sets; IPX; Iron Port;ISS Database Scanner; ISS SAFEsuite Decisions; Jenkins; JIRA; Kali-Linux.; Kiwi Sawmill; Linux; Linux Jumpstart; Mac OS X; Mcafee; Microsoft ISA; MS Network Monitor; Navision CCAPs; Navision Financials; Nessus; net x-ray; Netcache Proxy; Network ICE Gigabit; Nmap; Norton Anti-virus; Norton System Center; NT Server; Office 98-2013; OS/2 Warp 3.0; PGP; QAI; Raptor; Rational Rose; Redhat Linux; RegMon; Remote Control Systems ; SAN; Secure Objects; Server Sensor; Silent Runner; Slackware; Slackware 14.x; SMS; Sniffer Pro; Snoop; Snort; Solaris 2.5.1/2.6/2.7/2.8 ; Solaris x86; Splunk SIEM; SQL Admin; SQL 6.5-2014; SSL; StarTeam; Sygate firewall; TCP; TCPdump; TweakUI; UDP; Veritas Backup Exec; Visio; VNC; Web Sphere; WebInspect 5.0-10.20; Webinspect Enterprise; Win 2000,2003,2008,2012 Server; Windows 7,8.1, 10; WinHex; Winrunner; Wireshark; Zonealarm; C; C#; C++; COBOL; GNU C; MS C++; PERL and shell code; Python; Q basic; Visual Basic; Visual Studio 2015

PROFESSIONAL EXPERIENCE:

Confidential, San Diego, California

Malware Agent, Business Agent, Software Developer

Responsibilities:

  • Establish detection criteria and respond to malware infiltrations
  • Create tools to resolve recurring product issues
  • Coordinate with Managed Service Providers and Partners to resolve issues
  • Resolved issues with HIPPA compliance medical and dentist healthcare professionals
  • Research new threats and infiltrations
  • Present at ToorCon San Diego on ransom ware
  • Support customers with PCI-DSS compliance
  • Liaison with multiple teams to identify, prioritize, and achieve technical goals
  • Provide contributions and enhancements to Knowledge Base (KB) articles
  • Mentor high school students as an instructor at a cyber boot camp
  • Train and mentor new hires and enable them to become successful and contributing team members
  • QA all security products from 5.x, 6.x and 7.x series from smoke test to release.

Confidential, Roswell, Georgia

Founder, Product Manager, Penetration Tester

Responsibilities:

  • Conducted penetration testing and reporting and remediate findings with customers (Nessus, Burp, etc)
  • Created Security Threat Intel SIEM product the language used is C#
  • Created Splunk filters and Wireshark add-ons in order to filter large data sets
  • Provide security policies and countermeasures
  • Conducted PCI and HIPPA compliance checks with clients
  • Assisted with the SDLC security with QA and Development

Confidential, Alpharetta, Georgia

WebInspect Sr. QA Analyst, Sr. Information Security Analyst

Responsibilities:

  • Presented at HP Universe speaking on securing the SDLC from start to finish in a live demo
  • Won the Global Support Delivery Fab 5 award in December 2009 for creating the HP secure upload process this was used by 30k support engineers
  • Performed penetration tests for customers
  • Recommended security improvements for future releases
  • Investigated vulnerabilities and how to detect them with Arcsight, Confidential, Tipping Point and Webinspect products
  • Designed secure systems architecture and implemented solutions
  • Taught security and hacking methods and mentored colleagues
  • Built security lab environment for real customer testing
  • Assisted with PCI and HIPPA compliance with customers
  • Documented security lab procedures
  • Documented defects relating to WebInspect, AMP, DevInspect, and Secure Objects using Mercury Quality Center and Team Foundation Server
  • Created a web based security knowledge base running on python/plone
  • Analyzed customer scan data to identify exploitable vulnerabilities
  • Created HP support tools and reduced the number of support calls
  • Found XSS/SQL injection and other vulnerabilities in customer and client web sites
  • Performed QA and testing multiple lines executing up to 300 tests per sprint
  • Supported customers with relentless enthusiasm to ensure success with our team and products
  • Installed and tested IDS/IPS systems and worked with customers on issue remediation

Confidential, Roswell, Georgia

Sr. Systems and Security Administrator

Responsibilities:

  • Established an IDS system consisting of ISS Site Protector attached to a ISS Proventia’ G appliance
  • Established a weekly penetration test to ensure that there was no unknown systems
  • Documented procedure to close the system
  • Established a desktop defense system internally in the event of a front-line or perimeter breach
  • Created a central logging server for PIX 520, Linux, Solaris, and Cisco switch traffic
  • Maintained security on 1.5k+ production servers at customer sites and 250 internal workstations
  • Assisted with QA on the Digital Media Gateway to ensure it was released on time
  • Documented defects using Mercury Quality Center
  • Maintained and planned NT Exchange 5.5 to 2003 Exchange 2003 migration
  • Established Internet Ethics, Wireless, and General System Policies for the company
  • Audited our product and documented security vulnerabilities and solutions

Confidential, Atlanta, Georgia

Sr. Information Security Engineer

Responsibilities:

  • Advised and implemented solutions in all aspects of Network and Host Based Security
  • Converted a malfunctioning PIX 520 Firewall to Check Point NG Firewall-1
  • Established Dial-Up, Wireless, Secure Use, Safe Computer Practice, and Internet Ethics Policies
  • Developed campus wide IDS using Snort, Dragon and ISS Real Secure IDS
  • Performed and analyzed Penetration Tests
  • Geared the University towards security by leveraging the benefits and features of a secure well run corporate enterprise
  • Handled FBI investigations and reports on how and why an incident happened and how to prevent it, likewise reported events that were discovered internally
  • Performed security audits on internal and external machines and repaired them with responsible parties
  • Installed and configured Norton CVP anti-virus for gateways and Norton Symantec Web Security content filtering
  • Installed and configured Norton System Center for 1.8k+ workstations
  • Maintained Internet connection for 5k+ people
  • Changed e-mail remote and internal from no encryption to SSL
  • Managed 150K budget for security tools and protection

Confidential, Atlanta, Georgia

Sr. QA Analyst

Responsibilities:

  • Completed Check Point RealSecure 5.5-6.0 QA product lifecycle SDLC
  • Created IDS assessment policies for the Global Threat Operation Center (NOC)
  • Performed research on all current and past exploits, Trojans, DOS, DDOS, worms, virus, spy ware, IDS products, enterprise, and home firewall systems
  • Watched for and identified patterns in malicious data with network sniffing software
  • Tested IDS systems for accuracy
  • Developed capture files to replay the malicious data for IDS to test and for developers to build into the product
  • Performed demos to show the effects of vulnerable IIS servers that are deployed (Code Red, Code Blue, Nimda)
  • Wrote draft security advisories and supplied research for numerous publications to provide information to customers and the general Internet
  • Performed QA on RealSecure CheckPoint IDS product up to RealSecure 6.0 over 300 implementations of the product with Solaris, NT, and IPSO Nokia based systems each cycle
  • Used StarTeam and Visual Source Safe to control code and scenarios
  • Beta tested scenarios and customer feedback requirements
  • Evaluated products for purchase
  • Performed load testing and evaluations of the product under great network stress
  • Participated in FIRST teams, CERT, Trojan, DDOS, and worm disassembly to educated the public on the capabilities of IDS systems
  • Developed and reviewed Ethical Hacking training course that ISS offers (Penetration testing, IDS, CGI, IIS)

We'd love your feedback!