Cyber security analyst Resume
4.00/5 (Submit Your Rating)
Washington, DC
SUMMARY
- An experienced IT Security Analyst who possess the skills necessary to fill any IT security or information assurance position.
- I am confident to bring to your company a broad range of skills sets, experiences and abilities.
- I am an excellent collaborative team player who can hit the ground running while also being self-sufficient professional.
SKILL SET
- Google Sketchup
- C# Programming
- Microsoft Excel
- Microsoft Word
- Microsoft Access
- Microsoft Powerpoint
- 2 Years of Mandarin Chinese
- Autodesk AutoCAD
- Supporting the C&A Team during system security testing
- Experienced in the development of System Security Plans (SSP), Contingency Plans, Disaster Recovery Plans, Incident Response Plans/Training, and Configuration Management.
- Plans, System Security Checklists, Privacy Impact Assessments, POA&M,
- Familiar with VMware and other Virtual Machine Applications
- Good communication and writing skills
- Experienced working with NIST SP 800-53 rev 3 and rev 4
- Working knowledge of NIST 800-53, NIST RMF, FIPS and FISMA
PROFESSIONAL EXPERIENCE
Confidential,Washington, DCCyber Security Analyst
Responsibilities:
- FISMA Reports, Standard Operating Procedures (SOP) in accordance with FISMA law
- Reviewed ATO package documents such as CP, CPT, PIA, PTA, SORN, DRP, BIA, RA, IR, MOU, ISA, SLA POA&M, SSP, SAP and SAR
- Conduct the ST&E Kick-off Meeting and populate the Requirements Traceability Matrix (RTM) according to NIST SP 800-53A.
- Experience with NIST standard on cyber security and incident handling (800-63, 800-61)
- Reviewed and updated some of the system categorization using FIPS 199, Initial Risk Assessment, E-authentication, PTA, PIA, SAR,SSP, SAP & POA&M.
- Document and Review security plans (SP), contingency plans (CP), contingency plan tests (CPT), privacy impact assessments (PIA), and risk assessment (RA) documents per NIST 800 guidelines for various government agencies.
- Monitor controls post authorization to ensure continuous compliance with the security requirement
- Hold kick-off meeting with CISO and systems stakeholders prior to assessment engagement
- Worked with Certification and Accreditation team; performed risk assessment; updated System Security Plan (SSP), contingency plan (CP), Privacy Impact Assessment (PIA), and Plan of Actions and Milestones (POA&M)
- Conducted meetings with the IT team to gather documentations and evidences (Kick - off meeting) about their control environment.
- Negotiate with the ISSM to administer ATT’s and ATO’s
- Performed data gathering techniques in preparation for assembling C&A/A&A packages.
- Updated Plan Of Action and Milestone (POAM) and Risk Assessment based on findings assessed through monthly updates.
Cyber Security Analyst
Responsibilities:
- Helped guide System Owners and ISSOs through Certification and Accreditation (C&A) Process, ensuring that Operational, management and technical control securing sensitive Security Systems are in place and being followed according to the Federal Guideline (NIST SP 800-53).
- Determined Security Categorizations using the FIPS 199 as a guide
- Identified Security Controls and Construct a Compliance Matrix for tracking.
- Reviewed Privacy Impact Assessment (PIA) System of Record Notice (SOR)
- Reviewed ATO package documents such as CP, CPT, PIA, PTA, SORN, DRP, BIA, RA, IR, MOU, ISA, SLA POA&M, SSP, SAP and SAR
- Implemented information security requirements for IT Systems through System Life Cycle from requirement definition phased through disposition.
- Reviewed Clients’ processes relating to Vulnerability Mitigation, Training on C & A Tools.
- Provided Support for System Testing and Evaluation (ST&E)
- Conducted Security Risk Assessment and documented Key Controls.
- Developed Test Plans; Testing Procedures and documented test results and exceptions
- Performed ST&E, produced the test result and recommend solutions
- Reviewed Plan of Action and Milestones (POA&M)