Cyber Security Analyst Resume
5.00/5 (Submit Your Rating)
MarylanD
SUMMARY:
A Cyber Security Analyst with experience in Risk Management Framework (RMF), Security Control Assessment (SCA), Plan of Action & Milestone (POA&M), and Policies and Procedure documentation.
TECHNICAL SKILLS:
- Microsoft Word, Microsoft Excel, PowerPoint
- Microsoft SharePoint and Microsoft Outlook
- MS Project and MS Visio
- Nessus, TAF
- XACT
- CFACTS, and CSAM
PROFESSIONAL EXPERIENCE:
Confidential, Maryland
Cyber Security Analyst
Responsibilities:
- Prepare an Ongoing Authorization (OA) program design to review the security posture of designated systemsn a continual basis.
- Knowledgeable with NIST Publications geared towards protecting information systems
- Perform extensive Security Control Assessment (utilizing assessment motives of Examine, Interview and Test)using NIST 800 - 53A as a guide.
- Develop Plan of Action & Monitoring (POA&M) to remediate weaknesses identified during security controlassessment, vulnerability scanning, and any security findings identified during continuous monitoring.
- Efficient in Risk Management Framework using NIST 800-37
- Determine Security Categorizations using FIPS 199 as a guide
- Review and update security documents (FIPS 199, SSP, CP, Incident Response Plan, PTAP/PIA, C&D Memo) toassure that they are of FISMA compliance.
- Review and update System Security Plans (SSP) following NIST 800-18 and NIST 800-53 requirements.
- Prepare a comprehensive authorization package, which comprises of SSP, POA&M, and SAR before a system isgranted & Authorization to Operate (ATO).
- Develop a system security plan using NIST 800-18 Appendix A as a guide with all applicable security controlsand their implementation statements.
- Perform security testing using vulnerability scanning tools such as Nessus.
- Provide continuous monitoring support for control systems using FISMA guidelines and conduct FISMA-basedsecurity risk assessments.
- Communicate effectively through written and verbal means to coworkers, subordinates and senior leadership.