Information Security Assessor Resume
2.00/5 (Submit Your Rating)
Herndon, Va
OBJECTIVE:
An accomplished Information Technology Specialist with over 6 years of experience in Cyber Security, IT Governance, Risk Management, and Compliance. Adept at analyzing IT security issues, developing and implementing solutions using industry best practices and organization policies.
TECHNICAL SKILLS:
- FISMA
- NIST Series of Publications
- ST&E
- Audits
- ES (Executive Summary)
- SAR (System Assessment Report)
- RAR (Risk Analysis Report)
- Assessment and Authorization (A&A)
- Audits
- System Security Plan (SSP)
- System Assessment Plan (SAP)
- Plan of Action and Milestone (POA&M)
- Gap Analysis
- Continuous Monitoring
- Security Control Assessment (SCA)
- FIPS 199 & 200
- Risk Vision GRC
- RedHat Linux
PROFESSIONAL EXPERIENCE:
Information Security Assessor
Confidential,Herndon,VA
Responsibilities:- Schedule and lead kick - off meetings with system owners to help identify assessment scope, system boundary, the system’s security categorization and attain any artifacts needed in conducting the assessment.
- Work with a team of information system owners, developers and system engineers to select and implement security controls in safeguarding system information.
- Ensure that established internal control procedures are compliant by examining reports, records, documentations and operating practices.
- Perform continuous monitoring on asset vulnerabilities, prioritized vulnerability list and address critical weaknesses in the systems.
- Conduct gap analysis of organization’s policies and procedures against NIST requirements, identify compensation controls and provided gap analysis remediation for management consideration.
- Develop POA&M (Plan of Action & Milestones) to remediate actions resulting from security control assessments, monitor and track remediation progress using RiskVision GRC.
Cyber Security Analyst
Confidential,Hanover,MD
Responsibilities:- Applied defense-in-depth strategies in large and complex networks to rapidly identify vulnerabilities and threats, prioritize response actions, and develop effective countermeasures.
- Worked with assessment and compliance teams to ensure the day-to-day running of the data centers are compliant with NIST requirements.
- Monitored audit events and other data from various operating systems, databases, and applications to analyze and correlate event data, create situational awareness, and provide trending reports.
- Coordinated and responded to events on all monitored networks and the systems on them after detection of vulnerabilities, initial investigation, and reporting.
- Reviewed Security Assessment Reports (SAR) and Vulnerability Assessment Reports (VAR) for accuracy and provided findings to senior management.
Network Security Analyst
Confidential
Responsibilities:- Collaborated with the Chief Information Security Officer and security team to design, plan and audit effective network security frameworks and systems.
- Identified, created and managed security programs to enhance the confidentiality, integrity and availability of VF Ghana network (primary) & systems (secondary).
- Collaborated with security team members to create a unified security approach for VF Ghana.
- Assisted in design of IP network architecture for best practice and business-optimal security standards.
- Optimized network security in collaboration with the service security architect and security team using scanning tools, business processes and frameworks.