Cyber security analyst Resume
2.00/5 (Submit Your Rating)
Takoma Park, MarylanD
SUMMARY:
- Experienced in the development of System Security Plans (SSP), Contingency Plans, Disaster Recovery Plans, Incident Response Plans/Training, and Configuration Management.
- Plans, System Security Checklists, Privacy Impact Assessments, POA&M,
- Familiar with VMware and other Virtual Machine Applications
- Experienced working with NIST SP 800 - 53 rev 3 and rev 4
- Familiar with ISO 2700 series and PCI DSS compliance
- Good communication and writing skills
TECHNICAL SKILLS:
Software/Artifacts: MS Office (Word, Excel, PowerPoint, Access, Outlook), MS Project, CSAM, FIPS 199, SORN, E- Authentication, PTA, PIA, RA, SSP, CP, CPT, ST&E, SAR, POA&M, ATO, ISA, MOU
PROFESSIONAL EXPERIENCE:
Cyber Security Analyst
Confidential, Takoma Park, Maryland
- Performing Security Categorization (FIPS 199), Privacy Threshold Analysis (PTA), E-Authentication with business owners selected stakeholders.
- Developing and conduct security testing and evaluation according to NIST SP 800-53A.
- Perform compliance reviews, tracking, and continuous monitoring of newly submitted A&A packages.
- Conducting Risk Assessments, and drafting Plan of Action and Milestones (POAMs)
- Developing and maintaining Plan of Action and Milestones (POA&M) of all accepted risks upon completion of system (A&A)
- Performing evaluation of policies, procedures, security scan results, and system settings in order to address controls that were deemed insufficient during Assessment and Authorization (A&A), RMF, and continuous monitoring.
- Performing on-site security testing using vulnerability scanning tools such as Nessus
- Utilizing processes within the Security Assessment and Authorization environment such as system security categorization, development of security and contingency plans, security testing and evaluation, system accreditation and continuous monitoring.
- Overseeing the preparation of a Comprehensive and Executive Assessment and Authorization (A&A) packages for submission to the Information Assurance Program Office for approval of an Authorization to Operate (ATO).
- Maintain excellent working relationships with both internal and external customers using communication skills.
- Reviewing and updating some of the system categorization using FIPS 199, Initial Risk Assessment, E-authentication, PTA, PIA, SAR,SSP, SAP& POA&M, Authorization letter/memorandum (ATO).
- Supporting clients in creation of Standard Operating Procedures (SOP) as POA&M efforts
- Documenting and Reviewing security plans (SP), contingency plans (CP), contingency plan tests (CPT), privacy impact assessments (PIA), and risk assessment (RA) documents per NIST 800 guidelines for various government agencies.
- Sound understanding in Payment Card Industry Data Security Standards (PCI/DSS) compliance and ISO 27000 series
- Monitoring controls post authorization to ensure continuous compliance with the security requirement Conducted FISMA-based security risk assessments for various government contracting organizations and application systems - including interviews, tests and inspections; produced assessment reports and recommendations; conducted out-briefings. Assessments conducted following NIST 800 processes and controls.