Information Security Analyst Resume
4.00/5 (Submit Your Rating)
NewarK
TECHNICAL SKILLS:
- Cloud Services
- IDS/IPS
- Splunk
- HP Arcsight
- Nessus
- McAfee Endpoint
- McAfee Enterprise Security Manager
- Tripwire
- SolarWinds
- LAN / WAN Administration
- VPN
- TCP/IP
- Cisco Routers & Switches
- Juniper Switches
- VoIP
- Microsoft SQL server/Management studio
- MySQL
- Oracle.
PROFESSIONAL EXPERIENCE:
Confidential, Newark
Information Security Analyst
Responsibilities:
- Implementing controls for multi - tiered Software as a Service(SaaS) and Infrastructure as a Service(IaaS) products hosting Microsoft office 365 cloud service and IBM Smartcloud.
- Identifying and classifying cyber security vulnerabilities using OWASP framework, CVS dictionary and working on mitigation plans with system owners and tracking results of the plan execution.
- Analyzing security log data from a large number of heterogeneous security devices using Splunk Log Mgt and Event Sys.
- Administering risk/vulnerability assessments for corporate security using OWASP, NIST.SP.800-37, COBIT, ISO27001 standards, in-house/external risk matrices and with tools such Nessus (tenable securitycenter).
- Assisting in the development, implementation and review of IT policies, processes and security awareness programs.
- Performing audit activities in accordance with standards such as NIST, ISO27001, PCI and internal control frameworks.
- Reviewing access control policy of the organization (software/physical) to determine its adequacy and effectiveness.
- Conducting 3rd party/vendor IT risk reviews to ensure compliance and ensure vendor has adequate IT controls in place.
- Making decisions regarding real-time incident resolution providing immediate response and coordination aimed at minimizing the duration of service interruptions using ITIL and NIST.SP.800-61 frameworks.
- Coordinating patch management procedures to ensure critical and effective patching of information systems.
IT Security A n a l y s t
Responsibilities:
- Collaborate with business units to determine continuity requirements.
- Conducted BIA for vital functions; document recovery priorities of the key processes, applications and data
- Analyzed security incidents and presented a quarterly report to the CIO.
- Assistant administrator for Splunk Log Management and Event system for log review and analysis.
- Documented and provided Incident Response (IR) support when analysis confirms actionable incident.
- Processed Daily/Monthly Terminations and manage/maintain request queue (tickets), i.e Active Directory / LDAP access
- Performed audits on information systems to confirm compliance with standards such as COBIT, ISO27001, PCI, ITIL.
- Guided the development of information security standards, guidelines, and policies.
- Achieve compliance in information security awareness training for new employees and current staff.
- Performed application controls reviews, monitored segregation of duties and other key management controls.
- Achieve compliance in information security awareness training for new employees and current staff.
IT Security Officer
Responsibilities:
- Provided risk mitigation recommendations and worked with technology and business partners to help mitigate risks.
- Review system vulnerability scans and audit logs and work with system administrators to remediate findings.
- Reviewed user accounts and access on a regular basis to ensure regulatory and corporate compliance.
- Conducted regular vulnerability/risk assessments analysis and mitigation planning on critical operational systems.
- Managed McAfee Enterprise Security Manager(SIEM) to deliver accurate log management and information.
- Managed McAfee Endpoint Security to implement advanced controls to prevent threats and vulnerabilities.
- Managed IT risk monitoring audit program for SOX, Section 302 compliance, and conducted assurance testing in compliance with Section 404
- Ensured IT information security policies were tested, fully implemented and complied to.
- Implemented IT security roles and responsibilities to ensured confidentiality, integrity, and availability of systems, applications, and information.
- Ensured software’s were always patched and able to protect from threats.
Service Desk Analyst
Responsibilities:
- Troubleshooting hardware, software, guiding client through corrective steps and tracked status of problems and solutions.
- Documented and tracked all received requests in incident management system.
- Performed break fix, printer support, network connectivity and VOIP troubleshooting.
- Performed password administration, access and disabling support for Active Directory, Mail Exchange 2010/Outlook 2010 and a number of internal/proprietary systems and applications.
- Used Remedy ticketing system to log, track and manage Incidents and Service Requests.
- Configured and installed software for end-users Phones, desktops, scanners, terminals, and POS equipment.