Information Security Analyst Resume
4.00/5 (Submit Your Rating)
Atlanta, GA
SUMMARY:
Insightful, results - driven Information System Security Professional with experience in Risk Management Framework (RMF), Vulnerability Management, Risk Assessment, and System Development Life Cycle (SDLC). Ability to leverage industry standards and best practices to monitor and protect systems based on Confidential 800 Series, FIPS 199 and 200, and ISO27-1 and ISO27-2.
CORE COMPETENCIES:
- Cyber Security
- Confidential
- FIPS
- Manual Testing
- Confidential
- SDLC
- System Administrator
- Microsoft Office Suite
- Vulnerability Management
- Penetration Testing
- HTML
- Oral Communication
- Team Leadership & Development
- Performance Improvements
- Salesforce
- Network Support
- Hardware and Software
- Project Planning
- SSP
- QA
- Customer Service
- SAR
- Nessus
PROFESSIONAL EXPERIENCE:
Information Security Analyst
Confidential, Atlanta, GA
Responsibilities:
- Review existing SSP and POAM
- Perform security control assessments, develop security assessment report, and other specific documentation
- Support the organization in the development, oversight, and maintenance of Confidential compliant security programs
- Monitor controls post authorization to ensure continuous compliance in accord with established monitoring strategy
- Conduct regular risk assessments to ensure measures raised in the process are fully addressed following Confidential 800-30 and Confidential 800-37
- Review security controls and provide implementation response to meet existing requirements
- Create reports detailing identified vulnerabilities and recommend steps for remediation
- Familiar with Confidential SP 800-18, 800-30, 800-37 rev1, 800-53 rev4, 800-53A, 800-60 and Federal Information Processing Standards (FIPS) - 199 and 200
Technical Analyst
Confidential, Atlanta, GA
Responsibilities:
- Performed analysis and documentation of as-is capabilities about business processes and technology
- Assisted with the use and maintenance of software of Confidential (SaaS)
- Network troubleshooting for wired (Ethernet) and hotspot time clocks
- Provided intermediate network support and assistance with troubleshooting connectivity issues with client networks (firewall, IP issues, DHCP, DNS etc.)
- Assisted in development and testing of new business processes, capabilities and as appropriate their supporting technologies
- Assisted clients with iPad clocks by putting clock on AirWatch to gain access and correcting any issues clients had. Set up and modify users, roles and access groups for various clients
- Diagnosed and explain external hardware and software issues that affect the use and/or configuration of our software
- Assisted with the installation of the time clocks, configuration and use of our products.
- Used Salesforce for call management and case tracking to thoroughly document customer interactions
Security Control Assessor/Vulnerability Assessor
Confidential, Atlanta, GA
Responsibilities:
- Used automated tool (Nessus) to pinpoint vulnerabilities and reduce time consuming tasks
- Identify critical/high flaws in the LIS application and creating a report for them within Nessus
- Conducted network security audits and scanning on a weekly/monthly basis
- Used manual testing methods to gain a better understanding of the environment and reduce false positives
- Reviewed security policies and processes, developed assessment and authorization documentation, verified the existence of established security controls, interpreted security principles and requirements and developing plans to address gaps in the security posture
- Developed security recommendations following Confidential guidance and industry best practices
- Supported the development of security solutions
- Reviewed and tracked Security Plan of Action and Milestones (POA&M)
- Support the organization in the development, oversight, and maintenance of Confidential compliant security programs
- Provided all necessary support in submitting completed packages for on-going A&A to obtain ATO or renew it for new systems and applications, as needed
- Assisted with the development of Security Assessment Reports (SAR)
Departmental IT Specialist
Confidential, Carrollton, GA
Responsibilities:
- Coordinated, planned, supported, and executed IT projects
- Defined and initiated IT projects, developed and managed project plans, schedules, budgets and risk management plans
- Managed the execution and control of assigned project and closed out projects to the satisfaction of the University and the Housing Department