Senior It Security Analyst Resume
Rockville, MD
PROFESSIONAL SUMMARY:
An IT Security and Information Systems Professional with over ten (10) years’ combined experience in various Information Technology positions and responsibilities. I am Confidential results - driven, policy-oriented and mission driven IT Security Analyst with four years’ experience in Assessment and Authorization, Vulnerability Management, POAM management, Network Architecture and Troubleshooting.
PROFESSIONAL SKILLS:
- IT Security Analysis
- Security Assessment and Authorization
- Risk Assessment
- Risk Management Framework (RMF process); using Confidential 800-37
- POAM Management
- Quality Assurance and Operations Management
- Vulnerability Scanning and Management
- Network Design and Management
- Contingency Planning
- Business Impact Analysis (BIA)
- SQL
- Linux
- McAfee Enterprise
- Nessus
PROFESSIONAL EXPERIENCE:
Confidential, Rockville, MD
Senior IT Security Analyst
Responsibilities:
- Conducted meetings with the IT team to gather documentations and evidences (Kick - off meeting) about their control environment.
- Conducted network vulnerability assessments using tools such as Nessus and Retina to evaluate attack vectors, identify system vulnerabilities and develop remediation plans and security procedures
- Investigated potential or actual security violations or incidents in an effort to identify issues and areas that require new security measures or policy changes
- Granted access based on review and approval of SAR Request to the Financial Management System
- Ensured quality control of Confidential & Confidential documents and validation process
- Performed continuous monitoring using Confidential 800-137 as Confidential guide on asset vulnerabilities and Confidential & Confidential documentations
- Informed and advised government and contractor personnel on security issues
- Ensure organizational compliance with Confidential information security programs
- Reviewed and uploaded deliverables in C& Confidential database ( Confidential )
- Reviewed and updated the System Security Plan (SSP) using Confidential SP 800-18 guidelines and System Security checklists.
- Coordinated, participated and attended weekly ISSO meetings for security advice and updates
Confidential, Largo, Maryland
IT Security Analyst
Responsibilities:
- Conducted Information System Categorization using information types that the information system processes or stored and used Confidential 800-60 volume 1 as Confidential guide.
- Managed and coordinated Confidential team of information security professionals to conduct Security Authorization packages based on Confidential standards for general support systems and major applications.
- Performed RMF Assessment at the Census Bureau using both scanning tools and manual Assessment. The Assessments included initiating meetings with the System Owners and Information System Security Officers (ISSO), providing guidance of evidence needed for security controls, and documenting findings of the Assessment.
- Prepared all Assessment and Authorization documentations, worked very closely with the Information System Security Manager (ISSM), Information System Security Representative (ISSR) and the other members of the Information Assurance team.
- Configured and maintained McAfee Enterprise Manager
- Conducted incident prevention, detection/analysis, containment, eradication and aid recovery across IT systems using tools such SIEM
- Reviewed and updated some of the system categorization using FIPS 199, Initial Risk Assessment, Confidential -authentication, Confidential, PIA, SAR, SSP, SAP& POA&M
- POAM Remediation: Performed evaluation of policies, procedures, security scan results, and system settings in order to address controls that were deemed insufficient during Assessment and Authorization, and continuous monitoring processes.
- Identified vulnerabilities, recommend corrective measures and ensure the adequacy of existing information security controls
- Performed Assessments and document creation using Confidential SP 800-53 rev 4.
Database Administrator
Confidential
Responsibilities:
- Oracle database 11g and 12c Installation and Administration on Windows and Linux environments
- Oracle database 12c backup and recovery using RMAN
- Oracle database storage management using ASM
- Oracle database Redundancy and RAC management
- Oracle database remote access
- Oracle database performance tuning
- Oracle database patching using Opatch utility
Cable Splicing Technician and Maintenance Administrator
Confidential
Responsibilities:
- Performed fiber and copper telecom network building and testing.
- Troubleshoot and test fiber and copper network. Connected routers and switches on large and small customer premises.
- Managed network maintenance issues and customer service.