Hands On/sr. Manager/ Network And Cyber Security Resume
2.00/5 (Submit Your Rating)
SUMMARY:
Over 16 years of Security Operations Analyst experience utilizing Encase Cyber Security, Network Access Control Net - Witness Investigator and Informer, Encase Enterprise, Confidential 6 Console, Logger and Express, Fire Eye Email Protection, Fire Eye Web Protection, En Circle, Jump Server, Blue Coat, Snort, ASA Firewall, SCCM, Splunk, Air crack, Source Fire and Foot Print.
TECHNICAL TOOLS:
- Encase Cyber Security
- Confidential
- NBT Scan
- Metasploit
- CORE Impact
- Splunk
- Net Witness Investigator and Informer
- Encase Enterprise
- Confidential Console
- Logger and Express
- Web Sense
- Fire Eye Email Protection
- Fire Eye Web protection
- Jump Server
- Blue Coat
- Source Fire
- Foot Print
- Confidential Endpoint Protection
- Checkpoint
- McAfee
- Nessus
- Air crack
- Retina
- TCP Dump
- ASA Firewall
PROFESSIONAL EXPERIENCE:
Confidential
Hands on/Sr. Manager/ Network and Cyber Security
Responsibilities:
- Responsible for monitoring client networks to detect suspicious and hostile activity that would jeopardize the integrity of information systems. Responsible for reviewing logs/ threats/Vulnerabilities from various security tools
- Performed network traffic analysis . Integrated numerous types of cyber security data feeds into Confidential
- Performed threat monitoring - monitor industry resources and observe new technical developments, intruder activities and related trends to help identify threats to the Client systems. Perform vulnerability scanning and network discovery Assisting in ongoing vulnerability management across the enterprise
- Working with developers and administrators to remediate identified vulnerabilities
- Constant monitoring of intrusion detection systems.
- Creation of technically detailed reports based on intrusions and events.
- Provides assistance in computer incident investigations.
- Analyze and evaluate anomalous network and system activity.
- Assist in troubleshooting and problem solving a wide variety of client issues.
- Collaborate well with members of the IAM team on daily policy issues.
- Provide quality customer service with excellent communication skills.
- Recommend modifications to access control lists to prevent and mitigate intrusions.
- Writing reports-cat 1- Cat7 Reports base on alert/events.
- Conduct Certification and Accreditation (C&A) following NIST SP 800-53 REV.3/DHS 4300A directive guidelines.
- Create and maintain C&A documentations including Security Plan, Plan of Action & Milestones (POA&M), Software/hardware inventory, and Network diagrams, Contingency Plan, Risk Assessment and Security Assessment Report.
- Assist with implementation and administration of Information Assurance and Information Security procedures, in accordance with established NIST/DHS guidelines.
- Perform audits and inspections of information systems to ensure compliance with applicable policies and directives. Assist with clarification for Information Technology staff in technical matters concerning system accreditation requirements.
- Provide assistance as required to the customer regarding Information Assurance issues.
- Advise the Information Assurance Manager of all anomalies and corrective action required/taken.
- Maintain currency and compliance with NIST/DHS Information Assurance directives and regulations.
- Perform risk analyses, which also includes risk assessment (provide support for facilitating and helping agencies identify their current security infrastructure and define future programs, design and implementation of security related to IT systems).
Confidential
Security Advisor Manger
Responsibilities:
- Supported customer direct investigation of cyber activity targeting customer information and its information infrastructure.
- Reviewing logs/ Vulnerabilities utilizing Confidential (Compliance Issue Risk and APAR Tracking System) enables Confidential Integrated Technology Delivery to document, track, and resolve security noncompliance issues and patch advisories
- Assisted the customer-training department in the education of staff on the cyber threat.
- Configure and maintain host based and network Intrusion Prevention Systems, maintain and administer Network Access Control Systems; maintain patching system(s); maintain antivirus/anti-spam system(s), and perform network scans to identify and analyze network and system vulnerabilities.
- Intrusion detection system monitoring and analysis security event identification and analysis using Confidential, Confidential, Splunk, Net witness and Encase Enterprise.
Confidential
Lead Cyber && Network Security Analyst
Responsibilities:
- Supported the development of incident handling, detection and threat mitigation procedures.
- Created, maintained and troubleshot Confidential 5 dynamic interface content including Dashboards, Data Monitors, Active Channels, Rules, Filters, Reports, Zones.
- Integrated numerous types of cyber security data feeds into Confidential
- Researched Internet cyber security sites for information specific to customer system vulnerabilities.
- Worked with cyber analysts on research projects that involve event analysis to determine trends.
- System/application security log review maintains an understanding of the current vulnerabilities, response, and mitigation strategies used to support cyber security operations.
- Experience in computer intrusion analysis and incident response and investigating alerts.
- Perform computer network surveillance and monitoring.
- Experience in computer intrusion analysis and incident response and investigating alerts.
- Perform computer network surveillance and monitoring.
- Performed system/application security log review and maintain and understanding of the current vulnerabilities, response and mitigation strategies used to support cyber security operations. Provide trend analysis for correlated information sources and network data including event logs, IDS and network captures.
- Performed system/application security log review and maintain and understanding of the current vulnerabilities, response and mitigation strategies used to support cyber security operations. Provide trend analysis for correlated information sources and network data including event logs, IDS and network captures.
