Cyber Security Analyst Resume
4.00/5 (Submit Your Rating)
Fairfax, VA
SUMMARY:
- Practical use, implementation and a solid knowledge of information security principles
- Extensive experience with firewalls and an in - depth understanding of computer/network security concepts, VPNs, proxies, and networking
- Extensive experience working in a Security Operation Center
- Experience working with Cisco ASA SourceFire Suite
- Experience working with Splunk for SIEM in a Security Operation Center
- Experience working with HP ARCsight for SIEM in a Security Operation Center
- Experience with capture and analyzing of network traffic, using a variety of network tools such as Wireshark and Nmap to assess security-related events.
- Strong understanding of network security protocols and products from Cisco
- Hands on experience with Vulnerability Scanning & management (Nessus Security Center,HP Web Inspect etc...)
- Hands on experience with Enterprise Anti-Virus solutions (McAfee,etc...)
- Hands on experience with Patching using BigFix management,
- Hands on experience with intrusion detection/prevention systems IDS\IPS
- Experience hardening and creation of rules for firewalls, switches, routers and other network equipment
- Experience securing network system by establishing and enforcing policies; defining and monitoring access.
- Experience writing filters, plugging, access control lists, and monitoring rules for new and existing continuous monitoring products
- Hand on experience in security systems, including firewalls, intrusion detection systems, anti-virus software, authentication systems, log management, content filtering, etc
- Thorough understanding of the latest security principles, techniques, and protocols
- Experience installing and monitoring NIDS/NIPS and Access Controls Systems ( ACS) devices
- Familiarity with IBM Qradar System Event Management dashboard, application creation and back end infrastructure.
- Extensive knowledge of FISMA, C&A, NIST SP 800-series (53, 53a, 37, 60) FIPS 199, FIPS 200, RMF, SSP, SAR, IT Audit, Configuration Management, Contingency Plan, Privacy Impact Analysis (PIA), Privacy Threshold Analysis (PTA)
- NIST SP 800-53 Security Controls Assessment
- Review and update Risk Assessment (RA) using NIST SP 800-30 guidelines
- Review and update Contingency Plan (CP) using NIST SP 800-34 guidelines
- Review and update System Security Plan (SSP) using NIST SP 800-18 guidelines
- Experience configuring, implementing, and supporting solutions using Cisco network equipment
- Knowledge of IP traffic flow, protocol analysis, capturing and monitoring of live traffic streams
- Experience troubleshooting complex problems in a Cisco network environment
- Knowledge of LAN and WAN QoS configuration.
- Good knowledge of OSPF/EIGRP/Spanning Tree protocols
- Ability to use Network Sniffers, analyze data to resolve network issues
- Ability to analyze network performance data to identify trends and potential problems, and support recommendations to modify and/or upgrade network equipment or services
- Good experience with Cisco Nexus/Data Center deployment/operation
- Good experience with Network Operation Center
- Broad understanding of all aspects of LAN and WAN operation, load balancing, routing, topology, QoS,
- Experience implementing and supporting virtual private networks (VPN)
- Advance configuration knowledge of Cisco switches and routers
- Knowledge of the OSI seven layers model, TCP/IP four layers model, how network behaves at different level of the OSI and TCP/IP model
- In depth knowledge of networking principles including TCP/IP protocols, IPv4, IPv6 and Subnetting
- In depth knowledge implementing Cisco Catalyst switches, Cisco Nexus Switches
- Knowledge of VLAN configuration with VLAN Trunk and VLAN Access mode.
- Knowledge of static NAT and Dynamic NAT
- Ability to create and apply ACL’s to meet organizational security policy requirements
PROFESSIONAL EXPERIENCE:
Cyber Security Analyst
Confidential, Fairfax, VA
Responsibilities:
- Member of the SIEM alert analysis team, application vulnerability assessment, risk analysis and compliance testing.
- Performed impact analysis and risk assessment on security plans as submitted by the network and web scans result.
- Provided strong troubleshooting skills as needed for network related security issues.
- Identify, track and remediate vulnerabilities identified within all security tools
- Generated monthly metrics reports regarding outstanding issues for management review.
- Performed a compliance gap analysis and presented a list of recommendations
- Performed risk assessments to ensure compliance
- Assisted in the support and preparation of IT systems and applications risk assessments.
- Prepared reports on audit findings and made recommendations for correcting unsatisfactory conditions, improving operations and reducing the compliance cost.
- Provided strong troubleshooting skills as needed for network related security issues.
- Identify, track and remediate vulnerabilities identified within all security tools
Network Security Engineer
Confidential, Riverdale office, MD
Responsibilities:
- Member of the Incident Response Team in charge of Networking issues, using the Network Operation Center ( NOC ) and Cisco ASA SourceFire defense center to gathering information and respond quickly and effectively to security events and threats
- Participated in the continuous monitoring of the system using various tools such as: Nessus Scanner, WebInspect and Wireshark for packet capture.
- Lead of the continuous Vulnerability assessment team using Nessus Security Center and IBM Qradar Security Event Management for daily security check
- Frequently used of US-CERT alerts and threats publication and the National Vulnerability Database to maintain a good security posture of the system
- Perform monthly vulnerability scan using webinspect
- Frequently used of Nessus Security Center for vulnerability scanning, web application auditing and credentialed patch analysis and provide appropriate recommendations
- Extensive use of Wireshark for traffic capture and analysis.
- Frequently used of IBM BigFix for asset discovery,
- Part of the Security Operation Center team ( SOC ) using HP ARCsight SIEM Integration
- Used HP ARCsight SIEM integration to Monitor and recommend improvements based on events or incidents of apparent security breaches in networks areas and endpoints
- Used HP ARCsight SIEM integration to correlate events logs.
- Conducting event collection, log management, event management, compliance automation, and identity monitoring activities using HP ARCsight SIEM
- Responsible to provide response to all network Vulnerabilities and threats to the system
- Frequently use of Cisco ASA FireSight to rapidly retrieve and inspect the Network configuration
- Used Cisco ASA SourceFire defense center for advance threats monitoring, network and web visibility and analysis.
- Implemented TACACS+ authentication rules on Cisco devices across the network
- Used of Qradar for the Daily security checks and participated in the analysis of the findings as needed.
- Responsible for the monitoring of the posture of the Cisco NIDS/IPS within our system
- Participated in the Installing of ASA firewalls, networking, data encryption and other security measures
- Responsible for the regular update of the intrusion Prevention System sensors signature.
Security Analyst
Confidential, TUSTIN, CA
Responsibilities:
- Evaluated Information System threats and vulnerabilities to determine whether additional safeguards are needed for a wide range of IS security related areas including architectures, firewalls, electronic data traffic, and network access
- Used of Cisco ASA fireSight to monitor and stop advance threats on Endpoints
- Used of Cisco ASA FireAMP for advance malware analysis and protection
- Recommend and implement solutions to diagnose network performance issues
- Responsible for the evaluation and approval of Firewall changes(Cisco ASA)
- Perform inventory control and asset management log
- Part of the SOC team using Splunk SIEM
- Conduct security threats monitoring and detection using Splunk SIEM and NIDS/IPS perimeter monitoring devices
- Writing Nessus filters, choosing plugging for vulnerability scan and continuous monitoring of the system
- Used of Splunk for compliance during the continuous monitoring phase of the Risk
- Prepare/update System Security plan, Security Assessment Report and POA&M to maintain compliance status and reauthorization
- Develop, conduct, and prepare reports for security audits, reviews and other actions, as appropriate
- Develop enterprise risk analysis strategy to support the House network infrastructure, major applications, and desktop systems
- Identify and evaluate system technical, management, and operational security controls in accordance with NIST SP 800-53A
- Prepare assessment report for systems in compliance with SP 800-53a and document the assessment in the security assessment report (SAR) along with POA&M
- Prepare, update and maintain Plan of Action & Milestones (POA&M)
- Coordinate various cyber security activities that includes risk assessment, incident response, configuration change control, and vulnerability scan remediation
- Document and finalize Security Assessment Report (SAR)
IT Security Analyst
Confidential, Frederick, MD
Responsibilities:
- Provide technical oversight on Security Compliance Program to ensure all software systems are implemented according to information security policies and technical guidelines
- Conduct in-depth technical security review, risk assessment, and source code reviews of software systems during all phases of the system development life cycle and provides recommendations for improvements
- Participate in network and systems design to ensure implementation of appropriate systems security features
- Assist in the categorization, description of systems functionalities and boundaries in compliance with the NIST SP 800-60, FIPs 199
- Assist with C&A reviews, security test and evaluations (ST&E), and drafting associated reports
- Conduct security awareness training and expected rules of behavior for end-users
- Establish and maintain user accounts, profiles, file sharing, print sharing, access privileges and security
- Installing firewalls, networking, data encryption and other security measures
- Recommend and implement solutions to diagnose network performance issues
- Determine, diagnose and evaluate workstation and application performance issues
- Recommending security enhancements and purchases
- Implement policies and procedures for responding to security incidents, and for investigating and reporting security violations and incidents; assist with forensic investigations across the corporation
- Involve in determining system categorization, selecting/implementing security controls, and assessing the implemented controls to verify and ensure effectiveness
- Escalate issues when necessary, and following up on any escalated issues
- Perform systems testing and networking connectivity testing (including firewalls and VPN systems)
Helpdesk Technician
Confidential, Lanham, MD
Responsibilities:
- Provide technical assistance and support for incoming queries and issues related to computer systems, software, and hardware
- Respond to queries either in person or over the phone
- Maintain daily performance of computer systems
- Respond to email messages for users seeking help
- Walk users through problem-solving process
- Install computer peripherals for users
- Follow up with users to ensure issue has been resolved
Network Engineer
Confidential, Douala, Cameroon
Responsibilities:
- In charge of the building, development and deployment of the taxation network infrastructure for the littoral region
- Supervising a team of 16 engineers and network technician in the position of chief network analyst and infrastructure manager.
- In charge of maintain servers and workstation in the Unix and Informix platforms
- In charge of the migration from Unix server platform to Windows server 2003
- Managed installation, configuration and administration of Cisco equipment in IT architecture of organization. Configured IT LAN/WAN elements and held responsibility of maintaining and monitoring performance of network.
- Established and maintained user accounts, profiles, file sharing, print sharing, access privileges and security
- Assisted staff with the installation, configuration, and ongoing usability of servers, desktop computers, peripheral equipment and software
- Escalated issues when necessary, and following up on any escalated issues.
- Installed/troubleshoot application software (Windows OS, MS Office, etc), user account management (Active Directory)
