Cyber Security Architect/engineer Resume
Mclean, VA
SUMMARY:
- 17 years of network security experience.
- In - depth knowledge and proficiency in TCP/IP protocol and packet-level networking knowledge, DNS, DHCP, routers, firewalls, configurations, and security assessment tools.
TECHNICAL SKILLS:
Confidential, Nessus, WebSense, NIKSUN NetDetector, Stealthwatch Lancope, Symantec SNS, Symantec Manhunt, Fidelis XPS, ISS SiteProtector, Enterasys Dragon IDS, Bro, Argus, 3COM Tippingpoint IPS, NetForensics, Arcsight, Symantec Raptor Firewall, Secure Computing Gauntlet Firewall, CISCO PIX, CheckPoint Firewall, Eeye Retina Vulnerability Scanner, Nmap, Win/TCPdump, SNORT, Wireshark, Remedy Help Desk
EXPERIENCE:
Confidential, Mclean, Va
Cyber Security Architect/Engineer
Responsibilities:
- Provides engineering, operations and maintenance, and system administration support for CND systems, this includes daily operations, configuration modifications, upgrades, patches, and new version of SIEM.
- Engineers, administers, and develop content for Cisco IDS FirePOWER/FireSIGHT.
- Implements components of Splunk infrastructure, deployment, products, apps, reports, alerts, and dashboards
- Manages Splunk knowledge objects (Apps, Dashboards, Saved Searches, Scheduled Searches, Alerts, etc.)
- Performs Computer Security Incident Response activities for a large organization, coordinates with other government agencies to record and report incidents.
- Monitor and analyze Intrusion Detection Systems (IDS) to identify security issues for remediation.
- Analyze and report incidences and draft remediation strategies
- Configure, deploy, and implement IDS/IPS systems; create, modify and tune IDS/IPS signatures
- Lead internal incident response and liaison with appropriate agencies
- Design, develop, implement and integrate CND technologies in new and existing systems using a defense in depth approach
- Develop and maintain documentation including attack capabilities, standard operating procedures, equipment installation projects and configuration data
- Aid in ideas and prototypes for new tooling
- Collaborate with other team members toward shared product goals
- Analyze the IT environment to evaluate application and infrastructure risks and controls
- Coordinate, execute and manage the planning, testing and reporting phases for multiple concurrent IT audits (ie:ESM, CCRI, CPT, RMF, FISMA, DIACAP)
- Design, review and approve tests that identify control weaknesses, and provide strategic recommendations to enhance business operations
- Present findings to senior management and negotiate suggested action plans
- Mentor teams to develop skills and expertise with the CND process, technology, and client management
Confidential, Washington, DC
Defensive Countermeasures Engineer
Responsibilities:
- Manages configurations, develops custom signatures, and deploys defensive countermeasures for security appliances to include: McAfee IPS, Palo Alto firewalls, Fidelis Extrusion Prevention System, Snort and Bro IDS.
- Develops custom content and dashboards within ArcSight ESM and Splunk for SOC analysts to use in hunting for anomalous activity and near real - time monitoring mission.
- Tracks and mitigates zero day exploits, emerging threats, and create appropriate mitigations to enhance defense posture.
- Vets and action web content filtering (WCF) exception requests from workforce.
- Produces reporting and trending metrics for contract leadership and government end-client.
- Creates custom training documents and standard operating procedures (SOPs) for new and existing network security tools
- Performs Computer Security Incident Response activities for a large organization, coordinates with other government agencies to record and report incidents.
- Monitor and analyze Intrusion Detection Systems (IDS) to identify security issues for remediation.
- Recognizes potential, successful, and unsuccessful intrusion attempts and compromises thorough reviews and analyses of relevant event detail and summary information.
- Evaluate firewall change requests and assess organizational risk.
- Communicates alerts to agencies regarding intrusions and compromises to their network infrastructure, applications and operating systems.
Confidential, Washington, DC
Principal Security Engineer
Responsibilities:
- Performed Computer Security Incident Response activities for a large organization, coordinated with other government agencies to record and report incidents.
- Monitored and analyzed Intrusion Detection Systems (IDS) to identify security issues for remediation.
- Recognized potential, successful, and unsuccessful intrusion attempts and compromises through reviews and analyses of relevant event detail and summary information.
- Performed vulnerability management/engineering and assess organizational risk and documentation for cloud certification.
- Implemented counter-measures or mitigating controls to web content filters, firewalls, and various intrusion prevention technologies.
- Performed periodic and on-demand system audits and vulnerability assessments, including user accounts, application access, file system and external Web integrity scans to determine compliance.
- Prepared incident reports of analysis methodology and results.
- Provided guidance and work leadership to less-experienced technical staff members, and may have supervisory responsibilities.
Confidential, Arlington, Virginia
Security Analyst Team Lead
Responsibilities:
- Monitored several agencies of intrusion detection, attack and penetration, authorized use of vulnerability assessments, virus scanning, and investigation of non-compliant system usage.
- Queried appropriate Intelligence databases for relevant threat information and correlates data into standardized reports.
- Performed ArcSight content development for detection of intelligence derived from open source cyber-intelligence.
Confidential, Columbia, Maryland
Security Consultant
Responsibilities:
- Delivered professional service engagement to Federal Confidential customers
- Subject Matter Expert for the Confidential 3D Solution, performed knowledge transfer of peration, engineering, and administration of product
- Delivered services to multiple sub organizations within the Federal domain, including, Large scale government IDS/IPS Architecture in the range of 300,000 nodes
- Leveraged enterprise Administration and Management Skills of a global Security Operations Center
- Performed Snort content development for detection of intelligence derived from open source cyber-intelligence
- Developed integration strategies/processes
Confidential, Arlington, Virginia
Intrusion Detection System Analyst
Responsibilities:
- Managed a team of four (4) IDS Analysts to oversee all operations during watch.
- Monitored several agencies of intrusion detection, attack and penetration, authorized use of vulnerability assessments, virus scanning, and investigation of non-compliant system usage.
- Escalated detection of root-kit and Trojan methods, as well as evidence of hacking techniques and counter attack methodologies
- Reviewed all-source intelligence information and correlates it with data derived from various levels of perimeter defenses architecture (IDS, Firewalls, and Logs) in order to provide the customer with assessments and reports facilitating situational awareness and understanding of the current cyber threat.
- Queried appropriate Intelligence databases for relevant threat information and correlates data into standardized reports.
- Possessed good knowledge of principles and techniques applied in securing operating systems and LANs/WANs, with proficiency specifically in UNIX, Windows and Cisco IOS
- Possessed some experience in shell scripting and the use of regular expressions for parsing through data for pertinent information
Confidential, Arlington, Virginia
Intrusion Detection System Analyst
Responsibilities:
- Monitored several agencies of intrusion detection, attack and penetration, authorized use of vulnerability assessments, virus scanning, and investigation of non-compliant system usage.
- Escalated detection of root-kit and Trojan methods, as well as evidence of hacking techniques and counter attack methodologies
- Reviewed all-source intelligence information and correlates it with data derived from various levels of perimeter defenses architecture (IDS, Firewalls, and Logs) in order to provide the customer with assessments and reports facilitating situational awareness and understanding of the current cyber threat.
- Queried appropriate Intelligence databases for relevant threat information and correlates data into standardized reports.
- Possessed good knowledge of principles and techniques applied in securing operating systems and LANs/WANs, with proficiency specifically in UNIX, Windows and Cisco IOS
- Possessed some experience in shell scripting and the use of regular expressions for parsing through data for pertinent information
- Managed a team of five (5) CIRT members to coordinate all operations during watch.
- Approved and Escalated submission of incident reports for forensics, policy and planning, and disposition.
- Monitored several networks of intrusion detection, attack and penetration utilizing Internet Security Systems (ISS) Real Secure software coupled with Tivoli and packet analysis tools.
- Performed investigations of IP and DNS related attacks including, but not limited to malicious code attacks, buffer overflows, and spoofing to produce compromise or denial of services to Department of State users.
- Performed proper and expeditious incident response to malicious code attacks, unauthorized access, unauthorized utilization of services, disruption of service, or hoaxes.
- Assisted in the implementation of systems security policies, plans and enforce all policies.
Confidential, Washington, DC
Senior Systems Security Technologist
Responsibilities:
- Coordinated all information assurance activities for 17000 - customer W2K network & 15000-client NT4.0/Unix legacy network.
- Carried out all network security practices IAW DoD 5200.40 within the National Capital Region ensuring coordination with government customers and Information Assurance personnel.
- Administered with NT4 &W2K desktops and servers in an Enterprise as well as familiarity with UNIX & Solaris8.
- Performed proper and expeditious incident response to malicious code attacks, unauthorized access, unauthorized utilization of services, disruption of service, or hoaxes.
- Administered/Maintained Gauntlet, Checkpoint, Symantec Raptor firewalls, 60+ Netscreen VPN s, and 20+ various Intrusion Detection Systems deployed throughout National Capital Region.
- Administered with the following products: Vendor product experience with the Symantec and Computer Associates (CAI) products specifically Norton Antivirus Corporate Edition, Norton Antivirus Manager Special Edition, Symantec Raptor Firewall Manager Special Edition, Enterprise Security Manager, Intruder Alert, and Inoculate IT.
- Operated with Commercial-off-the-shelf (COTS)/Open Source products related to information security.
- Determines computer security compliance and effectiveness of processing systems in accordance with DoD-STD 5200.28 and associated manuals.
- Developed and applied advanced methods, theories, and research techniques in the solution f security environment requirements and problems.
- Provided information systems security training to other employees and performs oversight of all task-specific activities, such as document preparation, writing, and methodologies.
Confidential, Norfolk, VA
Systems Security/Intrusion Detection System Analyst
Responsibilities:
- Gathered and analyzed information from various areas within Confidential Computer and Network systems to identify possible security breaches.
- These include both intrusions from outside (attacks) and inside (misuse) of the system.
- Monitoring and analyzing both user and system activities, analyzing system configurations and vulnerabilities, addressing system and file integrity, ability to recognize patterns typical of attacks, analysis of abnormal activity patterns and tracking user policy violations.
- Exercised system security and intrusion skills including knowledge of the latest security guidelines and vendor products.
- Possesses knowledge of network security policy and federal regulations.
- Experienced in proper and expeditious response to malicious code attacks, unauthorized access, unauthorized utilization of services, disruption of service, or hoaxes.
