Cybersecurity Analyst Resume
SUMMARY:
To obtain a professional position with a company that provides opportunities to serve the customer with a secure network, against threats, and resolve security incidents of all kinds.
SKILLS & ABILITIES:
Cyber Security Tools: Kali Linux,LancopeSnort, Bivio, TippingPointWireshark, Bro, Argus, DragonNessus Scanner, FireEyes, InquestNetwitness, Fidelis, Niksun.
Cyber Security: Access Control Security implementations, assurance. NIST,DOD,DISA,IAVM, IAVM,GIG, Encryption, detection/prevention, network security
Threats and vulnerabilities.: ISCM,GLBA,HIPAA,SOX,FERPA,CIPA,NERC,HSPD 12 and best practice, Linux, Windows Security, Hacking and countermeasures, Ethics, case study and training.
Networking: TCP/IP /LAN/WAN / Cisco Router / - --OSI / FTP / SMTP / Telnet
Protocols: Network Technology, Network Systems Management, Network Development, GUI Applications
Hardware: Assemble/disassemble PC’s, Install, configure, troubleshoot and repair, Installation, testing and troubleshooting of cabling (Patch, Fiber, Twisted & Crossover), Risk Management maintaining compliance and developing a plan. Defining and performing risk assessment, Testing and quality assurance for production, Maintaining PCI DSS compliance.
Technical Support/Customer Service: Troubleshoot hardware/software, Troubleshoot network connectivity, Software installation support, Remote Access, Phone and e-mail support, Documentation, Degauss, sanitization and destruction
Software: Microsoft Office Suit, Exchange and Send mail for E-mail servers, Install, configure and troubleshoot, AutoCAD, Remedy, SCCM
Operating Systems: Windows 2000/7/XP/vista
Server: Windows Server 2003 / 2008 and 2012, Active Directory, Linux / Apache Web Server, VMware
Development: SQL database, server, Visual Basic, C++, Intro Programming, Python.
RELEVANT EXPERIENCE:
Cybersecurity AnalystConfidential
Responsibilities:
- Document and explain technical details clearly and concisely.
- Performing Confidential and digital forensics.
- Improvement of analyst effectiveness by optimizing signature quality in collaboration with other analyst, vendors and developer.
- Implemented investigation in host - based indicators of compromise and network traffic including analyzing log, forensic, malware, or other IR-related data, as needed.
- Prioritizing and differentiating between potential intrusion attempts and false alarms.
- Creating and tracking security investigations to resolution. Using a SIEM/ Arcsight, Splunk, Tanium and Bluecoat.
- Analyzing events from SIEM channels, identifying cyber threats, virus, malwares and network instructions. Investigate forensic analysis and data recovery of network assessments.
- Composing security alert notifications and other communications.
- Advising incident responders in the steps to take to investigate and resolve computer security incidents.
- Staying up to date with current vulnerabilities, attacks, and countermeasures.
- Determinate and recommend new detection and Prevention Methods and capabilities.
- Daily work environment to multitask to a variety of functions while under pressure. (Include but no limited to internal tools or open source tools).
- Monitor security intelligence sources (classified and Unclassified) to keep up-to-date on the latest security threats and trends. Report significant threats to internal team members only.
Analyst
Confidential
Responsibilities:
- Provide support monitoring using HP ArcSight SIEM, analysis and respond the Network 24/7. ( NIPR and SIPR Networks)
- Forensics/ Confidential .
- Monitoring and analyzing network traffic, Intrusion Detection Systems ( Confidential ) and Instruction Prevention Systems (IPS), security events and logs. Experience in detection, response, mitigation and/or reporting of cyber threats affecting classified and unclassified networks.
- Tune, monitor, Confidential /IPS Systems and others Tools. (Arcsight, RSA NetWitness, Dragon, Bro, FireEye, TippingPoint Websense, Niksun, Lancope, Argus, Bivio, Fidelis, Inquest, wireshark. Bluecoat, SourceFire,Cisco Defender Center, NetWitness,Tanium)
- Maintained Security principles, tools, and best practices, helping to ensure that all new solutions introduced into the environment take security into consideration and that all tools selected follow the organization DAR process.
- Prioritizing and differentiating between potential intrusion attempts and false alarms.
- Creating and tracking security investigations to resolution. Using a SIEM/ Arcsight.
- Analyzing events from SIEM channels, identifying cyber threats, virus, malwares and network instructions. Investigate forensic analysis and data recovery of network assessments.
- Composing security alert notifications and other communications.
- Advising incident responders in the steps to take to investigate and resolve computer security incidents.
- Staying up to date with current vulnerabilities, attacks, and countermeasures.
- Determinate and recommend new detection and Prevention Methods and capabilities.
- Daily work environment to multitask to a variety of functions while under pressure. (Include but no limited to internal tools or open source tools).
- Monitor security intelligence sources (classified and Unclassified) to keep up-to-date on the latest security threats and trends. Report significant threats to internal team members only.
Confidential
Cybersecurity Analyst
Responsibilities:
- Tune, monitor, Confidential /IPS Systems and others Tools. (Arcsight, RSA NetWitness, Dragon, Bro, FireEye, TippingPoint. Fidelis, Inquest, wireshark. Bluecoat, SourceFire,Cisco Defender Center, NetWitness,Sourcefire,redseal, McAfee ePO, Splunk )
- Maintained Security principles, tools, and best practices, helping to ensure that all new solutions introduced into the environment take security into consideration and that all tools selected follow the organization DAR process.
- Prioritizing and differentiating between potential intrusion attempts and false alarms.
- Creating and tracking security investigations to resolution. Using a SIEM/ Arcsight implementation to his new use.
- Analyzing events from SIEM channels, identifying cyber threats, virus, malwares and network instructions. Investigate forensic analysis and data recovery of network assessments.
- Composing security alert notifications and other communications.
- Advising incident responders in the steps to take to investigate and resolve computer security incidents.
- Staying up to date with current vulnerabilities, attacks, and countermeasures.
- Determinate and recommend new detection and Prevention Methods and capabilities.
- Daily work environment to multitask to a variety of functions while under pressure. (Include but no limited to internal tools or open source tools).
- Monitor security intelligence sources (classified and Unclassified) to keep up-to-date on the latest security threats and trends. Report significant threats to internal team members only.
- Document and explain technical details clearly and concisely.
- Performing Confidential and digital forensics.
- Improvement of analyst effectiveness by optimizing signature quality in collaboration with other analyst, vendors and developer.
- Implemented investigation in host-based indicators of compromise and network traffic including analyzing log, forensic, malware, or other IR-related data, as needed.
Vector Technical Tier II
Confidential
Responsibilities:
- Provide technical/help desk support to Confidential International users on side and remotely on the Network/SCCM . 24/7.
- Provide remote support of systems on desktops, laptops, printers and other network or user devices.
- Trouble shoot windows application issues, application software on PC and general questions concerning windows products and software's.
- Provided technical support on Mac, Dell and HP laptops, PC and think clients.
- Troubleshooting problems with Internet connections, printers, scanners, work stations/PC, laptops and networks servers.
- VPN and Citrix support 24/7 call center.
- Used familiarity with operating systems (windows Vista and windows 7, Windows 8.1, Solaris, Linux ) resolve issues remotely.
- Maintained accurate notes, and good service skills using SCCM .
- Coordinated Replace parts hardware of PC and Laptop with HP and Dell Technicians.
- Mobile device setup including, air cards, Blackberry phones, note book and tablets. (Verizon, AT&T and T-Mobile). Enterprise Activation
- Activation and resetting passwords on AD.
- Providing problem resolutions in person or over the phone for users.
- Identifies, diagnoses and resolved end users network and local printers issues, outlook, credentials, profiles, and network issues.
- Work in collaboration by helping others technicians in the best environment possible.
- Dealing daily with professional analytical, communication, organization, relevant, understanding of each individual issue or assignment.
- Supporting Cisco IP phones and devices.
- Activation and creating Lync accounts.
- Creating user enterprise accounts on AD and Outlook 2013.
- Experiences with software installations, applications, adds, HTML,XML and http, https and others.
- Working with active directory and administrator level.
- Malware detection, Analysis and mitigation 24/7. Using FireEye, McAfee manager console and ePolicyOrchestrator.
- Running updates, patch’s for vulnerabilities, on software applications. For PC’s, laptops, printers, firewalls, servers and others devices in the corporate Network.
- Scan desktop computers and laptops for vulnerabilities. ( Microsoft baseline Security Analyzer)
- Monitoring Network channels using Network Auditor and ArcSight.
Confidential
Customer Service Agent
Responsibilities:
- Provide technical/help desk support to the Army users on side and remotely on SIPR and NIPR Network .
- Provide remote support of systems on desktops, laptops, printers and other network or user devices.
- Trouble shoot windows application issues, application software on PC and general questions concerning windows products
- Provided technical support on Dell, Hitachi, and HP laptops and PC and think client.
- Troubleshooting problems with Internet connections, printers, scanners, work stations/PC, laptops and networks servers.
- Used familiarity with operating systems (windows Vista and windows 7, Solaris, Linux ) resolve issues remotely or walking in User offices.
- Maintained accurate notes, and good service skills using Remedy.
- Replace parts hardware (and software ) of PC and Laptops.(Dell,Hitachi,HP,Sony,Mac, and others)
- Mobile device setup including, air cards, Blackberry phones, note book and tablets. (Verizon, AT&T and T-Mobile). Enterprise Activation. CAC card reader for Blackberry phones.
- Activation and resetting passwords for CAC and security token. (NIPR and SIPR)
- Providing problem resolutions in person or over the phone for users.
- Identifies, diagnoses and resolved end users network and local printers issues, outlook certifications, credentials, profiles, and network issues.
- Repair PC software and hardware. (replacing drivers, and HD, video cards, and others)
- Work in collaboration by helping others technicians in the best environment possible.
- Providing services to customer with hard drives sanitization, degauss and destruction. This work include but no limited to Paper work Memorandums and certifications. Government requirements.
- Monitoring, managing and maintain assist using SCCM. (Doing process from start to resolved issues).
- Dealing daily with professional analytical, communication, organization, relevant, understanding of each individual issue or assignment.
- Working with active directory and administrator level.
- Experiences with software installations, applications, adds, HTML,XML and http, https and others.
- Running patch’s for vulnerabilities, on software applications.
- Creating user enterprise accounts on NIPR and SIPR networks.
- Activation of new NIPR CAC, resetting password and including provision and re-provision NIPR CAC. Fixing issues with certification and profile.
- Activation of new SIPR Token, resetting password. Fixing issues with certification and profile.
- Scan desktop computers for vulnerabilities.
Confidential
Administrator helper
Responsibilities:
- Provide technical/help desk support the school devices and users. provide remote support of systems on desktops, laptops, printers and other network or user devices.
- Trouble shoot windows application issues, application software on PC and general questions concerning windows products
- Provided technical support on Dell and HP laptops and PC and think client.
- Troubleshooting problems with Internet connections, printers, scanners, work stations/PC, laptops and networks servers.
- Used familiarity with operating systems (windows Vista and windows 7, Solaris, Linux )
- Resolve issues remotely or walking in User offices.
- Maintained accurate notes, and good service skills.
- Replace parts hardware (and software ) of PC and Laptops.(Dell,Hitachi,HP,Sony,Mac, and others)
- Mobile device setup including, air cards, Blackberry phones, note book and tablets. (Verizon, AT&T and T-Mobile).
- Identifies, diagnoses and resolved end users network and local printers issues, outlook certifications, credentials, profiles, and network issues.
- Repair PC software and hardware. (replacing drivers, and HD, video cards, and others)
- Work in collaboration and under supervisition of Confidential by helping others technicians in the best environment possible.
- Dealing daily with professional analytical, communication, organization, relevant, understanding of each individual issue or assignment.
- Working with active directory and administrator level.
- Experiences with software installations.
- Running patch’s for vulnerabilities, on software applications.
- Creating user enterprise accounts.
- Scan desktop computers for vulnerabilities.
