We provide IT Staff Augmentation Services!

Information Security Analyst Resume

3.00/5 (Submit Your Rating)

Pittsburgh, PA

OBJECTIVE

I seek a position as an Information Assurance Analyst or an Information System Auditor within an organization’s IT Security and Risk department

SUMMARY

  • With over 5 years of experience in Information Technology (IT) Security with emphasis on Federal Information Security and Management Act (FISMA), Sarbanes - Oxley Act (SOX) 404, PCI-DSS, testing information security controls, risk assessments and audits, developing procedures, policies and guidelines thereby strengthening organizations information security systems.
  • As part of a team, I have assisted System Owners and Information System Security Officers in putting together a Certification and Accreditation package for organizations information systems as directed by the confidential  implementing operational, management and technical controls documented in confidential Special Publications 800 series: 60, 37, 18, 34, 53 Rev4, 800-53A Rev4 etc.
  • As a Certification and Accreditation Analyst I have extensive knowledge of the FISMA regulation and the NIST risk management framework focusing on Categorization, Control Selection, Control Implementation, Control Assessment, System Authorization and Continuous Monitoring.
  • Created, reviewed and updated Security Policy documents and procedures such as FIPS 199, E-authentication, Contingency Plan, Configuration management plan, Privacy Threshold Analysis, Privacy Impact Assessment, System Security Plan (SSP), Continuous monitoring plan among others.

TECHNICAL SKILLS

Software/Platform/Artifacts: MS Office, FIPS199, PTA, PIA, RA, SSP, CP, CIPT, ST&E, SAR, POA&M, SORN, E-Authentication, ATO, 800-53A, ISA, MOU, CSAM, eRisk Manager, Risk Vision.

Standards: Confidentiality, Integrity, Availability, Access Control, Audit and Accountability, ITIL, ISO 27001, 27002, COSO/COBIT, Sarbanes-Oxley Act, SAS-70,SSAE 16, General Computer Controls, Application control, Testing, Compliance Testing, Risk Assessment, Change Management, Security Maintenance, Contingency Planning; Policies and Procedures, NIST 800-53, NIST SP 800-53A, NIST SP 800-37, NIST SP 800-30, FIPS, FISMA, FedRAMP, FISCAM.

PROFESSIONAL EXPERIENCE

Confidential, Pittsburgh PA

Information Security Analyst

Assisted with implementing the confidential Cyber security Framework at all stages of the security life cycle. Managed security framework projects and initiatives from initiation to deployment. Identified system boundaries and developed a system inventory. Ensured ATO package was complete to obtain signature from Authorizing Official. Created weekly compliance reports. Assisted in the development of corporate policies and procedures. Conducted cloud reviews for Cloud Service Providers (CSPs) contracted by Confidential for Software as a Service (SaaS), Infrastructure as a Service (IaaS) and Platform as a Service (PaaS) cloud solutions, reviewing SOC2, ISO 27001, Statement of Applicability (SOA), PCI-DSS and FedRAMP documents

Confidential, Austin TX

Information Security Analyst

Responsibilities:

Assisted confidentials and System Owners with the Certification and Accreditation (C&A) process, and that operational and technical controls for securing IT Systems and Security Systems are in compliance with federal guidelines - NIST 800-53. Process ensures that the right steps are adhered to in the implementation of information security requirements during the life cycle of IT based systems, from initiation requirements through completion. Other duties included the assurance of vulnerability mitigation, training on C&A tools, supporting System Testing and Evaluation (ST&E) efforts. Conducted security control assessment to evaluate if management, operational privacy and technical security controls implemented are adequate. Security Assessment Report (SAR) was generated emphasizing the results of the assessment along with plan of action and milestones (POA&M). Conducted Federal Risk and Authorization Management Program (FedRAMP) which ensure a standard focus regarding security assessment, authorization and information systems continuous monitoring for cloud based products and services. Conducted Privacy Threshold Analysis (PTA) and Privacy Impact Analysis (PIA) in partnership with the System Owner, Information System Security Officer (ISSO), Information Owner and the Privacy Act Officer (PAO). Advised organizations in the development of Information Security Continuous Monitoring Strategy (ISCM) to assist in maintenance of the ongoing awareness of information security, ensuring selected controls are effective, vulnerabilities, and threats that back the organization's decisions on risk management. Developed E-Authentication report to assist with technical guidance in the actual implementation of electronic authentication (e-authentication). Developed a risk assessment report with the purpose of identifying threats and vulnerabilities applicable to targeted systems. It further evaluates the potential that vulnerabilities can be exploited, assesses the impact associated with these threats and vulnerabilities, and identified the overall risk level.Confidential, Freddie Mac, Virginia

Information Security Analyst

Responsibilities:

Assisted in communicating and facilitating the requirements for security risk assessments for both custom developed and third-party applications within the Freddie Mac Infrastructure. Ensured that a Business Impact Analysis was performed for information systems. As part of a team, developed the technology risk matrix to highlight areas of high risk for each of the applications within Freddie Mac across risk management frameworks, namely SOX, PCI-DSS, FISMA and NIST. Assisted in identifying and communicating application control deficiencies and the associated risks. Developed action plans and/or recommended alternate solutions to resolve exceptions to standard operating procedures. Reviewed and updated System Security Plans (SSP), Security Risk Assessment Reports (SAR), Security Test and Evaluation Reports, Security Policies, Contingency Plans, Plan of Action and Milestones (POAM), and Incident Response Plans. Reviewed C&A package. Prepared and signed C&A evaluation report. Provided security consulting and advisory services to business units and project teams. Developed and maintained relationships with internal and external customers to formulate information security governance, risk management and compliance (GRC) solutions. Researched and maintained a knowledge base regarding information security issues, solutions and potential implications. Supported requirements gathering and design efforts of critical projects as needed. Responsible for implementing and maintaining a continuous process improvement work environment while executing security risk assessments in accordance with industry standards and best practices.

Confidential, Austin TX

SOX Consultant

Responsibilities:

Compliance Testing: Completion of application level controls of invoices and payments authorizations covering ERP packages and financial applications. Tested the effectiveness of key infrastructure controls, namely in disaster recovery, network security,, and change management. Conducted walk throughs and tested approximately 25 controls. Defined testing methodology and sample size selection for both automated and manual controls. Identified implemented roll forward procedures and exceptions.

Tested general computer controls provided by operations and business units and identified operation deficiencies. Sox 404 Remediation Project: Assisted the Director in carrying out fraud investigations. Planned audits and reviews of selected IT audit areas utilizing system walkthroughs and control risk assessments. Tested controls on selected systems and prepared work documentation in accordance with set department standards. Evaluated current auditing procedures and recommended changes where needed.

Analyzed processes and suggested system improvements. Worked with the Logging and Monitoring team as part of the Confidential SOX initiative. Helped the business unit elaborate and identify internal control processes. Participated in SOX, COBIT and PCI-DSS Framework sessions and provided tracking and consolidated risk management and deliverables calendar. Manually reviewed logs and provided documentation guidelines to Process owners and management. Utilized Active Directory for authenticating and authorizing all users and computers within a network on a Windows Operating System domain. Worked with Process owners to ensure timely identification and remediation of jointly owned risk related and or action plans.

Communicated and facilitated the requirements for security risk assessments for both custom developed and third-party applications within the bank. Helped develop the technology risk matrix, highlighting high risk areas for the critical SOX, applications within the bank. Assisted in identifying minimum security control requirements and communicated application control deficiencies and risks. Provide security consulting and advisory services to business units and project teams. Developed and maintained relationships to help formulate information security governance solutions. Researches and maintains knowledge base regarding information security issues, solutions and potential implications. Supports requirements gathering and design efforts of critical projects as needed. Assisted with continuous process improvement while executing security risk assessments.

Confidential, Austin TX

Compliance Analyst

Responsibilities:

Reviewed and conducted in-depth analysis on regulatory and legal changes affecting the institution. Prepared reports and analysis for compliance management. Developed and implemented policies, procedures and standards for confidential frameworks. Assisted projects, exams, audits and other tasks assigned. Prepared currency transaction reports in compliance with the Bank Secrecy Act. Managed projects required to implement regulatory and legal changes, including setting project goals, coordinating efforts between multiple departments, and monitoring for effectiveness. Verified that new and existing clients are not on the confidential list, minimized money laundering activities, prevented and detected fraud incidents and tracked key performance indicators. Identified areas that required increased security controls to protect the organization and its end users from future fraud, communicated with client fraud staff, outside authorities and law enforcement on fraud case inquiries via email, phone and fax, responsible for building and maintaining a strong level of customer service. Corresponded with the IT group to help close fraud gaps.

Confidential

Time & Access Systems Engineer

Responsibilities:

Served as assistant head of the organizations IT project team that implemented over 35 client-server, time and access control systems for organizations with employees ranging between 15 and 4000. These were systems that had a single or multiple access technology ie. magnetic stripe, proximity, biometric fingerprint, waist and full height turnstiles. Assisted in the integration of time and access systems with clients payroll system to facilitate accurate payroll calculation and also integrated with clients Human Resource system to provide accurate attendance and holiday information. Carried out over 200 marketing and technical presentations to prospective customers. Developed training manuals for the organizations clients on systems deployed. Lead the organizations training and customer support unit. Developed implementation guidelines for implementation teams. Worked closely with the marketing department to help write up material targeted at prospective clients and also towards the organization’s promotional drive. Ensured excellent customer service for our clientele

Confidential

IT Support

Responsibilities:

Assisted and managed the IT requirements of the organization. Member of software and hardware implementation team for our clients. Facilitated presentations and application demos to our customers for the implementation of client server applications for both time & attendance and access control systems. Performed both on-site and remote technical support. Supported both biometric and card-based time and access system customers

Confidential

Marketing & Sales Support

Responsibilities:

Assisted in the development of schematic diagrams for the organisations Uninterruptible Power Supply (UPS) power solutions. Assisted in the marketing function of the firm, this included trade shows, competitor analysis, product demos

Confidential

Technical Support

Responsibilities:

Provided direct technical support for the sales and marketing team for the organisations Wide Area Network (WAN) and Virtual Private Network (VPN) solutions using X.25 data packet switching technology from ECI Telematics. Assisted in generating technical solutions and diagrams for potential and existing clients using MS Visio and MS Project. Assisted in the programming, support and testing of the organisations commercial voicemail system. Assisted in developing and updating PowerPoint presentations for potential and existing customers for customized solutions.

We'd love your feedback!