Sr. Security Architect/sca Rep. Resume
3.00/5 (Submit Your Rating)
SUMMARY:
- Project Manager/Lead Engineer in a number of government contracts. I have extensive experience in design, implementation, and troubleshooting with a wide variety of products and technologies, in a complex network/security environment and has also been recognized as a highly accomplished network engineer/consultant and Cisco Certified Systems Instructor. I have received many awards for quality of instruction and is skilled at communicating knowledge and experience in a very clear and professional manner, relating it to business issues. I also have experience in assessing network/security technology, design, and procedure for strengths, weaknesses, and risk with a goal towards improvement.
- I was the Lead Security Advisor for the Confidential Chief Information Systems Security Manager.
- I have developed and managed, from the ground up, the Confidential Information System Directorate (C4ITSC IAD) web site and server. Through exceptional support and trusted relationship with the Confidential, I secured a new 5 year IA contract worth up to $60 million that increased the staff from 5 to 40 IA staff. I am currently assigned to Defense Threat Reduction Agency ( Confidential ) as a Certifying Authority Representative supporting the Confidential IA division performing independent assessment and validation of all IA controls.
- Furthermore, I was i nvolved in developing, the now very popular book, Cisco Certification: Bridges, Routers, and Switches for Confidential .
- Based on this book, I was involved in creating and teaching a custom course for students pursuing their Confidential certification.
- I am currently the Project Manager/Lead Information Assurance Engineer for Confidential, consulting on various projects, assessing client needs, recommending strategies that enhance efficiency and maximizing their ROI. (Return on Investment)
SOFTWARE, PROTOCOLS:
- Windows, Unix/Linux, Sun Solaris, Microsoft Office, CiscoWorks, CiscoSecure (Radius, TACACS+), Cisco Policy Manager, HP Openview, IPSEC, DES, 3DES, ISAMP, PPTP, L2TP
- Novell IPX/SPX; TCP/IP (DNS, DHCP, SNMP etc); Appletalk; DECnet; Frame - Relay; X.25; ISDN; ATM (LANE, CLIP, MPOA, etc); SDLC; HDLC; LAPB; PPP and all routing protocols. (Ex. RIP, OSPF, IGRP, EIGRP, BGP, ISIS, MPLS, NLSP, IPX RIP, RTMP.
- Telephony ( Q931, Q921, SS7, H323, H225, H245), Wireless (IEEE 802.1la, 802.11b, WEP)
- IP multicast (PIM, CGMP, IGMP), NAT/PAT, HSRP/VRRP. Transparent, RSRB, Source-route bridging. SNA, Netbios, DLSw+
- Ethernet, FastEthernet, Gigabit Ethernet, token-ring, FDDI, CDDI, ATM, SONET, Packet over Sonet, OC 3-192.
WORK EXPERIENCE:
Confidential
Sr. Security Architect/SCA Rep.
Responsibilities:
- Perform independent assessment, validation, and Risk Management of all IA controls
- Knowledge of FedRAMP, Cloud Security Assessment, and Risk Management
- Analysis of STIGs and SCAP/Vulnerability Scans
- Review and Validation of RMF documents/artifacts. i.e RAR, SAR, POAM, SSP, SCA Memo
- Develop document templates. i.e. Incident Response Plan, Contingency Plan, CONOPs, Continuous Monitoring Plan, Media Protection Plan, Audit Plan and many more.
- DIACAP to RMF transition support. i.e. Gap analysis of in place security controls and existing documentation; Identifying the scope of the development effort needed to conform to DoD RMF; Mapping DIACAP processes and IA controls to RMF; Enterprise Mission Assurance Support Service (eMASS) support; Assessing security controls and supporting the authorization process; Assisting in continuous monitoring activities and security plan maintenance.
- Track C&A Activity, provide daily status updates on all active CA Actions (i.e., Accreditations, Annual Security Reviews, FISMA reports, DITPR updates, etc.)
- Perform final, quality assurance review of all C&A documents before submission to SCA/AO for signature for accuracy and grammatical errors (i.e., ATO letters, Certification letters, Security Assessment Reports, Risk Assessment Reports, Quarterly and Annual FISMA reports, etc.)
- Perform final, quality assurance, reviews of all Accreditation Packages in eMASS for accuracy, validity, independence
- Answer all communications from assigned system owner representatives or other assigned CA Actions within one business day (i.e., NIPR/SIPR emails, voicemails, eMASS notices, etc.)
Confidential
Technical Project Manager
Responsibilities:
- Introduce new technologies, concepts, and processes that can improve the security, function, and operations of the Army/ Confidential DoDIN/DCO - IDM missions.
- Develop enterprise strategy for the Command, to include the identification of strategies, requirements, and advanced design/engineering.
- Provide systems engineering and technical expertise to the Confidential Commanding General and the Senior Technical Director (STD).
- Provide Project Management support for Army Network Modernization and Standardization effort. Which include Big Data analytics, Data and Sensor Strategy, and Modeling & Simulation tools.
- Improve Army Enterprise with System Engineering support for new emerging technology evaluation, Enterprise Capability Gap Analysis, and Continuous Mapping Strategy.
Confidential
Project Manager/Lead C&A/IA Engineer
Responsibilities:
- Lead C&A/IA Engineer, Confidential C4 Cybersecurity Division.
- Acts as a primary IA technical advisor to the respective program/system manager and when necessary, formally notify the Confidential and/or CA of any changes impacting the information system’s IA posture.
- Conduct IA assessments to ensure security controls are in place in order to facilitate confidentiality, integrity, authentication, and non-repudiation.
- Responsible for targeted project plan development and management, policy and process development, technical IA technology assessments and analysis, and related IA guidance interpretation and dissemination.
- Ensure C&A DIACAP process, guidance, and standard operating procedures are prepared, maintained, and implemented for the information system.
- Developed guidance and planning for DIACAP to NIST RMF transition.
- Developed guidance and planning for Xacta to Archer C&A tool migration.
Confidential
Project Manager/Lead Info. Assurance Engineer
Responsibilities:
- Project Manager for the Confidential Information Assurance Directorate comprising of three branches. Certification and Accreditation (C&A), Coast Guard Computer Incident Response Team ( Confidential ) and the Coast Guard Compliance and Reporting Branches (CRB). Consisting of 40 personnel.
- Lead C&A Engineer for the entire Confidential SIPRNET/NIPRNET systems comprising of hundreds of sites, Cutters and field offices.
- Project Manager to oversee the 24x7x365 operational support for Confidential Analyst Desk watch.
- Provide support to the Confidential in planning, organizing, implementing, and executing the Confidential cyber security programs.
- Respond to, provide notification, and work to resolve all cyber intrusions involving Confidential systems and networks.
- Resolve cyber incidents and correlate cyber incident data and perform trend analysis and reporting.
- Continuous monitoring of the various Confidential cyber monitoring systems to include, but not limited to McAfee IntruShield, Sourcefire, Snort, Trustwave, SCCM, and FW logs. Also configure, install, manage, and support the cyber security systems used by the CIRT to include but not limited to McAfee IntruShield, Sourcefire, Snort IDS, Trustwave SIEM, ACAS, WebInspect, Nessus Security Center, DOD JIMS, Guidance EnCase Enterprise, and Access Data FTK.
- Forensically sound collection of images and inspect to discern possible mitigation/remediation on enclave systems.
- Provided information assurance solutions including; configuration, operation and management of network systems, Vulnerability Management System (VMS), IAVA Management and Emergency Response Processes.
- Develop security and RMF/DIACAP documentation and templates, including standard operating procedures, statistical and compliance reports, DIP/SSP, Contingency Plan, DR/COOP Plan, Incident Response Plan, etc..
- Conduct Certification and Accreditation of the SIPRNET/NIPRNET Classified and SBU system, major application, and Platform Information Technology systems (PITS) under the DIACAP, NIST (RMF), and CNSS guidance/standards. I.e. SP 800-37 Rev 1 Risk Management Framework (RMF) ; NIST SP 800-53 Rev 3 Security Controls; DoDI 8500.2 Security Controls; CNSS 1253 controls; FISMA Compliance/Reporting; Continuous Monitoring; Risk Assessment Report; POAM Management; Vulnerability Scanning/Assessment; Privacy Threshold/Impact Analysis; FIPS-199; System Security Plan (SSP); DIACAP Implementation Plan (DIP); Contingency Plan; Security Test and Evaluation Plan (ST&E); Requirements Traceability Matrix (RTM); Security Assessment Report (SAR); Concept of Operation; Incident Response Plan.
- Conduct annual FISMA Self Assessment using the NIST SP 800-53 for systems accredited under the NIST SP 800-37 Rev 1, and assist/conduct annual IA Control Review for all accredited systems.
- Developed and managed Information Assurance web sites and servers.
- Review certification documentation such as test and evaluation plans (as applicable).
- Developed Connection Approval Packages (CAP) for systems that require connectivity to the SIPRNET/NIPRNET terminals
- Assist with and validated the security documentation (CAP, DIP, DIACAP Scorecard, Contingency Plans, Trusted Facilities Manual (TFM), Plan of Action and Milestones (POA&M) along with other Confidential documentations)
- Perform and conduct independent Test and Evaluation to ensure that the system’s confidentiality, integrity, and availability are maintained at the standards that are in accordance with the DOD Mission Assurance Category levels, Federal Information Processing Standards (FIPS) 199 and FIPS 200.
- Perform System Architectural Analysis to include review of network connections and interfaces, review system application specification and requirements, specifically those relevant to system security, and review other pertinent system development life cycle documentation.
- Conduct and create security assessments and risk assessment report.
- Have extensive experience and knowledge with systems: RMS, Xacta, S-RMS, eMASS, GIAP, PPSM and TAF.
- Obtain, retrieve, compile, draft and prepare necessary documentation for inclusion to the SSP and ensure that all drafts go thru Quality Assurance Review prior to delivery.
- Organized and maintained electronic libraries of all documents, C&A templates and task-associated documentation, deliverables, reference materials, memorandums, and relevant documentation through systems development life cycle to include: all drafts, versions, finals, updates, maintenance, and retirement to electronic archive.
- Performed certification processes, preliminary and post system analysis and data reductions designed to support the certification results and the accreditation decision of the Designated Accrediting Authority ( Confidential )/Authorizing Official and the Certifying Authority (CA)
Technical Director
Confidential
Responsibilities:
- Lead and manage a team of 12 security professionals on all aspects of Confidential .
- Security design and implementation, Security audit assessment, C&A and recommendations for a secure network infrastructure and network performance, using various products from Cisco, Checkpoint, Netscreen, and Intruvert.
- Security policy review and security product testing from various vendors. Develop and deliver network and security training to internal SMS engineers and clients.
- Chief advisor to the Chief Information System Security Manager of the Confidential . Assisted on all aspects of Security policy issues and wrote many security procedures and processes within DoD and DHS.
- Familiar with and consulted on security regulations and guidelines like NIST, FISMA, HIPAA,, Sarbane-Oxley. Implemented DoD and DHS policy, risk management, procedures and compliance reporting on processes like DITSCAP, DIACAP, INFOCON, IAVA Management, and Vulnerability Management/assessment.
- Performed risk, security assessments, Business impact analysis and develop IT security programs i.e. Business Continuity and Disaster Recovery Plan, including security policies and procedures.
- Work on engagement team to assist clients in creating a complete IT risk reduction approach addressing areas such as Intrusion and Virus Detection, Incident Response, Policies, Standards and Guidelines, and Physical Security.
- Design and implement information protection architecture and security cryptographic solutions.
- Manage all aspects of infrastructure security engagements in complex networked environments.
- Well versed in current security best practices, general IT concepts, and incident response recovery.
- Configured and implemented access-control for various network devices, including routers, switches, firewalls, VPN concentrators.
- Security Forensics using Encase forensics software.
- Provide analysis of client network and organizational architecture.
- Advise the Information Security Officer/Manager of changes in technical, legal and regulatory arenas affecting information security and computer crime.
- Serve as a security technical analyst and advisor on client initiatives to evaluate new technology resources for program compliance by effectively testing solutions using industry standard evaluation criteria, which includes the delivery of formal papers and technical reports on test results and findings.
Confidential
Lead Instructor/Senior Consultant
Responsibilities:
- Lead a team of 10 instructors to ensure that all instructors give the highest quality of instruction in a very professional manner. Helped developed strategic planning that allowed the training department to grow and increase revenue.
- Trained hundreds of engineers on all aspects of Cisco routers and switches.
- Pre-sale/Post-sale support for Federal and Commercial contracts.
- Helped in developing and editing the book Bridges, Routers, and Switches for Confidential . Based on this book help create and teach a customized Confidential prep. Course: Bridges, Routers, and Switches (BRS).
- Helped in Developing and taught the following custom courses: Confidential boot camp, Advanced OSPF/BGP, and CCNP boot camp.
- Implemented E-learning/Distance Learning system so that students can access various Cisco routers and switches remotely.
- Designed and installed VoIP solution for Confidential using IP phones, voice gateway routers and Call Manager.
- Designed and implemented a network security/ IPsec VPN system for Confidential using Cisco PIX, various routers and switches. Also designed, configured and implemented a remote-access solution using Cisco AS5300 and TACACS+ server.
- Project leader for the Federal Reserve Philadelphia. Oversaw the initial network design and documentation. Coordinated and managed a team of 5 engineers in all aspects of Cisco routers and switches configuration. Lead engineer in the token-ring to Ethernet switch migration project.
- Consultant Confidential
- Responsible for providing high availability design and implementation for a 20 site frame-relay hub and spoke topology with ISDN backup for a major home developer. Installed CiscoWorks 2000 suite of network management software.
- Consultant for the US department of Agriculture. Responsible for testing and troubleshooting OSPF routing protocol implementation over Frame-relay. Designed and tested redundancy and failover testing with routers, switches, and firewall. Planned and executed IPX to IP migration.
- Configured and deployed various Cisco routers and switches for the US Welfare Department throughout the United States.
Confidential
Senior Network Engineer/Application Task Leader
Responsibilities:
- Supervised a team of six people, responsible for all installation, configuration, maintenance, and troubleshooting of Routers, switches, network file servers, printers and software applications for the Department of Justice - Office of Justice Program contract.
- Responsible for all Network Administration/Engineering, with emphasis on planning, coordinating, and carrying out technical (Hardware and Software) support for more than 600 end users.
- Configured, managed and supported for more than 1500 remote dial-in grantees via modems, Commvision, Netware Connect, and various communication software (Citrix, Reachout and Rlink).
- Supervised and implemented World Wide Web server, Web pages, and Internet access for more than 600 users.
- Planned and documented OJP (Office of Justice Program) network security procedure, member of the CIRT team dealing within incident handling procedure, Business continuity and Disaster Recover planning, data-mirroring and disk duplexing.
- LAN/WAN Systems Analyst on the Agency Upgrade of Technology for Office Systems (AUTOS) contract for the United States Nuclear Regulatory Commission (NRC). Participated in designing, installing, and supporting an Agency Wide Area Network (AWN) consisting of 3,500 nodes dispersed around the country. Responsible for all aspects of Network installation and configuration; including various routers, switches, network printers, workstations and software applications. Assisted in planning and coordinating NRC’s relocation from many buildings to two main buildings.
- Network Engineer/Administrator after the relocation was complete; providing Network, Hardware, and Software Support for over 1500 on-site users.
