Information Security Analyst Resume
5.00/5 (Submit Your Rating)
Mclean, VA
SUMMARY:
Highly motivated and dedicated Information Security professional with strong experience in vulnerability assessment, security controls testing, POA&M management and FISMA/NIST 800 - 53 compliance.
KEY SKILLS:
- Risk Management Framework (RMF)
- Federal Information Security Management Act (FISMA)
- Assessment & Authorization (A&A)
- Plan of Action & Milestones (POA&M)
- Security Assessment Report (SAR)
- Security Categorization (SC)
- NIST Special Publications (NIST SP)
- System Security Plans (SSP)
- Continuous Monitoring (CM)
- Vulnerability Scanning
WORK EXPERIENCE:
Information Security Analyst
Confidential, Mclean, VA
Responsibilities:
- Responsible for providing day-to-day support for Federal Government IT systems to keep them up to date with Information Security Standards created by FISMA.
- Maintaining and updating the SSP (System Security Plan) Document findings in the Security Assessment Report (SAR) and review Plan of Action & Milestones (POA&M) for all controls that have weaknesses and deficiencies.
- Maintain and monitor identified POA&M items through completion Review Contingency Plans (CP) Update and Review Privacy Threshold Assessments (PTA), Privacy Impact Analyses (PIA), E-Authentication Assessments, System of Record Notices (SORN) Support System owners through A&A (Formally C&A) process Establish Continuous Monitoring for each system (Vulnerability Scanning and Testing Controls)
- Review and assess Vulnerability scan results Participate in SCA meetings Respond to system audit requests
Cyber Security Analyst
Confidential, Woodbridge, VA
Responsibilities:
- Helped guide System Owners through Certification and Accreditation (C&A) Process, ensuring that Operational
- Management and Technical controls securing sensitive Information Systems were in place and followed the FISMA Federal Guidelines (NIST SP 800-53).
- Performed Security Categorizations using the FIPS 199 and NIST SP 800-60 Reviewed C&A documentation including System Security Plan (SSP), Privacy Threshold Analysis (PTA), Plan of Action and Milestones (POA&M), Security Assessment Report (SAR) and System Contingency Plans (CP)
- Conducted gap analysis to make sure correct controls were in POA&M Performed vulnerability scanning with Confidential Reviewed artifacts and removed any PII (Personal Identifiable Information) for audit requests
EDUCATION
George Mason University’s Volgenau School of Engineering - IT Network Security - B.A.
2006 - 2010
