Senior Information Systems Security Engineer Resume
4.00/5 (Submit Your Rating)
PROFESSIONAL SUMMARY:
- Confidential is an Information Technology Security Professional with MSCS degree, MCSE and over 29 years of increasing technical, supervisory, project management, software development, helpdesk/customer support and IT security responsibilities.
- CISSP - trained with core expertise in Systems, Networks and 3rd-party Applications Development / Implementation, Administration/Security, Certification and Accreditation (C& Confidential ) now called Confidential & Confidential, Risk Assessments, Disaster Recovery/Contingency Planning (COOP), Vulnerability Assessments, Data Center Consolidations, etc.
- Experience working with Federal Security Regulations including FISMA, FISCAM, HIPPA, OMB Circular Confidential -130, Confidential, Sarbanes-Oxley (SOX), Special Publication Series 800 and FIPS Publications, ITSCAP/DIACAP/NIACAP, DISA/DoD 8500 Series.
- Highly proficient in both CSAM and Trusted Agent Confidential & Confidential product variants, also experience with Confidential, Tenable, various penetration, detection and reporting tools, proprietary and open-source. Cloud experience / administration ( Confidential side job) supporting mostly VMWare, OpenStack, etc.
PROFESSIONAL EXPERIENCE:
Senior Information Systems Security Engineer
Confidential
Responsibilities:
- Currently supports Confidential Information Assurance Division (IAD) performing Subject Matter Expert security support.
- Provides enterprise-wide security oversight, infrastructure support, guidance, and reviews for the Confidential IT environment.
- Supports large technology integration projects, enterprise-wide change control ( Confidential ), new enterprise-wide technology deployments, Confidential PKI functions, and also evaluates new and existing IT Security products that can enhance Confidential ’s security posture.
- Interfaces with other Confidential groups to maintain appropriate technology alignment and incorporates security infrastructure into the Emerging Technologies and the Enterprise Architecture group.
- Builds the security infrastructure and secure foundation leveraged by all Confidential Enterprise systems.
Senior Information Systems Security Engineer
Confidential
Responsibilities:
- Supported Confidential Information Assurance Division(IAD) performing Subject Matter Expert security support
- Provided enterprise-wide security oversight, infrastructure support, guidance, and reviews for the Confidential IT environment.
- Supported large technology integration projects, enterprise-wide change control ( Confidential ), new enterprise-wide technology deployments, Confidential PKI functions, and also evaluates new and existing IT Security products that can enhance Confidential ’s security posture.
- Interfaced with other Confidential groups to maintain appropriate technology alignment and incorporates security infrastructure into the Emerging Technologies and the Enterprise Architecture group.
- Builds the security infrastructure and secure foundation leveraged by all Confidential Enterprise systems.
Security Analyst
Confidential
Responsibilities:
- Conducted C& Confidential & Confidential ) kick-off briefing
- Conducted security assessment Prepared Assessment Packages including FIPS-199, PIA, SSP, ST&E with test results, Risk Analyses, Security Assessment Report, POAM reports.
- Acted as liaison between the ISSO and system owners/administrators.
- Worked closely with system POA&M stewards (assistance, recommendations) for all work on POA&M items (creation, updates, validation, milestones completions/approvals/closures).
- Coordinated contingency plan test dates with System Owner, CP coordinator for compliance under annual assessment testing or re-certification testing.
IT Security / Documentation Analyst
Confidential
Responsibilities:
- Managed, monitored and updated all security artifacts in support of Confidential Services Team based on the latest official version of FISMA, Confidential SP 800-53 (baseline through rev 3), and the Confidential Computer Security Handbook, Managed, monitored and updated all security artifacts in support of Confidential Services Team
- Certification & Accreditation documentation skills to include support the performance of reviews and ensure updates are completed for Confidential DIT systems security documentation.
- Produced reports, tests and reviews of security requirements with Senior Level understanding of environments containing Windows desktops, Windows and Solaris Servers and Cisco Network Equipment.
- Recognized known intrusion techniques based on the footprints or artifacts left by different types of attack in the incident reports.
- Provided analysis of and correlation between incidents to notice what has not been seen before ( Confidential new attack technique, footprint, intruder tool, attack vector, etc.) post event forensics and infection remediation.
Documentation Analyst
Confidential
Responsibilities:
- Managed, monitored and updated all security artifacts in support of Confidential ( Confidential ) based on the latest official version of FISMA, Confidential SP 800-53 (baseline through rev 3), and the Confidential Computer Security Handbook.
- Certification & Accreditation documentation skills to include support the performance of reviews and ensure updates are completed for Confidential DIT systems security documentation.
IT Security Specialist
Confidential
Responsibilities:
- Assisted the CSAM (C&AWeb) s/w development team with creation of CSAM helpdesk
Senior IA Engineer
Confidential
Responsibilities:
- Supervised the team that built Confidential new Financial System to handle Contract Data from the integrated Business Units from Confidential and Confidential
Systems / Network Administrator
Confidential
Responsibilities:
- support for all in - house and customer unix, Linux, and/or Windows systems and equipment within Confidential Data Center environment in accordance with current or revised Help Desk Techwikis and/or customer service level agreements.
- Troubleshoot problems encountered using microcomputer software;
- Perform hardware/software testing and installation; Evaluate firmware, peripherals, software packages, etc., for use by staff and provide recommendations to accomplish the desired objectives;
- Perform network and desktop based resolution/mitigation of all customer issues, as well as implementation of all requested new h/w s/w installations, migrations, upgrades and maintenance, including automated and manual software updates, patches, registry changes;
- Detect, contain and eliminate virus infestations, denial-of-service attacks, spam and phishing detection, etc;
- Ensure technical safeguards are maintained to provide controlled user access, integrity of electronic mail, applications (web/apache, MySQL, mostly) and user data.
- Virtualization / Cloud-based services (ESXi, HyperV, VMware, Openstack, Xen)
- Network administration (routers/switches/firewalls)
