We provide IT Staff Augmentation Services!

Cyber Security Consultant/services Engineer Resume

4.00/5 (Submit Your Rating)

Washington, DC

SUMMARY:

  • Sixteen years’ experience as an information assurance professional in the Federal government and private sectors.
  • Extensive experience compiling complete authorization to operate (ATO) packages, including data gathering, analysis, security testing, and POA&M generation/management.
  • Use Confidential guidance and IA tools to identify and close gaps.
  • Project management experience in risk assessment, compliance, and full SDLC/ Confidential RMF/FedRAMP/Cloud projects.
  • Provide independent audits of security documentation to obtain ATOs and ensure compliance with applicable regulations.

PROFESSIONAL EXPERIENCE:

Confidential, Washington, DC

Cyber Security Consultant/Services Engineer

Responsibilities:

  • Duties include composing ATO documentation for various clients, including Confidential .
  • Worked on a team engineers to develop a proprietary system ( Confidential ) designed to automate the ATO process.

Confidential, Washington, DC

Cybersecurity Consultant

Responsibilities:

  • Provided expert security and compliance guidance to clients implementing Google G - Suite and Amazon Web Services (AWS) cloud solutions into their organizations.
  • Compiled a full security assessment documentation package resulting in the initial ATO for a new cloud system using G-Suite, AWS, and Slack.
  • Collaborated with external auditors to identify security deficiencies and generate POAMs to remediate deficiencies.
  • POAMs included timelines and budget to remediate each finding.
  • Worked with Foreign Affairs Network ( Confidential ) management and technical staff to gather data and assemble packages resulting in closing open POAMs.

Confidential, Washington, DC/McLean, VA

Senior Security Engineer

Responsibilities:

  • Compiled an initial ATO package for a new financial accounting system performing daily transactions, managing over $6T in Federal assets.
  • Conducted independent audits of security documentation and closed compliance gaps to obtain ATOs.
  • Act as Senior Systems Engineer/Consultant in a client facing role, directly supporting the agency’s CISO. Provide client with quick turnaround deliverables and long term strategic advice.

Confidential, Washington, DC

Independent Consultant

Responsibilities:

  • Drafted an FY16 System Security Plan (SSP) in compliance with Confidential SP-800-18 and other supporting security documentation.
  • This project utilized my experience with FAA systems to update a critical system’s SSP from the Confidential 2014 to the Confidential 2016 format.

Confidential, Washington, DC

Director of Information Assurance

Responsibilities:

  • Cultivating a comprehensive information security program to ensure Confidential compliance, developing policies and procedures, internal auditing and compliance reporting, and working with agency technology leaders to remediate known security deficiencies.
  • Performed a full audit of a client’s SAS application using FISMA, Confidential, and Confidential guidance. This audit identified 21 security deficiencies. Drafted new finding and recommendation ( Confidential ) documents for all deficiencies and worked with the client’s staff to determine timelines and optimum remediation strategies.
  • Performed an internal audit under the Ambit CIO to prepare the company for an upcoming ISO 27000 compliance audit.

Confidential, Washington, DC

Senior Security Consultant

Responsibilities:

  • Led data gathering (interviews, documentation reviews, and physical system inspections), auditing, and system security testing initiatives to determine the posture of Federal information systems and identify gaps with Confidential compliance.
  • Drafted recommendations based on data gathering findings and presented them to senior management.
  • Performed and analyzed results of security analysis and system scans (using Confidential ) to determine optimal remediation strategies, recommendations, and implement innovative technologies and processes.
  • Interviewed and evaluated potential employees. Mentored new hires.
  • Presented findings to senior management level clients, absorbed feedback, and addresses any concerns.

Confidential, Arlington, VA

Senior Security Consultant

Responsibilities:

  • Designed and implemented comprehensive management solutions for Federal clients using Federal guidance, analysis, accepted standards, and best practices.
  • Created and presented project performance metrics for weekly, quarterly, and annual reporting and budgeting both internally and to clients.
  • Acted as Operations Manager on a project which implemented a full information security management program that raised the client’s Federal security scorecard grade from a D- to an A+ over three years. Task Lead and primary client point of contact on a project which determined and assigned security classification levels and prepared C&A packages for 100% (16) of a large Federal agency’s major IT systems using FIPS 199 guidance.
  • Prepared business cases supporting a client’s IT investments (CPIC) and successfully demonstrated earned value in each investment.
  • Authored 25+ IT security policies and procedures for clients.

We'd love your feedback!