Cyber Security Consultant/services Engineer Resume
4.00/5 (Submit Your Rating)
Washington, DC
SUMMARY:
- Sixteen years’ experience as an information assurance professional in the Federal government and private sectors.
- Extensive experience compiling complete authorization to operate (ATO) packages, including data gathering, analysis, security testing, and POA&M generation/management.
- Use Confidential guidance and IA tools to identify and close gaps.
- Project management experience in risk assessment, compliance, and full SDLC/ Confidential RMF/FedRAMP/Cloud projects.
- Provide independent audits of security documentation to obtain ATOs and ensure compliance with applicable regulations.
PROFESSIONAL EXPERIENCE:
Confidential, Washington, DC
Cyber Security Consultant/Services Engineer
Responsibilities:
- Duties include composing ATO documentation for various clients, including Confidential .
- Worked on a team engineers to develop a proprietary system ( Confidential ) designed to automate the ATO process.
Confidential, Washington, DC
Cybersecurity Consultant
Responsibilities:
- Provided expert security and compliance guidance to clients implementing Google G - Suite and Amazon Web Services (AWS) cloud solutions into their organizations.
- Compiled a full security assessment documentation package resulting in the initial ATO for a new cloud system using G-Suite, AWS, and Slack.
- Collaborated with external auditors to identify security deficiencies and generate POAMs to remediate deficiencies.
- POAMs included timelines and budget to remediate each finding.
- Worked with Foreign Affairs Network ( Confidential ) management and technical staff to gather data and assemble packages resulting in closing open POAMs.
Confidential, Washington, DC/McLean, VA
Senior Security Engineer
Responsibilities:
- Compiled an initial ATO package for a new financial accounting system performing daily transactions, managing over $6T in Federal assets.
- Conducted independent audits of security documentation and closed compliance gaps to obtain ATOs.
- Act as Senior Systems Engineer/Consultant in a client facing role, directly supporting the agency’s CISO. Provide client with quick turnaround deliverables and long term strategic advice.
Confidential, Washington, DC
Independent Consultant
Responsibilities:
- Drafted an FY16 System Security Plan (SSP) in compliance with Confidential SP-800-18 and other supporting security documentation.
- This project utilized my experience with FAA systems to update a critical system’s SSP from the Confidential 2014 to the Confidential 2016 format.
Confidential, Washington, DC
Director of Information Assurance
Responsibilities:
- Cultivating a comprehensive information security program to ensure Confidential compliance, developing policies and procedures, internal auditing and compliance reporting, and working with agency technology leaders to remediate known security deficiencies.
- Performed a full audit of a client’s SAS application using FISMA, Confidential, and Confidential guidance. This audit identified 21 security deficiencies. Drafted new finding and recommendation ( Confidential ) documents for all deficiencies and worked with the client’s staff to determine timelines and optimum remediation strategies.
- Performed an internal audit under the Ambit CIO to prepare the company for an upcoming ISO 27000 compliance audit.
Confidential, Washington, DC
Senior Security Consultant
Responsibilities:
- Led data gathering (interviews, documentation reviews, and physical system inspections), auditing, and system security testing initiatives to determine the posture of Federal information systems and identify gaps with Confidential compliance.
- Drafted recommendations based on data gathering findings and presented them to senior management.
- Performed and analyzed results of security analysis and system scans (using Confidential ) to determine optimal remediation strategies, recommendations, and implement innovative technologies and processes.
- Interviewed and evaluated potential employees. Mentored new hires.
- Presented findings to senior management level clients, absorbed feedback, and addresses any concerns.
Confidential, Arlington, VA
Senior Security Consultant
Responsibilities:
- Designed and implemented comprehensive management solutions for Federal clients using Federal guidance, analysis, accepted standards, and best practices.
- Created and presented project performance metrics for weekly, quarterly, and annual reporting and budgeting both internally and to clients.
- Acted as Operations Manager on a project which implemented a full information security management program that raised the client’s Federal security scorecard grade from a D- to an A+ over three years. Task Lead and primary client point of contact on a project which determined and assigned security classification levels and prepared C&A packages for 100% (16) of a large Federal agency’s major IT systems using FIPS 199 guidance.
- Prepared business cases supporting a client’s IT investments (CPIC) and successfully demonstrated earned value in each investment.
- Authored 25+ IT security policies and procedures for clients.