Senior Cyber Security Consultant Resume
2.00/5 (Submit Your Rating)
SUMMARY:
- Twenty four years of diverse information technology, operations, security and process integration experience in the retail, banking, energy, oil and software industries.
- Recent training include Cloud Securitymicro - certification and SANS security recertification.
- Projects include risk-gap analysis and remediation strategy architecture, threat analysis identification, mitigation planning and compensating control implementation, data loss prevention strategy consulting, malware handling process improvements, risk/gap analysis, server hardening strategy and authored a server hardening white-paper, strategizing asset inventory scanning for various environments (development, quality assurance, staging, production) identification of threats within the cloud infrastructure, and asset explorer deployment to keep vendor SLAs and vendor Linux/Windows upgrade dates aligned with business goals.
- Currently taking a Python programming class
- Currently studying for the CISM to be taken early 201 9
- Scheduled to take the CISSP in early 201 9 .
- Attained GIAC Information Security certificate valid until 2021
- Analytical thinker who quickly identifies the security issues in an organization and creates and executes innovative solutions to resolve them.
- Demonstrated track record of delivering timely and successful results with numerous security projects in an environment lacking direction and focus.
- Consistently identifies measures, assesses, and monitors information technology risk by performing independent risk assessments.
- Communicates and recommends security and business continuity controls for business units.
- Expert at reviewing and analyzing vendor contracts for compliance with banking security standards, business continuity and disaster recovery requirements with recommendations for appropriate verbiage in order to comply with regulations.
- Advanced skill at developing overall security awareness programs strategy with buy-in by key management business stakeholders.
- Excellent presentation skills using PowerPoint as well as Excel
TECHNICAL SKILLS:
- Security risk gap analysis
- Risk control implementation malware mitigation
- Incident Handling Processes vulnerability scanning strategy and implementation
- Risk remediation strategies
- Security Infrastructure operations improvements
- Installing and monitoring application agents to provide application data for analyzation (SIEM)
- Governance, Risk and Compliance responsibilities
- Information Technologies
- Palo Alto Network Firewall (Maintaining)
- SSL Certificates / VeriSign Administration
- DDoS Mitigation Playbook vulnerability remediation
- Security vendor management
- Server Hardening for Linux and Windows
- Data Loss Protection Implementation
- Linking Tableau, Logrhythm, Tripwire and various security applications and databases, data applications to Splunk
- Cloud security implementation
PROFESSIONAL EXPERIENCE:
Confidential
Senior Cyber Security Consultant
- Led a team of three associates for governance, r isk and compliance with discovery of departmental identification of issues , interviews with client to gain insight in risks and control implementation for regulatory ( HIPAA ) based remediation which achieved 100% compliance with HIP A A auditors
- Day-to-day security strategizing security upgrades and deployments based on business operations in order to stay 100% compliance with TLS, operating system and SLAs for clients
- Managed systems with responsibilities for network URL blocks and whitelist maintenance in order to stop and mitigate attacking malware
- Ensure d and wrote policy documentation and enhanced procedures for vulnerability controls and remediation to reduce risk and increase business security and decrease risk tolerance level to 31% from 43% based on a risk assessment comparison.
- Utilized and managed security tools to help secure the environment (TripWire, McAfee, LogRhythm and QualysGuard ) for a layered security strategy approach to reduce risk threat levels
- Researched, identified and presented security technologies to business leaders and management peers at client sites in order to gain budget for yearly requirements as well as get buy in for security awareness for the business goals and steering committee approval to increase security awareness throughout many clients organizations.
- Managed 3rd party security vendor assessments to ensure defense in depth and validation of security requirements for clients to stay 100% compliant for the HIPA A regulation with CIS and NIST security frameworks
- Negotiated and reduced security vendor services saving PwC $100,000 over the course of a three year contract while updating SLA agreements for faster turn around time on all critical and major Service desk tickets which reduced risk by 20% and reduced ticket volumes by 15%.
Confidential
Cyber Security Consultant
- Managed security operations and strategy processes responsibilities that includ ed Palo Alto Network firewall administration with identified URL blocks, whitelist and blacklist management in order to secure the perimeter
- Met with board members and steering committees to present securi ty strategy in order to get buy in to proceed with security projects which included, vulnerability management, virus/malware tools for email, SIEM log tool implementation, configuration management, printer upgrades due to vulnerabilities, network VLAN segmentations and MSSP network monitoring for critical systems an applications that are web based to reduce threats and risk by 20%
- Managed a team of four personnel to assist with vulnerability remediation, continuous vulnerability scanning strategies for critical systems and reporting functionality of our critical assets to ensure 100% compliance with HIPPA and CIS standards and risk levels totaling 40%
Confidential, San Bruno, California
Information Security Engineer
- Assisted management with security policies and procedures with GRC compliance governance using Archer platform tool in order to align with business goals and stay 100% in line with legal and security compliance modeling using Archer for tracking
- Ensured and wrote documentation with enhanced procedures for Malware handling, DDoS playbook creation, Verisign SSL certificates deployment strategies, LDAP / SUDO identity access levels for developers to restrict access and achieve 100% access level administration
- Manage SSL certificate process using VeriSign administration
- Analyze Akamai KONA/WAF Security Monitoring Alerts.
Confidential, San Bruno, California
Senior Security/ Network Operations Engineer
- DDoS handling procedures and Tier 1 escalation of security events.
- Collaborated with all application teams to ensure security of website is scrutinized and implementing timely security tools and products to assist with this task.
- Managed a team of 6 as a senior SOC Analyst Provided added value to the business experience by making the website secure, expeditious, reliable, content-rich, and easy to navigate with up-to-date promotions.
- Mastered communication and collaborative tools including SharePoint, JIRA, and Confluence-based platforms to meet high level management requirements and exceed customer communication standards.
- Expert at release process improvements as well as pushing code to the site with an efficient and cloud based process.
Confidential, Dallas, Texas
Network Analyst III
- Installed, supported, and maintained new server hardware and software infrastructure.
- Blocked malicious IP addresses; installed firewall for telecom network to increase security.
- Worked closely with other departments/organizations and collaborated with other IT staff.
Confidential
Project Manager
- Supervised and coordinated projects and activities for a team engaged in upgrading the data center environment.
- Restructured and functioned as primary lead for instituting a plan of action to identify and reallocate over five hundred data center servers and telecommunications circuits.
- Recipient of Star Performer Award for strategizing, planning and successfully moving three hundred data and telecommunications circuits over a two days with 100% uptime.
