Soc Security Analyst Resume
Reston, VA
SUMMARY:
To secure a position that maximizes over 20 years of IT experience in information and network security, telecommunications and system administration.
TECHNICAL PROFICIENCIES:
Hardware: ArcSight NSM/ESM, Damballa, FireEye, Palo Alto, Niksun, Netscreen Security Manager (NSM), Juniper Intrusion Detection and Prevention Systems (IDPS) 600f, 8200, Cisco PIX firewalls, Nokia IP290/390, Cisco 2500, 3640, Cisco ASA Ethernet, Sun Sparc 5/20, Dell & Hewlett - Packard laptop/desktop PC
Operating Systems and Protocols: Unix Sun Solaris 9, Red Hat Linux, TCP/IP, UDP, Cisco IOS, Junos, Windows 95, 98, XP, Windows 7, Routing Information Protocol (RIP), Border Gateway Protocol (BGP), PPP, SMTP, Nagios monitoring, Solarwinds/ORION, VPN, ISDN, RADIUS/AAA, TI, T3, OC3, OC12
Software: Junos OS, Checkpoint NG/NGX, Nessus/Tenable, Remedy, McAfee EPO, Microsoft Office Suite
PROFESSIONAL EXPERIENCE:
Confidential, Reston, VA
SOC Security Analyst
Responsibilities:
- Monitor FDIC Network for malware, viruses, and other related malicious activity
- Recognize vulnerabilities and publicly known attack patterns and signatures
- Responsible for collection, analysis, proactive monitoring and eradication of identified threats
- Write and maintain Standard Operating Procedures for the Security Operation Center
- Conduct research on emerging security threats and vulnerabilities
- Develop threat trend analysis reports and metrics, including correlation and trending of FDIC's cyber incident activity
- Maintains situational awareness reports for advanced threats such as Advanced Persistent Threat (APT) and Focused Operations (FO) incidents
Confidential, Rockville, MD
Security Specialist
Responsibilities:
- Security Lead for the Intrusion Detection and Prevention Systems (IDPS) project
- Monitor Intrusion Detection and Prevention Systems for alerts and omitting false positives and escalation of attacks
- Perform weekly monitoring and status checks of the Juniper IDPS to include by- weekly signature updates and tuning
- Develop selected Standard Operating Procedures (SOP) and policies for IDPS systems
- Ensure that IDPS systems are in compliance with National Institute of Standards Technology (NIST) Publications 800-94 and 800-61 series guidelines
- Analyze information security systems and applications and recommend and develop security measures to protect information against unauthorized modification or loss
- Prepare IT security documentation for continuity of operations plans for the IDPS platform, including procedures for risk assessment, incident response, disaster recovery and oversee the continuous monitoring process
- Responsible for tracking POA&M's and ensuring completion with artifacts for documentation
Confidential, Arlington, VA
Internet Security Engineer
Responsibilities:
- Create and manage over 800 accounts for customer firewalls
- Configure Checkpoint hardware and software to ensure customers' proper configuration
- Monitor ArcSight for network intrusion attempts, including denial of service attacks, port scans and buffer overflows
- Monitor security websites, such as SANS Storm Center and Spamhaus to keep abreast of security threats and trends
- Review firewall logs for anomalies
- Monitor Netcool for network alarms and outages and work proactively to resolve any network issues
- Ensure all SLA's and procedures for customer outages are met in a timely manner
Confidential, Fairfax, VA
Server Operations/Internet Operations Engineer
Responsibilities:
- Remote monitoring and troubleshooting of over 900 production servers deployed world-wide including mail, news, DNS, ftp and radius servers
- Installed system upgrades and security patches for Sun and Microsoft systems
- Performed Unix and Microsoft operating system installs on all internal workstations
- Setup and maintained servers, LAN/WAN hub equipment racks
- Implemented Internet proxy/firewall policies and solutions for intrusion detection
- Installed and maintained current Anti-virus software on personal computers
Confidential, Lexington Park, MD
LAN Administrator/Lead Operator
Responsibilities:
- Served as primary network support, maintained PC equipment and peripherals
- Installed Ethernet backbone cabling, setup PC/LANs, software installs
- Diagnosed hardware and software problems, repair and replacement of defective hardware
- Supervised technicians in the daily operations of network center
- Maintained security of classified Department of Defense network, both physical and operational
- Responsible for primary disaster recovery and tape backup and restore of essential mission critical information and classified documentation and equipment
Confidential, La Plata, MD
Satellite Operations Technician
Responsibilities:
- Monitored satellite data telemetry on secure classified network
- Commanded spacecraft and performed data analysis of secure data
- Coordinated pre and post ground equipment analysis to ensure information accuracy
- Maintained security of archived mission critical classified data
- Performed weekly mainframe critical system tape backups
- Served as project management lead on numerous Total Quality Improvement groups