Information Security Analyst Resume
3.00/5 (Submit Your Rating)
Upper Marlboro, MD
SUMMARY:
- Dynamic, detail - oriented IT Security Analyst, highly regarded for demonstrated experience developing complex technical solutions for industries. High expertise in directing risk management, implementing and enhancing key information security objectives and control frameworks to maximize productivity. Skilled in providing effective security analysis and resolving technical issues quickly. Outstanding presentation and communication skills, understanding business requirements to cross-collaborate and increase profits.
TECHNICAL SKILLS:
Security Tools: NMAP, Nessus, Splunk, SSH; SSL Digital Certificates; Palo Alto, Wireshark
Systems: Windows (all), VMware, and Linux
Networking: LANs, WANs, VPNs, Routers, Firewalls, TCP/IP, Symantec Encryption
Ticketing: Remedy
PROFESSIONAL EXPERIENCE:
Confidential, UPPER MARLBORO, MD
Information Security Analyst
- Working with developers, system/network administrators, and other associates to ensure secure design, development, and implementation of applications and networks
- Performing network traffic analysis using raw packet data, network flow, Intrusion Detection Systems (IDS), and custom sensor output from communication networks
- Assisting the Cyber Security Manager with the development of the IA related Procedures.
- Tracking performance metrics and providing timely updates to SOC management
- Developing, improving and help implementing best practices for risk reduction across a broad range of enterprise applications, systems, networks and interfaces
- Assisting with the development of processes and procedures to improve incident response times, analysis of incidents, and overall SOC functions
- Working with clients to implement system security measures, assists with computer security plans and documentation and provides technical guidance and training
- Investigating on an emerging threat, updating emerging threats, and detection capabilities.
- Analyzing most prevalent vulnerabilities, threats, attack methods, and infection vectors.
- Assisting with New SOC hire training on networking fundamentals, including a detail understanding of TCP/IP and other core Internet protocols.
- Working with well-known security tools such as NMAP, Nessus, Wireshark etc.
- Responding to network and host-based security events, and participating in detecting, investigating, and resolving security events.
- Monitoring Security Information and Event Management (SIEM); Intrusion Detection System (IDS); Network Monitoring and Response Services; Email and Web activities.
- Analyzing AV Logs, Content Filtering and Remote access logins.
- Managing global threat landscape by tracking changes in directing Manage services.
- Monitoring computer data network system, included LAN and WAN, firewall and anti-spam data security infrastructure.
- Investigating incidences of data access violations and data corruption or loss and reported findings to supervisor for direction or resolution
- Identifying user behavior of potential malicious or counter intelligence related activity.
Environment: SIEM, IDS, Splunk - Remedy, NMAP, Gigabit, 802.11 a/b/g/ac Wireless
Confidential, MD
Systems Administrator / Compliance
- Installed, configured, and maintained servers & systems including hardware and software
- Maintained and troubleshot local user accounts, email services, client network connectivity problems, system failures, and account problems.
- Led team to resolving client requests, reduced problem resolution.
- Led Disaster Recovery Team, tore down and setup systems in a company Warm site.
- Redesigned IT Service Center by combining all known problem resolutions to reduce the technicians time to fix issues.
- Developed HIPAA compliance reports documenting auditing finding and corrective actions. These reports were submitted to the ISSO.
- Involved in the security awareness and training of staff on HIPAA requirements as it related to information technology.
- Conducted Certification and Accreditation (C&A) on general support system and major application using the six steps of the Risk Management Framework (RMF) from NIST SP in order to meet the necessary Federal Information Security Management Act (FISMA).
- Audited user accounts and distribution and security groups and deleted obsolete groups.
- Coordinated and provided emergency response to circuit outages using SDN.
- Examined and evaluated computer software and hardware to uncover access attempts.
- Configured, patched and upgraded physical and virtual servers (rack mounts/blades, and VMs)
- Directed the implementation and performance tuning of Server 2012 environment for client’s global operations.
Environment: Servers, Workstations, Remedy, Switches, FWs, VPN, DHCP, SNMP and TCP/IP
