Cyber Security Assessor/analyst Resume
4.00/5 (Submit Your Rating)
Washington, DC
SUMMARY:
- Cyber Security professional with 4 years of experience in Risk Management Framework (RMF), vulnerability management, security control implementation, assessment and authorization, POA&M management, continuous monitoring, Authentication & Access Control, System Monitoring and Regulatory Compliance in accordance with NIST, OMB, FISMA and industry best security standards.
- Outstanding proven experience in security control assessment, risk mitigation, security and privacy management.
- I have a 4years experience using vulnerability scanning tools like Nessus and MBSA, as well as 4years experiences using Trusted Agent Fisma (TAF).
- Excellent multi - tasking skills; experience managing multiple project simultaneously
- Team player; dynamic and professional with the ability to adapt well to changing environments and interact well at all levels Proven ability to lead and direct, solve problems creatively, and make strategic decisions in any given environments
PROFESSIONAL EXPERIENCE:
Cyber Security ASSESSOR/ANALYST
Confidential, Washington DC
- Perform ongoing Assessment and Authorization projects in support of client security systems and ensuring quality control of A&A documents.
- Conduct risk assessments and collaborate with clients to provide recommendations regarding critical infrastructure, network security operations and Continuous Monitoring processes.
- Extensive knowledge in Categorizing Information Systems (using FIPS 199 as a guide)
- Create, update and revise System security Plans, FISMA, Contingency Plans, Incident Reports and Plan of Action & Milestone
- Participate in ST&E Kick-off Meeting and populate the Requirements Traceability Matrix (RTM) per NIST SP A
- Document and finalize security Assessment Report (SAR) and Performing security assessment and continuous monitoring on multi-agency systems in accordance to FISMA security control baselines.
- Determine security controls effectiveness (i.e., controls implemented correctly, operating as intended, and meeting security requirements).
- Evaluate threats and vulnerabilities based on tenable and MBSA reports; use CVSS calculator to determine the severity of vulnerabilities and Implement Risk Management Framework (RMF) in accordance with NIST SP .
- Classification and categorization of information Systems using the RMF processes.
- Provide assessment exit briefings to Information System Security Officer (ISSO) and system stakeholders and also ensuring that all findings are documented as Plan of Action & Milestones within their Trusted Agent FISMA tool and are remediated.
- Generate/analyse excel and pdf reports of web traffic from Sophos UTM manager.
- Generate, review and update System Security Plans (SSP) against NIST and NIST requirements.
