Information Security Analyst Resume
3.00/5 (Submit Your Rating)
Woodbridge, VA
SUMMARY:
- Seeking for a Cyber Security /Information assurance position that will utilize my knowledge and experience in Cyber Security processes that ensure the Confidentiality, Integrity, and Availability of Agency’s Information system.
TECHNICAL SKILLS:
NIST SP 800 Series, FIPS Publications, POA&M, FISMA, Risk Management Framework, A&A, SSP, Risk Assessment, IT Security Controls, Microsoft Office Suite, COOP, Contingency Planning, MOU, PII, PIA, Privacy Threshold Analysis, Wire Shark, Vulnerability Management, Information Assurance Vulnerability Management (IAVM).
PROFESSIONAL EXPERIENCE:
Confidential, Woodbridge, VA
Information Security Analyst
Responsibilities:
- Develops and completes security assessment plans based on NIST SP - 80053A
- Periodically communicate control weaknesses to stakeholders via email and meetings
- Prepares risk assessment reports and provides recommendations to the client
- Manages POA&M for accuracy and currency
- Assists with contract and vendor management issues directly related to security requirements and deliverables of projects
- Created or updated the System Security Plan and conducted an Annual Self-Assessment.
- Performs and oversees basic to complex security analysis, standards design, and security gap analysis
- Ensure management, operational and technical controls for securing either sensitive Security Systems or IT Systems are in place and are followed according to federal guidelines (NIST SP 800-53)
- Take appropriate steps to implement information security requirements for IT systems throughout their life cycle; from the requirement definition phase through disposal
- Supporting Systems Test and Evaluation (ST&E) efforts and other support to the IT Security Office
- Developed and implement information assurance standards and procedures.
Confidential, Dumfries, VA
Information Security Analyst
Responsibilities:
- Coordinate effectively to evaluate and develop security programs to improve organization’s information assurance solutions to supports client’s requirements
- Effectively utilized CSAM to carry out assessment, document, manage, and report system security status.
- Provided mitigation and remediation recommendations in support of the system assessment
- Processed and lead mitigation and remediation effort by directly engaging with the system administrator’s.
- Worked with ticketing systems to track CR and security assessment requests. Provide metrics on mitigation activities.
- Analyzed and interpret vulnerability and compliance reports for system administrators to understand and remediate security risks.
- Developed NIS/FISMA documentation for systems and networks undergoing certifications
- Document residual risks by conducting a thorough review of all vulnerabilities, architecture and defense in depth and provide the IA risk analysis and mitigation determinations results for risk exceptions.
- Documented and managed POA&Ms, false positives, and risk exception artifacts worked with team members to identify and address security and compliance issues
- Review vulnerability scans to identify to missing patches for remediation actions.
