Lead Associate Resume
SUMMARY
- I offer twenty plus years of experience in teh Information Security field.
- I has worked in numerous InfoSec capacities; from IP Security Analyst to IA Security Engineer; Forensic Investigator to Manager of a Security Operations Center.
- I has accredited systems under teh both teh DIACAP and RMF processes.
- I am also familiar with teh DCID 6/3 and ICD 503 processes.
- I has held my CISSP certification since March 2002.
- Most importantly, I offer integrity and adaptability.
TECHNICAL SKILLS
DIACAP, RMF, JSIG, DCID 6/3, ICD 503, SCAP, MBSA, NIST 800 - 53, Windows, Linux, VMware, Wireless, Cisco PIX/VPN, Harris STAT Scanner, eEye Retina, Nmap, McAfee ePolicy Orchestrator, NetDetector, BlueCoat, Proxy Firewalls, Checkpoint, Snort, Tripwire, EnCase, LogiCube, PKI, RSA-SecurID, Websense
PROFESSIONAL EXPERIENCE
LEAD ASSOCIATE, CORPORATE INFORMATION SYSTEM SECURITY MGR
Confidential
Responsibilities:
- Support Special Access Program Facility (SAPF) accreditation under Risk Management Framework (RMF) in accordance with (IAW) NIST 800-53 Rev4 & JSIG
- Conduct weekly security audits of information systems IAW NISPOM Certification and Accreditation (C&A) and RMF requirements
- Chair a firm-wide Working Group for all ISSMs/ISSOs and appointed ISSMs/ISSOs as a forum to share industry standards, best practices, lessons learned, and help direct firm policy
- Perform Internal Process Reviews of other Booz Allen cleared facilities across teh US to assess their security program
- Work with teh Booz Allen InfoSec team in drafting firm policy and procedures
- Perform OS and Anti-Virus updates on information systems IAW C&A requirements
- Perform security hardening of windows and linux based systems
- Served as an A/CSSO for two years
CONTRACTOR, IA SECURITY ENGINEER
Confidential
Responsibilities:
- Assisted with STIG compliance evaluations and Security Readiness Review (SRRs)
- Researched vulnerability remediation options and develop risk mitigation strategies
- Worked with system developers to address assessment findings and creating POAMs
- Assisted in development of DIACAP documentation and system test plans
- Implemented Army and local facility secure computing policies and procedures
CONTRACTOR, IA SECURITY OFFICER
Confidential
Responsibilities:
- Administered role-based (ie. SysAdmn, IASO, IAO, etc) access controls within a Solaris and Redhat environment
- Responsible for reviewing Tripwire audit and Oracle log data for events
- Worked with teh IAO to audit teh configuration and integrity of teh system
- Reviewed and implemented system configurations changes to address POA&M findings
CONTRACTOR, WIRELESS SECURITY
Confidential
Responsibilities:
- Maintained a wireless compliance program with customer instructions
- Maintained wireless scanning hardware and software (Kismet, Wireshark, Yellowjacket, etc.)
- Provided professional response in tense situations where security violations are found
- Maintained Linux and Windows Operating Systems used in wireless scanning
CONTRACTOR, IA SECURITY ENGINEER
Confidential
Responsibilities:
- Audited network assets for DISA Security Technical Implementation Guides (STIGs) compliance
- Performed workstation/server hardening based on DISA STIGs
- Analyzed network traffic for events
- Managed Anti-Virus solution (deployment, definition updates, reporting, etc.)
- Managed Cisco PIX firewall and VPN solutions
- Managed BlueCoat Proxy and Web Filter solution
CONTRACTOR, IA SECURITY ENGINEER
Confidential
Responsibilities:
- Audited network assets for DISA Security Technical Implementation Guides (STIGs) compliance
- Performed workstation/server hardening based on DISA STIGs
- Analyzed network traffic for events
- Managed Anti-Virus solution (deployment, definition updates, reporting, etc.)
- Managed Cisco PIX firewall and VPN solution
- Managed BlueCoat Proxy and Web Filter solution
SECURITY ENGINEER
Confidential
Responsibilities:
- Assessed Enterprise firewall change requests were inline with Confidential Security Policy
- Provided security consulting for customers as to how to better protect their assets
- Supported security solution implementations and teh overall solution integration
- Provided security recommendations regarding network design to external customers
- Ran lead on autantication services (SecurID, PKI Registration Authority, etc.)
- Served as a single point of contact for customers on Managed Security issues until resolution
SR IP SECURITY ANALYST
Confidential
Responsibilities:
- Traveled to customer sites to implement Raptor and Checkpoint firewalls
- Diagnosed customer firewall issues as well as other networking related issues
- Conducted firewall log analysis
- Developed/facilitated network security training sessions