We provide IT Staff Augmentation Services!

Information Assurance Analyst Resume

3.00/5 (Submit Your Rating)

SUMMARY

  • Accomplished with a 7 - year professional track record of successfully assessing information security risks and coordinating remediation efforts.
  • I’m looking to apply my skills and expertise to help achieve Enterprise-wide information risk goals and objectives.
  • Proven ability to lead and direct, solve problems creatively, and make strategic decisions in fast paced environments.
  • Effective team leader, constantly empowering team members through coaching, guidance and motivation.
  • Working Knowledge of NIST SP 800-37, Sp 800-60, Sp 800-53 Rev 4, Sp 800-18, Sp 800-30, Sp 800-53A and SP 800-137 during documentation review and update
  • Work effectively in a team environment and participate in collaborative initiatives that foster the mutual exchange of knowledge and expertise
  • Ability to multi-task, work independently and as part of a team, share workloads, and deal with sudden shifts in project priorities
  • Excellent interpersonal skills and verbal/written communication skills
  • Have working knowledge of Microsoft Office Suite

PROFESSIONAL EXPERIENCE

Information Assurance Analyst

Confidential

Responsibilities:

  • Worked with project manager to ensure incoporation of security activities in all ongoing projects and to identify security impact of new releases.
  • Plan and lead POA&M teams to remediate vulnerabilities of various clients, Regional Offices, Insurance centers, Data centers and their Cloud Service providers for low, moderate and high impact systems.
  • Lead ATO team to help remediate, validate, prepare and collate Security artifacts for commercial building facilities in order to pass their ATO.
  • Lead teams to work onsite with each facility’s technical team and leadership to ensure recommendations are maximized.
  • Lead ATO team to develop all ATO documents for new systems from cradle to grave.
  • Develop POA&M (Plan of Action & Milestones) document to take corrective actions resulting from ST&E (System Test & Evaluation).
  • Prepare and review Authorization to Operate (ATO) packages (i.e. SSP, RA, CMP, ISCP, DRP, IRP and PIA) for over 120 systems and facilities.
  • Communicate with peers by sharing (department) “best practices" and providing accurate, thorough documentation on “best practices" or other documentation tools.
  • Responsible for monitoring compliance with information security policies by coaching others within the organization on acceptable uses of information technology and how to protect organization systems.
  • Participate in the FIPS 199 process in which security categorization takes place, and selecting the technical, operational and managerial controls using NIST SP 800-60 guidelines.

IT Security & FISMA Compliance Analyst

Confidential - Ashburn, VA

Responsibilities:

  • Conduct the IT risk assessment and documented key controls
  • Develop test plans; testing procedures and document test results and exceptions.
  • Conduct walkthroughs, formulate test plans, document gaps, test results, and exceptions; and develop remediation plans for each area of testing.
  • Perform IT operating effectiveness test in the areas of security and operations.
  • Create from scratch and document change management Process, and email authentication. Develop the audit plan and performed the General Computer Controls testing of Information Security, Business Continuity Planning
  • Identify gaps, develop remediation plans, and train and advise IT managers on the SOX/FISMA compliance activities and controls.
  • Help business unit elaborate and identify internal control process
  • Manually reviewed logs and provided documentation guidelines to process owners and Management
  • Develop, maintain and communicate a consolidation risk management activities and deliverables calendar
  • Develop the audit plan and performed the General Computer Controls testing of Information Security

Network System Analyst

Confidential - Chantilly VA

Responsibilities:

  • Diagnose hardware and software problems, and replace defective components.
  • Perform data backups and disaster recovery operations.
  • Maintain and administer computer networks and related computing environments, including computer hardware, systems software, applications software, and all configurations.
  • Plan, coordinate, and implement network security measures in order to protect data, software, and hardware.
  • Perform routine network startup and shutdown procedures, and maintain control records.
  • Design, configure, and test computer hardware, networking software and operating system software.
  • Recommend changes to improve systems and network configurations, and determine hardware or software requirements related to such changes.
  • Monitor network performance in order to determine whether adjustments need to be made, and to determine where changes will need to be made in the future.
  • Analyze equipment performance records in order to determine the need for repair or replacement.
  • Maintain logs related to network functions, as well as maintenance and repair records.

We'd love your feedback!