Information Assurance Analyst Resume
3.00/5 (Submit Your Rating)
SUMMARY
- Accomplished with a 7 - year professional track record of successfully assessing information security risks and coordinating remediation efforts.
- I’m looking to apply my skills and expertise to help achieve Enterprise-wide information risk goals and objectives.
- Proven ability to lead and direct, solve problems creatively, and make strategic decisions in fast paced environments.
- Effective team leader, constantly empowering team members through coaching, guidance and motivation.
- Working Knowledge of NIST SP 800-37, Sp 800-60, Sp 800-53 Rev 4, Sp 800-18, Sp 800-30, Sp 800-53A and SP 800-137 during documentation review and update
- Work effectively in a team environment and participate in collaborative initiatives that foster the mutual exchange of knowledge and expertise
- Ability to multi-task, work independently and as part of a team, share workloads, and deal with sudden shifts in project priorities
- Excellent interpersonal skills and verbal/written communication skills
- Have working knowledge of Microsoft Office Suite
PROFESSIONAL EXPERIENCE
Information Assurance Analyst
Confidential
Responsibilities:
- Worked with project manager to ensure incoporation of security activities in all ongoing projects and to identify security impact of new releases.
- Plan and lead POA&M teams to remediate vulnerabilities of various clients, Regional Offices, Insurance centers, Data centers and their Cloud Service providers for low, moderate and high impact systems.
- Lead ATO team to help remediate, validate, prepare and collate Security artifacts for commercial building facilities in order to pass their ATO.
- Lead teams to work onsite with each facility’s technical team and leadership to ensure recommendations are maximized.
- Lead ATO team to develop all ATO documents for new systems from cradle to grave.
- Develop POA&M (Plan of Action & Milestones) document to take corrective actions resulting from ST&E (System Test & Evaluation).
- Prepare and review Authorization to Operate (ATO) packages (i.e. SSP, RA, CMP, ISCP, DRP, IRP and PIA) for over 120 systems and facilities.
- Communicate with peers by sharing (department) “best practices" and providing accurate, thorough documentation on “best practices" or other documentation tools.
- Responsible for monitoring compliance with information security policies by coaching others within the organization on acceptable uses of information technology and how to protect organization systems.
- Participate in the FIPS 199 process in which security categorization takes place, and selecting the technical, operational and managerial controls using NIST SP 800-60 guidelines.
IT Security & FISMA Compliance Analyst
Confidential - Ashburn, VA
Responsibilities:
- Conduct the IT risk assessment and documented key controls
- Develop test plans; testing procedures and document test results and exceptions.
- Conduct walkthroughs, formulate test plans, document gaps, test results, and exceptions; and develop remediation plans for each area of testing.
- Perform IT operating effectiveness test in the areas of security and operations.
- Create from scratch and document change management Process, and email authentication. Develop the audit plan and performed the General Computer Controls testing of Information Security, Business Continuity Planning
- Identify gaps, develop remediation plans, and train and advise IT managers on the SOX/FISMA compliance activities and controls.
- Help business unit elaborate and identify internal control process
- Manually reviewed logs and provided documentation guidelines to process owners and Management
- Develop, maintain and communicate a consolidation risk management activities and deliverables calendar
- Develop the audit plan and performed the General Computer Controls testing of Information Security
Network System Analyst
Confidential - Chantilly VA
Responsibilities:
- Diagnose hardware and software problems, and replace defective components.
- Perform data backups and disaster recovery operations.
- Maintain and administer computer networks and related computing environments, including computer hardware, systems software, applications software, and all configurations.
- Plan, coordinate, and implement network security measures in order to protect data, software, and hardware.
- Perform routine network startup and shutdown procedures, and maintain control records.
- Design, configure, and test computer hardware, networking software and operating system software.
- Recommend changes to improve systems and network configurations, and determine hardware or software requirements related to such changes.
- Monitor network performance in order to determine whether adjustments need to be made, and to determine where changes will need to be made in the future.
- Analyze equipment performance records in order to determine the need for repair or replacement.
- Maintain logs related to network functions, as well as maintenance and repair records.
