Information Assurance Resume
3.00/5 (Submit Your Rating)
QUALIFICATION SUMMARY
- Over 15 years of experience in many areas of technology including: cybersecurity, software development, project management, team leadership, quality control and infrastructure with a focus on Security. Experienced in enterprise, startup, waterfall, agile and devops environments. Fluent in both English and French.
PROFESSIONAL EXPERIENCE
Information Assurance
Confidential
Responsibilities:
- Design, implement, maintain and operate secure systems, policies and procedures
- Solid understanding of risk management and controls with a preference towards preventive technical controls
- Experience working with frameworks such as the Microsoft SDL, BSIMM and ISO 27001
- Aligning security requirements with regulations such as SOX, GLBA, FTC Standards, PCI, IRC 7216, etc.
- Perform penetration testing manually and with automated tools such as Burp Suite, Netsparker, Kali Linux, Nessus, Nexpose, metasploit, ettercap, aircrack - ng and many others tools
- Implementing SSO w/ Federation in a claims based model (WS-Trust, WS-Federation, SAML-P, SWT)
- Perform static analysis using FxCOP, Sonar, splint and other tools.
- Perform threat modeling using the Microsoft SDL threat modeling tool
- Perform code reviews for common vulnerabilities (OWASP top 10, SANS top 25)
- Solid experience in log management and monitoring solutions (OSSIM SIEM, SecureVUE, Splunk, Logstash, Elasticsearch, Kibana, Syslog, WMI, SNMP)
- Perform Fuzz Testing using custom scripts and tools
- Promote and implement secure software development processes
- Implement secure data exchanges, storage, authentication, integrity validation and non-repudiation using symmetric and asymmetric encryption as well as hashing algorithms
- Configure, maintain and monitor intrusion detection systems and web application firewalls (Snort, OSSEC, Tripwire, fail2ban, mod security, PHPIDS, IBM Proventia, etc)
- Configure and maintain Cisco routers and firewalls (Routers, Catalyst Switches and ASA)
- Experience with hardening operating systems, services and devices (CIS Benchmarks).
- Experience with disaster recovery planning
- Malware/Botnet identification and removal
- Experience managing enterprise endpoint security products (Symantec Endpoint Security)
- Experienced managing the implementation of backup systems (CDP, Dedup, Disk to Disk,Tape based and offsite storage)
- Experienced implementing L2TP, PPTP and SSL based VPN (Cisco, Windows, FreeSwan, OpenVPN)
- Experienced working with file and socket level Encryption (PGP, GnuPG, Windows PKI) and SSL (OpenSSL, stunnel)
Software Development
Confidential
Responsibilities:
- Strong experience developing cloud applications using the Microsoft Azure platform. Exposure to other platform such as Amazon AWS, Google AppEngine, Softlayer and others
- Extensive experience in the development of enterprise web, client, server and SOA based applications using the C#, C++ and C languages
- Intermediate experience with other languages such as Python and Java
- Expert knowledge of Microsoft Windows, Linux, Solaris, IRIX, MP-RAS and other platforms.
- Strong knowledge of web development technologies (HTML, HTTP, ASP.NET Webforms/MVC, PHP, JavaScript, JQuery, JSON, REST and Web Services (SOAP/WSDL and WCF))
- Fluent in XML based technologies using XML Schema, XPath and XSLT
- Database background with Microsoft SQL Server, MySQL, Informix and Oracle using ADO.NET, ODBC, Embedded SQL and other similar client access technologies
- Architect and implement from the smallest Korn or PowerShell scripts up to large, high volume, cross-platform, scalable, secure and reliable cloud based architectures
- Development of business intelligence solutions using Microsoft Reporting Services
- Skilled in troubleshooting, debugging, profiling and optimization techniques
- Design and Develop systems following best practices, using object oriented design patterns as well as enterprise design patterns
- Test engineering experience conducting load testing, stress testing, scalability testing, code and database profiling, unit testing, code coverage analysis and test automation.
- Experienced using threads (managing concurrency issues), regular expressions and network socket programming
- Competent with build technologies such as make, MSBuild, Bamboo and Team Foundation Server.
- Experienced using source code control technologies such as TFS, SourceSafe, Subversion, Git, Mercurial, etc.
- Working with ORM technologies such as LINQ to SQL, Entity Framework and RedBeans
Project Management
Confidential
Responsibilities:
- Responsible for leading Confidential's application security program based on Microsoft SDL, BSIMM and OWASP guidelines.
- Head of startup technology department; responsible for software development, IT and security teams’ activities and budgets and a team of 10-15 people.
- Produce and deliver project charters, project plans, work breakdown structure (WBS) documents, technical designs and presentations
- Experience managing agile projects