Information Security Specialist / Information Security Auditor Resume
SUMMARY
- Working to achieve CompTIA Security+ (Sec+ SY501), Cyber Security Analyst (CySA+), Certified Information Security Auditor (CISA) and Certified Information System Security Professional (CISSP) certifications
- 5+ years of information security consultation / project management experience for ABC’s Shark Tank entrepreneurs
- Knowledge of HIPAA; Strong understanding of information security principles
TECHNICAL SKILLS
Proficient in: HTML5, CSS3, JavaScript, C++
Knowledge of: Python, Angular.JS, Node.JS, MySQL, R, Ruby, Ruby on Rails, Swift and PowerShell
Proficient in: Windows (XP, Vista, 7, 8, and 10) and Mac OS X
Knowledge of: Kali Linux; (Primarily basic keyboard shortcuts)
Technology: Vtiger and Salesforce CRM modules; Active Directory; AlienVault SIEM (USM Anywhere)
PROFESSIONAL EXPERIENCE
Confidential
Information Security Specialist / Information Security Auditor
Responsibilities:
- Provide guidance and assistance regarding information security matters such as the interpretation of information security policies and requirements or their applicability to particular situations
- Assist with implementation of counter - measures or mitigating controls, and security systems as threats evolve based on strategic choices made by the organization
Confidential, Lynbrook, NY
Information Security Specialist / Information Security Auditor
Responsibilities:
- Provided guidance and assistance regarding information security matters such as the interpretation of information security policies and requirements or their applicability to particular situations
- Ensured the integrity and protection of the network, systems, and applications by the technical enforcement of organizational security policies though monitoring of AlienVault SIEM
- Managed Active Directory for user authentication services and identity management; includes verification and monitoring of accounts for compliance to policies and include efforts toward a Single Sign On policy for multiple application access
- Participated in the evaluation of firewall and other infrastructure changes and assisted in the assessment of organizational risk
- Performed computer security incident response activities, and prepared incident reports to present to Senior Management
- Assisted with implementation of counter-measures or mitigating controls, and security systems as threats evolve based on strategic choices made by the organization
- Conducted periodic and on-demand system audits and vulnerability assessments, including user accounts, application access, phishing, file system, and external web integrity scans to determine compliance
- Facilitated new Help Desk workflow process to resolve consumer issues; improved level of service and efficiency by 40%
- Created HIPAA compliance, identifying Information Security Best Practices and Preventing Workplace Harassment training for 150 employees
- Partnered with Senior Information Security Auditor at third party firm to help company achieve HITRUST certified status
Confidential, New York, NY
Information Security Analyst / IT Project Manager
Responsibilities:
- Optimized project management guidelines/protocols implemented by Shark Tank brands; tracked projects from implementation to completion
- Developed and laid the groundwork for work related policies at the NYC Department of Mental Health and Hygiene (acceptable use, social media, HIPAA compliance etc.)
- Identified opportunities to reduce risk within the clients’ companies; detected and delegated remediation tasks to IT teams to tackle vulnerabilities; ensured compliance and audit readiness with regards to HIPAA, NIST, and HITRUST frameworks
- Made recommendations for corrective action and documented management decisions regarding acceptance or mitigation of risk scenarios
Cyber Security Consultant
ConfidentialResponsibilities:
- Liaised with various partners and vendors regarding the security maintenance of their systems and applications
- Provided input into all aspects of the third-party risk assessment process including vendor manager communications, report generation, and issue remediation tracking
- Participated in the development and facilitation of security awareness education and training