Security Information Analyst Resume
4.00/5 (Submit Your Rating)
PROFESSIONAL SUMMARY
- Cybersecurity Information Analyst with 11+ years’ experience in Risk Management Framework (RMF). Skilled in making critical decisions TEMPeffectively; meets challenges rationally; ambitious; and works well under pressure.
- An exceptional team lead who is greatly experienced in risk and operational management with the ability to instantly identify and resolve security threats using the NIST guidelines.
TECHNICAL SKILLS
- Risk Management Framework (RMF)
- NIST 800 - Series
- FISMA FedRAMP FIPS
- System Security Plan (SSP)
- System Assessment Plan (SAP)
- System Assessment Report (SAR)
- Plan of Action and Milestones (POA&M)
- AWS Tenable Nessus
- SNORT
PROFESSIONAL EXPERIENCE
Security Information Analyst
Confidential
Responsibilities:
- Performs Security Control Assessments on assigned systems using the Risk Management Framework guidelines (RMF).
- Reviews technical security controls and provides implementation responses to meet requirements.
- Conducts interviews with key client stakeholders to evaluate current information security practices.
- Reviews provided and/or requested artifacts and Plan of Action & Milestones (POA&M) to determine if the required security controls are implemented correctly.
- Review and convert System Security Plan (SSP) using updated templates for current assessment.
- Utilizes NIST 800-53 and 800-53a, to review implemented controls and enter information into the Requirements Traceability Matrix (RTM) and findings into the Security Assessment Report (SAR).
- Collaborates with other team members and system owners/technical managers to schedule and conduct kick off meetings and interviews to discuss findings.
- Provides weekly status reports to Information Systems Security Officer (ISSO).
Information Security Analyst
Confidential
Responsibilities:
- Performed Step 4 (Security Control Assessments) using the Risk Management Framework (RMF).
- Created comprehensive recommendations for compliance.
- Reviewed requested Artifacts and Plan of Action & Milestones (POA&Ms) for proper security controls implementation.
- Reviewed vulnerability reports from engineers.
- Coordinated A&A schedule with the Information Systems Security Officer (ISSO).
- Utilized NIST 800-53 (rev. 4) and 800-53a to document and transfer findings into the Requirements Traceability Matrix (RTM) and Security Assessment Report (SAR).
- Collaborated with other team members and system owners/technical managers to schedule and conduct kick off meetings and interviews to discuss findings.
- Provided weekly status reports.
Information Assurance Specialist
Confidential
Responsibilities:
- Analyzed and updated System Security Plan (SSP), Risk Assessment (RA), Privacy Impact Assessment (PIA), System Security test and Evaluation (ST&E) and the Plan of Actions and Milestones (POA&M).
- Designated systems and categorize its C.me.A. using FIPS 199 and NIST SP 800-60.
- Conducted interviews with selected personnel, documented and evaluated business processes, and executed audit test programs to determine the adequacy and TEMPeffectiveness of internal controls and compliance with regulations.
- Conducted cloud system assessments, primarily with AWS (Amazon Web Services) by utilizing FedRAMP and NIST guidelines.
- Supported the Security Assessment and Authorization process of the Client’s systems.
Security Specialist/Entry Level Information Security Analyst
Confidential
Responsibilities:
- Worked in a SOC environment and implemented NIST in assessing vulnerabilities identified in a system.
- Monitored networks by utilizing a multitude of tools including SNORT.
- Provided trend analysis and data reports associated with tracking case workload and cycle time associated with all work performed.
- Reviewed requests for security clearances, evaluating the sensitivity classification of the position by applying need-to-know principles and pertinent security guidelines.
- Conducted facility clearance surveys for contractors entering the NISP.
- Conducted recurring security vulnerability assessments, physical security inspections of contractor plants and facilities performing work for the government involving the storage and/or production of sensitive arms, ammunition and explosives.
- Conducted security vulnerability assessments of cleared industrial facilities performing on classified contracts for the U.S.
- Provided security oversight and assistance to assigned contractor facilities for information systems (IS) processing classified information.
