We provide IT Staff Augmentation Services!

Security Information Analyst Resume

4.00/5 (Submit Your Rating)

PROFESSIONAL SUMMARY

  • Cybersecurity Information Analyst with 11+ years’ experience in Risk Management Framework (RMF). Skilled in making critical decisions TEMPeffectively; meets challenges rationally; ambitious; and works well under pressure.
  • An exceptional team lead who is greatly experienced in risk and operational management with the ability to instantly identify and resolve security threats using the NIST guidelines.

TECHNICAL SKILLS

  • Risk Management Framework (RMF)
  • NIST 800 - Series
  • FISMA FedRAMP FIPS
  • System Security Plan (SSP)
  • System Assessment Plan (SAP)
  • System Assessment Report (SAR)
  • Plan of Action and Milestones (POA&M)
  • AWS Tenable Nessus
  • SNORT

PROFESSIONAL EXPERIENCE

Security Information Analyst

Confidential

Responsibilities:

  • Performs Security Control Assessments on assigned systems using the Risk Management Framework guidelines (RMF).
  • Reviews technical security controls and provides implementation responses to meet requirements.
  • Conducts interviews with key client stakeholders to evaluate current information security practices.
  • Reviews provided and/or requested artifacts and Plan of Action & Milestones (POA&M) to determine if the required security controls are implemented correctly.
  • Review and convert System Security Plan (SSP) using updated templates for current assessment.
  • Utilizes NIST 800-53 and 800-53a, to review implemented controls and enter information into the Requirements Traceability Matrix (RTM) and findings into the Security Assessment Report (SAR).
  • Collaborates with other team members and system owners/technical managers to schedule and conduct kick off meetings and interviews to discuss findings.
  • Provides weekly status reports to Information Systems Security Officer (ISSO).

Information Security Analyst

Confidential

Responsibilities:

  • Performed Step 4 (Security Control Assessments) using the Risk Management Framework (RMF).
  • Created comprehensive recommendations for compliance.
  • Reviewed requested Artifacts and Plan of Action & Milestones (POA&Ms) for proper security controls implementation.
  • Reviewed vulnerability reports from engineers.
  • Coordinated A&A schedule with the Information Systems Security Officer (ISSO).
  • Utilized NIST 800-53 (rev. 4) and 800-53a to document and transfer findings into the Requirements Traceability Matrix (RTM) and Security Assessment Report (SAR).
  • Collaborated with other team members and system owners/technical managers to schedule and conduct kick off meetings and interviews to discuss findings.
  • Provided weekly status reports.

Information Assurance Specialist

Confidential

Responsibilities:

  • Analyzed and updated System Security Plan (SSP), Risk Assessment (RA), Privacy Impact Assessment (PIA), System Security test and Evaluation (ST&E) and the Plan of Actions and Milestones (POA&M).
  • Designated systems and categorize its C.me.A. using FIPS 199 and NIST SP 800-60.
  • Conducted interviews with selected personnel, documented and evaluated business processes, and executed audit test programs to determine the adequacy and TEMPeffectiveness of internal controls and compliance with regulations.
  • Conducted cloud system assessments, primarily with AWS (Amazon Web Services) by utilizing FedRAMP and NIST guidelines.
  • Supported the Security Assessment and Authorization process of the Client’s systems.

Security Specialist/Entry Level Information Security Analyst

Confidential

Responsibilities:

  • Worked in a SOC environment and implemented NIST in assessing vulnerabilities identified in a system.
  • Monitored networks by utilizing a multitude of tools including SNORT.
  • Provided trend analysis and data reports associated with tracking case workload and cycle time associated with all work performed.
  • Reviewed requests for security clearances, evaluating the sensitivity classification of the position by applying need-to-know principles and pertinent security guidelines.
  • Conducted facility clearance surveys for contractors entering the NISP.
  • Conducted recurring security vulnerability assessments, physical security inspections of contractor plants and facilities performing work for the government involving the storage and/or production of sensitive arms, ammunition and explosives.
  • Conducted security vulnerability assessments of cleared industrial facilities performing on classified contracts for the U.S.
  • Provided security oversight and assistance to assigned contractor facilities for information systems (IS) processing classified information.

We'd love your feedback!