It Security & Risk Analyst Resume
5.00/5 (Submit Your Rating)
Houston, TX
SUMMARY:
- A resourceful and dynamic professional wif demonstrated success in risk assessment and management, vulnerability assessment, Risk Management Framework (RMF), ISO, security control implementation
- POA&M development and management, monitoring of security controls, identification & Authentication control, contingency control, Audit & Accountability controls, Access controls, system communication & Protection control and teh Categorization of information systems.
- me possess strong noledge of NIST (Risk management guide), NIST Vol 1 & 2, (Categorization of information systems), NIST, FIPS 199 (Standard for security categorization), and NIST (Selection of Security and Privacy controls).
- Predictive Analytics* Cybersecurity *Web Application Security *Cloud security Management *Data Management *System Vulnerability Analysis *Cryptography *Data and information security *Data Analytics *Understanding of RMF steps (Categorize Information System, Select Security Controls, Implement Security Controls, Assess Security Controls, Authorize Information System, Monitor Security Controls) *NIST
PROFESSIONAL EXPERIENCE:
Confidential, Houston TX
IT Security & Risk Analyst
Responsibilities:
- Categorize information system (HMS) to protect security objectives.
- Maintains and updates security documentation including diagrams, security standards, and disaster recovery manuals (contingent control).
- Participates in system Categorization using NIST (NIST Special Publication Volume II Revision 1 Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories) as guidelines and FIPS (Federal Information Processing Standard )199 as standard.
- Participates in selection of security controls to mitigate against risk using NIST rev 4.
- Monitors implemented security controls and POA&M.
- Participates in SSP development and ensures dat other artifacts are ready for external auditors for assessment purposes.
- Performs vulnerability assessment of information System utilizing Nessus scanner to detect potential risk in order to ensure adequate assessment and evaluation of such risks.
- Provides expertise, guidance, recommendations, and documented security configurations for implementation of security tools and processes.
- Interface wif groups and individuals to resolve security issues related to implementation of network, systems, and applications security.
Confidential, Houston TX
IT Security & Risk Analyst
Responsibilities:
- Categorized information system (HMS) to protect security objectives in Microsoft Azure, Windows application and Suites.
- Maintained and update security documentation including diagrams, security standards, and disaster recovery manuals (contingent control).
- Provided expertise, guidance, recommendations, and documented security configurations for implementation of security tools and processes.
- Used vulnerability analysis of various products and applications and provide professionally written reports including deep technical analysis and high - level non-technical overview of teh system.
- Interfaced wif groups and individuals to resolve security issues related to implementation of network, systems and applications security.
- Assisted in investigating, documentation, and resolution of identified security weaknesses, and recommend documented solutions for improvement.
- Maintained necessary documentation to support security strategy by outlining teh requirements and benefits of specific security tools and/or solutions.
Confidential, Houston TX
IT Security & Risk Analyst
Responsibilities:
- Efficiently managed multiple simultaneous tasks across new projects and existing systems, including management of on-call duties.
- Provided up-to-date reports on project and task progress, and centrally track, in near real-time, incoming and existing problems.
- Used vulnerability analysis of various products and applications and provide professionally written reports including deep technical analysis and high-level non-technical overview of teh system.
- Assisted in investigating, documentation, and resolution of identified security weaknesses, and recommended documented solutions for improvement.
- Participated in ST&E development using NIST A as guide.
- Conducted risk assessment and collaborated wif clients to provided recommendations regarding critical infrastructure, network security operations and continuous monitoring process.
- Participated in documenting Security Assessment Report (SAR) and preparing security authorization package (SAR, SSP, POA&M) in preparation for Authority To Operate (ATO) by teh Authorization officer.
- Evaluated threats and vulnerabilities based on tenable reports and implemented Risk Management Framework (RMF) in accordance to NIST .
Confidential, Houston TX
Security and Data Analyst
Responsibilities:
- Administered company information security testing and protection plans.
- Oversee hardware infrastructure and keep updates wif latest technology.
- Ensured software is patched and able to protect from threats.
- Made recommendations for mitigating identified risks.
- Managed deployment of Service Pack 1 for Windows 7 to all physical and poor performance and degradation.
- Ensured dat appropriate steps are put into consideration for teh implementation of security requirements for teh information systems through its life cycle from teh system initiation phase to teh disposal phase.
- Conducted security control assessments to assess teh adequacy of management, operational privacy and technical security controls implanted utilizing NIST A
- Participated in ensuring dat SSP document and other artifacts are ready for external auditors for assessment purposes.
Confidential, Houston TX
IT Security Analyst
Responsibilities:
- Identified and evaluated potential threats and vulnerabilities.
- Monitored live systems to discover real-time threats.
- Demonstrated effectiveness of security controls.
- Developed custom PAM authentication module for single sign-on users from Solaris to Microsoft.
- Wrote security portions of teh IPP (Internet Printing Protocol) standard of teh IETF. (RFC 2910).
- Conducted security audit of Xerox web applications, identified several vulnerabilities and recommended corrections.
- Monitored thesecurityof critical systems (e.g., e-mail servers, database servers, web servers, etc) and changes made to highly sensitive computersecuritycontrols to ensure appropriate system administrative actions, investigated and reported on noted irregularities.
- Investigated potential or actualsecurityviolations or incidents in an effort to identify issues and areas dat require newsecuritymeasures or policy changes.
Confidential, Houston TX
Analyst
Responsibilities:
- Provided application support of Drilling applications such as Well Cat, Well Plan, Drill Bench, Compass, Well Scan, and Stress Check.
- Administered teh configuration and testing of Drilling applications.
- Conducted Application Testing and Quality Control.
- Audited and migrated 4500+ wells using Excel, Petra, SMT, ILX, OpenSpirit and OpenWorks
- Advised teh technical team on geological related issues.
- Took a high-level inventory of both companies operated and operated wells as well as seismic data.
- Ensured teh standard compliance of company policy.
- Conducted network vulnerability assessments using tools to evaluate attack vectors, identify system vulnerabilities and develop remediation plans and security procedures.
- Ensured organizational compliance wif CFCU informationsecurityprograms.
- Managed teh SIEM infrastructure.
- Evaluated threats and vulnerabilities based on tenable reports and implemented Risk Management Framework (RMF) in accordance to NIST .
Confidential, Houston, TX
AD,Server & ApplicationEngineer
Responsibilities:
- Performed cross platform audits of Active Directory (AD) objects and user permissions.
- Managed User Accounts on Windows NT and UNIX Platform (Creation, Deletion, Permissions, and VPN Access).
- Developed organizational units in Active Directory (AD) and managed user security wif group policies.
- Created and maintained email addresses and distribution lists in MS Exchange.
- Implemented various solutions for WAN, LAN, Intranets and extranet dat ranges from design, installation, configuration, and implementation.
Confidential, Fort Worth, TX
ApplicationEngineer
Responsibilities:
- Implemented and ensured standardization, compliance and enforcement of group security policies.
- Administered 33 Active Directory (AD) domains and related services supporting 145K users and 97K clients.
Confidential, Houston, TX
Server and Network Analyst
Responsibilities:
- Analyzed system performance and proffered improvement plans.
- Implemented various architectural designs of complex web application and solution.
- Developed technical specifications for system enhancements.
