We provide IT Staff Augmentation Services!

Systems Security Administrators Resume

2.00/5 (Submit Your Rating)

SUMMARY

  • Certified - Data security analysts/systems security administrators, and Security Operation Center Analyst, result oriented with over 4 years of incident response, cyber threat & analysis, Internet security, network security monitoring & risk mitigation, monitoring data centers, firewalls, IDS/IPS, end users network activities as well InfoSec seeking a Security Operation Center Analyst position.
  • Defining processes for managing network security. Discovering vulnerabilities in information systems.
  • Evaluating and deconstructing malware. Using intrusion prevention systems.
  • Understanding security regulations and standards.
  • Installing firewalls and data encryption programs.
  • Maintaining security records.
  • Monitoring compliance with information security procedures and policies.
  • Performing cyber and technical threat analyses.
  • Providing host-based forensics.
  • Technical ability in data loss prevention.
  • Proven accountable, dependable, and reliable work ethic.
  • Demonstrable knowledge of secure coding practices and teh ability to conduct security assessments and analysis of applications.
  • Strong knowledge of network protocols, network analysis tools, and network architecture.
  • Good experience with Network Operation Center.
  • Experience configuring, implementing, and supporting solutions using Cisco network equipment.
  • Knowledge of IP traffic flow, protocol analysis, capturing and monitoring of live traffic streams.
  • Experience troubleshooting complex problems in a Cisco network environment.
  • Knowledge of LAN and WAN QoS configuration.
  • Good knowledge of OSPF/EIGRP/Spanning Tree protocols.
  • Ability to use Network Sniffers, analyze data to resolve network issues.
  • Ability to analyze network performance data to identify trends and potential problems, and support recommendations to modify and/or upgrade network equipment or services.
  • Broad understanding of all aspects of LAN and WAN operation, load balancing, routing, topology, QoS,
  • Experience implementing and supporting virtual private networks (VPN)
  • Advance configuration knowledge of Cisco switches and routers
  • Knowledge of teh OSI seven layers model, TCP/IP four layers model, how network behaves at different level of teh OSI and TCP/IP model
  • In depth knowledge of networking principles including TCP/IP protocols, IPv4, IPv6 and Subnetting
  • In depth knowledge implementing Cisco Catalyst switches, Cisco Nexus Switches
  • Knowledge of VLAN configuration with VLAN Trunk and VLAN Access mode.
  • Knowledge of static NAT and Dynamic NAT
  • Ability to create and apply ACL’s to meet organizational security policy requirements.

TECHNICAL SKILLS

  • Splunk
  • Wireshack
  • Nmap
  • Kali Linux
  • Trend Micro
  • Fire Eye NX/ PX/ EX
  • Symantec Endpoint Manager
  • McAfee ePO Orchestrator (HBSS)
  • Carbon Black
  • DBProtect,
  • Digital guardian,
  • Cylance

PROFESSIONAL EXPERIENCE

Confidential

Systems Security Administrators

Responsibilities:

  • Tier II Security Operation Center Analyst using Splunk SIEM, Cisco FirePower Threat defense center, Carbon Black endpoint protection and other tools to gathering information and respond quickly and effectively to security events and threats.
  • Support Tier I analysis with deep analysis using various in house tools and authorized OSINT Tools.
  • Performed security event analysis with Splunk
  • Created and run search queries in Splunk SIEM tool to halp with identifying and troubleshooting security issues
  • Tracking suspicious network, application, and user behavior within Tanium report.
  • Used of Carbon Black for threat hunting and incident response
  • Used of Carbon Black phishing automation to protect system against most recent threats
  • Frequently used of Tanium for traffic analysis and containment in case of breach.
  • Provide second level IDS monitoring, analysis and incident response to information security alerts events
  • Performs detailed examination and analysis of Phishing sites;
  • Performs detailed analysis of other fraud types (Vishing, 419 Scams, and Pharming).
  • Conducted Vulnerability Scanning, analysis and remediation management for a large scale enterprise
  • Conduct Vulnerability Assessments of Network and Security devices with Nessus Tenable
  • Participated in teh continuous monitoring of teh system using various tools such as: Nessus Scanner, WebInspect and Wireshark for packet capture.
  • Lead of teh continuous Vulnerability assessment team using Nessus Security Center and IBM Qradar Security Event Management for daily security check
  • Frequently used of Nessus Security Center for vulnerability scanning, web application auditing and credentialed patch analysis and provide appropriate recommendations
  • Provide first level IDS monitoring, analysis and incident response to information security alerts events.
  • Analyze network traffic and IDS alerts to assess, prioritize and differentiate between potential intrusion attempts and false alarms.
  • Compose and send alert notifications.
  • Recommend IDS filters to eliminate false positives.
  • Performs detailed examination and analysis of Phishing sites.
  • Performs detailed analysis of other fraud types (Vishing,419 Scams, Pharming)
  • Analyze a variety of network and host-based security appliance logs (Firewalls, NIDs, HIDS, sys Logs, etc.) to determine teh correct remediation actions and escalation paths for each incident.
  • Respond to audible and visual alarms by taking ownership, creating trouble-tickets, trouble-shooting teh causes, and escalating accordingly.
  • Provide telephone support and respond to support requests from teh consumer call centers, Enterprise customers, Enterprise halp desks, and several internal HNS support teams.
  • Proactively identify issues, creating tickets to ensure dat all details are captured accurately, follow escalation procedures as documented, use teh notification system in order to effectively communicate issues to customer service and upper management, and trouble-shoot teh events in a short time frame.
  • Performed risk assessments to ensure compliance.

Confidential

Information Security Analyst

Responsibilities:

  • Member of teh Incident Response Team in charge of Networking issues, using teh System Operation Center ( SOC ) and Cisco ASA SourceFire defense center to gathering information and respond quickly and effectively to security events and threats
  • Research, analysis, and response for alerts; including log retrieval and documentation. Conduct analysis of network traffic and host activity across a wide array of technologies and platforms.
  • Perform general SIEM monitoring, analysis, content development, and maintenance. Assist in incident response activities such as host triage and retrieval, malware analysis, remote system analysis, end- user interviews, and remediation efforts.
  • Compile detailed investigation and analysis reports for internal SOC consumption and delivery to management.
  • Track threat actors and associated tactics, techniques, and procedures (TTPs) by capturing intelligence on threat actor TTPs and developing countermeasures in response to threat actors. Analyze network traffic, IDS/IPS/DLP events, packet capture, and FW logs. Analyze malicious campaigns and evaluate effectiveness of security technologies.
  • Review alerts generated by detection infrastructure for false positive alerts and modify alerts as needed. Provide forensic analysis of network packet captures, DNS, proxy, Netflow, malware, host-based security and application logs, as well as logs from various types of security sensors.
  • Participated in teh continuous monitoring of teh system using various tools such as: Nessus Scanner, WebInspect and Wireshark for packet capture.
  • Lead of teh continuous Vulnerability assessment team using Nessus Security Center and IBM Qradar Security Event Management for daily security check
  • Examined and evaluated computer software and hardware to uncover access attempts.
  • Assessed incoming threats and developed plans to close loopholes.
  • Performed risk assessments to halp create optimal prevention and management plans.
  • Maintained and tested corporate response plans.
  • Identified and evaluated potential threats and vulnerabilities.
  • Designed training manuals to increase security awareness throughout company.
  • Monitored live systems to discover real-time threats.
  • Demonstrated effectiveness of security controls.

Confidential

Information Security and Software developer

Responsibilities:

  • Development of Personnel Management Software for teh OFON II project with an Oracle Database in Visual Basic (Visual Studio)
  • Successfully installed and configured Oracle 11.1.0.7.
  • Monitored different databases and application servers using Oracle Enterprise Manager (OEM) 10g Grid Control.
  • Perform Backup and Restauration of database and critical project’s files.
  • Checking Databases Backup and Restore validity periodically, and Data refreshes from Production to Non-Production environment, Creation Duplicate Databases using RMAN Backups.
  • Extensively worked with dba jobs, dba scheduler jobs, functions, procedures, and packages.
  • Responsible for tuning teh database performance issues like query tuning and memory tuning (SGA tuning) and partitioned teh tables and indexes for better performance.
  • Loading data from flat files to database using SQL*Loader, External Tables.
  • Oversee hardware infrastructure and keep updates with latest technology.
  • Ensure software is patched and able to protect from threats.
  • Make recommendations for mitigating identified risks.

We'd love your feedback!