We provide IT Staff Augmentation Services!

Security Analyst/assessor Resume

5.00/5 (Submit Your Rating)

Washington, DC

SUMMARY

  • Skilled information security analyst wif 7 years of experience seeking for a challenging and rewarding career where I will learn, grow, and leverage my experience to teh next level using strong critical thinking, inter - personal skills, people skills and hard work to contribute to an organization mission, vision, and value.
  • Experience on Managing ISO 27001 controls as well as sans-20 critical security controls.
  • Risk assessment and vulnerability assessment, generating report and responding to critical and severity of vulnerability.
  • Ability to review vulnerability scans and setting up remediation meeting to discuss security weaknesses and making recommendation for addressing and resolving security weaknesses.
  • Experience in managing teh vulnerability management team and chairing teh vulnerability meeting. Run a biweekly vulnerability meeting to discuss vulnerabilities found in teh network. Teh risk scorecard supports teh remediation process.
  • Experienced in teh development of System Security Plans (SSP), Contingency Plans, security assessment plan (SAP), Incident Response Plans, and Gap analysis whilst implementing NIST 800 53 R4.
  • Experience in working on Window and Linux environment in processing data and information.
  • In-depth knowledge of HIPAA and Privacy for information security systems that holds PPI and sensitive information and data.
  • Experience in conducting risk and information security assessment based on NIST 800-53A. Reviewing of assessment reports and making recommendation for teh security weaknesses.
  • Experience in creating and reviewing POA&M wif cyber security asset and management tool such as CSAM.
  • I have teh capability of developing and managing teh ST&E (security and evaluation test), to support risk management processes.
  • Working knowledge of NIST series {800}60 v1&2, 18, 30, 53 rev4, 137, 115, 34,53A, 59 FIPS 199 & 200 and FISMA guideline to comply wif federal and private agencies.
  • Managed teh development of System Security Authorization Agreements wif vendors and third-party providers and customers.
  • Knowledge of payment card industry data security standards (PCI DSS) making sure organization meets security requirements to promote and protect card holder’s data.
  • Experienced in reviewing POA&M and ATO package to ensure compliance.
  • Experience in teh development of policies and procedures following NIST800-53 control document.
  • Ability to work under difficult and fast paced terrain and meet deadlines in required time frames.
  • Maintain excellent working relationships wif both internal and external customers using communication skill.
  • Vulnerability Scanning and Pen Test Tools NESSUS, Nexpose Rapid 7, Web Inspect, Nmap and Kali Linux Metasploit, FireEye, Network Security Monitor, Symantec endpoint protection and Tenable. Force point.
  • Security information, Event Management, Log Monitoring and Ticketing Manage Engine- Event Log Analyzer, Symantec.
  • Other: Knowledge on LAN/WAN, TCP/IP, Subnetting, DMZ, Routers, Antivirus, Firewalls, IDS/IPS, Proxies and Splunk; Knowledge on Cloud Computing and Services, IAM and SIEM; Experience wif Microsoft Office Tools: Microsoft Excel, Microsoft Word, Microsoft Access, Microsoft PowerPoint, SharePoint, Windows operating System,
  • Analyze endpoint application data in real time to identify potential threats, rogue systems, vulnerabilities.
  • Responsible for operating and maintaining Symantec Endpoint Security Manager
  • Working knowledge of Azure Services IaaS, PaaS, and SaaS and coming trends in teh Cloud space.
  • Serving as a hands-on subject matter expert for DevOps and Automation in an Azure/AWS infrastructure environment
  • Participate in planning, implementation, and growth of our infrastructure on Amazon Web Services
  • Test and certify new versions of windows operating system providing better solution and integration for teh application like VMware and SharePoint.
  • Responsible for assessing and distributing Microsoft Monthly Patches, which falls on a Microsoft patch Tuesday and another on teh fourth Tuesday of teh month.
  • Managed software distribution projects including Microsoft Security upgrades and standard desktop software.
  • Prioritize and coordinate security patch and software testing schedules and distributions.
  • Great understanding and implementation of GDPR General Data Protection regulation, (2018). Provide training and awareness to stakeholders, employee, and auditing facilities to meet compliance.
  • Expert in cloud security, Azure Data services, Firewall, Checkpoint, Migration, Service Now; AWS and One Drive manager; Experience in Software testing and developing script to generate testing reports; Experience in using Encase to conduct digital forensic investigation and expert in analyzing of digital images.
  • DLP agent packaging, upgrading strategies, integration, testing and support. Automate scanning solutions for improving efficiencies wif DLP scanning program for Data at Rest. Work wif different teams to improve teh DLP solution by updating teh policies, fine tuning, and remediation to meet internal & external regulatory requirements.

PROFESSIONAL SUMMARY

Confidential, Washington, DC

SECURITY ANALYST/ASSESSOR

Responsibilities

  • Perform security control assessment in accordance wif National Institute of Standards and Technology (NIST) Risk Management Framework (RMF)
  • Audit information systems applications to ensure that appropriate controls exist, are properly implemented, and are producing teh desired results.
  • Audit information systems to ensure that teh organization’s processes are in compliance wif teh policies and procedures.
  • Conduct security control assessment of low, moderate, and high impact information systems.
  • Review security assessment results in a Security Assessment Report (SAR)
  • Produce a complete assessment report via XACTA & defined Security Control Assessment templates
  • Review existing security documents (PTA, PIA, SSP, Risk Assessment, incident response, contingency plan, Disaster Recovery) and perform quality gap analysis for improvements.
  • Constructed and introduced an Ethical phishing program that rivaled own creation in overall effectiveness. Provided recommendations for improvement at teh request of teh senior leadership team.
  • Implementing, reviewing, maintaining, and monitoring Information Security Management Systems, involved in International and commercial projects in accordance wif ISO/IEC 2700 series (ISO/IEC 27001-27005).
  • Conduct teh full range of effective and comprehensive technical assessments and consultancy services to teh highest standards, including IRM core technical services.
  • Maintain an accurate and up to date knowledge of information security issues, keeping track of new technologies, methodologies, techniques, vulnerabilities, and market trends and communicate dis throughout teh team.
  • Produce concise and accurate technical reports and executive summaries, in line wif client and company expectations in accordance wif teh QA manual and wifin defined deadlines.
  • Participate in more specialist areas of technical assessments and consultancy services where required.
  • Participate in delivery of security management consultancy including health checks, risk assessments and compliance and standards-based audits, where required.
  • Engage wif and fully participate in research & service development projects.
  • Reviewed and updated some of teh system categorization using FIPS 199, Initial Risk Assessment, E-autantication, PTA, PIA, SORN.
  • Conduct kicks off meetings to categorize agency's systems according to NIST requirements of Low, Moderate or High system.
  • Public and private SSL certificate management, Websense / Force point Proxy support, and DLP/File Integrity Monitoring.
  • Conduct assessment and authorization Process, ensuring that Operational, management and technical control securing sensitive Security Systems are in place and being followed according to teh Federal Guideline (NIST SP 800-53).
  • Developed and conducted ST&E (security test and evaluation), Security Assessment plan (SAP) according to ISO27001.
  • Ensure clients are in compliance wif security policies and procedures following ISO27001 and NIST 800-53 and NIST 800-53A.
  • Support teh risk management process by determining and assigning risk impact ratings for systems in accordance wif ISO27001 compliance as well as Federal Information Processing Standards (FIPS) 199, which determines teh level of effort required for teh certification and accreditation process of a system and determines teh security controls for teh protection of an information system.
  • Contribute to initiating FISMA metrics such as Annual Testing, POA&M Management, and Program Management.
  • Perform comprehensive Security Controls Assessment (SCA) and write reviews of management, operational and technical security controls for audited applications and information systems.
  • Reviewed security logs and providing documentation guidelines to business process owners and management system.
  • Experience in reviewing third party suppliers to ensure they comply wif teh company’s information security standards. Also, in carrying out security audit, security assessment and continuous auditing and monitoring third party hosting servers, replicating backups, data, and information.
  • Work wif ISSOs to ensure documenting and remediating audit findings, security planning and reporting, and mitigation of security vulnerabilities are completed in a timely manner.
  • Perform risk assessments for teh organization and laisse wif third party auditors to plan information security audits in relation to ISO27001 standards. I also review all security findings and draft corrective action plan set to resolve all security findings by reviewing evidence, interviewing personnel, tests and assessing controls and producing assessment reports and recommendations.
  • Create and reviewed security artifacts (PTA, PIA, SORN, SAP, CP, CP test, SSP, Incident Response) to make sure controls are meeting desire outcome.
  • Knowledge in data protection and GDPR. Conducting seminar and workshop, presenting security weaknesses to stakeholder and employee. Also, advised teh business on data protection and privacy requirements to protect customer’s data and information and to compliance wif GDPR.
  • Support teh organization in providing training and awareness to employee, stakeholder, and contractors as a process to meet compliance as well as collecting data, needed for business purposes.

Confidential, ATLANTA, GEORGIA

INFORMATION SECURITY ANALYST

Responsibilities

  • Assist in research and development of security systems, processes and procedures following industry best practice.
  • Track, review and analyze security alerts and vulnerabilities from vendors and other sources.
  • Knowledge of payment card industry data security standards (PCI DSS) and ISO27001.
  • Experienced in reviewing POA&M and ATO package to ensure compliance.
  • Experience in teh development of policies and procedures following NIST800-53 control document. Manage and support all information security projects, policies and procedures.
  • Identify, investigate, and report on events generated by security tools.
  • Perform information security risk & vulnerability assessments.
  • Managed teh development of System Security Authorization Agreements.
  • Maintain excellent working relationships wif both internal and external customers using communication skills.
  • Risk assessment and vulnerability assessment, generating report and responding to critical and severity of vulnerability.
  • Reviews changes to information systems to ensure compliance wif security standards. Installs and provides maintenance of security software, penetration tools, DLP, IDS, Antivirus. Instructs computer users on security.
  • Directly oversaw teh Arc Sight, which included teh response to hardware issues involving security infrastructure. Partnered wif teh infrastructure team and led teh Ethical phishing program and vulnerability scanning initiatives.
  • Convinced teh CTO to start a department wide initiative to train IT staff in teh use of Windows PowerShell.
  • Provided training and instruction to co-workers and peers on PowerShell scripting techniques and practices.
  • Manages programs related to awareness and training to deliver compliance and to foster a data privacy culture, creating campaign such as gloden rules for information security, posters, and phishing campaigns.
  • Providing data protection training in relation to GDPR compliance to promote teh culture of security and privacy, draft policies such as information classification.
  • Providing monthly newsletters on data privacy and data protection and retention period to enable teh organization meets teh goals of security.
  • Create and deliver reports to business lines pertaining to endpoint security, compliance, etc.
  • Manage Endpoint and alerting tools (agent deployment/setup, correlation, and rule tuning, etc.
  • Provided training and instruction to co-workers and peers on PowerShell scripting techniques and practices.

We'd love your feedback!