We provide IT Staff Augmentation Services!

Consultant Resume

3.00/5 (Submit Your Rating)

VA

PROFESSIONAL SUMMARY:

  • Confidential is a Sr. Security Consultant serving as a full time Cloud/Infrastructure Security Lead for teh consulting practice for teh federal practice at Confidential .
  • He provides consulting services in several areas of Cyber security including penetration testing, application and infrastructure vulnerability assessments, static and dynamic code analysis as well as secure cloud implementations.

PROFESSIONAL EXPERIENCE

Confidential, VA

Consultant

Responsibilities:

  • Responsible for coordinating, conducting and managing penetration testing engagements wifin EIA’s Salesforce and AWS Cloud environments.
  • Responsible for Analyzing source code wifin teh Salesforce Development environment prior to Production Migration
  • Responsible for analyzing Nessus Vulnerability Scan results wifin EIA’s AWS and Salesforce Environments in order to identify communicate and or remediate Firmware related vulnerabilities.
  • Responsible for generating reports as well as reporting all vulnerabilities and system deficiencies to key Business Stakeholders
  • Responsible for conducting and managing Technical security assessments for all internal components wifin EIA AWS Hybrid Cloud
  • Responsible for conducting and managing Technical security assessments for all internal components wifin EIA’s Salesforce Sales Cloud, Service Cloud and, Marketing Cloud environments

Confidential, Arlington, VA

Consultant

Responsibilities:

  • Responsible for teh overall operation and maintenance of teh Information Security program in support of teh Migrant Student Information Exchange (MSIX) system owned by teh Office of Migrant Education (Department of Education)
  • Responsible for conducting Web Application Vulnerability Assessments/Security tests on web applications in support of CMS (Center of Medicare and Medicaid Services) in order to identify and validate web application vulnerabilities wifin their client’s IT infrastructure.
  • Responsible for conducting Database Security Assessments in order to identify and validate backend vulnerabilities and or security findings wifin CMS’s (Center of Medicare and Medicaid Services) DB environments and or technical system build processes.
  • Responsible for development of Security Configuration and operation Standards for mission critical applications and information systems in direct support of teh IRS ACA (Affordable Care Act).
  • Responsible for assessing teh manual (non - automated) and automated security controls applicable to BoC (Bureau of Census) applications and information systems in support of teh 2018 US Census.
  • Responsible for teh development of teh CMS Million Hearts System Security Plan as well as teh revision of teh MSIX System Security Plan
  • Utilizes DISA STIGs in order to develop Security Configurations for Core technologies found wifin our Client’s IT Infrastructure
  • Utilizes FedRAMP controls along wif DoD Cloud Computing SRG in order to perform an assessment on Cloud-based applications and Cloud infrastructure in use by our Public Sector/Government clients
  • Assess complex governance requirements/controls, to include FedRAMP, DISA STIGS and NIST guidelines in order provide clients wif leading practice recommendations as it relates to IT Security controls wifin an enterprise environment
  • Assess cyber security and enterprise information security management practices through pre-implementation reviews

Confidential, Fairfax, VA

Applications Specialist/Engineer

Responsibilities:

  • Responsible for conducting automated and manual security assessments in accordance wif teh Security Assessment and Authorization process on information systems in a controlled non production environment in order to identify and remediate vulnerabilities found wifin teh IT environment (Utilized NIST 800-53, 800-37 & 800-79 guidelines)
  • Responsible for teh development of teh Standard Operations and Procedures document (SOP) to include teh remodeling of Disaster Recovery/Business Continuity plans as well as escalation procedures
  • Utilized FISMA Standards and guidelines in order to enhance and improve teh security posture of information systems
  • Performed malware debugging specific to CBP workstations and 3rd party applications
  • Conducted vulnerability assessments using Nessus, port scanning using Wireshark and intrusion detection/prevention monitoring using Snort on all information systems across teh network in order to identify vulnerabilities, malicious content intrusion and other possible security threats
  • Received requests from customers for service or problems resolution; prioritizes requests and routes to appropriate staff for action; maintains a database of customer requests & tracks teh progress of service & problem resolution; contacted customers to keep them informed of teh status of their requests
  • Actively participated in teh testing and implementation of new web applications and new systems
  • Actively participated in system and log/event monitoring using HP Arcsight
  • Provided in-servicing sessions for users in teh operation of computer and communications equipment, system applications, and software products

Confidential, Washington DC

Systems Administrator

Responsibilities:

  • Performed daily system monitoring, verifying teh integrity and availability of all hardware, server resources, systems and key processes, reviewing system and application logs, and verifying completion of scheduled jobs such as backups
  • Executed regular security monitoring to identify any possible intrusions
  • Performed daily backup operations, ensuring all required file systems and system data are successfully backed up to teh appropriate media, recovery tapes or disks are created, and media is recycled and sent off site as necessary
  • Repaired and recover from hardware or software failures. Coordinate and communicate wif impacted constituencies
  • Achieved ongoing performance tuning, hardware upgrades, & resource optimization as required.
  • Configured CPU, memory, and disk partitions as required.
  • Developed and maintained installation and configuration procedures

TECHINICAL SKILLS

  • Certifications
  • Operating Systems
  • Software Tools
  • Languages
  • Rackspace “Cloud U” Certificate
  • Windows 2000, ME XP, Vista 7, 8.1, 10
  • Tenable Sec Nessus
  • SQL
  • CompTIA Security +
  • Windows Sever 2003, 2008, 2012
  • “Wireshark”
  • PHP
  • ITILv3 Foundation
  • MAC OS 10.6, 10.7, 10.8, 10.9
  • Metasploit Framework
  • Javascript
  • Cloud Security Alliance Certificate of Cloud Security Knowledge (CCSK)
  • Oracle Linux, Linux Red Hat, CentOS, Ubuntu (MAAS), BackTrack, Kali Linux Kali 2.0“NMap/ZenMap”
  • Python
  • EC-Council Certified Ethical Hacker (C|EH)
  • EC-Council Certified Hacking Forensics Investigator (C|HFI)
  • Solaris 10, BSD
  • WinDbg/IDA Pro
  • SQLMap
  • Burp Suite Pro
  • Checkmarxx
  • Bash/Shell Scriptin

We'd love your feedback!