Security Analyst/assesso Resume
SUMMARY
- Skilled information security analyst wif 7 years of experience seeking for a challenging and rewarding career where me will learn, grow, and leverage my experience to the next level using strong critical thinking, inter - personal skills, people skills and hard work to contribute to an organization mission, vision, and value.
- Experience on Managing ISO 27001 controls as well as sans-20 critical security controls.
- Risk assessment and vulnerability assessment, generating report and responding to critical and severity of vulnerability.
- Ability to review vulnerability scans and setting up remediation meeting to discuss security weaknesses and making recommendation for addressing and resolving security weaknesses.
- Experience in managing the vulnerability management team and chairing the vulnerability meeting. Run a biweekly vulnerability meeting to discuss vulnerabilities found in the network. The risk scorecard supports the remediation process.
- Experienced in the development of System Security Plans (SSP), Contingency Plans, security assessment plan (SAP), Incident Response Plans, and Gap analysis whilst implementing NIST 800 53 R4.
- Experience in working on Window and Linux environment in processing data and information.
- In-depth noledge of HIPAA and Privacy for information security systems that holds PPI and sensitive information and data.
- Experience in conducting risk and information security assessment based on NIST 800-53A. Reviewing of assessment reports and making recommendation for the security weaknesses.
- Experience in creating and reviewing POA&M wif cyber security asset and management tool such as CSAM.
- me has the capability of developing and managing the ST&E (security and evaluation test), to support risk management processes.
- Working noledge of NIST series {800}60 v1&2, 18, 30, 53 rev4, 137, 115, 34,53A, 59 FIPS 199 & 200 and FISMA guideline to comply wif federal and private agencies.
- Managed the development of System Security Authorization Agreements wif vendors and third-party providers and customers.
- Knowledge of payment card industry data security standards (PCI DSS) making sure organization meets security requirements to promote and protect card holder’s data.
- Experienced in reviewing POA&M and ATO package to ensure compliance.
- Experience in the development of policies and procedures following NIST800-53 control document.
- Ability to work under difficult and fast paced terrain and meet deadlines in required time frames.
- Maintain excellent working relationships wif both internal and external customers using communication skills.
PROFESSIONAL EXPERIENCE
SECURITY ANALYST/ASSESSO
Confidential
Responsibilities:
- Perform security control assessment in accordance wif National Institute of Standards and Technology (NIST) Risk Management Framework (RMF)
- Audit information systems applications to ensure that appropriate controls exist, are properly implemented, and are producing the desired results.
- Audit information systems to ensure that the organization’s processes are in compliance wif the policies and procedures.
- Conduct security control assessment of low, moderate, and high impact information systems.
- Review security assessment results in a Security Assessment Report (SAR)
- Produce a complete assessment report via XACTA & defined Security Control Assessment templates
- Review existing security documents (PTA, PIA, SSP, Risk Assessment, incident response, contingency plan, Disaster Recovery) and perform quality gap analysis for improvements.
- Implementing, reviewing, maintaining, and monitoring Information Security Management Systems, involved in International and commercial projects in accordance wif ISO/IEC 2700 series (ISO/IEC 27001-27005).
- Conduct the full range of TEMPeffective and comprehensive technical assessments and consultancy services to the highest standards, including IRM core technical services.
- Maintain an accurate and up to date noledge of information security issues, keeping track of new technologies, methodologies, techniques, vulnerabilities, and market trends and communicate this throughout the team.
- Produce concise and accurate technical reports and executive summaries, in line wif client and company expectations in accordance wif the QA manual and wifin defined deadlines.
- Participate in more specialist areas of technical assessments and consultancy services where required.
- Participate in delivery of security management consultancy including health checks, risk assessments and compliance and standards-based audits, where required.
- Engage wif and fully participate in research & service development projects.
- Reviewed and updated some of the system categorization using FIPS 199, Initial Risk Assessment, E-autantication, PTA, PIA, SORN.
- Conduct kicks off meetings in order to categorize agency's systems according to NIST requirements of Low, Moderate or High system.
- Conduct assessment and authorization Process, ensuring that Operational, management and technical control securing sensitive Security Systems are in place and being followed according to the Federal Guideline (NIST SP 800-53).
- Developed and conducted ST&E (security test and evaluation), Security Assessment plan (SAP) according to ISO27001.
- Ensure clients are in compliance wif security policies and procedures following ISO27001 and NIST 800-53 and NIST 800-53A.
- Support the risk management process by determining and assigning risk impact ratings for systems in accordance wif ISO27001 compliance as well as Federal Information Processing Standards (FIPS) 199, which determines the level of effort required for the certification and accreditation process of a system and determines the security controls for the protection of an information system.
- Contribute to initiating FISMA metrics such as Annual Testing, POA&M Management, and Program Management.
- Perform comprehensive Security Controls Assessment (SCA) and write reviews of management, operational and technical security controls for audited applications and information systems.
- Reviewed security logs and providing documentation guidelines to business process owners and management system.
- Experience in reviewing third party suppliers to ensure they comply wif the company’s information security standards. Also, in carrying out security audit, security assessment and continuous auditing and monitoring third party hosting servers, replicating backups, data, and information.
- Work wif ISSOs to ensure documenting and remediating audit findings, security planning and reporting, and mitigation of security vulnerabilities are completed in a timely manner.
- Perform risk assessments for the organization and laisse wif third party auditors to plan information security audits in relation to ISO27001 standards. me also review all security findings and draft corrective action plan set to resolve all security findings by reviewing evidence, interviewing personnel, tests and assessing controls and producing assessment reports and recommendations.
- Create and reviewed security artifacts (PTA, PIA, SORN, SAP, CP, CP test, SSP, Incident Response) to make sure controls are meeting desire outcome.
- Knowledge in data protection and GDPR. Conducting seminar and workshop, presenting security weaknesses to stakeholder and employee. Also, advised the business on data protection and privacy requirements to protect customers data and information and to compliance wif GDPR.
- Support the organization in providing training and awareness to employee, stakeholder, and contractors as a process to meet compliance as well as collecting data, needed for business purposes.
- Manages programs related to awareness and training to deliver compliance and to foster a data privacy culture, creating campaign such as gloden rules for information security, posters, and phishing campaigns.
- Providing data protection training in relation to GDPR compliance to promote the culture of security and privacy, draft policies such as information classification.
- Providing monthly newsletters on data privacy and data protection and retention period to enable the organization meets the goals of security.
INFORMATION SECURITY ANALYST
Confidential
Responsibilities:
- Assist in research and development of security systems, processes and procedures following industry best practice.
- Track, review and analyze security alerts and vulnerabilities from vendors and other sources.
- Respond to information security incidents on an as needed basis.
- Knowledge of payment card industry data security standards (PCI DSS) and ISO27001.
- Experienced in reviewing POA&M and ATO package to ensure compliance.
- Experience in the development of policies and procedures following NIST800-53 control document. Manage and support all information security projects, policies and procedures.
- Identify, investigate, and report on events generated by security tools.
- Perform information security risk & vulnerability assessments.
- Managed the development of System Security Authorization Agreements.
- Ability to work under difficult and fast paced terrain and meet deadlines in required time frames.
- Maintain excellent working relationships wif both internal and external customers using communication skills.
- Risk assessment and vulnerability assessment, generating report and responding to critical and severity of vulnerability.
TECHNICAL SKILLS:
Vulnerability Scanning and Pen Test Tools: NESSUS, Nexpose Rapid 7, WebInspect, Nmap and Kali Linux Metasploit, FireEye, Network Security Monitor, Symantec endpoint protection and Tenable.
Event Management: Log Monitoring and Ticketing Manage Engine- Event Log Analyzer, Symantec.
Other: Knowledge on LAN/WAN, TCP/IP, Subnetting, DMZ, Routers, Antivirus, Firewalls, IDS/IPS, Proxies and Splunk; Knowledge on Cloud Computing and Services, IAM and SIEM; Experience wif Microsoft Office Tools Microsoft Excel, Microsoft Word, Microsoft Access, Microsoft PowerPoint, SharePoint, Windows operating System, PowerShell, PeopleSoft.
