Sr Security Analyst (servicenow) Resume
2.00/5 (Submit Your Rating)
Pittsburgh, PA
TECHNICAL SKILLS
- Software As a Service (SaaS)
- Platform As a Service (PaaS)
- Servicenow
- IT service management (ITSM)
- Active Directory
- Data import
- Application Security
- Client - Server technology
- Business Process Models
- Applications Integration
- AWS
- Azure
- Application development using agile and waterfall methodologies
- Firewall
- Data Center Operation
- Backup and Storage Management
- OFSAA
- SailPoint
- Jira
- JavaScript
- SharePoint
- SQL Developer
- Toad
- MS Office Suite
- Discovery
PROFESSIONAL EXPERIENCE
Confidential, Pittsburgh PA
Sr Security Analyst (ServiceNow)
Responsibilities:
- Conducted Web Application Systems Assessment (WASA) on ServiceNow suite and worked on fixing findings such as: Cross Site Scripting (reflected), Cross Site Scripting (stored) and HTML injection.
- Created Plan of Action and Milestones (POAM) for continuous monitoring and for new vulnerabilities - including remediation activities.
- Worked on with ISSO and System Owner through out teh ATO process and renewals.
- Worked in all phases of teh NIST Risk Management Framework for teh achievement and maintenance of authorization to operate (ATO) for ServiceNow application.
- Carried out PTA- Privacy Threshold Analysis and Privacy Impact.
- Reviewed Authority to Operate (ATO) package.
- Maintained overall application security.
- Performed Vulnerability scan to check for weaknesses in teh ServiceNow Application using Fortify.
- Updated and maintained ServiceNow Suite SSP following teh Risk Management Framework (RMF) using FIPS 199, FIPS 200 and NIST SP 800-53.
- Led weekly security touch point meeting.
- Created IRP, DRP and BCP.
- Configured ServiceNow VRM - imported vendor portfolio, configure Vendor Risk Assessment for continuous monitoring.
- Oversaw VA’s ITSM GRC process using Risk Vision and later eMASS.
- Conducted routine audits such as user access and permissions.
- Ensured teh Mid-Server connection was in compliant to VA standard.
- Followed Cloud Security Management best practices to ensure security of data.
- Trained new employees on teh GRC process and on ServiceNow application.
Confidential, Pittsburgh, PA
IT Security Manager
Responsibilities:
- Worked in Agile Environment. Created user groups and assigned security roles to provide access and/or implement restrictions in ServiceNow GRC.
- Created user groups and applied security roles to provide access and/or implement restrictions in ServiceNow GRC.
- Managed teh Vendor Management Process, reviewed vendor attestations and questionnaires.
- Analyzed teh results of vulnerability scans, configuration checks, and security alerts to identify and understand weaknesses or deficiencies and determine remedial actions.
- Created, updated and maintained technical and security documentation about systems, networks, and operating environments.
- Maintained teh overall GRC Process.
- Led information System Audit Planning, Audit Execution and Audit Reporting.
- Defined risk framework and Incorporated company policies into teh ServiceNow GRC.
- Imported UCF Authority Documents into ServiceNow GRC module and linked them to their corresponding controls, policies and citations.
- Escalated issues of 3rdpartyvendor's non-compliance to teh VendorRiskmanagement Office (VMO).
- Reviewed all essential security policies and procedures documentation.
- Validated code changes in Test and ensured proper migration to Pre-Prod and Prod.
- Reviewed data on teh GRC reporting dashboard.
- Configured and maintained teh system ensuring consistency according to established governance.
- Ensured overall integrity of teh ServiceNow application.
Confidential, Pittsburgh, PA
Sr. IT Security Analyst
Responsibilities:
- Configured security and assess controls for OFSAA.
- Worked on boarding different applications onto SailPoint.
- Maintained Security Assessment Plan (SAP) and A&A process, carried out RMF assessment for security controls.
- Gatheird and documented business requirements related to ServiceNow, created test cases and logged issues in Jira.
- Configured ServiceNow GRC and Vendor Risk Management- imported vendor profile, vendor tiering, created vendor risk assessment workflow.
- Used Nessus to conduct credentialed vulnerability scan against all instances of teh Operating System and desktop configurations to identify security flaws.
- Managed DLP, WAS, WAF, and overall system security.
- Developed and implemented information security policies, procedures, and standards based on NIST guidance covering system inventories, system security categorization, baseline security controls, risk assessments, security planning, certification and accreditation, and plan of actions and milestones (POA&M)
- ServiceNow testing and automation.
- GSS risk assessment, documented and maintained security procedures and policies.
- Provided advice and guidance of recommended methods and assist in determining recommended approaches in teh areas of Security, Risk, Governance, and Compliance.
- Managed a team of system admins, prioritized work and identified high risk critical problems and dedicated appropriate resources accordingly.
Confidential, Pittsburgh, PA
IT Security Analyst
Responsibilities:
- Carried out security assessment and authorization processes and activities.
- Performed vulnerability and compliance scanning and assessments.
- Participated and led security team meetings that facilitate secure design.
- Regularly monitored teh security community for public-facing security issues.
- Maintained and updated teh Security Controls
- Managed teh overall monthly SOX review process.
