Cyber Incident Responder Resume
Quantico, VA
TECHNICAL SKILLS
Security Tools: Magnet Axiom imager, Encase, Paladin, KAPE, Talino,Splunk, ArcSight Logger, Palisade, Resilient,Carbon Black, Crowd Strike Falcon, Tanium, Cisco Threat Grid,,Cisco Source Fire, RSA Net witness, Symantec A/V,McAfee EPO, Palo Alto Panorama, FireEye (EX, AX, NX),Cisco IronPort, Proof Point TAP/TRAP
Protocols: TCP/IP, VPN, Telnet, SSH, SSL EIGRP, OSPF, ICMP, SNMP, IPSEC and DHCP
PROFESSIONAL EXPERIENCE
Confidential - Quantico, VA
Cyber Incident Responder
Responsibilities:
- Capture and analyze packets using Wireshark and TCP dump to identify and assess malicious activity.
- Conduct static and dynamic analysis of malware and its delivery mechanism.
- Investigates security incidents, events, and alerts using open source and commercial security tools.
- Monitors SIEM and logging environments with Splunk, and McAfee suite from security events and alerts to threats, and compromise.
- Compose and present reports on findings to leadership for intrusion incidents.
Confidential - Alexandria, VA
Cyber Threat Analyst
Responsibilities:
- Utilize Splunk enterprise SIEM in addition to other security logging environments to identify and remediate daily incident response events for potential or active cyber security threats.
- Investigating computer and information security incidents to determine extent of compromise.
- Conducts computer evidence seizure, computer forensic analysis, and network assessments.
Confidential - Charlotte, NC
Cyber Security Analyst/Jr. Forensic Analyst
Responsibilities:
- Utilize Splunk enterprise SIEM in addition to other security logging environments to identify and remediate daily incident response events for potential or active cyber security threats.
- Manages Proofpoint enterprise security tool to provide incident handling and response for all malicious email threats and phishing campaigns.
- Conduct employee cyber security awareness education training.
- Correlates Cyber threat intelligence to identify indicators of compromise and assess the risk of attack.
- Assist in the creation of new Security Operation department, establishing and documenting process and polices.
- Responsible for conducting static and dynamic malware analysis.
- Responsible for conducting live and dead box forensic investigation.
- Confiscation of evidence and utilizing proper chain of custody of company assets.
Confidential - Charlotte, NC
Cyber Security Analyst
Responsibilities:
- Participated in cyber security daily threat and intelligence briefings to identify new indicators of compromise.
- Monitored, evaluated, and maintained security systems to protect critical information assets from internal and external threats and vulnerabilities.
- Maintained a core set of security tools including firewalls, intrusion prevention systems, and malware protection.
- Ensured all security tools, and platforms were functioning as designed, and adjusted to regulatory changes.
- Assisted Cyber Incident Response Team’s development and improvement process.
Confidential - Charlotte, NC
System Engineer
Responsibilities:
- Conducted troubleshooting of security incidents that had impacted network capacity and availability performance.
- Identified critical capacity trends and breaches within cyber security space.
- Monitored network performance of Citrix Web Application Firewalls, Tipping Point IDS/IPS, Bluecoat Web Proxies and F5 Load balancers.
- Gathered and analyzed network data to collaborate with network architects and third-party vendors on network optimization and network capacity modification to meet current, forecasted and planned capacity requirements.
- Secured network systems by establishing and enforcing security policies and compliance standards within the banks network.
Confidential
Network Administrator
Responsibilities:
- Provided configuration and troubleshooting of Cisco series IP routers and Ethernet switches for TF Odin’s command center and aircrafts.
- Provided user account management with Microsoft active directory.
- Utilized Remedy ticketing system to address network and desktop support issues within customer SLA standards.
- Conducted memory upgrades and maintenance of Windows server 2008 R2 platform for ISR mission FMV archive.
- Loading of Cryptographic Key Material and Configuration of KG-250X, KG-175D devices to provide network communication security on IP networks.
Confidential - Millersville, MD
Network Engineer
Responsibilities:
- Provided network design, hardware installation and configuration of LAN/WAN access and distribution layer nodes for Cisco and Brocade switches and routers to remote and local government sites.
- Troubleshooting of Cisco system DATA/VOIP/VTC/VLANs along with Upgrades of system software, installation of latest code version and maintains updates on new network drawings and diagrams.
- Maintenance of VOIP network infrastructure for Cisco VOIP phones (7945/7965 series) and VTC TANDBERG teleconference equipment.
- Managed multiple projects and held weekly meetings with senior level project managers and customer liaison for the planning and implementing of future network projects.
- Provided technical leadership in the planning of site surveys, maintenance and testing support for customers located in remote and local sites.
Confidential - Columbia, MD
Network Administrator
Responsibilities:
- Successfully managed IT-Modernization projects with the deactivation and redesign of CONUS government site legacy network architecture and upgrading Cisco network equipment (ATM’s, Routers, Switches, Phones and network level encryption devices) while following the configuration standards of DOD network infrastructure.
- Provided Tier One (I) and Tier Two (II) maintenance and testing support for Cisco and Brocade LAN/WAN, Telephony/Media equipment and software within NOC environment.
- Configured (TACLANE-GigE (KG175A/D) to provide network communication security on ATM and IP networks.
- Created Network infrastructure diagrams to show network topologies, overall system architecture and illustrate data communication center layouts for IT-Modernization using Microsoft Visio software.
