Information Security Analyst Resume
2.00/5 (Submit Your Rating)
PROFILE SUMMARY
- Outstanding Information Security Professional wif extensive noledge in Risk Assessment, Risk Management Framework (RMF), and vulnerability assessment tools such as Retina Network Security Scanner (RNSS), Nessus and MBSA. Excellent writing and communication skills, noledgeable in Windows environments and exceptional customer service.
TECHNICAL SKILLS
- Extensive noledge of FISMA, FIPS standards, NIST SP 800 series.
- Strong interpersonal skills wif proven ability to provide exceptional customer service in a courteous manner and work TEMPeffectively wif diverse groups of people at various levels wifin the organization.
- Excellent written and verbal skills wif ability to pay close attention to details .
- Strong organizational skills sufficient to prioritize work and complete projects accurately independently or as part of a team.
- Conversant wif security - scanning tools such as NESSUS, MBSA and RETINA
PROFESSIONAL EXPERIENCE
Confidential
Information Security Analyst
Responsibilities:
- Performed Federal Information Security Management Act (FISMA) audit reviews and the Security Authorization process using NIST SP 800-37 rev 1.
- Coordinated in-depth interviews and examined documentation/ artifacts in accordance wif NIST SP 800-53A
- Updated IT security policies, procedures, standards, and guidelines according to department and federal requirements.
- Performed risk assessments, developed and updated Security Assessment Plan (SAP), System Security Plans (SSP), Plans of Action and Milestones (POA&M), Security Control Assessments, Contingency Plans (CP), Incident Response Plans (IRP), and other specific security documentation using the following standards:
- FIPS 199, FIPS 200, NIST SP 800-37rev1, NIST SP 800-53rev4, NIST SP 800-53A, NIST SP 800-30, NIST SP 800-34 and NIST SP 800-18, NIST SP 800-60.
- Performed vulnerability scans on the client and host network using Retina Network Security Scanner (RNSS) and Nessus.
- Identified vulnerabilities, recommended corrective measures and ensured the adequacy of existing information security controls.
- Analyzed and assessed vulnerability scan outputs and provided feedback to CISO and system owners.
- Recommended preventive, mitigating and compensating controls to ensure appropriate level of protection and adherence to goals of the overall information security strategy.
- Developed Rules of Behavior (RoB), Interconnection Security Agreement (ISA) and Memorandum of Understanding (MoU) for clients.
- Developed plans to safeguard computer files against unauthorized modification, destruction, or disclosure of information.
- Monitored use of data and regulated access to safeguard information against unauthorized modification or disclosure.
- Conferred wif users regarding computer data access needs, security violations and programming changes.
- Assisted extensively in developing security awareness materials, security presentations, and information security sessions.
