Diacap Engineer Resume Profile
5.00/5 (Submit Your Rating)
OBJECTIVE
Obtain an Information Assurance position in the Intelligence community in which will utilize my TS/SCI security clearance, and which will challenge my skill set and gain knowledge to further my career in the field through problem solving and learning from other professionals, which I will work side by side with to encourage top-notch services to the client.
TECHNICAL HIGHLIGHTS
- Increase and promote information technology interaction with mission.
- Serve mission information users as customers.
- Facilitate process improvement.
- Modernize and integrate defense information infrastructure. Upgrade technology base.
- Improve information technology management tools. Build information assurance framework.
- Build information assurance architecture and support services. Improve acquisition processes and regulations.
- Assess information assurance posture of DoD operational systems
PROFESSIONAL EXPERIENCE
DIACAP Engineer
Confidential
- Prepare IA certification validation plans as part of the DIACAP Implementation Plan DIP in accordance with the Interim DIACAP validation requirements and methods.
- Conduct validation of IA controls listed in DoDI 8500.2 based on Mission Assurance Category and Confidentiality Level.
- Prepare IA validation artifacts and scorecards.
- . Validate Implementation status of physical security, operational security, disaster recovery and all other DIACAP IA controls.
- Provide the IA scorecard and supporting artifacts to the ACA for an operational IA risk determination.
- Provide detailed DIACAP report briefings to customers and management.
- Make certification determination decision for an Authorization to Operate ATO , Interim Authorization to Operate IATO , Interim Authorization to Test IATT , or Denial of Authorization to Operate DATO to the Designated Approval Authority DAA .
- Maintaining a repository for all systems' Certification and Accreditation documentation and modifications to support Designated Approving Authority DAA .
- Pursuing my professional currency requirements for certification at Level III in Information Assurance Management IAM-III based on DoD8570.01-M and Information Assurance assessment methodologies as required by AR 25-2. CISSP
- Certified as DIACAP Validator through Secure Info in August 2008.
- Receive certificate of completion for the Official Certified Information System Security Professional Course held at Fort Gordon Army facility in January 2009.
DIACAP Engineer contract to hire
Confidential
- Prepare IA certification validation plans as part of the DIACAP Implementation Plan DIP in accordance with the Interim DIACAP validation requirements and methods.
- Conduct validation of IA controls listed in DoDI 8500.2 based on Mission Assurance Category and Confidentiality Level.
- Prepare IA validation artifacts and scorecards.
- Validate Implementation status of physical security, operational security, disaster recovery and all other DIACAP
- IA controls.
- Provide the IA scorecard and supporting artifacts to the ACA for an operational IA risk determination.
- Provide detailed DIACAP report briefings to customers and management.
- Make certification determination decision for an Authorization to Operate ATO , Interim Authorization to
- Operate IATO , Interim Authorization to Test IATT , or Denial of Authorization to Operate DATO to the Designated Approval Authority DAA .
- Maintaining a repository for all systems' Certification and Accreditation documentation and modifications to support Designated Approving Authority DAA .
- Pursuing my professional currency requirements for certification at Level III in Information Assurance Management IAM-III based on DoD8570.01-M and Information Assurance assessment methodologies as required by AR 25-2.
Senior Information Assurance Officer
Confidential
- Principal point of contact for information assurance activities at the IT system level at the Air Force Communication Agency AFCA . Responsible for ensuring that management operational and technical controls for securing either National Security Systems or SBU level IT Systems are in place and are followed. This includes ensuring that appropriate steps are taken to implement information security requirements for IT systems throughout their life cycle, from the requirements definition phase through disposal.
- Served as the primary liaison to other agencies and application developers regarding requirements to facilitate security accreditation of systems and their secure operations at multiple sites.
- Developed and implemented documentation outlining system operating environment, to include the overall mission, floor layout, hardware configuration, software, type of information processed, user organizations and security clearances, operating mode, interconnections to other systems/networks of users, their security personnel, and associated responsibilities.
- Assisted in the development of the overall system security document, the Information System Security Plan, which contains all necessary security procedures, instructions, operating plans, and guidance also participated in the development or revision of System-specific security safeguards and local operating procedures
- Provided IT security consulting to system owners as to the other security documents, for example, security incident reports, equipment/software inventories, operating instructions, technical vulnerability reports, and contingency plans and provided expertise in classified and unclassified ratings to customers.
- Worked closely with Certifiers to navigate the DIACAP Certification Accreditation process and produce all appropriate accreditation documentation.
- Familiar with Nessus and Retina vulnerability scans and has worked in detail with the DISA Gold security scans.
Sr. Server Administrator
Confidential
- Served as server administrator and provided Operations and Maintenance support to National Geospatial- Intelligence College NGC server systems and student workstations.
- Developed an MS Access database to streamline tracking of department IS equipment and ISR submissions. Provided Information Systems Weekly Report to include status of information system readiness, workstations, servers and software.
- Coordinated security plans to include event log auditing, virus scanning for standalones, workstations and laptops, and system configurations.
- Responsible for assuring the most up to date vulnerability scans were completed and security risks were corrected to over 250 computers in his working office.
- Performed security auditing and vulnerability analysis for the Microsoft platform.
- Ran the DISA Gold disk on all the systems to assure that the Certification and Accreditation was the most up to date and that all his systems were Approved to Operate ATO under DITSCAP guidance.
- Advised management on recommendations for equipment purchase, sparing, and exchange. Troubleshot systems and peripherals as problems arise via visual inspection and user interaction.
- Installed, maintained, and configured COTS and specialized software packages on NGC servers and workstations. Created, deleted and maintained user accounts and files systems following accepted guidelines and standards. Installed, maintained, configured and troubleshot audio/visual equipment.
- Prepared, submitted and maintained Site Security Plans SSPs for NGC and submitted to the Information Assurance team as needed.
Information System Security Officer
Confidential
- Acted as the overall DITSCAP/ DCID 6/3 professional for over seventy systems within the National Geospatial-Intelligence Agency NGA .
- Worked closely with clients in the process of registering their system with the DAA staff which involved working closely with high-level staff on very tight time schedules.
- Worked on System Security plans on systems which were both unclassified up to Top Secret, which involved knowing the security controls involved in a TS system and precautions needed to be compliant with NSA regulations.
- Explained the DCID 6/3 regulations to clients as well as giving unclassified briefing to the systems local security representative. This proved to increase the local security representative's knowledge of security and proved to lighten the burden of my ISS team members.
- Volunteered to give new hire presentation on the local Computer Network Defense team locally and this was a great representation of my oral skills when speaking in large groups and answering some unique and difficult questions that the new employee may have on their first day.
- Volunteered to hold training on removable media after the task was given to my team. This was required for all those who required any media that was removable. Designed a PowerPoint presentation for this training and received letter of appreciation for this effort.
- Maintained a Top Secret SCI clearance threw out my career at NGA.
Desktop Support Specialist
Confidential
- Served as Tier II helpdesk technician at the National Geospatial- Intelligence Agency NGA which involved working with both Peregrine Service Center along with Remedy to pull help desk tickets and maintain statuses throughout the life of the ticket.
- Displayed extreme amount of public relations with the continuous communication to clients at their desk along with over phone communications.
- Setup, configured and tested all new printers, scanners and workstations for deployment to users.
- Displayed an extreme technical background by troubleshooting applications, LAN lines, and port configuration while resolving the problem tickets assigned to myself.
- Provided technical assistance to those issues on the team that were not able to be mitigated issues assigned to them.
- Displayed great teamwork and team pride while working with the Tier II helpdesk team, also learning from those who were senior to myself.
- Received several awards for my dedication and abilities to the NGA team.
