We provide IT Staff Augmentation Services!

Security Engineer Resume

4.00/5 (Submit Your Rating)

SUMMARY

  • Worked within established operating procedures to detect & respond to cyber incidents from external threats as an integral part of a Security Operations Center (SOC).
  • Able to provided expert level analysis and support for the Security Operations organization
  • Developed use cases and supports the continuous improvement of the organizations monitoring and detection capabilities
  • Managed multiple investigation requests through the entire lifecycle of initiation, data collection, analysis, and data production
  • Performs malicious code analysis and reverse engineering
  • Ability to obtain a government security clearance - US Citizenship Required
  • Experience with threat assessment, vulnerability analysis, risk assessment, information gathering, correlating and reporting
  • Ability to utilize common sandbox technology to perform dynamic malware analysis
  • Ability to identify and recommend mitigations for vulnerabilities, exploits, patches
  • Understanding of "attacker" methodologies and tactics, including kill-chain analysis
  • Familiarity with Advance Persistent Threat groups and Hacker activity
  • Experience analyzing phishing attacks
  • Significant experience in network intrusion detection
  • Experience monitoring third party security related websites, forums and social media sites for information regarding vulnerabilities and exploits
  • Familiarity with Splunk, ArcSight, QRadar, Sourcefire, Snort
  • In-depth knowledge and hands-on experience with satellite communications hardware (I-Direct net modem, ComTech, C-Band, Ku-Band, Inmarsat, and Iridiu

PROFESSIONAL EXPERIENCE

Confidential

Security Engineer

Responsibilities:

  • Monitored and analyzed Intrusion Detection Systems (IDS) to identify security issues for remediation.
  • Recognized potential, successful, and unsuccessful intrusion attempts and compromises thorough reviews and analyses of relevant event detail and summary information.
  • Established links between suspects and other violators by piecing together evidence uncovered from a variety of sources
  • Performed detailed investigation and response activities for potential security incidents
  • Provided accurate and priority driven analysis on cyber activity/threats
  • Perform payload analysis of packets using Wireshark
  • Recommended and assisted with implementation of counter-measures or mitigating controls.
  • Analyzed a variety of network and host-based security appliance logs (Firewalls, NIDS, HIDS, Sys Logs, etc.) to determine the correct remediation actions and escalation paths for each incident
  • Research the vulnerabilities reported by CIRT and other security organizations
  • Used Splunk 6 to analyze IDS, IPS, Firewall, Proxy, Server and Database logs and events.
  • Worked with SIEM platforms, such as RSA Security Analytics, Splunk, and ArcSight; also Firewalls, Intrusion Detection/Prevention Systems (Snort, Mcafee IPS, Sourcefire), Proxies, FireEye and/or Pen Testing
  • Designing, writing and monitoring rules to safeguard Alliants information assets, and effectively identify and mitigate both internal and external threats to these goals
  • Researching and identifying key indicators of malicious activities on the network and end user workstations
  • Reviewing industry and vendor security alerts for vulnerabilities and security and fraud issues
  • Maintaining awareness of trends in security, fraud, regulatory, technology and operational requirements
  • Participated in security and fraud incident response efforts by maintaining an in-depth knowledge of common attack vectors, common security/fraud exploits, and countermeasures
  • Participating in post-mortem investigation of security and fraud incidents, preparing related incident reports documenting the findings and enhancing systems to reduce similar events
  • Initiated escalation procedure to counteract potential threats/vulnerabilities

Confidential

Network Support Analyst

Responsibilities:

  • Research, design, develop, operate and maintain support services for existing and new business applications and/or information systems solutions through integration of technical and business requirements per standard Confidential IT process methodology (such as ITIL and ITSM).
  • Responsible for completing a variety of assignments/tasks on a telecommunication helpdesk supporting LAN and wireless infrastructures support to USPS, Confidential end users and various functional areas such as Supply Chain, Research and Development, Marketing, Finance, a business, or the company for wireless related operational needs to complete business tasks.
  • Monitor, escalate, and resolve alarms for WLAN controllers, autonomous and Lightweight Access Points (LWAPs) using Wireless Monitoring Systems such as WCS navigator, WCS Servers, And Cisco Prime.
  • Log into wireless controllers to search for association and authentication of specific access points or other clients such as scanners or work group bridges.
  • Monitor and escalate Splunk alerts for Radius server when no Radius authentication have been processed on the server for a specified period of time which affects YMS VX8 Clients, DSS, PASS, and MPOS clients.
  • Troubleshoot wireless issues with the USPS sites which consisted of dead spots, antennas, Cisco Access Points, controllers, Cisco router, Cisco switches, radius authentication servers, and site gateways being down.
  • Call tracking and reporting to ensure that problems are resolved within SLA parameters.
  • End-to-end problem ownership. Provide moderator and operator assistance call services.
  • Open or take ownership of trouble tickets from Remedy/Service Now/Salesforce.com and resolve identified issues associated with telecommunications and/or application support.
  • Provide clear ownership and resolution of incidents/faults logged against applications supported by the application support team to agreed SLA's.
  • Ensure completeness of root cause of incidents and suggest improvements to mitigate future incident.

Confidential

Intrusion Detection/Security Analyst

Responsibilities:

  • Monitor real-time network traffic to identify abnormal and malicious activity using Splunk, Sourcefire IPS, Bluecoat Proxy, Fire Eye, and ArcSight SIEM.
  • Review daily logs data gathered from various resources (ArcSight 6.0, Enterasys IPS, Snort, Blue Coat Reporter 9.4.1, & McAfee EPO) and including but not limited to sensors alert logs, firewall logs, content filtering logs, Security Event Manager.
  • Validate traffic and/or network activity (per alerts/logs) as anomalous in accordance with previously established Standard Operating Procedure.
  • Monitors all spam emails, checking them for any malicious content, possible re-directional URL’s, spoofed sites along with monitoring spam emails for viruses, pulling the URL checking if it has been black listed and running it against Virus Total.
  • Stay in constant contact with the firewall team to adjust our ACL’s to alleviate the threats to our system. Research Bot-nets, DOS attacks and possible Malware downloaded on host machines.
  • Perform traffic queries and log analysis to identify malicious activity.
  • Collaborate with the Intrusion Prevention Engineers to update and create active channels and custom signatures.
  • Check the Data Loss Prevention Console (DLP) for unauthorized Personally Identifiable Information leaving the network.
  • Examine spam/phishing emails to clients and identify threats.
  • Conduct incident handling procedures and provided remediation solutions to eliminate vulnerabilities, viruses, malware, and possible system compromises.
  • Submit viruses to different vendors (McAfee, SOPHOS).
  • Re-categorize Malicious URLs on McAfee Web Gateway through Trusted source.
  • Perform risk assessment to prioritize intrusion events and other alerts. Process FLASH message.
  • Utilized MalZilla for exploring malicious pages. Also, used various malware and URL online scanning services (Virus Total, Sucuri SiteCheck, IPVoid, Jotti, URLvoid, Quttera, & urlquery).
  • Prepared Monthly reports for Security related alerts and trends”, also monthly reports for insertion into “US-CERT Report”.
  • Completed monthly report on the status and progress of all current problem tickets and ad-hoc assignments
  • Utilized McAfee e-Policy Orchestrator to examine systems for Virus and Pest Control infection and used Windows SCCM for system patches and maintenance status.
  • Inspected infected system using MS System Configuration Center Manager on SMS downloads, security patches and systems updates.
  • Submitted identified malware to vendors to add to Scan Engine DAT files and notified USCERT. Notified internal security Engineers to block identified malware on the proxy Firewall and Network/Host Monitoring tools.

Confidential

VSAT Engineer / Senior Desktop Analyst

Responsibilities:

  • Responsible for the installation, configuration, and support and troubleshooting of networks and VSAT systems.
  • Installed, configured and troubleshot/repaired all VSAT and network equipment. Gave support as necessary on a 24-7 basis to limit system down time during internal or external outages and peak enrollment periods.
  • Used Scrutinizer on multiple troubleshooting opportunities to isolate what type of traffic was causing the heavy utilization and also what offending devices were doing it. Used to protect the network against zero day threats, Bots, and Advanced Persistent Threats.
  • Monitored network bandwidth and traffic patterns Confidential an interface-specific level. Drilled down into interface level details to discover traffic patterns and device performance. Got real-time insight into the network bandwidth with one minute granularity reports.
  • Detected a broad spectrum of external and internal security threats using Continuous Stream Mining Engine technology. Tracked network anomalies that surpass our network firewall. Identified context-sensitive anomalies and zero-day intrusions using NetFlow Analyzer.
  • Analyzed IP service levels for network-based applications and services using NetFlow Analyzer IP SLA monitor. Ensured high level of data and voice communication quality using Cisco IP SLA technology. Kept a tab on key performance metrics of voice and data traffic.
  • Provide technical computer assistance to users by diagnosing and resolving problems for over 3,000 clients in Kandahar region by phone, remote support, or in person as needed to minimize downtime. The services included installation of PC’s, printers, scanners, and other PC peripherals.
  • Ensured that computers connect seamlessly with diverse systems including validation systems, file servers, email servers, application servers and administrative systems.
  • Deploy configuration files to Cisco routers, Cisco switches, and configure VoIP phones.
  • Image workstations using Desktop Deployment Planning Services with WinPE and Ghost images.

Confidential

Field Systems Technician/Support Specialist

Responsibilities:

  • Support over 2,000 users on a 24/7 rotation for off-hours responses to network issues.
  • Responsible for the remediation of any and all malware or viruses found on computers attached to our corporate network
  • Implemented and maintained Watchguard Firebox M Series Firewalls.
  • Provided after-hour and weekend support, on a rotation basis within a team, as needed to assist with operational duties and emergencies.
  • Handle all major or minor PC repair issues that included virus and spyware removal
  • Contributed to effectiveness of the Information Security Program by assisting w/ documentation and implementation of plans that deter security threats & minimize the impact of possible system breach.
  • Supported McAfee Anti-Virus by pushing recommended updates and patches out to end users also scheduling Virus scans.
  • Supported Microsoft Desktop applications including MS Exchange/Outlook/Active Directory.
  • Supported Citrix XenApp and Thin Clients, also managed Servers and Desktops in a virtualized environment
  • Imaged desktops and laptops using Norton’s ghost, also migrated users profile and data from PC to PC.
  • Worked with Active Directory (AD) management including forest and domain trust, operation master roles, domain controllers, group policy design, password policies, and PKI.
  • Contribute to the conversion of Windows XP desktops to Windows 7, assuring successful migration of application sets & user data, troubleshooting issues, deploying associated hardware and providing resolutions.
  • Configured and troubleshoot VPN connections for remote users logging into corporate network.
  • Perform hands-on fixes Confidential the desktop level, including installing and upgrading software, installing hardware, implementing file backups, and configuring systems and applications.
  • Audit, construct, test, document, and support LAN and wireless networks.
  • Perform scheduled server and hardware maintenance tasks as outlined in recurring task assignments.
  • Assist in ensuring backup systems are correctly functioning, tapes are rotated according to schedule, user data is protected and recovery practices are tested.

Confidential

Structured Cabling and Network Integration Field Technician

Responsibilities:

  • Remodels consisting of Countertop replacement, S/S upgrade, and Confidential install. Deleting and installing lanes. Installing new phone lines to offices off of 66 block and analog.
  • Provided functional and technical support, troubleshooting, and diagnosing hardware and software problems including desktop, laptop, WAN, LAN, and remote systems.
  • Imaged Laptops and Desktop PC's, completed final configuration for distribution to staff
  • Expertly installed, configured, monitored and troubleshot PC's and related hardware on all OS platforms.
  • Procured, received, documented, and tracked inventory of all computer equipment and software licenses.
  • Identified, removed computer viruses, and provided major repairs in accordance with outside vendors.
  • Planned installations by surveying and evaluating location; identifying installation requirements; laying-out equipment and wiring plan.
  • Installed IDF’s, Cisco switches, Muxlab, Altronics, Distribution amps, Variants, and power supplies; ran and pulled wiring (cat5); programmed and calibrated equipment; adhere to codes, regulations, and standards.
  • Installed and terminate data communication cabling, including Cat 3, 5E/6, LMR 400, and Coax, 66/110 blocks
  • Verify system is functioning by testing equipment, connections, and signals; identifying and correcting problems.
  • Supervised the work of junior and senior technicians.

Confidential

Automated Tactical Data System Specialist

Responsibilities:

  • Provided preventative maintenance, troubleshooting, and quickly resolves moderately complex problems to ensure user satisfaction.
  • Anti-Virus reporting 24/7, to include review of logs, open tickets, recommended process for remediation
  • Performed system administration, troubleshoots and determine solutions for multiple versions of Windows operating systems, both local and remote.
  • Operating field artillery tactical data systems on a Multiple Launch Rocket System (MLRS) Team.
  • Support infantry and tank units while supplementing cannon artillery in combat.
  • Launch various missiles and ammunitions in quick strikes during combat.
  • Used Power point and Excel for working with Supply in tracking and accessing products/equipment
  • Established, maintained, and operated communications systems and received assistance in the preparation of over 4 computer centers and satellite sites for operations.
  • Performed computer operations, fire mission processing, fire plan schedules, and database construction.

We'd love your feedback!