We provide IT Staff Augmentation Services!

Sr. Information Security Engineer/ Siem Engineer Resume

0/5 (Submit Your Rating)

Farmington Camden, NJ

SUMMARY

  • Experienced Professional as an IT Security Professional in IT Infrastructure, Risk security, Information Security, and Cyber Security.
  • Information - security expert with Confidential diverse technical background in enterprise networking, server infrastructure, database technologies, and system security.
  • Experience in configuration management and policy implementation.
  • Experience in vulnerability scanning g with relevant tools e.g., Nessus, HPE Fortify for SCA (Static Code Analysis) and Web Inspect, and Rapid 7 Nexpose.
  • Experience in managing Network infrastructure security using HPE Arcsight ESM/ Splunk for monitoring and classifying and responding to incidents and threats.
  • Strong knowledge of risk management and computer forensic tools, technologies, and methods. Experienced in IT security design and implementation with Confidential solid understanding of disaster recovery, intrusion detection systems (IDS), intrusion protection systems (IPS), and web application firewalls (WAF). Analytical problem solver adept at managing network changes and troubleshooting network issues to ensure maximum up time.
  • Experience in in OSINT and TECHINT reconnaissance.
  • Working as Confidential VMware andWintelserver DatacenterEngineer, facilitating Datacenter (DC) migration.
  • Developed and implemented Confidential global IT general risk controls framework to ensure compliance (COBIT, NIST 800) for the organization and other governance guidance documentation.
  • Generated notification based on different templates on record content values using RSA Archer.
  • Thorough Understanding of Identity and Access Management Fundamentals.
  • Experience with Identity IQ lifecycle manager, applications onboarding, certifications, and workflow.
  • Supports to generate all kinds of reports and extensively used in the workspace dashboards using RSA Archer and Force point.
  • Experience configuring and deploying modules and products like McAfee ePO, McAfee VSE, McAfee HIPS, McAfee Endpoint Encryption, McAfee Network DLP, McAfee DLP Endpoint, McAfee SIEM.
  • Tracks all the incidents happened in all the stores and used for recovery and settlements using RSA Archer.
  • Working knowledge of McAfeeNitroSIEM and log management technologies.
  • Experience with Risk assessment using Industry standards like NIST Rev3 and Rev4, HIPPA, PCI/DSS and develop Security policy as per these standards.
  • Daily Data feeds to have up to date locations information of all the stores using RSA Archer.
  • Leveraged Amazon Web Services through AWS console and API Integration.
  • Experience with SOC and all time operations.
  • Knowledge of distributed Splunk installation with Forwarders, Clusters, Search head cluster.
  • Skilled with Penetration testing (white, grey, and black box) with passive and active modules using Burp suite, Metasploit, custom scripts, and other necessary tools.
  • Recommend remediations for flaws discovered in the penetration test.
  • Expert understanding on the Cyber-Kill-Chain and APT.
  • Experience with network monitoring with SIEM IBM QRadar and Wireshark, Information Security & Network security configuration and functions.
  • Experience in configuring deployment server, Splunk Apps and add-ons.
  • Hands on experience with several vulnerability forms i.e., SQL injection, XSS etc.
  • Hands on Experience with Security frameworks such as NIST, HIPAA
  • Experience with NIST SP Confidential and NIST SP .
  • Experience in Paulo Alto Firewall, VPN’s, and networking with protocols i.e. NetBIOS, SNMP, telnet, SSH, ARP, etc.
  • Senior Engineer for Microsoft Office 365 Tenant messaging environment comprised of 100,000 objects.
  • Experience with industry recognized SIEM (Security Information and Event Management) solutions such as IBM QRadar, Splunk, and LogRhythm.
  • Perform vulnerability scan with Nessus for improper configurations, missing patches, hosts, network, and insecure credentials and accounts.
  • Experience with HPE Fortify for code Vulnerability analysis reviews and Web Inspect scan.
  • Experience with application security.
  • Excellent understanding of SAST, DAST, IAST and RASP best practices.
  • Having hands on experience for Documentation and log analysis
  • Experience and better understanding of scripting languages, command shells and regular expressions such as Python.
  • Installing Maintenance Levels and updates onWintel/Windows Platform.
  • Experience with identity and access management solutions such as LDAP, Active Directory, XAML, SAML and multi factor authentication
  • Excellent understanding of computing environments Linux: RHEL-7/DEB-KALI, Windows 7/10, Server 2012/2016 and Unix Operating systems.
  • Perform Risk Assessment, Gap analysis & create Risk Mitigation plan.
  • Strong understanding of enterprise, network, system/endpoint, and application-level security issues and risks.
  • Delivered more than 30 migrations from on premise Exchange platforms to Office 365.
  • Oversee Vulnerability assessment / penetration testing of scoped systems and applications to identify system vulnerabilities.
  • Excellent knowledge of FISMA, HIPAA and NIST Compliance usage, rules and regulations
  • Use IBM QRadar Security Manager to identify threats and assigned category.
  • Solid Understanding of IBM QRadar, Palo alto NGFW and SDLC
  • Having Strong understanding of DLP Architecture.
  • Provide support in security architecture, design, developing, monitoring and supporting enterprise infrastructure environment
  • Experience with supporting Business and Third party Risk Assessment
  • Antivirus McAfee Virus Scan Enterprise, Symantec Endpoint Protection Suite

TECHNICAL SKILLS

DLP: Websense, Symantec & McAfee

End Point Security: McAfee Suits (VSE, HIPS & HDLP), McAfee MOVE AV, Symantec McAfee Email Security Gateways GUI & CLI (1 year)McAfee Network Data Loss Prevention (2 years), McAfee NITRO SIEM - Security Information and Event Management (1 year)

IPS/IDS: McAfee IPS, Secure Works IDS/IPS, SNORT

SIEM: IBM QRadar security manager, Splunk, LogRhythm, IBM QRadar 7.3.2, Basic knowledge on MacAfeenitro

MSS: Vulnerability Assessment, Content Filter, Antispam, IDS/IPS Management

Vulnerability Management Tools: Nessus, Nmap, Nexpose, Wireshark, Fortify

Security Tools: IBM QRadar, McAfee Vulnerability management solutions, Nessus, Solarwinds, LogRhythmPlatforms/Applications: Continuous MonitoringVulnerabilityManagement, Web Application Scanning, ThreatProtect, Policy Compliance, Cloud Agents, AssetManagement, Governance, RiskManagementand Compliance, Solarwinds, Nexpose, Rapid7EventManagement RSA Archer, Blue Coat Proxy, IBM QRadar, NTT Security, LogRhythm, PenTest Tools Metasploit, Burpsuit, NMAP, Wireshark and Kali

Security Software: Nessus, Ethereal, NMap, Metasploit, Snort, RSA Authentication

Networking: LAN, WAN, Wi-Fi, DNS, WINS, DHCP, TCP/IP, ISCSI, Firewalls/IPS/IDS

Protocols: TCP/IP, L2TP, PPTP, IPSEC, IKE, SSL, SSH, UDP, DHCP, DNS, NetBIOS, SNMP, TLS etc.

Operating System: Windows, Linux, Unix

Security Intelligence: WhiteHat Web Security, iDefence, NTT Security, LogRhythm

PROFESSIONAL EXPERIENCE

Confidential, Farmington Camden NJ

Sr. Information Security Engineer/ SIEM Engineer

Responsibilities:

  • Responsible for capturing security and privacy requirements for clients to be compliant with Payment Card Industry (PCI).
  • Experienced with DLP, Bluecoat websense, Proofpoint, Trend Micro, and IBM QRadar Enterprise SIEM security tools to monitor network environment
  • Assisted engineers with IBM QRadar troubleshooting and deployment
  • Created IBM QRadar dashboards for investigations
  • Perform QRadar product support and implementation
  • Hands on experience with the Deployment of Imperva Web Application Firewall (WAF)installing, configuring including the administration of SecureShpere portal.
  • Automated the centralized detection of security vulnerabilities with scripts for Vulnerability assessment tools like Arc Sight and Splunk.
  • Hands on with SSO protocols, specifically SAML v2, Open ID Connect.
  • Provide expertise with incident response, security event monitoring, vulnerability management, asset security compliance and data loss prevention utilizing McAfee Nitro (SIEM), McAfee ePO, McAfee DLP. coverage in regions of operation, mapping includes frameworks such as NIST,COBIT, GDPR, Security Advisories
  • Managed Multi-tenant platforms for Office 365 Enterprise level tenant.
  • Provide Level 2 Operations support for end user resolution investigating RSA Archer events to determine any true intrusions (Cyber Ark combined).
  • IdentityGovernance and Administration through Sail PointIdentityIQ, Privilege Access Management utilizing Cyber Ark Privilege Application Security (PAS)
  • Experience in supporting Symantec EndpointProtection 12.1 workstation clients in an enterpriseenvironment. Installation, configuration, and day-to-day management of Symantec EndpointProtection.
  • Extensive Experience with Symantec DLP and RSA DLP architecture and implementation for enterprise level.
  • Hands-on experience withNitro(ESM),
  • Experience with identity and access management solutions such as LDAP, Active Directory, XAML, SAML and multi factor authentication
  • Provided support and management forWintelserver operations in physical and virtual environments through the use of Hyper-V and vSphere
  • DevelopedCyber SecurityStandardson NIST Frameworksand insured their proper implementation to reduce the risk of vulnerability to IT assets.
  • Monitoring and remediating daily security alerts generated by end users with the tools like Intel/McAfee SIEM, Force Points Websense, and Intel/McAfee EPO and also responsible for effectiveness of tools and scans, as well as assessing and tracking risk of exposure.
  • Monitor client environment using Security Event and Information Management (SIEM) IBM QRadar technology to centralize the storage and interpretation of logs; collect data into Confidential central repository for trend analysis and provide automated reporting for compliance and centralized reporting, which provides more situational awareness and real-time analysis of security alerts. user authentication to client and internal users leveragingPingFederate (PingIdentity) and SSO support for employees via ADFS 3.O for accessing O365 applications
  • Coordinate and conduct event collection, log management, event management, compliances automation, and identity monitoring activities using SIEM platform.
  • Performed audits using HIPAA, SSAE 18,COBIT, COSO, PCI DSS and SOX Frameworks.
  • Experience with Risk assessment using Industry standards like NIST Rev3 and Rev4, HIPPA, PCI/DSS and develop Security policy as per these standards.
  • Develop, implement, and execute standard procedures for administration, content management, change management, version/patch management, and lifecycle management of the SIEM.
  • Hands on with SSO protocols, specifically SAML v2, Open ID Connect.
  • Hands on experience in QRadar and MacAfeenitroSiem.
  • Troubleshoot installation, network connectivity, certificate validation, DNS Record issues, and integration issues with Lync and Office 365 products.
  • Support day to day event parsing and repairing of events that have missing or incorrect information, create log sources extensions, and flow management.
  • Create and develop correlation and detection rules within SIEM to support alerting capabilities within the Threat Management Center.
  • Consult clients on automating business processes & risk management activities in theRSAArcherGRC platform.
  • Successfully Worked with Ping identity professional services in establishing multi factor authentication in the organization.
  • Create technical detailed reports on the status of the SIEM to include metrics on items such as number of logging sources, log collection rate, and server performance.
  • Review risk assessments completed by security team based on National Institute of Standard and Technology (NIST) and International Standard Organization (ISO) by using its methodology is based on the PDCA cycle, which builds the management system that plans, implements cyber security, maintains, and improve the whole system.
  • Monitoring using Splunk/ Wily Introscope and setting up Web Sphere Global Security for access to the adminconsole. Configuring theHTTPServer for various clustered application servers using virtual hosting and enabling SSL security.
  • Consult clients on automating business processes & risk management activities in theRSAArcherGRC platform.
  • Installation and Configuration of SIEM Product (Arcsight, RSA Envision, McAfeeNitroAnd NetIQ Sentinel)
  • In-depth knowledge of Sarbanes-Oxley Act, HIPAA, FISMA, PCI DSS, COSO andCOBITframework methodologies for designing and validating business process controls
  • Configuration ofMcAfeeAntivirus products on end-points (Clients/Servers).
  • Perform proxy policies management Bluecoat.
  • Perform proxy authentication with ACL.
  • Working on federation single sign on between third party vendors making both inbound and outbound calls security exchanging the attributes in SAML both asIdentity and Service provider
  • Configuration of the RSAArcherplatform with effective solutions and applications that support variety of business needs and to achieve organizational objectives.
  • Assist penetration testing and investigation.
  • Designed Symantec DLP architecture, implemented Symantec DLP.
  • Worked with Symantec DLP upgrades and patches.
  • Implementation with NIST SP Confidential and NIST SP .
  • Perform vulnerability scans using Nessus and prepare reports.
  • Static Code analysis (SCA) for present vulnerabilities and Web Inspect for servers with HPE Fortify.
  • Perform log analysis utilizing IBM QRadar and various other security software and tools
  • Manage IBM QRadar configuration files like inputs, props, transforms, and lookups. Upgrading the IBM QRadar Enterprise and security patching. management console also supporting day to day security operation function by managingNitroSecurity (McAfee Acquired) SIEM
  • Create policies, alerts and configure using SIEM tools
  • Assist with vulnerability scans and reporting to clients and IT departments, use of Nessus scan and Report, Review the vulnerability scan that affects the assets and find critical devices that have critical vulnerability
  • Manage enterprise security systems, identifying key security risks, reporting risks to management with recommendations for corrective action utilizing NIST frameworks.
  • Work experience with IT policies, procedures, and standards are related to doing security review using the NIST standard specifically with NIST and NIST for HIPAA security rules. Review the Logs for malicious user activities
  • Complete security project management to ensure that clients remain on track for their annual security assessments.
  • Create advanced dashboards, alerts and visualizations using Splunk environment.
  • Advanced administration of Splunk platform, installation and configuration of apps and add-on.
  • Implement solutions as Confidential part of the project support which include EventSentry SIEM, Nessus Vulnerability scanner and Palo Alto Firewall.
  • Deploy IBM QRadar SIEM from scratch for security log monitoring and alerting in production environment including switches, routers, firewalls, load balancers, VPN and expand the deployment to the corporate domain.
  • Configuring Dashboards, Reports, Notifications and Real time alerts in McAfeeNitroSIEM.
  • Experience with Risk assessment,CobitI help Malware Analysis.
  • Perform incident response on requirement with defined policies.
  • Manage and Maintain Nessus Vulnerability scanner 6.11.0, add additional scan engine to Confidential production environment and identify gaps in patching.
  • Create dynamic groups for discovered assets by asset location and operating systems to run full system audit scans.

Information Security Engineer/cyber security engineer

Confidential, NY

Responsibilities:

  • Responsible for monitoring and, providing analysis in Confidential 24x7x365 Security Operation Center (SOC) using various SIEM, IDS/IPS tools.
  • Perform and maintain SAST, DAST, IAST and RASP best practices.
  • Assist with the development of process and procedures to improve incident response times, analysis of incidents, and overall SOC functions.
  • Provide network intrusion detection expertise to support timely and effective decision making of when to declare an accident.
  • Different kinds of calculations, text, date, attachments, sub-form, cross-references, record permissions and values list fields were created using RSA Archer.
  • Assisted engineers with Splunk troubleshooting and deployment
  • Created Splunk dashboards for investigations
  • Document all activities during an incident with status updates during the life cycle of the incident.
  • Implement(SAML)XML-based standard for exchanging authentication and authorization data between security domains
  • Create, modify and tune the McAfeeNitroSIEM rules to adjust the specifications of alerts and incidents
  • Documented IT general and application processes and developed and identified key internal controls which address the organization's risk areas under SOX 404 compliance using COSO andCoBiTguideline
  • Analyze network and host-based security appliance logs (Firewalls, NIDS, HIDS, Sys Logs, etc.).
  • Provide information regarding intrusion events, security incidents, and other threat indications and warning information.
  • Monitor security tool dashboards for breaches, events, and other incidents occurring in the environment.
  • Worked on Enterprise UsersSingleSign Onthrough browser and through services with third party application hosted in enterprise or cloud using Ping Federate, Ping One
  • Including Outlook 365 mail and domain change for all PCs.
  • Helped to set-up Microsoft Office 365 infrastructure on both PCs and mobile devices.
  • Installing, patching and maintaining McAfee EPO 5.X and DLP, utilizing McAfee Orchestrator, and able to deploy DLP and reporting and working knowledge in ENS 10.
  • Monitoring and remediating daily security alerts generated by end users with the tools like Intel/McAfee SIEM, ForcePoints Websense, and Intel/McAfee EPO 5.X and also responsible for effectiveness of tools and scans, as well as assessing and tracking risk of exposure.
  • Experience with Risk assessment using Industry standards like NIST Rev3 and Rev4, HIPPA, PCI/DSS and develop Security policy as per these standards.
  • Working on federation single sign on between third party vendors making both inbound and outbound calls security exchanging the attributes in SAML both as identity and service provider
  • Managed Cyber Security threats through prevention, detection, response, escalation and reporting in effort to protect Enterprise IT Assets through Computer Security Incident Response Team (CSIRT).
  • Configured and Implemented rules in SIEM based on Global Threats. Designed test cases to detect various attacks as per client requirements.
  • IntegratedNitroLog sources on customer critical servers/devices
  • Experience with Risk assessment,CobitI help Malware Analysis.
  • Responsibilities for CSIRT included SIEM, Context Filtering, Web Security, Arc Sight, Incident Tracking, IPS/IDS and Malware Analysis.
  • Generated notification based on different templates on record content values using RSA Archer.
  • Supports to generate all kinds of reports and extensively used in the workspace dashboards using RSA Archer.
  • Tracks all the incidents happened in all the stores and used for recovery and settlements using RSA Archer.
  • Supported development with integration of Mobile Apps using OAuth/SAMLin Ping Federate.
  • Resolved tenancy technical issues and monitored Office 365 systems.
  • Provided leadership in architecting and implementing security solutions towards Qualys and SIEM tools like Splunk, Solutionary, LogRhythm, SCCM, Altiris, LanDesk, BigFix, and McAfee/Symantec.
  • Implemented remediation solutions for standards like PCI-DSS, ISO 27000 series andCoBIT
  • Push configurations and updates to multiple Splunk Enterprise instances via the Splunk Deployment Server
  • Experience withSIEMplatforms (Splunk, QRadar, McAfee/Nitro, Arcsight, LogRhythm, Carbon Black)
  • Had to deal with SIEM solutions such as Rapid7 Nexpose, Force point, Splunk
  • Daily Data feeds to have up to date locations information of all the stores using RSA Archer.
  • Network Admin, logging and securing network data using RSA Archer (TCP/IP data analysis).
  • Design DLP architecture and handle Third party Risk Assessment and ManagedSOXaudits
  • Facilitated FISMA Continuous Monitoring Test Cases NIST Rev 4 Update.
  • Configure and Install IBM QRadar Enterprise, Agent, and Apache Server for user and role authentication and SSO.
  • Implemented Symantec DATA Loss prevention to secure all end points. Configured and instrumented Symantec management console, Symantec management server and Symantec database on Oracle.
  • Perform command line scripting in Linux and UNIX to configure Splunk.
  • Performed real-time proactive Security monitoring and reporting on various Security enforcement systems, such as IBM QRadar (SIEM), McAfee, Internet content filtering/reporting, malware code prevention HPE Fortify, Firewalls, IDS& IPS, Web Security, Anti-spam and Fire Eye
  • Imported existing information from legacy systems into RSAArcherApplications and questionnaire. Integrated the RSAArcherwith External data sources with WebAPI.
  • Managed and coordinated activities for multiple Data privacy information security.
  • Responsibilities for CSIRT included SIEM, Context Filtering, Web Security, Incident Tracking, IPS/IDS and Malware Analysis.
  • Skilled in working with distinct SIEM platforms including Arc Sight,Nitro, LogRhythm, QRadar, and Splunk
  • Worked with the implementation team on Office 365.
  • Support IT teams based on latest risks and possible remediation. Involved in integration of Splunk with Service Now, Active directory and LDAP authentication
  • Used Splunk Deployment Server to manage Splunk instances and analyzed security based events, risks & reporting.
  • Deploy, configure and maintain IBM QRadar forwarder in different platforms.
  • Ensuring that the application website is up and available to the users.
  • Continuous monitoring of the alerts received through mails to check if all the application servers and web servers are up.
  • Experience with SymantecDLPand RSADLParchitecture and implementation for enterprise level. Designed SymantecDLParchitecture, implemented SymantecDLP. Worked with SymantecDLPupgrades and patches. Implemented SymantecDLP Policy and Content Blade creation and tuning. Provided input into customer's operational and processes and procedures. management console also supporting day to day security operation function by managingNitroSecurity (McAfee Acquired) SIEM
  • Responsible for testing vulnerability updates for all releases and patches of IBM QRadar SIEM.
  • Integration of IDS/IPS to SIEM and analyze the logs to filter out False positives and add False negatives in to IDS/IPS rule set.
  • Develop content for IBM QRadar like correlation rules, dashboards, reports and filters, Active lists and Session list.
  • Configure Symantec Critical System Protection IDS to forward logs to IBM QRadar for File Integrity Monitoring. Configured remote logging to IBM QRadar with flexible fields.
  • Responsible for testing and implementation IBM QRadar with setup to AD (Active Directory) and LDAP.
  • Troubleshooting the issues which are related to IBM QRadar.

Cyber Security Engineer/ Vulnerability analyst

Confidential

Responsibilities:

  • Conducted onsite penetration tests from an insider threat perspective.
  • Performed host, network, and web application penetration tests.
  • Analysis of Offenses created based on vulnerability management tools such as: Rapid7
  • Developed Black Box Security test environments & conducted tests as part of team for precautionary measures.
  • Developed approaches for industry-specific threat analyses, application-specific penetration tests and the generation of vulnerability reports.
  • Information protection solutions including Monitoring, DLP and Security Auditing solutions from Symantec and McAfee.
  • Configuring Dashboards, Reports, Notifications and Real time alerts in McAfeeNitroSIEM.
  • Conducted Security Risk Assessment on all new applications, IT Systems or changes to existing IT systems to verify if they satisfy established security baseline before adoption into Corporate Regional offices.
  • Conducted Security Risk Assessment on new Vendors and annual Vendor Risk Assessment.
  • Assisted management in authorizing the IT Systems for operation on the basis of whether the residual risk is at an acceptable level or whether additional compensating controls should be implemented.
  • Designed processes inArcherusing workflows, notifications, and data feeds.
  • Assisted teams in the design and development of management reporting and dashboards from the designed solution inArcher.
  • Coordinated with system owners and ISSOs across the organization to ensure timely compliance
  • Participated in meetings to discuss system boundaries for new or updated systems to help determine information types for categorization purposes. Determined the classification of information systems to aid in selecting appropriate controls for protecting the system.
  • Worked with Palo Alto Panorama management tool to manage all Palo Alto firewall and network from central location.
  • Create, modify and tune the McAfeeNitroSIEM rules to adjust the specifications of alerts and incidents
  • DevelopedCyber SecurityStandardson NIST Frameworksand insured their proper implementation to reduce the risk of vulnerability to IT assets.
  • Performed risk assessments to ensure corporate compliance.
  • Developed detailed remediation reports and recommendations for compliance and security improvements across industries based on changing threats.
  • Performed Vulnerability Assessments and Data Classification and their impacts
  • Suggested the Patches for windows machines with vulnerabilities identified.
  • Performed application security and penetration testing using IBM Appscan.
  • IntegratedNitroLog sources on customer critical servers/devices
  • Performed security reviews of application designs, source code and deployments as required, covering all types of applications (web application, web services, mobile applications, thick client applications, SaaS)
  • Participate in Security Assessments of networks, systems and applications.
  • Reviewed and involved in the Web Sphere Application server hardening process from Security Team.
  • Utilized monitoring tools to identify cyber security alerts of active threats, intrusions, and compromises

Environment: Linux, White Hat Security Source, Nessus, Wire Shark, Sql Map, Checkmarks, Nmap, Metasploit, AWS Cloud Watch and Stack Driver, Rapid 7

System Administrator

Confidential

Responsibilities:

  • Configure and install various network devices and services (e.g., routers, switches, firewalls)
  • Administering, configuring and troubleshooting of Windows Server 2008, 2012.
  • Installation, Configuration and Administration of Web Servers (IIS and Apache)
  • Design, implement and maintain VMware vSphere infrastructure.
  • Infrastructure Development on AWS by employing services such as EC2, RDS, Cloud Front, Cloud Watch,
  • VPC, etc.
  • Security Audit, Budget Violation, Operational Violation, Best practice check in client AWS environment.
  • Coordinated with Network Administrator regarding BGP/OSPF/EIGRP routing policies and designs, worked on implementation strategies for the expansion of MPLS VPN networks.
  • Troubleshooting the Network Routing protocols (BGP, MPLS EIGRP and RIP) during the Migrations and new client connections.
  • Responsible for notifying systems owners of potential events and remediation. Responsible for drafting and conducting daily briefings to customers.
  • Designing and maintaining production-quality Splunk dashboards.
  • Working with Client teams to find out requirements for their Network Requirements.
  • Monitor performance of network and servers (Microsoft and Linux) to identify potential problems and bottleneck.
  • Real time monitoring and network management using Cisco Works LMS and Solarwinds.
  • Provided technical support on hardware and software related issues to remote production sites.
  • Coordinated and managed team activities during assessment engagements.
  • Established schedules and deadlines for assessment activities.
  • Monitored controls post authorization to ensure continuous compliance with the security requirements.
  • Developed Cyber Security Standards on NIST Frameworks and insured their proper implementation to reduce the risk of vulnerability to IT assets
  • Updated the controls changes from NIST rev 3 to NIST rev 4 and control assessment changes from NIST Confidential to NIST 53A rev4
  • Assisted in deployment of AWS (Amazon Web Services) database and encryption, reducing operational costs by 50%.
  • Configuration, installation and support of equipment in Confidential MS Environment to terms of client proposals.
  • Installation, configuration and administration of Asterisk based VOIP Telephony
  • Troubleshoot and resolve computer/network issues by providing both on-site and remote support.
  • Maintaining software applications, operating systems Win2K, Win XP, Win2007, and Linux.
  • Responding to inquiries from staff, administrators, service providers, site personnel and outside vendors
  • And to provide technical assistance and support.
  • Supervising administration of systems and servers to ensure availability of services to authorized users.
  • User administration, setup, maintaining system and verifying peripherals are working properly.
  • Quickly arrange repair in occasion of hardware failure and Monitor system performance
  • Install software & create Confidential backup and recovery policy & Updating Antivirus and its Patches.
  • Administering multi Server windows LAN, WAN.

We'd love your feedback!