Vulnerability Specialist (vat) Resume
0/5 (Submit Your Rating)
Washington, DC
OBJECTIVE:
- Seeking a full - time position in the field of information technology where a strong background in Cyber Security, computer hardware/networks, effective communication skills, and a complete knowledge of network security and operating systems can be fully utilized to improve operations and offers professional growth.
PROFESSIONAL SUMMARY:
- Results oriented, energetic, highly motivated team player with 6 years of Information technology experience. Excellent data analysis and expert skills in computer networking, cyber security and computer internet security. Solid background in performing under pressure with outstanding results with good communication skills.
- Computer Networking
- Internet Security
- Window 7 and 10 Admin
- Risk Management Framework
- ACAS administrator
- Professional and Development
PROFESSIONAL EXPERIENCE:
Vulnerability Specialist (VAT)
Confidential
Responsibilities:
- Perform Vulnerability verification through remediation scan to make sure vulnerability has been mitigated.
- Identify Vulnerability incident based on findings in security center and follow up to resolve them.
- Perform site initiation, create organization, ; create user account, add IP address to repository, scan zone and asset list so subscribers can run their scans.
- Conduct monthly vulnerability reports and email to subscribers to stay in compliance with DISA best practice.
- Check job Queue for all servers on low sites to make sure no scans are running more than 24 hours and
- Run remediation scans as requested to mitigate any threat and email scan reports and scan results for subscribers to keep them updated on scans credentials.
- Work with other teams, CLOUD, PITT, WATCH and Mission Team to resolved ACAS issues.
- Identify problems and Work with organizations to resolved them in other to stay compliance.
- Review, analyze and document any cyber-attack (posture) at subscriber's sites.
- Work with problem management staff to identify corrective actions to the root cause and track them to closure
- Help clients with ACAS access, unlock their account and delete accounts as 6requested.
- Reviewed NIPRNet and SIPRNet Dashboard to identify and prioritize current tasks for ACAS environment
- Assist subscribers with ACAS related issues, help them walk through to resolved issue.
- Investigate IPs Address and white list IPs through ACL.
- Follow up with clients to make sure their request was satisfied either by phone or email.
- Performed vulnerability analysis and system reporting support
- Reviewed team Dashboard for Jira Tickets, Assigned Tickets to myself, resolved ticket issue, complete ticket and closed ticket or reassigned ticket.
- Reviewed, identifying and verifyingCMRS configuration forsubscriber sites
- Perform research and conduct assessments of emerging threats, troubleshoot requests from or incidents from tickets.
- Establish and maintain communication with all stakeholders and parties to the resolution during and immediately following the incident.
- Maintain situational awareness of the incident status and impact, and provide the latest information through the Government communication and command structure.
- Evaluated subscriber network cyber posture against vulnerability and make sure they stay compliance.
- Reassigned or escalated the ticket when tasked completed or closed the ticket if required to do so.
Cybersecurity Analyst
Confidential, Washington DC
Responsibilities:
- Maintain the information assurance program for enterprise services by enforcing command IA policies and procedures in accordance with DHS policies and guidelines.
- Implement the operation system support network security program by conducting and verifying appropriate security test and vulnerability scans on a regularly scheduled basis.
- Provide a regularly updated list of systems scanned and individual scan results.
- Provide scan results to system engineers for mitigation efforts.
- Maintaining configuration items and executing functions on vulnerability management platform, to include ACAS, Nessus, STIG Validation Scans and Manual Checks.
- Assist in annual Command Cyber Operational Readiness Inspection and provide risk assessment analysis support.
- Create essential documentation (procedures, scanning reports, remediation reports, etc.), providing analysis and metrics on vulnerabilities, and driving remediation of vulnerabilities throughout the organization.
- Identify Major IT incident Events, based on reporting from SOC work centers both internal and external to the program.
- Receive notification of an issue, either from a user calling the Help Desk or from staff observation, and triage the incident and run it to completion.
- Pull in the responsible parties (internal or external) to diagnose, fix, and communicate the IT problem/status/resolution.
- Establish and maintain communication with all stakeholders and parties to the resolution during and immediately following the incident.
- Provide IT incident coordination, track investigation and provide resolution activities across participating teams.
- Maintain situational awareness of the incident status and impact, and provide the latest information through the Government communication and command structure.
- Work with problem management staff to identify corrective actions to the root cause and track them to closure.
- Using passage point to check for employee s status and contractor s access level. Authorized access be granted or denied to employees or contractors.
- Attend meetings and provide recommendations concerning Risk Management and mitigation efforts for organizational assets.
- Facilitate proactive remediation of new vulnerabilities by collecting information from threat and vulnerability feeds, analyzing the impact/applicability to our environment and communicating applicable vulnerabilities and recommended remediation actions to the impacted teams.
- Provide technical support to system and technology owners to propose mitigation and remediation solutions.
Confidential, Washington, DC
Responsibilities:
- Responsible for identifying and classifying cyber security vulnerabilities and work on mitigation plans with system owners, ensure plans are documented understood and track the results of the plan execution
- Perform policy compliance scans and deliver reports to the technology owners
- Ensure the network monitor and building access is used by authorized individual and
- Create and maintain comprehensive documentation for all implemented networks.
- Analyze network alarm monitor and traffic and capacity requirements.
- Report all suspicious activities to DHS Mega center, document all incident and inform local law enforcement authorities
- Information assurance/cyber security duties. (RMF, EMASS, and ACAS)
- Administer network security and/or maintain network security appliances.
- Maintains access codes and other computer security controls used to insure appropriately limited access to computer software and data.
- Maintains a comprehensive Systems Security Authorization database that encompasses all platforms and systems.
- Issue personal identity verification (PIV) card to new employees, contractors, grant access to facility through their PIV card and denial access and cancel PIV, upgrade employees badges from secret clearance to top secret to grand them access base on clearance.
- Provide analytical support to critical infrastructure incident response activities led by the Department of Homeland Security (DHS), Office of Cyber an
- Work with Information Security team and update Security Standards for all technologies ( Databases, Operating Systems & Network devices)
- Help build/improve an exception process to manage policy compliance deviation
