Sr. Security Consultant | Principal Resume
Silicon Valley, CaliforniA
SUMMARY:
- Technically sophisticated, high - performance IT professional with strong background implementing, supporting, and managing complex enterprise LAN | WAN networks. Skilled in directing multiple tasks effectively and managing complex Linux based networks utilizing Cisco Network technologies and security protocols. Proven track record of providing technical support and handling equipment installations and upgrades; monitoring, configuring, and administering network security operations. Keen ability to analyze technical needs and develop appropriate solutions to maximize system performance.
- Network Security Monitoring | Incident Response | Vulnerability Management
- Penetration Testing | Threat Intelligence | Target Profiling | Firewall Change Management
TECHNICAL SKILLS:
Platforms: RHEL | CentOS | Check Point GAiA R77 | KALI Linux | HP Webinspect
Arcsight SIEM solutions | IBM Qradar SIEM | Tripwire nCircle 360 | Rapid7 Nexpose
Applications: Metasploit | Maltego |
Hardware: Cisco | Check Point Secure Gateway | Fortinet | QualysGuard |
PROFESSIONAL EXPERIENCE:
Confidential, Silicon Valley, California
Sr. Security Consultant | Principal
Technical Scope: Vulnerability Assessment, Penetration Testing
Responsibilities:
- Performed automated scanning of low risk web applications
- Performed QA analysis on findings results to suppress false positives
- Researched vulnerabilities and remediation steps to assist application teams
Confidential
Qualys Lead
Technical Scope: Qualys Enterprise, HP Service manager, System Center Configuration Manager (SCCM)
Responsibilities:
- Successfully remediated all active vulnerabilities within all server environments one month ahead of schedule.
- Completed Vulnerability Analysis on entire server environment to determine level of effort for full scope remediation of all current vulnerabilities.
Confidential
Security Consultant - PCI Remediation
Technical Scope: PCI-DSS 3.2 implementation and process creation
Responsibilities:
- Created process to perform anti-tamper inspection on all Payment Capture Devices owned by the Client.
- Developed procedure to utilize Qualys devices to assist in managing the CDE inventory as part of the Inventory Management Process.
Confidential, San Francisco, California
Security Consultant - Vulnerability Management
Technical Scope: Tripwire nCircle360, Rapid7 Nexpose, Rapid7 Metasploit
Responsibilities:
- Responsible for creating a new vulnerability scan profile that incorporates entire corporate IP space. Created new vulnerability scan templates to assist in detection of zero day vulnerabilities.
- Developed Proof of Concept for Rapid7 Nexpose deployment, including: detailed integration processes for other platforms (Splunk, Imperva), demonstrated the features and usage of Metasploit and Nexpose to assist with the detection and exploitation of vulnerabilities, and utilized the features of Nexpose to demonstrate the entire lifecycle of the vulnerability management process from detection to mitigation and post mitigation reporting.
Confidential, San Francisco, California
Security Program Manager - Firewall
Technical Scope: Cisco Security Devices (ASA, FWSM, ISE, NAC)
Responsibilities:
- Refined Firewall Exception process to a 50% average decrease in firewall exception request cycle time within the first quarter, and maintained that level continuously.
- Drove process to update all stale firewall tags, lowering the average from 8 stale tags to an average of less than one for 17 consecutive weeks (first quarter onward)
- Managed firewall exceptions from over a 30-day average cycle time to a current average of 11 days, with a steady decline over the past 3 quarters.
Confidential, Farmington Hills, Michigan
Network Consultant
Technical Scope: Cisco | Check Point SG
Responsibilities:
- Drove project to gather existing application connectivity requirements to develop and consult on implementation of a new firewall rule set between MBFS and global business partners
- Updated and consolidated existing firewall rule sets and consulted with multiple corporate partners on the implementation of those rule sets for ongoing data center migration program ed for supplying outstanding SME support and significant contributions to multiple high priority network projects - November 2013
Confidential
Network Engineer
Technical Scope: Cisco network (switches, routers, aironet devices), Fortinet Fortigate
Responsibilities:
- Created, implemented and managed security monitoring process for entire IT department. Configured and deployed company provided SIEM solutions to monitor and respond to Network Security Incidents including: malicious software, virus propagation and unauthorized access
- Credited for designing, building, and managing robust satellite-based voice | data network, consistently maintaining 99% uptime for 12 months in combat environment (Number 1 out of 80 sites)
