Security Analyst Resume Profile
Charlotte, NC
SUMMARY:
- Over 20 years of information technology experience and education
- 15 years of system administration and technical helpdesk customer support
- Several years of information security experience in governance, risks, and compliance guidelines
- Masters of Science, Cyber Security
- Great communicator, active listener, highly approachable, and a career professional
- Ability to analyze information systems infrastructures, and recommend ways to remediate risks and compliance issues base on business needs and processes
- Possess a thorough knowledge and understanding of information security methodologies, solutions, and concepts
- Goal and detailed oriented, organized, self-motivated, loyal, and dependable individual with strong personal skills
TECHNICAL HIGHLIGHTS:
Desktop Applications Knowledge Areas: Adobe CS Suite MS Office Suite 95 - 2013 MS Project FrontPage Lotus SmartSuite Anti-virus programs Norton, McAfee, Central Point PKI middleware Active Client Top of Mind Vantive Web Design
System Security Forensics Monitoring Tools Knowledge Areas:
Symantec DLP Symantec Data Insight SNORT NESSUS Cain Abel NMAP Wireshark TOOLBOX Enterasys Dragon IDS QualysGuard Imperva-Secure Sphere Aruba AirWave System Center Configuration Manager SCCM HP Server Manager LogRhythm IRD Incident Response Database Dell SecureWorks Ballast Point Incident Management Tracking ITSM, ITIL RSA Archer McAfee IPS Mandiant Cyveillance Verdasys Digital Guardian NBAD Network Behavior Anomaly Detection F5 Load Balancer Putty Arbor PeakFlow Proteus Symantec Endpoint Security Tea Leaf Silent Runner AT T Prolexier NetQoS C2Police
Working Knowledge of Operating System Environments: Windows-Desktop MSDOS, Win95 Win7 Server WinNT Win2008 Linux/Unix Fedora- Red Hat Ubuntu MAC Novell ver. 3.1 4.0
Hardware Integration Knowledge Areas:
Client/Server Systems: laptops desktops VDI Zero Clients docking stations Proliant Servers Dell Power Edge Servers BlackBerry Citrix Mobile Device Management Maas360 Virtual Servers/Blades Wintel Servers
Networking Devices: Cisco 3Com HP switches, hubs, routers, patch panels Backup systems Veritas, Tivoli print servers printers multifunctional devices PKI devices UPS Video devices and other peripheral devices
Software Applications Knowledge Areas:
Administration, Remote Packages, protocols Tools: SMS Client Tools Directory Services Active Directory AD , Directory and Resource Administration DRA Radia Quest NetIQ web console MS Exchange 2010-2013 Hyena Norton Ghost DameWare Windows Terminal Server 2000 DHCP TCP/IP Citrix VPN SharePoint VMWare MS Virtural Desktop
Communication Packages: Lotus Notes Cisco WebEx Office Communicator MS-Outlook Citrix ICA Client IBM Client Access Rally terminal emulation Attachmate Winframe Client PC-anywhere Novell GroupWise 4x-5.5x CC-mail Word Perfect Mail Futurous Co-Session
Information Security Standards and Policies: Healthcare Insurance Portability and Accountability Act HIPAA , North America Electric Reliability Corporation NERC , PCI Data Security Standards PCI DSS , Financial Industry Regulatory Authority FINRA
PROFESSIONAL EXPERIENCE:
Confidential
Job Title: Security Analyst
Key Responsibilities and Accomplishments
- Participate in establishing groundbreaking DLP technology in an enterprise environment including end-point and network based methodologies
- Solution provider and user of the enterprise Data Loss Prevention DLP framework and Data Insight tools
- Analyze and report anomaly findings from DLP scans in order to help tune smart response rules
- Interact with technology teams and business units as their governance remediation liaison
- Help establish DLP processes and procedures
- Document custom report formats and event types for use in security alerting and remediation workflow
- Respond to escalations from DLP incident response team to provide technical expertise
- Perform risk assessment of alerts generated from DLP
- Provide oversight and guidance with business units in order to help protect unprotected PII
- Utilize DLP and Data Insight tools in order to determine who, what, and where PII information resides
- Work with team members to exchange information and discuss advanced DLP solutions
- Maintain working knowledge of incident response processes through event escalations
- Assist in establishing guidelines and processes to support the DLP environment
- Work closely with peers in a team environment, pair with coworkers to train, answer questions, and help with assignments
Confidential
Key Responsibilities and Accomplishments
- Assess security incident impacts in an investigative resolution response approach utilizing various incident response, vulnerability analysis, threat management, network behavioral, and Cyveillance tools
- Investigate events, remediate network infrastructure alerts and anomaly activities utilizing third-party monitoring resources LogRhythm, Aruba AirWave, Imperva-WAF, Mariner, Mandiant, Cyveillance, Arbor Peakflow , McAfee IPS, QualysGuard, Enterasys Dragon, Symantec Endpoint Monitoring, and NBAD
- Analyze and obtain intelligence from security and system logs when alerts are triggered in order to investigate and address malicious activities
- Ensure system alert tools are facilitating actionable intelligence throughout an investigation
- Accurately document incident details in accordance with SOC Security Operations Center processes into Logrhythm, Ballast Point, and Dell Secureworks.
- Responsible for providing timely and accurate communications to SOC security teams and management regarding incident impacts and remediation
- Diagnose incident resolutions by providing workarounds derived from engaged security teams within the SOC while investigating incidences
- Provide leadership to ensure SMEs Small to Medium Enterprises , department, and vendors are focused and engaged during the incident handling process
- Engage leadership immediately on any potential information security risks and issues that may have a negative impact on business operations
- Follow up and facilitate meetings with incident stakeholders when necessary to prioritize and resolve important incident related issues
- Maintain knowledge of security administration concepts, theories, and practices to better understand the issue through consistent team engagement, schooling, educational materials, and research
- Perform root cause analysis and incident resolution by utilizing a variety of incident management tools LogRhythm, Ballast Point, Dell Secureworks, Dragon NIDs , McAfee IPS, Aruba, and QualysGuard
- Manage time with quality researching techniques of CVEs Common Vulnerabilities and Exposures while investigating incidences by multitasking, applying initiative, being flexible, and exercising good judgment within SOC guidelines
- Utilize interpersonal communication skills to effectively engage with various levels of the business members and clients
- Perform due diligence when analyzing and investigating any type of organization security issues
Confidential
Key Responsibilities and Accomplishments
- Responsible for building relationships with end user clients, customers, and team members to support business functions and operational needs
- Established communication link between the business, vendors, IT, and the supplier to discuss overall business needs and provide analytical assessments
- Conducted in-house site security and workstation audits in order to ensure site was prepared for third-party audits
- Responsible for processing documentation, and attend change management meetings in order to validate the business needs for the change and provide impact analysis for the site regarding the change
- Performed business impact analysis for site pilot testing projects, implementations, and requests
- Managed multiple projects concurrently within the call center to help minimize impacts to the business
- Engaged in various meetings to discuss IT, business, and call center initiatives, implementation, process concerns with End User Computing and IT Site Lead team
- Produced reports to summarize testing results while incorporating contingency recommendations based on organizational standards
- Identified problems and reviewed related information in order to develop and implement contingency solutions
- Analyzed pilot testing data and relayed results to IT team in order to identify security threats, trends, patterns, or warnings that may impact business functions
- Provided analytical feedback regarding business justifications of new cost-efficient technology solutions
- Attended, provided input, and helped enhance emergency management disaster recovery and contingency plans as in-house technical consultant
- Helped to developed testing, educational, and training plans for the site as new technologies and innovations were introduced
- Helped reduced site costs by addressing server capacity issues, workstation issues, advisor downtime issues while improving business performance and operations by providing weekly site assessments
- Enhanced and established new processes to help minimize site costs through education and training
- Gained knowledge of business operations and application awareness in order to validate requirements against client expectations
- Provided quality feedback and clarified pilot testing use cases to IT headquarters team within project deadline
- Partnered with Headquarters support teams of various technical complexity to leverage cross-functional IT application issues, innovations, auditing and capacity management dependencies for the call center
- Engaged, delegated, and coordinated incident response tasks with onsite techs utilizing incident management processes and initiatives
Confidential
Key Responsibilities and Accomplishments
- Provided guidance on implementing information security policies and procedures according to organizational guidelines
- Evaluated and optimized existing service procedures to meet or exceed client expectations
- Conducted in-house security audits as squadron's ISSO to ensure site was prepared for ACC annual audits
- Prepared certification and accreditation network compliancy packages for classified system
- Conducted annual Information Assurance Awareness Protection to all internal personnel
- Managed CMI investigations on the classified network
- Responsible for making sure all business functions were maintain and in network compliance
- Bridged business requirement analysis between the squadron and external sources within the ACC command
- Business support liaison for internal and external customer by providing face to face, over the phone, and digital media communications
- Performed classified file conversion utilizing Air Force ISR Agency's TOOLBOX application to move classified files to the unclassified network
- Established and created business continuity and risk management documentation for the organization
- Monitored and optimized Windows 7 based desktop operating system performance objectives according to MS system hardening procedures and guidelines
- Resolved all network systems failures by isolation and troubleshooting workstations connections i.e. Cisco Catalyst switches, patch panel connections and CAT5 Ethernet cables
- Performed remote application installation and configuration of Verizon 3G/4g access, Citrix VPN access, DameWare, and Hyena
- Responsible for creating, managing, and configuring network accounts, security groups, MS Exchange access and permissions on classified/non-classified network utilizing MS Active Directory, NetIQ, Quest, and Directory and Resource DRA System Management tools
- Provided business impact and cost analyst for network infrastructure assets to include hardware device acquisitions workstations, docking stations, laptops, and peripheral devices .
- Leveraged communication between NOSC and Headquarters Financial Management FM by translating IT requirements into squadron business needs
- Responsible for providing support and basic hands-on windows 7, Unix/Linux, and MAC OS-X based client side system training to new customers accessing front-end system applications
- Performed system refreshes, windows 7 installations and configured them for classified network usage
- Analyzed, documented, and reported business operational risks from security audits
- Implemented Static TCP/IP and DHCP protocols on peripheral devices being attached to the network
- Managed, configured, and installed RAID 5 Microsoft Windows Server based platforms i.e. NT, 2000, 2003
- Maintained infrastructure operational uptime for the Headquarters Financial Management Squadron's Billion dollar plus annual budgeting for the entire Air Force
Confidential
Key Responsibilities and Accomplishments
- Performed classified file conversion utilizing Air Force ISR Agency's TOOLBOX application to move classified files to the unclassified network
- Site liaison for creating LAN and Exchange account management, access, and group permissions
- Primary approving Information Systems Security Officer ISSO for classified accounts
- Identified system performance indicators and measures in order to develop continuity action plan that improved or corrected performance issues, relative to the system architecture
- Analyzed and reviewed current business continuity and disaster recovery plans for essential business functions and/or information systems to help identify acceptable recovery times and resource requirements
- Analyzed, documented, and reported business operational risks from security audits
- Enforced and insured all personnel followed the guidelines for network security compliance issues
- Conducted in-house security audits as squadron's ISSO to ensure site was prepared for ACC annual audits
- Prepared certification and accreditation network compliancy packages for classified system
- Conducted annual Information Assurance Awareness Protection to all internal personnel
- Managed CMI investigations on the classified network
- Coordinated hardware devices and software application installations with users, including upgrade preparation and implementation for SDLC
- Installed, configured, and maintained windows 7 based workstation operating systems
- Liaison between the Base Command and Squadron staff on all business and technical aspects of project
- Coordinated project stages and business implications throughout the entire project
- Responsible for assuring anti-virus definitions McAfee and Norton were updated and maintained by performing system scans
- Monitored progress of projects to assure SLA deadlines and standards were met
- Responsible for documenting network configuration changes and provide written report to senior management by utilizing MS Office Suite products i.e. MS Word, MS PowerPoint, MS Excel, and MS Access
- Managed equipment assets and maintain documentation logs for inspection
- Responsible for providing basic hands-on windows 7, Unix/Linux, and MAC OS-X based client side system training to new customers accessing front-end system applications
- Performed system refreshes, windows 7 installations and configured them for classified network usage
- Configured static TCP/IP addresses and monitored DHCP on peripherals being attached to the network
- Managed, configured, and installed RAID 5 Microsoft Windows Server based platforms i.e. NT, 2000, 2003
- Maintained working knowledge of Adobe and Microsoft Suite products
- Responsible for processing helpdesk tickets through Remedy software application to track system issues
Confidential
Key Responsibilities and Accomplishments
- Conferred with clients to assess business requirements and provided recommendations based on SDLC
- Ensured Air Force application packages were compliant with organizational needs and base standards
- Monitored project deliverables and milestone
- Liaison technical support lead for the Joint Task Force Civil Support JTFCS Ft. Monroe, VA and Homeland Security HLS Norfolk Naval Base, VA
- Managed CMI investigations on the classified network
- Maintained compliancy updates for anti-virus definitions McAfee and Norton within the infrastructure
- Installed, configured and troubleshoot Air Force financial systems
- Provided technical service support in the areas of hardware installation, movement, and maintenance
- Performed system administration duties establishing network accounts and determining user access rights
- Documented and logged problems reported by customers into a Remedy trouble ticket/incident reporting system to facilitate tracking, workflow management, escalation, and resolution of issues
- Managed log documents utilizing Microsoft Access and Excel of all static TCP/IP addresses for all peripherals being attached to the network
- Managed work breakdown structure WBS of IT project initiatives
- Developed training modules to educate users become more knowledgeable with their computer applications
- Maintained system assets by developing an internal asset management control system
- Processed requests and managed desktop installation of hardware assets, software application, and peripherals devices i.e. UPS power supply, PKI middleware, Active client, ADHoc, OCS, and Smart Card readers
