Information Security Analyst Resume
SUMMARY:
Seasoned professional with five years of troubleshooting network infrastructure and security, designing, implementing, execution, monitoring and resource balancing skills with ability to support multiple simultaneous projects in a matrix organizational structure. Proven record of evaluating system vulnerability in order to recommend security improvements as well as improve efficiency while aligning business processes with network design and infrastructure. Well versed at communicating with stakeholders to provide accurate reporting and information regarding ongoing projects and initiatives. Superior capacity to solve complex problems involving a wide variety of information systems, work independently on large - scale projects, and thrive under pressure in fast-pace environments while directing multiple projects from concept to implementation.
CORE COMPETENCIES INCLUDE:
- Information Assurance
- Hardware Installation
- File integrity monitoring
- SIEM tools
- Team leadership skills
- Risk management
- Penetration Testing
- Systems Development Life Cycle
- Technical Writing
- Privacy
- Security Life Cycle
- Project Management and Support
- IT Compliance management
- Vulnerability Evaluation
- Policy/Procedure development
TECHNICAL AND SPECIALIZED SKILLS:
Retina Vulnerability Scanner, Nessus Vulnerability Scanner, Microsoft Baseline Security Analyzer (MBSA), QuickBooks Pro, Peachtree Accounting, ACT CRM, SugarCRM, vTiger CRM, Microsoft Project, Visio, Excel, Word, PowerPoint, Access, Microsoft Windows, Server 2003/2008, CentOS Linux, Ubuntu Linux, ConfigServer Security & Firewall, Webmin and cPanel, and Asterisk PBX.
PROFESSIONAL EXPERIENCE:
Confidential
Information Security Analyst
Responsibilities:
- Established and maintained a Security Configuration Baseline program per National Institute Standards and Technology (NIST) 800-53, Federal Information Security Management Act of 2002 (FISMA), and Federal Information Processing Standards (FIPS) series 140 (U.S. Government computer security standards) guidance.
- Prepared and reviewed documentation to include System Security Plans (SSPs), Authorization to Operate (ATO) Risk Assessment Reports (RAR) and System Requirements Traceability Matrices (SRTMs).
- Performed penetration tests, vulnerability/risk assessment analysis to support certification and accreditation (C&A).
- Develop, track, create and manage POA&Ms using tools like TAF, Xacta IA Manager, CFACTS, CSAM.
- Trained staff on network and information security procedures.
- Reviewed and updated the Contingency Plan (CP) annually as part of the system security documents.
- Coordinated the CP test annually for my assigned systems, which included Tabletop exercise (simulated/scenario discussion type test) and full disaster recovery test at the offsite disaster recovery (DR) location of the company where the systems are recovered from the backup data or tapes.
Confidential
IT Risk Analyst
Responsibilities:- Evaluated security solutions to ensure they met security requirements for processing classified information.
- Developed and analyzed security policies, procedures and technical standards including corporate compliance, security training, and end-user awareness
- Monitored Medical applications, systems, and networks to ensure the integrity, availability, and confidentiality of information and ensured the integrity and availability of IT systems.
- Enhanced and optimized the existing log monitoring and analysis process to identify, scope, track, and report on potential security incidents, unauthorized configuration changes, and policy violations.
- Developed and implemented POA&M to remediate weaknesses system-wide.
