Information Assurance/security Manager Resume
Charleston, SC
SUMMARY:
- IT professional with over 17 years of experience.
- Well versed in driving organization growth and advancement through the development and implementation of advanced technology systems, solutions, architecture, and applications. Natural leader who thrives in challenging environment.
- Superior interpersonal communication skills, with ability to successfully build and foster rapport within internal and external networks.
TECHNICAL SKILLS:
Strategic Planning and Positioning - Collaborate with cross-functional teams for strategy planning activities, focusing on short and long term IA solutions with an emphasis on efficiency, budget, flexibility, and stability.
Information Assurance/Security Subject Matter Expert - Evaluate, analyze, and implement security solutions and emerging security technologies, aligning with future vision of organization infrastructure and IT best practices.
PROFESSIONAL EXPERIENCE:
Confidential, Charleston, SC
Information Assurance/Security Manager
Responsibilities:- Accomplished at performing full DIACAP/NIST based Certification and Accreditation (C&A) efforts
- Responsible for identifying requirements needed to successfully execute the information systems program, estimate activity duration, and develop schedules and staffing plan
- Experience performing Privacy Impact Assessments (PIA) and knowledge of best practices protecting Personally Identifiable Information (PII) and Protected Health Information (PHI)
- Experience directing remediation efforts, building Residual Risk Reports and tracking POA&Ms
- Practical experience using Nessus, Retina, Rapid7, Gold Disk, SRR scripts, Wireshark, STIGs, and Nmap
- Establishes metrics, key performance indicators, and service level agreements to drive system performance
- Collaborates with customers to identify, develop, and implement strategic plans and requirements that ensure the information system are protected against threats to confidentiality, integrity, and availability
- Key role in implementing agile management into IA activities
- Familiar with IA Best Practices relating to the following technologies; Windows Operating Systems, Oracle/WebLogic Databases, Web Technologies, Network Infrastructure, Hardware Virtualization, and Unix Operating Systems
- Recruited, trained, and mentored IA staff
Confidential, SC
Senior Information Assurance Engineer
Responsibilities:- Served as project manager/team lead, responsible for planning, directing, and implementing information technology policies
- Interpreted DoD IA policies and provide IA support for U.S. Navy systems following Navy, DoD, DoN, FISMA, and NIST guidelines
- Prepared RFPs, analyzed proposals, recommended purchases, select services, and managed new approaches in development processes
- Performed Independent Verification and Validation (IV&V) testing of systems to ensure adherence to FISMA and other regulatory guidelines
- Created, updated, and maintained C&A artifacts to include; System Security Plans, Incident Response Plans, Security Test & Evaluation Plans, Contingency Plans, Risk Management Plans and Vulnerability Management Plans using NIST/DIACAP guidelines
- Developed IA staff capabilities through restructuring according to knowledge, skills, and abilities of resources
Confidential, Charleston, SC
Systems Information Analyst II
Responsibilities:- Shift lead responsible for improving situational awareness of Navy Medicine networks and providing technical and subject matter expertise (SME)to assist with administration of network security devices
- Provided innovative information systems products and services to projects through effective and efficient program management, ensuring the privacy of customers and compliance to state and federal regulations
- Managed perimeter security for 26 global sites, which included 26 Cisco 7200/3800 perimeter routers, Cisco 6509 FWSM, Cisco PIX/ASA firewalls, McAfee sensors and IDS monitors
- Daily duties included log analysis, STIG reviews, creating and maintaining router configurations, and updating documentation
- Developed working relationships with customers and employees, facilitating the resolution of problems, providing strategic IT direction, and management of project phases
- Mitigated issues, potential risks, and deficient audit results through on going system analysis and security reviews
Information Security Analyst IV
Responsibilities:- Served as team lead of 3-4 personnel, deploying internationally to facilitate healthcare systems upgrades
- Evaluated the functionality of the IT infrastructure, and communicated issues, potential risks, and audit results to key personnel
- Provided installation and support of Composite Health Care Systems (AHLTA) worldwide
- Configured and installed Windows 2000 servers, workstations, Internet Information Servers, and Tardis.
- Monitored network and firewall configurations, researched action to prevent system/security complication, and made recommendations when needed
- Utilized Link Analyst, WireShark, and Network Instruments Observer to create graphical LAN/WAN mappings and solve LAN/WAN network problems
- Conducted briefings with military customers, facilitating needed information and documentation
Confidential, IL
Training Development Specialist II/Cisco Networking Academy Instructor
Responsibilities:- Provided Cisco Networking Academy Programming instruction.
- Maintained lab network as System/Network Administrator,
- Taught Internetworking technology courses, including Basic Routing and Switching, Advanced Routing and Switching, Cisco Network Design, and Network Security
- Configured and performed IOS upgrades for extensive selection of Cisco routers and switches.
- Reviewed and evaluated the functionality of systems and IT infrastructure, ensuring they aligned with organizational goals and training program standards
- Evaluated the design and implementation of security controls to ensure that information assets were safeguarded
