Security Consultant Resume
2.00/5 (Submit Your Rating)
Atlanta, GeorgiA
TECHNICAL SKILLS:
- WNT/2000/2003 Server Administration
- Active Directory, Group Policy, NTFS, DNS, DHCP, Client/Server networking
- Access/Citrix/Nortel, Cisco VPN/Access Manager
- Mainframe RACF, ACF2, CICS, IMS & TPX
- DB2 experience
- Remedy 4/5/6 ticketing system
- UNIX user Administration
- IdM Management
- SAP security, role and user Administration
- Sarbanes Oxley (SOX) compliance and audit
- Novell Netware Administration
- NERC/FERC regulatory compliance
- Technical writing skills
- SQL 2000/2005/2008 Server database Administration
- Oracle 8/9/10g system and user Administration
- Sybase role and user security
- Exchange 2003 server/client Administration
- RSA enVision Administration
PROFESSIONAL EXPERIENCE:
Confidential, Atlanta, Georgia
Security Consultant
Responsibilties:- Determine access, software/tool and process flow needs of first, second and third level support teams in reference to security access request and provisioning
- Identify and develop strategic and tactical plans across technologies and systems
- Consult within Security Operations and throughout the enterprise on matters involving Information Security and data governance.
- Perform technical leadership role in providing direction, tools, process support and incident handling via Service Now to other associates for tools such as SAP IdM, BASIS, Active Directory, Hitachi Password Manager, AS400 and CA Technologies SiteMinder
- Participate in the Architectural Review Team for privileges assigned to functional roles and elevated access roles for AD, Basis, Kronos, SAP and Sharepoint
- Review job title for appropriateness of assigned functional role, when appropriate, correct mapping of SAP HR permutations to IdM roles
- Role creation/maintenance and user provisioning/administration for SAP and SAP IdM
- Familiar with SAP IdM user administration including user provisioning, reprovisioning, history views and submission of application access request
Confidential, Atlanta, Georgia
Security Administrator
Responsibilties:- Provide security solutions through identification, investigation and resolution of security events and incidents detected by IDS / IPS real - time monitoring systems
- Research attempted efforts to compromise security protocol and recommends solutions using IBM ISS IDS/IPS Proventia Appliances and Site Protector, Bluecoat Web filtering ProxySG solution and Cisco AIP-SSM-10 Intrusion Prevention modules using Cisco Security Manager (PIX, ASA, IPS) and provide analysis and reporting for security events using Cisco MARS
- Manage CISCO Access Control Server (TACACS), DLP/Antivirus/IPS via McAfee ePolicy Orchestrator (ePO), wireless network detection, sniffing and IDS via Kismet, and Unix and Windows OS changes via Tripwire
- Manage RSA Envision for log correlation and incident response investigations and decode traffic flow at packet level traces (TCPDUMP, PCAPs, traffic generators) from various applications including Check Point Firewall, Juniper, Oracle, SQL, Unix, and AS400 logs
- Use regulatory and audit mandates to ensure environments meet PCI, FFIEC, SOX and corporate standards
- Use knowledge of TCP/IP, HTTP, FTP, cookies, authentication, virus scanning, web servers, SSL/encryption and reporting packages for security detection and prevention
- Responsible for updating weekly and monthly status reports for new and ongoing issues and project status
- Responsible for updating in place documents and creating procedures for handling any new threats discovered that require on-going evaluation and/or monitoring according to PCI, SOX audit compliance
- Management of enVision SIEM platform for application/device logging and report/alert creation and configuration
- Configure REGEX expressions for policy exception processing
- Configure DLP collection technology (Symantec, Code Green, McAfee) to finger print databases and files
- Configure and manage DLP discovery and scanning
Confidential, Atlanta, Georgia
Security Analyst
Responsibilties:- Governed the architecture, design, and development of the Coke One Risk and Compliance and Access Controls within the Security and Controls area
- Contributed critical knowledge and deep subject matter expertise to the security designs of SAP security (ECC, HR, MDM), and SOX compliance areas and access controls
- Documented security procedures for Coke Cola Enterprises and vendor applications according to Sarbanes Oxley (SOX) regulations and corporate policies
- Created and terminated of all user accounts, administration of user and group permissions in RACF/ACF2, UNIX, BASIS, Windows Active Directory, SAP, Exchange 2007 and other proprietary systems
- Governed template change requests for the respective solution area
- Provided key input for product strategy and evolution for the solution area
- Performed select configuration and testing of the Security solution and related integration
- Delivered knowledge transfer to targeted teams, such as Standards, Deployment, Bottlers, etc. and ensure the solutions are in compliance with related TCCC standards
- Created documentation according to SOX audit guidelines for procedures on template creation, access approval, provisioning and access removal for company applications
- Provided training for offshore employee on the correct producers for researching and handling accounts that fall outside of SOX and The Cola-Cola Company (TCCC) guidelines for access authority
Confidential, Tampa, Florida
Security Analyst
Responsibilties:- Collaborated with teams members that researched, tested and implemented new technology onto TECO’s network including P Synch Password Management, Exchange 2003, GIS (Geographical Information System)
- Documented security procedures for TECO and vendor applications according to Sarbanes Oxley (SOX), NERC/FERC regulations and corporate policies
- Created new documentation, where applicable, for any new implementation of software, access right approval, provisioning, granting and removal according to NERC/FERC, and SOX guidelines
- Streamlined auditing process for accounts and access not accordance with policies auditable by NERC/FERC representatives
- Designed SharePoint security through Active Directory group membership
- Managed Windows Server Update Services (WSUS) for client/server patch management
- Incident response/investigation of security incidents involving internal users with various tools including Windows audit logs, McAfee ePO, Checkpoint firewalls and RSA enVision SIEM software
- Managed first level events from enVision platform, including logging and report failures
- Managed Group Policies to centralize and automate the enforcement of access control to network resources
- Created, terminated user accounts, administered user and group permissions in RACF/ACF2, Oracle 9 and 10, SQL Server 2000/2005, UNIX, Novell, Windows Active Directory, SAP, Sybase, GroupWise and Exchange 2007
- Administered accounts via UNIX IDM client
- Administered SAP HR/Payroll security including user and role authorizations using various transactions as required (PFCG, PA30, PO13, SU01, etc)
- Provided training on NERC/FERC and SOX audit procedures, provisioning, research, backups, emergency incident response, and incident ticket handling to new employees and contractors
Confidential, Tampa, Florida
Technical Consultant
Responsibilties:- Managed a rotating team of 13 people on second and third shift
- Configured, maintained and troubleshoot the following technologies in a large corporate environment: Outlook POP/SMTP and Exchange configuration, Lotus Notes 5.0/6.0/6.5, Mainframe (RACF, ACF2, DB2, TPX and UNIX), Solaris, Blackberry, Sametime, LCS, McAfee, Cisco Trust Agent, Symantec Client Security, MS Office, Extra Attaché Mate, Hummingbird, Reflections, Remedy, PcAnywhere, VNC, URC, NetMeeting
- Reviewed initial IDS, DLP and IDLP reports via RSA and McAfee suites
- Implemented of new software onto Verizon’s Network including Lotus Notes/Exchange 2003/Single Sign On (SSO)/Secure Remote Software/SAP
- Supported, configured and administered of remote access with 2 factor authentication including certificates and synchronous token authentication
- Took inbound support calls to provide first and second level technical support with the ability to analyze and resolve issues via telephone and remote assistance
- LAN, TCP/IP, DNS, WINS, DHCP network connectivity troubleshooting & fundamentals
- Managed accounts for SAP, PeopleSoft, Windows, UNIX, IDM. Novell, RACF/AFC2 and UNIX mainframes
- Collaborated with team members to implement and test laptop encryption software
- Installed, setup and managed of encryption protection software for laptops
- Administered account provisioning for Windows 95/98/00/Novell/ Mainframe
- Used Remedy 5.0/6.0 and Service Center ticketing systems
