It Security Consultant Resume
PlymoutH
PROFESSIONAL SUMMARY:
A security/forensics position with a progressive growing company allowing me to utilize my hardware, software, networking, cyber security, computer auditing and forensics skills in a challenging environment while providing the opportunity to learn new elements of enterprise technologies which I can further use to support the company.
QUALIFICATION HIGHLIGHTS:
- 16 years as a Systems/Network Administrator
- 7 years working with multiple SIEM technologies (ArcSight, LogRhythm, Splunk, QRadar, RSA Envision).
- 7 years of system and network monitoring, auditing, compliance and forensics (Netwitness, Archer, Solarwinds, PRTG, ELK, EnCase, FTK, Netwrix, Manage Engine).
- 7 years of supporting VMWare ESXi 4.0 and 5.0 enviroments
- 9 years of Enterprise Storage Solutions: EMC VNX & NSX, HDS, Compellent, 3PAR, VBLOCK.
- 16 years of supporting Backup Exec, Symantec Norton Anti - Virus Corporate Edition, Symantec Endpoint Protection
- Network design, infrastructure, and security, Ethernet, TCP/IP, Fibre Channel, iSCSI, Jumbo Frame, VPN, LAN/WAN including Cisco Layer 2 switching devices, Cisco layer 3 routing devices, Sonic Wall firewalls, Juniper SSG firewalls, Cisco switches/firewalls, Palo Alto firewalls, Brocade switches, Checkpoint appliances, F5, Ecessa.
- 7 years of risk management, compliance and vulnerability assessment.
TECHNICAL SUMMARY:Systems: Windows 9X/XP, Windows 7, Exchange 2007/2010/2013 , Server 2003/2008/2012 STD & ENT, Red Hat Enterprise, CentOS, Ubuntu, Citrix, Kali, Backtrack
Hardware: Juniper SSG series Firewalls, Sonicwall TX series Firewalls, Cisco ASA, Cisco Load Balancers, Palo Alto, Brocade Fabric, Checkpoint appliances, 3com & Netgear switches, Hubs, Laptops & Workstations & Servers (Dell), Raid, SCSI, Memory, Network Card, HP, Xerox and Ricoh Printers, PBX, Compellent Series 30/40/8000, HP StorageWorks
Software: VMWare ESXi (4.0, 5.0), VSphere, Adobe Acrobat Standard, AutoDesk Inventor 2009, OrCAD, Sage MAS 500, Sage SalesLogix, HP Service Desk, Exchange 2007, Sonicwall Global VPN Client, Netscreen Remote, MS SQL Express, MS SQL 2005/2008/2012 , Symantec Backup 10d and 12, AVG Anti-Virus, Active Directory, Elsinore Issuenet, Dell SCOS, Symantec Critical System Protection, MBAM, Siteminder, Lotus Notes, InfoBloxSkills:
- ELK
- Github
- Atlassian
- Jenkins
- Netwitness
- SCCM
- Infoblox
- Encase
- ePolicy Orchestrator
- Wireless Central Manager
- Netbrain
- Arcsight
- Falconhost
- Cisco Telepresence Suite
- Volatility
- Bluecoat
- Solarwinds
- Crits
- Nessus
- Palo Alto
- ACS
- Request Tracker
- Metasploit
- Wireshark
- ISE
- Splunk
- LogRhytm
- Wildfire
- Malware Analysis
- Ironport
- Checkpoint Encryption
- Bitlocker
- Infoblox
- Group Policy
- Symantec A/V
- Kaspersky A/V
- Linux
PROFESSIONAL EXPERIENCE:
IT Security Consultant
Confidential, Plymouth
Responsibilites:- Improved processes, policy and procedure on modification and remediation of systems and networks.
- Developed and updated documentation that would be used for training and best practices
- Assisted with completing backlog of over 900 incidents that involved clean up of firewall objects, groups and rules from Palo Alto firewalls.
Security Architect
Confidential, Apple Valley
Responsibilites:- Design, implement and maintain overall security posture to the organization.
- Design, implement and maintain application-level monitoring, logging and reporting using tools such as Jenkins, Docker, Atlassian, ELK, Github
- Develop and adopt security framework using ISO, ITIL, NIST and FedRAMP guidelines.
- Ensure that data encryption is set to standard while in transit and at rest.
- Perform internal/external Penetration Tests against all organization systems, networks and online applications.
- Set security accomplishments and competence by planning delivery of solutions; answering technical and procedural questions for less experienced team members; teaching improved processes; mentoring team members.
- Determine security requirements by evaluating business strategies and requirements; researching information security standards; studying architecture/platform; identifying integration issues; preparing cost estimates.
- Plans security systems by evaluating network and security technologies; developing requirements for local area networks (LANs), wide area networks (WANs), virtual private networks (VPNs), routers, firewalls, and related security and network devices; designs public key infrastructures (PKIs), including use of certification authorities (CAs) and digital signatures as well as hardware and software; adhering to industry standards.
- Implements security systems by specifying intrusion detection methodologies and equipment; directing equipment and software installation and calibration; preparing preventive and reactive measures; creating, transmitting, and maintaining keys; providing technical support; completing documentation.
- Verify security systems by developing and implementing test scripts.
- Maintain security by monitoring and ensuring compliance to standards, policies, and procedures; conducting incident response analyses; developing and conducting training programs.
- Upgrade security systems by monitoring security environment; identifying security gaps; evaluating and implementing enhancements.
- Prepare system security reports by collecting, analyzing, and summarizing data and trends.
- Update job knowledge by tracking and understanding emerging security practices and standards; participating in educational opportunities; reading professional publications; maintaining personal networks; participating in professional organizations.
- Enhances department and organization reputation by accepting ownership for accomplishing new and different requests; exploring opportunities to add value to job accomplishments.
- Establish and communicate a corporate security incident response plan and be available to lead a team through an innocent. Took the lead on incidents and able to communicate while under pressure and be able to direct the team to resolve the incident.
- Establish and communicate a corporate vulnerability management process that builds upon the existing corporate process.
- Provide leadership in the threat and vulnerability assessment process.
- Communicate with other members of the infrastructure and product development team to keep senior leadership apprised of the risks and threat landscape. Offer recommendations on the best course of action to stay in line with budgets and resources.
- Conducted penetration tests against all web applications.
- Oversee roadmap planning and timelines for all Infrastructure related projects.
- Research, developed and implemented new security processes to handle PII data and ensure data is encrypted and at rest.
- Lead both on-site and off-site teams on data privacy and overall IT security.
- Interacted with all segments within the organization including the leadership team by conducting security awareness training, provide security best practices and ensure the safety of data.
- Oversaw and implemented new mechanisms and controls to the overall physical security and access control to the facility.
- Oversaw and audited all Physical mechanisms/controls, access controls, inventories,
- Established a patch management program to the organization.
- Defined roles and responsibilities within the information security program.
- Updated and defined a Disaster Recovery Plan.
- Updated and defined a Business Continuity Plan.
Sr. Security Engineer
Confidential, St. Louis Park, MN
Responsibilites:- Implement and manage IT Infrastructure in compliance with IT strategies and road-maps, as well as provide technical support in an integrated, multi-platform system environment. This includes: system hardware, software, desktop, networks, voice communications, disaster recovery, monitoring, and security.
- Ensure availability and accessibility of infrastructure systems accordingly established Service Level Agreements (SLAs). Collaborate with third party vendors and manage delivery of contracted services ensuring compliance with processes and best practices.
- Engage with other IT departments and business partners to translate business objectives into cohesive recommendations and solutions, define infrastructure design, and deliver quality services and solutions.
- Evaluate and implement new products available through outside vendors.
- Implementation of Qradar into Production. Integrate with network devices, systems and VPN logs.
- Implementation of Archer into Production. Integrated with all company assets.
- Establish and document operational standards and procedures.
- Collect and analyze security requirements from internal customers; reconcile and remediate any conflicts with information security policies and standards.
- Design and test security solutions utilizing existing products in the security-engineering portfolio: firewalls, proxy servers, intrusion detection/prevention, data loss prevention, anti-virus, anti-spam, vulnerability scanning, security information and event management.
- Implement security solutions, or work with vendor partners to implement solutions per the organization’s change management process and procedures.
- Provide operational oversight of vendor’s performance in managing security solutions.
- Manage work requests related to security incidents and security engineering services.
- Works with users, IT support staff and vendor partners to troubleshoot and resolve problems associated with security products and related processes, including after-hours support.
- Develop and maintain documentation of the design, implementation and operation of security products and processes.
- Work with vendor partners to monitor security products for evidence of unauthorized activities or violation of the organization’s security policies, standards and procedures; reports incidents and violations to management.
- Develop, implement & execute control activities to ensure that security products, processes and procedures are working as intended; remediate any deficiencies detected;
- Provide documentation and other artifacts related to the design and operation of the security products, processes and procedures to auditors and regulators upon request.
- Develop and collect metrics that measure the volume and trends of work activities and events within the security operations capability; provides regular reports to management.
- Assess risks to the confidentiality, integrity and availability of the organization’s information assets; makes risk treatment recommendations to management; researches, evaluates, and recommends new security products, processes and procedures.
Information Security Analyst
Confidential, Minneapolis MN
Responsibilites:- Monitor and investigate notifications and alerts regarding malicious activity on the network by Advanced Persistent Threats
- Investigate email phishing attacks by using malware analysis tools in the sandbox environment
- Implementation of Qradar into Production. Integrate with network devices, systems, VPN logs. Integrated logs to feed into Request Tracker and CRITs using STIX and TAXII.
- Implementation of Archer into Production and integrate with core business needs.
- Support HR and legal departments for ethics and security investigations
- Use forensics tools such as Encase, Netwitness, and Arcsight to investigate current intrusions
- Gather intel across all internal and external resources in order to block threats before they are inside of the network
- Work with the Department of Defense, FBI, InfraGard, and the Defense Security Information Exchange to track down suspicious activity
- Obtained secret clearance (with option of top secret) and five service commitment awards
Systems/Network Security Administrator
Confidential, Edina MN
Responsibilites:- Configure and manage nexus core switches
- Troubleshoot system and network appliances
- Design, implement and maintain application-level monitoring, logging and reporting using tools
- Use of SIEM technologies to investigate and intrusions and detect anomalies on the network
- Configuration and management of Windows and Linux server
- Responsible for hardening in-house IIS, applications, operating systems and network infrastructure
- Develop, implement and improving information security controls
- Analyze security incidents as well as liaise with customers on security issues
- Design and configure network security and enterprise network monitoring
- Upgrade wireless access gateways and configure guest network with enhanced security
- Configuration and management of Active Directory and VMware environment
Network Security Administrator
Confidential, Eagan, Minnesota
Responsibilites:- Assist creating new users, groups and OUs in Active Directory
- Use of SIEM technologies to investigate and intrusions and detect anomalies on the network
- Configure security hardening with security groups using GPO and content filtering appliances
- Enabling SSL certificates in apache; general apache configuration
- Create blogs, documents and troubleshooting tips and upload them to Confluence
- Implement, manage and upgrade of Checkpoint R70 to R77; configuration of ACL entries; managed Nodes and groups on Smart Dashboard; configuration of site to site VPN tunnels
- Configuration of VPN tunnels using Cisco Firewall ADSM
- Implement and management of Cisco wireless network. Configure High Availability and redundancy; Deploy and discovery of access points and guest wireless networks; Configuration of Flex Connect to support multiple CAPWAP tunnels to the WLC; create wireless users and groups with limited access to network resources; Configuration of Network Policy server granting specific groups to be authorized.
- Troubleshoot client connectivity to Citrix environment. Administer users and groups
- Assist users with authentication and connectivity issues to network and to applications both internally and externally
- Deployment and management of software prohibiting users from copying files from the network to optical drive or USB drive using Symantec Endpoint Protection device control policies
- Assist developing and implementing backups of systems and data on appliances.
- Develop and implement IT security procedures and policies
- Implement security policies to protect critical systems, hardware, users and physical equipment
- Monitor data center environment and respond to all alerts regarding network equipment and systems
- Assist with resetting network login accounts, mainframe accounts, oracle and other internal applications
- Management and administration of staging and production Single Sign On servers
- Create, test and implement FTP, SFTP and SecureFX accounts. Setup firewall rules to allow FTP and SSH connections
- Create and test outbound SFTP connections to Test and Production
- Assist with configuring user’s handheld devices (iphone, ipad, Android) with enterprise email access.
- Creation and modification of user access to claims and payment databases and mainframes. Assist with user connection and lockout issues.
- Management of DHCP Scope and DNS using Infoblox. Implement scope ranges within IPAM; and management of DNS
- Modification of IIS Security on web servers; Run vulnerability and risk assessments and detect and remediate all threats
- Configuration and management of Cisco Load balancer; Setup of SSL Offloading to termination SSL connections at the load balancer
- Implement and monitor event and system logs collected from LogRhythm appliances
- Assist every third weekend with maintenance to network appliances and systems (patching, replacing/upgrading equipment)
- Create DLP policies to monitor events to workstations across the network. Setup web content filtering on McAfee appliances and deploy to the network; audit removable device attempts
- Conduct internal and external penetration tests and audits of the network; perform SSAE16 audits and provide results to auditor to finish report
- Administration of all oracle accounts; update and reset user access to oracle databases
- Assist end users accessing voice mail boxes
System Administrator
Confidential, Minneapolis, Minnesota
Responsibilites:- Administer and support 3000+servers in a multi-platform environment consisting of Windows Server 2003, 2008 and 2012
- Build, implement, manage and retire systems in Production, Development and DMZ
- Installation, configuration and management of EMC VNX and HP 3PAR SAN solutions
- Troubleshoot hardware and software related issues with EMC and 3PAR SAN solutions
- Provide technical expertise to end users and customers via phone and email support
- Manage and approve patching and updates for all workstations and development systems
- Management, upgrade and migration of Endpoint Security solution
- Conduct backup and restore of SQL databases
- Monitor SQL cluster and oversee maintenance, performance tuning and failover of SQL servers
- Enhance product knowledge through the review of technical documentation
- Provide technical expertise troubleshooting disk space, performance and memory issues across all Windows Versions
- Complete Change Management, Incident Reports, access requests and user/account maintenance
- Travel to DR site to build, implement, manage, retire and troubleshoot all systems in Production, Development and DMZ
Systems Analyst
Confidential, Minnesota
Responsibilites:- Research, design and deploy Compellent SAN to customer sites
- Proactively discover issues on customer SAN systems, identify solution and remediate in a timely manner
- Proactively review assigned customer systems to verify for proper use of purchased features, potential issues, efficiencies and improvements
- Computer monthly reporting for each assigned account and review each report with the client
- Conduct on-site Health Checks of customer’s storage center environment
- Work with Confidential clients troubleshoot SAN infrastructure and integrate SIEM technologies
- Proactively engage customer requirements relating to product enhancements that would improve product serviceability & usability. Represent/present the customer requirement to the appropriate engineering organization to ensure clear understanding and implementation of approved enhancements
- Act as an escalation point for assigned accounts to help manage cases to ensure issues are recorded, tracked and resolved. Deliver frequent updates on the status of the case to the customer, Business Partner, sales or account team as needed. Ensure consistent fault isolation and root cause analysis
- Enhance product knowledge through the review of technical documentation, assigned training courses and materials, marketing documents, OEM manuals, troubleshooting guides, etc
- Provide technical expertise to Confidential team members on advanced storage design and integration with Enterprise applications
- Conduct analysis and provide input on recommended configuration, tuning and optimization of Storage Center and advanced storage technologies
- Conduct vendor-specific certifications based on software releases as necessary
- Assist in managing aspects of the demo lab including installations, updates and troubleshooting in Microsoft, VMware and Oracle environments
- Define integrated product solutions using third party products, develop and executes test plans and create solution papers and best practices white papers
- Perform and document analysis of competitive solutions to help device competitive strategies
Systems Engineer
Confidential, Minnesota
Responsibilites:- Manage and maintain security and hardening policy for Linux based webservers used to host customer websites
- Manage and maintain PKI used for smart card VPN authentication for a custom web application
- Manage an In house multi-tenant Exchange 2010 solution
- Support out of state remote sites through site to site VPN and visit local remote sites
- Create and manage a Hyper-V solution for virtualizing core infrastructure
- Install, manage and support on-site SAN solutions (Dell MD series)
- Create and manage VMware solution for virtualizing customer core infrastructure
- Implement and maintain workstation images for user computers, removing local admin rights & ensuring necessary applications continued to function with user only access
- Develop risk assessments and keep corporate and customer sites in compliance with PCI and ISO
- Create and maintain group policies to further lock down user workstations and improve security
- Manage and approve patching and updates for all workstations, servers and network hardware
- Designed and maintain backup solutions for disaster recovery
- Design, test and implement Cisco, Sonicwall & Checkpoint Security appliances to customer sites
- Configured and maintain all firewall configurations
- Perform day to day administration tasks on core systems used to host services for customer sites
- Perform on-site and off-site vulnerability tests (external and internal penetration testing)
- Implement network security for remote access. Tasks includes configuring site to site and clients
Network Administrator
Confidential, St Paul, MN
Responsibilites:- Held multifaceted responsibilities to configure, install and administer network infrastructure and telecommunications systems that supported staff of 50 personnel. I Fulfilled administrative responsibilities including the addition and changes to user desktop, email and PBX accounts.
- Install, manage and support VBLOCK, EMC NSX and VNX SAN solutions
- Troubleshoot for all hardware and software running in-house
- Monitoring all network equipment and perform updating when necessary
- Troubleshoot Hardware, Software, tcp/ip, dns, dhcp and LAN/WAN issues
- Manage and maintaining network backups
- Support out of state remote sites through site to site VPN and visit local remote sites
- Management and monitoring of SonicWall TZ series and Juniper SSG series firewalls
- Managed and monitored security infrastructure and provided risk and compliance assessments
- Design, implement and manage checkpoint appliances
- Configure Checkpoint appliances with network security policies which includes access control, NAT, content security and authentication
Business Support Center Analyst
Confidential, Minneapolis, MN
Responsibilites:- Receive customer problems via email and/or phone regarding product functionality/problem
- Resolve complex or high priority cases immediately or determine resources to resolve
- Troubleshoot cases & maintain documentation for steps and activities taken to resolve
- Assist user’s with program functionality using remote tools (Bomgar, RDP)
- Verify site outages with network monitor and company website
- Making additions, changes and deletions of users, computers and groups in Active Directory
- Research issues when answers are not readily available with the use of Web tools/search engines.
- Create technical documentation for publication in Knowledge Base
Enterprise Support Analyst
Confidential, Eden Prairie, MN
Responsibilites:- Receive customer problems via website and/or phone regarding product functionality/problem.
- Resolve complex or high priority cases immediately or determine resources to resolve.
- Troubleshoot cases & maintain documentation for steps and activities taken to resolve.
- Escalate unresolved customer problems as necessary to ensure timely resolution.
- Routinely update customer on open cases to gain additional information or advise of status.
- Identify service gaps and escalate as appropriate.
- Interface with other Concur departments as necessary to resolve customer issues.
- Maintain working knowledge of Concur products including new releases and products.
- Write, peer review and/or edit knowledge-base information on Concur products.
- Use SQL queries to investigate customer issues.
Technical Support Analyst
Confidential, Plymouth, MN
Responsibilites:- Receive customer problems via email and/or phone regarding company product functionality/problem.
- Open new cases in ticketing system and assign to appropriate segment or incident management.
- Escalate unresolved problems to incident management to ensure timely resolution.
- Check on status of system outages and maintenance on Intranet site.
- Review knowledgebase as a resource to document and troubleshoot problems.
- Use of remote tools to resolve end users computer issues.
- Plan, prioritize, organize and complete goals to achieve service level agreements.
Desktop Support
Confidential, Minneapolis, MN
Responsibilites:- Responsibilities included setting up peer-to-peer network and management of Sonicwall firewall.
- Manage and maintain office PC’s, printers, and phone system
- Troubleshoot PC, printer, email and phone system issues
- Manage and maintain internet, security, PC’s and phone system
- Implement, manage and maintain network for all office systems
- File reconciliation
- Diagnose hardware issues
- Troubleshoot TCP/IP, DNS and DHCP issues
