Principal Cybersecurity Vulnerability Analyst Resume
5.00/5 (Submit Your Rating)
SUMMARY:
- To secure a position allowing me to grow and advance in information security field by utilizing a solution - based approach to information security based upon my detailed knowledge of security tools, policies, procedures, and analysis, as well as my familiarity with IT infrastructure and controls.
TECHNICAL SKILLS:
- Ability to work as a team and as well an individual
- Adaptable to changes
- Managing/leading others
- Proficient in using XACTA
PROFESSIONAL EXPERIENCE:
Confidential
Principal Cybersecurity Vulnerability Analyst
Responsibilities:
- Prepare SA schedule.
- Conduct C&A Kick-off Meetings.
- Review and analyze automated scan results.
- Prepare security assessment plan (SAP)
- Conduct ST&E Findings Meeting with the System Owner, ISSO and other system personnel as required.
- Populate the Requirements Traceability Matrix (RTM) with results of Security controls assessment.
- Create a Security Assessment Report (SAR).
- Create a Plan of Action and Milestones (POA&Ms).
- Mapping of the vulnerabilities to the security controls.
- Review and closure of Plan of Action and Milestones (POA&Ms).
- Communicate with my ISSOs on continuous monitoring activities related to Plan of Action and Milestone closures, waivers and exceptions.
- Coordinate courtesy scans with ISSOs and Security Engineers when needed.
- Review and give recommendation on Request of Change (RFCs).
- Participate in Ongoing Authorization (OA) process for my assigned Systems.
Confidential
IT Security Analyst
Responsibilities:- Develop, update and review enterprise-wide and system specific policies and procedures.
- Participate in risk assessments to identify potential risks and security breaches.
- Manage Plan of Action and Milestone (POA&M) for accuracy and currency.
- Develop and complete security plans based on the NIST standards.
- Develop and conduct security test and evaluations based on NIST 800-53A
- Complete risk assessments based on NIST standards
- Participate in Certification and Accreditation (C&A) process and conduct security controls assessment
- Prepare Security Test and Evaluation (ST&E) plan
- Conduct vulnerability scanning using Nessus and analyze the result in support of security controls assessment.
- Ensure proper system categorization using FIPPs 199
- Develop Security Control Assessment (SCA) plan and created Security Assessment Report (SAR) using NIST guidelines.