Junior Security Analyst Resume
3.00/5 (Submit Your Rating)
Largo, MarylanD
SUMMARY
With continuous monitoring, I can interpret and prioritize threats using Intrusion Detection/Prevention Systems; Security Incident/Event Management (SIEM). I can analyze packets using various security tools and recognize potential, successful, and unsuccessful intrusion attempts and compromises through analysis and review of security events, logs and network traffic. I can also perform static and dynamic malware analysis in an isolated virtualized environment.
TECHNICAL SKILLS:
- Nitro
- ArcSight
- Splunk
- NetWitness
- FireEye
- TippingPoint
- Snort
- App Detective
- IDS Policy Manager
- Nmap
- Nessus
- RSA Security Analytics
- Firewall Logs
- Remote Administration (VNC
- Putty
- SSH)
- CheckPoint Firewall
- Wireshark
- TCPdump
- REMnux
- and various tools for Malware and Packet analysis
PROFESSIONAL EXPERIENCES:
Confidential, Largo Maryland
Junior Security Analyst
Responsibilities:
- Analyze systems on client's network to identify vulnerabilities, anomalous network behavior, compromised network hardware, and advanced malware
- Provide prioritized recommendations to either remove or mitigate issues detected, helping to harden and defend the client's network
- Utilize commercial, open - source and internal, custom-built tools and techniques
- Aid the client in implementing many of the corresponding countermeasures
- Provide guidance in handling incidents where malicious network traffic behavior is identified and in removing malware from the network
- Perform Computer Security Incident Response activities and coordinate with other government agencies to record and report incidents
- Monitor and analyze Intrusion Detection Systems (IDS) to identify security issues for remediation
- Recognize potential, successful and unsuccessful intrusion attempts and compromises thorough reviews and analyses of relevant event detail and summary information
Confidential, Beltsville, MD
Junior Security Analyst
Responsibilities:
- Monitor intrusion detection and prevention systems and other security event data sources on a 24x7x365 basis.
- Determine if security events monitored should be escalated to incidents and follow all applicable incident response and reporting processes and procedures.
- Ability to problem solve, ask questions, and discover why things are happening.
- Correlate data from intrusion detection and prevention systems with data from other sources such as firewall, web server, and DNS logs.
- Develop and produce reports on all activities and incidents to help maintain day to day status, develop and report on trends, and provide focus and situational awareness on all issues.
- Reporting outputs will be reviewed and approved to ensure quality and metrics are maintained.
- Responsible for tuning and filtering of events and information, creating custom views and content using all available tools following an approved methodology and with approval and concurrence from management.
