We provide IT Staff Augmentation Services!

It Security Analyst Resume

5.00/5 (Submit Your Rating)

Streamwood, Il

SUMMARY

  • Highly dedicated Information Assurance and IT Security specialist with over Five(5)+years of experience in information systems security, documenting Information System Security Assessment and Authorization ( Confidential ) process from initiation to continuous monitoring, ensures compliance with operational policy and procedures focus on FISMA requirements.IT Networking .Multi Lingual (Speaks French and English fluently) with leadership and management skills
  • Excellent written and spoken communication skills,Strong Work Ethics, excellent team spirit, technical skills and availability
  • FIPS 199, control selection FIPS 200, NIST SP 800 - 53A, NIST SP 800-53 rev4 and NIST SP 800 137 documentation.OMB,Developing Security Plans (SSP), Contingency Plans (CPs), Privacy Impact Assessments (PIA), PTA, POA&Ms management and reports in accordance with FISMA requirements. AIX, Solaris, Linux, HP-UX,, Firewall, Palo Alto
  • Linux,JIRA, Wintel and ESX operating systems,Cisco IOS, ACAS/Nessus/SCAP.Confideciality Intergrity and Availability(CIA),ADFS,Ping, Siteminder, SAML

TECHNICAL SKILLS

  • Windows: XP
  • NT
  • 2000 Professional
  • Server (2000/ 2003)
  • Outlook
  • Microsoft office. Network Security
  • Network and Systems Administration
  • Active Directory
  • VPN. Detection/Prevention Systems (Snort
  • Bro
  • Mcafee IPS
  • Sourcefire)
  • Proxies
  • WAF (Imperva
  • f5 ASM)
  • WebLogic
  • SailPoint
  • Symantec DLP
  • CyberArk
  • End Point Protection
  • Enterprise Directory Services
  • MS Office Suite Access
  • Power Point
  • Microsoft Visio
  • Internet Explorer
  • and Publisher Adobe: Acrobat7.0 professional and Standard. Network Security Policies
  • Systems Installation
  • Java.
  • NIST 800-53. WebLogic and WebSphere
  • Java
  • IPS/IDS
  • DNS
  • DHCP
  • web security
  • TACACS+
  • VPN and NAC
  • Knowledge of Big-IP F5 GTM/LTM devices
  • Starfish
  • IBM Guardium
  • CampusVue
  • PeopleSoft.
 

PROFESSIONAL EXPERIENCE

Confidential, Streamwood , IL

IT Security Analyst

Roles and Responsibilities:

  • Ensured that protective measures are in place and operate effectively to counter any identified IT security threats to confidentiality, integrity and availability. Multi-factor authentication, X.509 token, single sign-on, federated identity, and certificate management solutions.
  • Performed review of security documentation such as Security Risk Assessment, Contingency Plans, Security Test and Evaluation Plans, Weakness Matrices, Security Controls, and System Security Plans.
  • Work on a team of technical staff responsible for configuration, security, and support of enterprise office PC systems and software, using System Center Configuration Manager (SCCM) for imaging and deploying workstation configurations & software, updates, and patches for Windows and workstation software,i nterpreting, and reporting vulnerability assessments.
  • Security Awareness and HIPAA Compliance, vulnerability assessments using various scanning tools
  • Responsible for antivirus/antimalware system administration, monitoring, and response in coordination with our systems security teams. Network Security Policies, Systems Installation
  • Work closely with colleagues responsible for corporate email services, Active Directory, Group Policy, remote access, and desktop video conferencing systems (including WebEx and Skype for Business).
  • Reviewed monthly vulnerability scans report to support continuous monitoring strategies.
  • Security Test and Evaluation (ST&E): Performed Security Test and Evaluation assessment on several different environments using both scanning tools and manual assessment. Environments tested include Windows server, Windows XP, RedHat, Oracle, Cisco IOS, custom created applications, and COTS applications. COBIT implementation. FireEye and/or Pen Testing ¿May also perform QA functions to ensure quality ticketing practices across the team. JIRA administrator Security Documentation: Performed updated to System Security Plans (SSP), Risk Assessments, and drafting Plan of Action and Milestones (POAMs). Active Directory Federation Services (ADFS
  • NIST SP documentation: Performed assessments and document creation using NIST SP 800-53 Rev.2.
  • Document and Review security plans (SP), contingency plans (CP), contingency plan tests (CPT), privacy impact assessments (PIA), and risk assessment (RA) documents per NIST 800 guidelines for various government agencies. Network protocol and Topology,TCP/IP,UDP,HTTP/HTTPS.Network Firewall security, Palo Alto and general Network Security Assessment & management
  • VPN technologies such as PKI, IKE, IPSEC, SSL/HTTPS, and digital certificate management.
  • Monitor controls post authorization to ensure continuous compliance with the security requirement.
  • Manage Imperva Database monitoring .
  • Performs FISMA-based security risk assessments and application systems including interviews, tests and inspections; produced assessment reports and recommendations. computer networking and network-based information assurance devices. Confideciality Intergrity and Availability(CIA)
Confidential, Houston , TX

Cyber Security Analyst/Compliance Officer

Roles and Responsibilities:

  • Documented and reviewed SSP, CPs, CPT, PIA, PTA and Risk Assessments according to NIST SP 800 guidelines. Risk Management Framework (RMF) packages
  • Provides continuous monitoring support for control systems in accordance to FISMA guidelines.
  • Evaluated, review and recommend corrections for prepared A&A packages for Information systems that go through Security Annual Assessments. Java; J2EE; EJB; deployed on Websphere
  • Compliance with federal, state, and local legal requirements
  • IT Products Knowledge and Help Desk, Database Management, IAM tools such as TAM, OIM, and Sailpoint, scripting tools to automate routine tasks in Remedy and BladeLogic .
  • Security Awareness and HIPAA Compliance, Analyst/Administrator
  • Data and Records Retention, TSM standards and change control procedures
  • Physical and Logical Networking, LAN,MAN,WAN,Splunk, and Checkpoint.
  • Network Topology and Protocol -TCP/IP,UDP,HTTPS,Trouble shooting
  • SIEM platforms, such as RSA Security Analytics, Splunk, or ArcSight; also Firewalls, Intrusion SOC (CSIRT) monitoring, incident. Relational database experience, Oracle

We'd love your feedback!