It Security Specialist Resume
Silver Spring, MD
EXECUTIVE SUMMARY:
A seasoned IT professional with over 18 years of IT Management with emphasis on IT Infrastructure and Security Management. Strong understanding of the NIST Risk Management Framework, FISMA, FedRAMP, Federal Information Processing Standard (FIPS) 199 and NIST Special Publications. Strong experience in establishing and maintaining security programs based on established industry standards, controls and best practice. Ability to apply critical thinking, problem solving, and research and analytic skills. Sound understanding of networking and associated protocols. Excellent written and verbal communication skills to effectively communicate across various levels of the organization.
KEY AREAS OF EXPERTISE:
- Security operations expertise, including security mechanisms such as firewalls, intrusion detection, intrusion prevention, security information and event management, and end - point security
- IT Compliance & Auditing, Process Implementations, Strategic & Tactical Planning, Project/ Program Management, Vendor and Supplier Relationship Management
- Server installation, operating systems installation, application installation, configuration, migration, and tuning
PROFESSIONAL EXPERIENCE:
Confidential, Silver Spring, MD
IT Security Specialist
Responsibilities:
- Review information systems for compliance with applicable RMF methodology, Confidential, NOAA, DOC directives and guidance, and make recommendations to the Confidential systems
- Lead system security assessments based on the NIST RMF methodology for all NWS systems categorized as high and moderate.
- Prepare reports resulting from the yearly assessments, to include, but not limited to: Security Assessment Plan (SAP), Security Assessment Kickoff brief, Security Control Assessment Spreadsheet (SCA), Vulnerability Assessment Report (VAR), Security Assessment Report (SAR, and ATO Brief Slides
- Track completion of the Security Assessment Package and report status
- Review, coordinate, and respond to IS security issues as requested by the Information Technology Security Officers
Confidential
Responsibilities:
- Provide consulting services including comprehensive assessment of IT infrastructure and internal wireless network installation, configuration and management
- Systems and network infrastructure topology using service tools to understand dependencies
- Assist customers in identifying and properly mitigating risks to minimize losses related to data confidentiality, data integrity, and disruption of service
- Utilize key security controls to protect their critical infrastructure assets (computers, networks, programs and data) from attack, unintended or unauthorized access, change or destruction/damage
- Assist with establishing policies and procedures for critical client processes
Confidential, Laurel, MD
Vice President of Information Technology
Responsibilities:
- Created and documented plans of action and milestones for corrective actions in response to identified vulnerabilities Developed and implemented security policies, plans and strategies to address audit findings
- Maintained and continuously monitored organization's dynamic computing environment leveraging tools such as IDS, NIPS, syslogs, firewalls, SIEM, network scanners, content filters, etc.
- Vulnerability management including vulnerability assessment, vulnerability scanning, patch management, audit collection, audit review, endpoint protection, and SIEM for event correlation
- Implemented preventive, detective, and corrective controls to support monitoring, problem identification, data analysis, and resolution of security related incidents
- Chaired the Oversight Committee Team to establish a security program for the organization in accordance to guidelines set forth by National Credit Union Administration (NCUA)
- Participated in the enterprise-wide risk assessment to ensure that internal and external IT vulnerabilities and threats were identified, addressed, and mitigated
- Managed the planning, implementation, and testing of a disaster recovery plan and a business continuity scheme for the organization
- Researched and managed the planning, coordination, and implementation of integrated security system solutions to ensure the confidentiality, integrity, and availability of organizational data and systems were maintained
- Established and maintained IT policies, processes, and procedures and oversaw the IT Security awareness program to the staff
- Served as the primary POC between the organization and NCUA and other external IT auditors
- Led and planned the overall management of the decoupling of the organization IT and supporting infrastructure from its sponsor Ahold USA
- Led the pre-merger due diligence of IT infrastructure including systems assessment and evaluation.
- Managed pre-merger and post-merger data conversion, consolidation and integration of both internal and external IT systems to eliminate redundancies
- Led the assessment and evaluation of hardware/software needs and provided innovative solutions leveraging of open-source software when appropriate for cost control and create value
- Managed vendor relationships to provide oversight and ensure Service Level Agreements (SLAs) were met, contract management and renegotiation, cost negotiation
Confidential, Beltsville, MD
IT Specialist
Responsibilities:
- Utilized Remedy for incident, problem, configuration, and change management
- Perform system administrative activities and provide technical support in a Windows and Unix client/server environment
- Participated in the management, update and testing of the credit union's Business Continuity Plan
- Problem resolution, including dealing with software and hardware vendor technical support
- Configured network devices including switches, routers, and firewall to ensure secure telecommunications across 5 organization branches and within each LAN
- Prepared documentation for support and operations personnel
