Information System Security Officer Resume
SUMMARY
- Management responsibility with an organization where demonstrated skills in client service, communication skills, team leadership, analysis, organization and technical ability can be translated into improved customer satisfaction, growth and profitability.
- Over 18 years of extensive IT, consulting, management, technical and work experience in the design, development, and implementation of information systems, professional services for the Confidential, Confidential and Confidential, FEMA (DHS), Confidential and Confidential ( Confidential ).
PROFESSIONAL EXPERIENCE
Confidential
Information System Security Officer
Responsibilities:
- Peer reviewed ISSO’s System Security Plan for accuracy and integrity;
- Performing independent compliance reviews, tracking, and continuous monitoring of sustained systems which has already been granted ATO;
- Collaborate with security team members on federal government processes, federal government regulations and standard of operation procedures;
- Develop IT systems security documentation to support the certification and accreditation of software systems;
- Develop Standard Operation Procedures (SOP’s) for assigned systems
- Engage senior leadership to ensure mission, strategic and information security goals are in alignment;
- Assist government officials with Privacy Documentation, E - Authentication and FIPS199 artifacts
- Conduct Annual FISMA Self-Assessments
- Conduct Penetration Test for assigned systems
- Collaborate with other contractors, cross functional team members and government IT professionals to ensure security processes and concepts are integrated into new IT projects.
- Responsible for continuous monitoring for information systems in sustainment
- Responsible for information system POA&M management
- Responsible for obtaining ATO (Authority To Operate) for Confidential information systems
- Maintain system documentation in GOOGLE Suite (GOOGLE DOCS)
- Responsible for reviewing NETSPARKER vulnerability scans for Confidential information systems
Confidential
Manager/Information System Security Officer
Responsibilities:
- Managed eight ISSO’s alongside to make sure Confidential mission statement is adhered to;
- Responsible for obtaining ATO (Authority To Operate) for six systems and continuous monitoring for two systems.
- Responsible for training the government personnel on FISMA Compliance, XACTA IA Manager, POA&M weakness and remediation, ISSM Duties;
- Developed IT systems security documentation to support the certification and accreditation of software systems;
- Performed independent compliance reviews, tracking, and continuous monitoring of newly submitted Certification & Accreditation (C&A) packages;
- Engaged senior leadership to ensure mission, strategic and information security goals are in alignment;
- Detailed knowledge of government rules and regulations governing Cyber Security protection and actively review NIST Publications 800 Series, DHS Directive and System Policies and ISO guidance for information security, industry best practices and strategic periodicals support the development of comprehensive IT audit remediation plans;
- Maintained documentation repositories (XACTA IA MANAGER) where C&A project documentation and artifacts are stored;
- Collaborated with other contractors, cross functional team members and government IT professionals to ensure security processes and concepts are integrated into new IT projects;
- Communicated with all the clients and customers to receive and understand the set expectations and assess their needs and provided assistance where needed within the component;
- Created Standard Operation Procedures for Federal Protective Services Component for ISSO’s to comply when completing the security plans for assigned systems;
- Conducted Security Meetings with clients, Vencore team and other stakeholders concerning system projects, timelines and security awareness;
- Communicated, listen and express security information to all individuals or group forums in reference to cyber-security awareness and cyber-security issues;
- Advised and assist with the Lifecycle Certification and Accreditation (C&A) process for all DHS/FPS Systems.
- Worked closely with program office stakeholders to identify and approval processes and authorities.
- DHS follows the RMS Workflow (Categorize, Select, Implement, Assess, Authorize and Monitor). All ISSO’s must comply with the RMF Workflow in order to achieve an Authority To Operate (ATO) for specified systems.
Confidential
Information System Security Officer for Financial Systems
Responsibilities:
- Maintained four financial systems for the Confidential within Confidential;
- Task Lead for Confidential with five team members alongside to make Confidential’s mission statement is adhered to;
- Developed IT systems security documentation to support the certification and accreditation of software systems;
- Performed independent compliance reviews, tracking, and continuous monitoring of newly submitted Certification & Accreditation (C&A) packages;
- Detailed knowledge of government rules and regulations governing Cyber Security protection and actively review NIST Publications 800 Series, DHS Directive and System Policies and ISO guidance for information security, industry best practices and strategic periodicals support the development of comprehensive IT audit remediation plans;
- Engaged senior leadership to ensure mission, strategic and information security goals are in alignment;
- Advised and assist with the Lifecycle Certification and Accreditation (C&A) process and developing a Systems Security Plan (SSP);
- Monitored and track C&A activities through Authorization to Operate (ATO);
- Maintained documentation repositories (XACTA IA MANAGER) where C&A project documentation and artifacts are stored;
- Developed evaluating, and implementing security programs designed to anticipate, assess, and minimize system vulnerabilities;
- Communicated, listen and express security information to all individuals or group forums in reference to cyber-security awareness and cyber-security issues;
- Extremely detailed oriented when creating, reviewing and monitoring documentation;
- Collaborated with other contractor and government IT professionals to ensure security processes and concepts are integrated into new IT projects;
- Supported and evaluates three significant financial systems that processes assess of $5 million dollars or more yearly, reviews, analyze and provide security artifacts that are internally review cyber-security, leadership and external auditors;
- Communicated with all the clients and customers to receive and understand the set expectations and assess their needs and provided assistance where needed within the component;
- Implement conflict resolution strategies for cross functional teams and provide assistance where needed within the component in order to satisfy the client’s and customer’s needs and expectations;
- Served as the primary PoC during Financial Statement Audit meetings (walkthroughs) to discuss procedures within the audit scope inclusive of audit logging, vulnerability management, and system security plan;
- Coordinated the implementation of security programs across platforms;
- Worked closely with program office stakeholders to identify the appropriate certification/approval processes and authorities;
- Recommended evaluated alternatives to specific issues/concerns in reference to cyber-security information which is relevant to the discussion/topic during a group forum;
- Record/register actions concerning project approvals to operate in the C&A database;
- Read and analyze SSPs and develop understanding of systems and applications into security test plans;
- Utilized the SPLUNK Log Management tool to review and analyze the Operating System audit logs for the financial systems;
- Reviewed and analyze the database audit logs for any anomalies for the financial systems;
- Coordinate C&A actions and system testing with appropriate security personnel
- Developed risk assessment reports;
- Assembled and submit C&A packages to Principal Accreditation Authority/Designated Accreditation Authority;
- IT-Project Planning and schedule security project timeline and milestones;
- Formulated risk management plans;
- Lead and mentor the security project staff;
- Maintained communication with project stakeholders and manage expectations;
- Developed project scope, objectives, staffing, resources and deliverable;
- Review IA Compliance Validation Tests and Reports;
- Continuous monitoring of audit logs for financial systems.
- Utilized Tenable NESSUS Vulnerability Management tool to read and manage vulnerabilities for the OCFO financial systems.
Confidential
Information System Security Officer
Responsibilities:
- Performing independent compliance reviews, tracking, and continuous monitoring of newly submitted Certification & Accreditation (C&A) packages;
- Advise and assist with the Lifecycle Certification and Accreditation (C&A) process and developing a Systems Security Plan (SSP);
- Monitor and track C&A activities through Authorization to Operate (ATO);
- Maintain documentation repositories (RMS and TAF) where C&A project documentation and artifacts are stored;
- Work closely with program office stakeholders to identify the appropriate certification/approval processes and authorities;
- Record/register actions concerning project approvals to operate in the C&A database;
- Read and analyze SSPs and develop understanding of systems and applications into security test plans;
- Coordinate C&A actions and system testing with appropriate security personnel
- Develop risk assessment reports;
- Assemble and submit C&A packages to Principal Accreditation Authority/Designated Accreditation Authority;
- Review IA Compliance Validation Tests and Reports.
Confidential
Project Task Leader/Scheduler
Responsibilities:
- Maintain continuous alignment of program scope with strategic business objectives,and make recommendations to modify the program to enhance effectiveness toward the business result or strategic intent;
- Brainstormed with the entire team on ways to be productive, efficient and customer oriented in the workforce;
- Researched inventory assets to survey for replacing with new and updated systems;
- Communicated and presented in documentation format to upper management on finding through detailed research;
- Build credibility, establish rapport, and maintain communication with stakeholders at multiple levels, including those external to the organization;
- Effectively and efficiently coach, mentor and lead personnel within a technical team environment;
- Schedule, maintain and distribute daily tasks and assignments to the technicians throughout the project;
- Consult the team members in reference to estimating procedures as a means of ensuring that proper planning is completed prior to the commencement of work;
- Track and communicate to upper management the project status by the use of PMR (Program Management Reports)and Weekly Reports;
- Minimizes exposure and risk on project;
- Ensure project documents are complete, current and stored appropriately;
- Identify and resolve and/ or escalate issues appropriately in a timely fashion; Collaborated with cross-functional IT team members to coordinate the technical requirements and changes;
- Execute, Monitor and Control all the team’s hard work within the program on a daily basis.
Confidential
Information Assurance Security Officer
- Created System CoN for one of our testing areas in New Orleans;
- Supported Security Test and Evaluations (ST&E) for clients to include generating the Security Assessment Reports for use in the Certification and Accreditation process;
- Supported customers in their Certification and Accreditation (C&A) efforts. Utilizing the latest in security scanning software such as Retina, and other approved IA tools on Microsoft Windows systems running web services and portals in a Service Oriented Architecture;
- Tracked and reported all Information Assurance Vulnerability Alerts (IAVA’s) to my superiors and team members;
- Reviewed Retina scan reports for system compliancy;
- Supported DIACAP certification and accreditation process for DOD/DISA DoD 8510.01;
- Utilized good Information Security (INFOSEC) skills to protect information and information systems from unauthorized access, use, disclosure, disruption, modification or destruction;
- Ensured all employees complied with Army Regulations and Guidance pursuant to AR 25-1 and AR 25-2;
- Department of Defense Certified Information Assurance Security Officer (IASO);
- Provided an in depth assessment of the client’s security program and policies;
- Actively tested customer's encrypted password databases for alignment with company policy and/or governing regulations;
- Assessed and detected leakage of regulatory and/or sensitive information through Internet perimeter networks;
- Reviewed the Plan of Action and Milestones (POA&M) documentation for tracking and mitigating cyber security and system-level weaknesses within the environment to make sure the document was accurate according to DOD policy;
- Utilized VMS database for uploads of documents and record keeping of such documents for future references;
- Monitored and Reported internal network usage with Websense Security Tool.
- Ensured correct completion of government DD Forms 2875 to access certain environments and tools within all locations;
- Conducted Information Assurance meetings for status updates;
- Provided monthly metric reports to our COL of the project;
- Developed Standard Operation Procedure for processing DD 2875 and Add, Remove, Change (ARC) forms for employees.
Confidential
Technical Support Service Desk Manager
Responsibilities:
- Ensure all requests from users for assistance are handled promptly and effectively for all requests that cannot be directly resolved, provided an effective interface between users and service providers; ensure that escalation procedures were applied effectively and all complaints were resolved professionally;
- Provided higher level Tier 2/3 support when problems couldn’t be resolved at the Tier 1 level;
- Analyze requirements and researched solutions to meet user desktop IT requirements;
- Provide user feedback of problem progress on a regular basis;
- Initial point of contact for the Support Desk, dealing with support calls, operating the Support Desk on a daily basis, logging and resolving first line support calls;
- Assist IT Support staff with hardware and software installations when required;
- Produce reports on help desk status and provided metrics to management.
Confidential
IT Service Desk Manager
Responsibilities:
- Managed IT Helpdesk Support and procedures for old and new employees;
- Handled all the IT activities performed on daily basis within the Service Desk;
- Coordinated and Prepared Team Weekly Reports on a weekly basis to management;
- Call Logging, Monitored and Delegated tickets to the appropriate directorate support leads via e-mail and Service Desk notification;
- Monitored several policies, procedures, Service Level Agreements and controls that must be met without exception. Coordinated between IT team and other support teams depending on information provided;
- Experienced in training, motivating, and supervising IT technicians;
- Prepared documentation and training materials, coordinated technology related training;
- Built a cohesive help desk team through innovative hiring and training techniques;
- Collected users’ feedback to further enhance customer’s satisfaction level;
- Tracked CA Servicedesk logged tickets until closure and managing request from customers;
- Set priorities and impact of incidents to meet the customers’ satisfaction;
- Quickly and Effectively solved customer challenges and customers requested tasks;
- Created new employee tickets and departing employee tickets accordingly;
- Conduct weekly meetings to keep the team informed and to brainstorm new ideas;
- Performed employee evaluations for the Service Desk Team;
- Monitored employee timesheets to make sure all are up to date;
- Developed and maintained formal procedures for consistency and increased productivity;
- Chose appropriate technology and other resources to maximize help desk effectiveness;
- Implemented innovative staffing schedules for guaranteed coverage on the servicedesk;
- Re-engineered the service desk according to industry best practices;
- Maintained formal procedures for consistency and increased productivity;
- Analyzed help desk performance through various statistical and reporting methods.
Confidential
Project Manager/Senior Systems Administrator
Responsibilities:
- Coordinated across teams for replacing old Dell systems with new Dell systems for Aberdeen Proving Ground and Adelphi sites;
- Effective trained, motivated and mentored onsite technicians;
- Managed team of technicians and executed approved plan and successfully implement the solution; Managed the installation and successfully ledthe phase team to migration completion of numerous machines by the deadline date across the DOD enterprise;
- Managed multiple projects from planning to closing including user acceptance, implementation to customer support;
- Recorded detailed customer requirements, constraints, and assumptions with stakeholders in order to establish the project deliverables using requirement-gathering techniques such as planning sessions, brainstorming and focus groups;
- Developed schedules to ensure timely completion of project across the DOD enterprise;
- Executed the tasks as defined in the project plan in order to achieve the project goals;
- Measured project performance using appropriate tools and techniques in order to monitor the progress of the project and perform any required corrective actions, and communicate to stakeholders;
- Established and maintain relationship with stakeholders to make sure their needs are being met;
- Distributed and prepare weekly reports in accordance with the communications plans as required and present reports to senior ARL managers and CIO’s office;
- Documented detailed requirements in order to establish the project deliverables;
- Conduct phase closures and lesson learned meetings;
- Conduct training courses and training remediation;
- Ghost Dell systems using ghost 8.3 to image or reimage the customers desktops and laptops;
- Utilized UniCenter ServicePlus Service Desk to enter, modify, and close tickets;
- Utilized UniCenter Desktop and Server Management to remote into customers desktops and laptops;
- Utilized Track IT Database to make sure IP addresses matched the system and location;
- Installed, Patched, Upgraded and troubleshoot Java, Apache Tomcat and Microsoft .DLL files
- Utilized Escalade System to scan computer systems for IAVA (Information Assurance Vulnerability Alert) patches and updates to make sure they were compliant;
- Secured systems to Army, DISA & DOD standards manually, and with WSUS/CA, UAM/USD and Retina Scans, in conjunction with IA;
- Responded to computer security incidents/spilliages presented within the network of the Army;
- Utilized Proxy Host Master to remote control the customer system with permission to resolve problems;
- Rebuilt desktops and laptops with Windows 2000 images, replacing it with an updated Windows XP imaged and then deploying systems back to the customers;
- Supported Microsoft Office 2003 and 2007 applications on desktops and laptops;
- Supported Windows Vista on desktops, Bitlocker Drive Encryption, and Microsoft EFS Assistant;
- Utilized Internet Explorer 7 on desktops and laptops;
- Utilized Active Directory to unlock accounts and entering computer names for installations;
- Utilized Microsoft Baseline Security Analyzer 2.0.1 on workstations;
- Configured DHCP, WINS,and DNS on workstations and laptops;
- Utilized Robocopy on workstations;
- Utilized PortQry on workstations;
- Utilized Microsoft Network Monitor 3.0 on workstations;
- Utilized Lockoutstatus on workstations;
- Configured VPN on laptops for the customers;
- Utilized RegCure to fix and clean most registry on workstations;
- Utilized Lotus Sametime Green Force Tracker Connect 8.
Confidential
Senior Systems Administrator
Responsibilities:
- Migrated classified and unclassified systems from Windows NT 4.0 to Windows XP;
- Confidential Remedy Ticketing database for submitting, modifying, and closing out Helpdesk tickets;
- Created new user accounts utilizing Active Directory for classified and unclassified systems;
- Created new Exchange accounts for classified and unclassified systems;
- Administered Microsoft Windows XP on the desktop to support and resolve network issues;
- Utilized SMS to remote control the user’s computer to resolve help desk issues;
- Assisted with monitoring classified and unclassified systems security and machines in accordance with State Department security standards;
- Configured profiles for the user on the unclassified and classified computer systems. Supported Microsoft Office 2000 suites (Microsoft Outlook 2000, Microsoft Word 2000, Microsoft Excel 2000 and Microsoft PowerPoint 2000);
- Microsoft Exchange administrative duties: Update mail distribution lists and update user information in the Global Directory Listing (GAL);
- Performed weekly maintenance of Norton Anti-versions and virus definitions using Norton Anti-Virus Control Console;
- Utilized Windows 2000, XP, Microsoft Exchange 2003, Active Directory, Microsoft Office Suites, Outlook, CableXpress (Lotus Notes), Adobe Acrobat 6.0 and 7.0, Adobe Professional 6.0 and 7.0, Citrix, Remote Access Client, Blackberry, Ultrabac and LCD Projectors.
Confidential
Systems Administrator
Responsibilities:
- Administer Microsoft Windows 95, 98, 2000, Windows NT4.0 and Windows XP on desktops and laptops. Provided support to end-users with hardware and software issues.Hardware Support: Supported and resolved issues with printers (HP, Lexmark, and Unisys) and spoolers;
- Troubleshoot and replaced faulty hardware and components (NIC, Hard drives, RAM, keyboards, mice, monitors, and computers);
- Supported and resolved issues with Palm Pilot connectivity and synchronization such as (Palm IIIe, Palm IIIC, Palm III, Palm V, Palm Vx, PalmV IIIx, Palm m130, Palm m125, Palm m105, Palm m500, Palm m505, Palm m515, and Palm 525).Software Support: Installed Microsoft Windows NT 4.0 service pack 6 on desktops and laptops;
- Installed Citrix RAS client on laptops. Configured hardware profiles;
- Supported and resolved issues with Microsoft Office 2000 suites;
- Resolved issues with Microsoft Internet Explorer 6.0 and the Coast Guard Intranet;
- Advised users on how to manage their capacity space on the server while utilizing Quota Advisor Software.
- Utilized Hyena to remotely shutdown a customer’s system;
- Process back-ups and restores for the users using Veritas Backup Exec version 7.2 and 8.0;
- Utilized Microsoft Management Console 2.0 version 5.1 (SMS) to remote control users computers while troubleshooting or resolving current user issues;
- Utilized Win-AT version 2.0 command scheduler to perform remote installation of software.Microsoft Exchange Administrator Duties: Updated mail distribution lists and updated the user’s information in the Global Directory Listing;
- Utilized Remedy Ticketing system for submitting, modifying, and closing out tickets for the users.Maintained and upgraded operating systems (Windows NT 4.0, Windows 95, 98, 2000 and Windows XP) and anti-viruses (Norton and McAfee) software at the remote sites.Installed and replaced peripherals (Tapes, back-up drives, hard drives, NIC’s and modems);
- Performed user account management. Created and maintained user groups, assigned permissions to resources and provided user account management. Troubleshoot and resolved software and hardware issues.
TECHNICAL SKILLS
- Project Management Book Of Knowledge (PMBOK)
- PMP In Depth, Project Management Professional Study Guide for PMP and CAPM
- Microsoft Project 2003 and 2007
- Microsoft Office Suites 2003 and 2007
- Microsoft SharePoint
- Cyber Recruiter Web-Based Recruiting Application
- Rational Suite
- IBM Rational RequisitePro
- Q-Tip Scanning Tool
- Retina Scanning Tool
- Remedy version 7.1
- BelManage 2010 System Management
- SPLUNK Audit Logging Management Tool
- Tenable NESSUS Vulnerability Management Tool
- XACTA IA Manager Documentation Repositories
- XACTA Continuum Tool
- NIST Publications 800 Series
- FIPS Publications 199, 200, 201-2 and 202
- Federal Information System Control Audit Manual (FISCAM)
- OWASP (Open Web Application Security Project) Top 10, version 3.0.1 and version 3.1.1
- Industry Standard Coding Guidelines
- Risk Management Framework (RMF Workflow)
- Federal Information Security Management Act (FISMA)
- NETSPARKER TOOL (Vulnerability Scans)
