Subject Matter Expert Resume
Atlanta, GA
SUMMARY:
- Extensive experience in the management and deployment of solutions protecting information technology for military and National Intelligence agencies.
- Experienced in application security test planning, development and execution.
- Self - motivated solutions-focused leader and team oriented Information Security Expert with broad-based experience and detailed in-depth knowledge of security tools, technologies and best practices. Expert in Risk management and Vulnerability Assessment.
- Experience briefing high level government executives, Generals, and large groups.
- Proven ability to successfully analyze an organization's critical support requirements, identify deficiencies and potential opportunities, and develop innovative solutions for increasing reliability and improving productivity.
- A broad understanding of Information Technology, including installation, configuration, management, troubleshooting, and support.
- Results-oriented leader and professional with successful management experience of a decentralized, international/multinational workforce.
- Articulate, proven professional with the ability to explain complex technical details to audiences of various technical levels.
TECHNICAL SKILLS/KNOWLEDGE:
Risk Management Framework, Cybersecurity Framework, Cloud Cybersecurity, Confidential, FAR, OWASP, FISMA, DIACAP, DITSCAP, Confidential & Confidential, PII (privacy), Policy, Technical-writing, SSAA/SSP, Business Continuity, ITIL, Confidential, ISO 9001, Confidential 800-53, Confidential 800-171, Confidential 800-63, Confidential 800-60, PII, PHI, FEDRamp, WebSense web content filter, Tenable Security Center, Nessus vulnerability scanner, Retina vulnerability scanner, Burp Suite, WireShark, NMAP, Splunk, SIEM, Symantec SEP, Data Loss Prevention; PKI, McAfee ePolicy Orchestrator, HBSS, ACAS, STIG, TCP/IP, Routers, DNS, SMTP, FTP, HTTP, CT&E, ST&E, INFOSEC, Certification & Accreditation, SOC, COBIT, SOX, PCI DSS, FCC, DHS, Identity Access Management (IAM), Privileged Account Management (PAM), Multi-factor Identity, Datacenters, SAP, SharePoint, Windows Server 2008, Windows Server 2012, Windows 10, Windows 7, Solaris, Linux, VMWare, CISCO IOS, Encryption, Physical Security, Sensitive Internet Protocol Router Network (NIPRNET), Secret Internet Protocol Router Network (SIPRNET), Assured Compliance Assessment Solution (ACAS), Global Command and Control System (GCCS), Joint Worldwide Intelligence Communications System (JWICS), Confidential CDI, CUI.
PROFESSIONAL EXPERIENCE:
Confidential, Atlanta, GA
Subject Matter Expert
Responsibilities:
- Responsible for leading the risk management framework-based accreditation process for authorizing applications and systems to operate safely and securely within compliance of national and international standards; perform vulnerability assessments, vulnerability reporting, writing and monitoring Confidential & Confidential, and overseeing the security of applications throughout the product lifecycle; interface with individuals from diverse cultures, different levels of technical expertise from various national and international agencies to develop and maintain secure and effective information solutions.
Confidential, Huntsville, AL
Cybersecurity Subject Matter Expert
Responsibilities:
- leading a cross-functioning team of managers, developers, and administrators in meeting Confidential SP 800-171 compliance; and solving cybersecurity issues of vulnerability and risk management. 3rd party supplier system administrators, application developers, and other security personnel.
- Assess changes in Confidential and Confidential driven security requirements, identify impacts of new or changed requirements; define/design technical solutions to satisfy requirements.
Confidential, Atlanta, GA
Senior Security Management ConsultantResponsibilities:
- Completed short term contract conducting research to solve complex problems in areas of computer science, information technology, communications, networking, and socio-technical systems. Research for public and private clients supports national security; emergency response; integration of health care systems; interoperability and security of interconnected systems; education and learning; technology strategy, planning, and decision support; development of public policy; and commercial product realization. Research experience include:
Confidential
Senior Security Management Consultant, Atlanta, GA
Responsibilities:
- Senior Security Test Program Manager for Confidential ’s global security test project.
- Responsibilities included development and execution of test plans, test cases and testing methodology for web applications hosted on Linux servers to comply, PII Data Loss Prevention, architecture and framework and manual testing checklists for web applications.
- Worked closely with Development, Product Management, Design, Support, and other key stakeholders utilizing the Scrum Agile methodology.
- Conducted reviews of policy, procedures and high level documentation.
- Responsible for interviewing, hiring and training Security Test Team personnel.
- Identify mitigation strategies to meet security business and regulatory requirements
- Comprehensive Security Test Plan integrating security into software development lifecycle
- Control & Compliance Test Plan and High Level Documentation
- Privileges Access, Roles & Permissions Testing
- Traceability Matrix for Identification and mapping of business requirements & processes
- Detailed Manual and Automated Security Test Cases for cloud services
- Daily and Weekly progress and status reports
Confidential, Columbia, SC
Senior Security Management ConsultantResponsibilities:
- Principal Information System Security Program Manager overseeing the DIA information assurance program conducting vulnerability assessments, vulnerability reporting, writing and monitoring Confidential & Confidential, Web Application security, risk assessment, Symantec SEP, Data Loss Prevention, auditing, SIM, SIEM, certification and accreditation, and overseeing the continuity & incident response processes.
- Responsible for writing technical standard operating procedures, SSA/SSP, security policies and in-depth status reports reviewed by executive management.
- Performed risk assessments of applications, systems, tools, and infrastructure, to include risk identification, assessment, evaluation and control monitoring.
- Developed training and technical guidance for Information Security strategies and technologies Facilitated Configuration/Change Control Board.
- Monthly and Weekly Status Reports and Audits to Director, Defense Intelligence
- Confidential Risk Management Framework Compliance; Privileged Account Management
- Application Security Assessment, Testing and Certification process; Site Transition Plan
Confidential
Area Operations Manager
Responsibilities:
- Implemented the ITIL service framework throughout Southwest Asia area of operations
- System Security Plan, Concept of Operation, Continuity of Operations, Network Architecture
- Statements of Work, Memorandums of Agreement, Requests for Proposal
- Successful implementation of Multi-factor Identity for Confidential
- Facilitate acquisition of work visas, country clearances, transportation and living arrangements
Confidential, San Antonio, TX
Information System Security Program Manager
Responsibilities:
- Executed Intelligence Information System programs including technical and procedural security policies that implement a Confidential approach to managing the risk, Data Loss Prevention and survivability of Information Systems resources.
- Coordinated penetration and web application testing performed by the Confidential ( Confidential ).
- Developed and maintained System Security Plan. P erformed risk assessments of applications, systems, tools, and infrastructure, to include risk identification, assessment and control monitoring. Developed training and technical guidance for Information Security strategies and technologies .
- Configuration Management Plan and Change Management process
- Survivability Plans - Incident Response Plan, Business Continuity Plan
- Created information review and transfer process reducing information spillage
- Letter of Commendation from Senior intelligence Officer for Data Loss Prevention solution
- Received cash award for Leadership and technical excellence
