Senior Security Engineer Resume
4.00/5 (Submit Your Rating)
Nashville, TN
PROFESSIONAL EXPERIENCE
Confidential, Nashville, TN
Senior Security Engineer
Responsibilities:
- Design, Implement, and maintain secure systems and environment within a high - growth retail organization.
- Vulnerability Scanning, remediation planning, and reporting
- Incident response and Disaster Recovery
- Implemented DR and IR policies and mechanisms
- Lead Engineer in DR exercises
- Internal forensics (no ‘chain of custody’ involvement)
- The ‘Who What Where’ identification for purpose of improving processes.
- Creation and training regarding policies and procedures within the environment from an Information Security perspective.
- Working actively with following toolsets and technologies
- Qualys Vulnerability Scanner (Lead Engineer)
- Implementation of Scanners and infrastructure
- Design and Implementation of policies and procedures for scanning and remediation
- Threat-Hunting and ‘Best Practice’ implementation
- QRadar SIEM (Lead Engineer)
- Onboarding of log sources
- Working directly with SOC to identify thresholds and threat events
- McAfee EPO, IPS, MVM, AV, HIPS, PA, DLP, NTR, MAR, ENS (Lead Engineer)
- Implementation, design, and engineering of all components.
- Operational oversight of all components for SOC and Engineering team
- Threat Hunting approach and design
- Symantec/Veritas Data Insight (Lead Engineer)
- Designed and Implemented for entire storage infrastructure
- Design and oversight of ‘Data Classification’ components and organization of unstructured data
- Compliance and DLP integration design and implementation including oversight of ongoing operations.
- Vontu DLP (Symantec) (Lead Engineer)
- Designed and Implemented for entire organization
- Design and oversight of ‘Data Classification’ components and organization of unstructured data
- Compliance and Data Insight integration, design, and implementation including oversight of ongoing operations.
- Palo Alto (Layer 7 Firewall) (Lead Engineer)
- Threat Response and Identification
- Rule creation, implementation, and troubleshooting
- Includes utilization of App-ID, Threat Identification/AV, and Wildfire components
- Checkpoint Firewall
- Rule Creation and segmentation design
- Wireless IPS (Motorola and Aruba) (Lead Engineer)
- General oversight and inclusion with SOC monitoring methods and response.
- Lancope Stealthwatch (Netflow Aggregation and Reporting)
- Used for troubleshooting, monitoring, and threat hunting.
- Monitoring of organizational ‘Hot Areas’
- Password Manager Pro
- Design and Implementation of organizational Password Management solution.
- Oversight of ongoing operational components.
- Citrix NetScaler (Lead Engineer)
- Access Gateway for Xen VDI design, management, and implementation
- Created thresholds, logging criteria, and workflow for SOC monitoring of Web Application features and other advanced protection mechanisms for 78 web applications.
- Design, creation of, and architecture of following components for 200+ web applications
- Response Policies
- Rate Limiting
- Web Application Firewall
- Rewrite Policies
- General load balancing
- Failover/Recovery of applications across multiple locations
- Involved with (guidance, planning, etc) the following initiatives
- Internal Phishing campaign
- Data Classification
- Secondary Data Center design and architecture
- Auditing/Response for PCI and ISO based requirements
- PCI GAP remediation, ROC deliverable.
Confidential, Nashville, TN
Consulting Engineer
Responsibilities:
- Providing IT Security and HIPAA assessments to healthcare organizations.
- Security Auditing of Healthcare organizations
- Network assessment and redesign for Healthcare organizations (LAN and WLAN)
- Network security and penetration testing
- Physical security and penetration testing
- Providing services to assist healthcare organizations to meet compliance requirements.
- Performing Vulnerability Assessments, Compliance/Policy assessments, and Security Monitoring services.
