We provide IT Staff Augmentation Services!

Information Security Analyst Resume

3.00/5 (Submit Your Rating)

Irvine, CA

PROFESSIONAL SUMMARY

Comptia Security+ certified Information Security Analyst with over 7 years of experience in Information Security, Vulnerability Scanning, Penetration Testing, Web Application Penetration Testing, Application Security, Network Penetration Testing, Security Operations SOC, DLP, Security Monitoring, Incident Response, Identity and Access Management, Endpoint Protection and Mobile Device Management.

PROFESSIONAL EXPERIENCE:

Confidential, Irvine, CA

Information Security Analyst

Responsibilities:

  • Experience in Vulnerability Assessment using Nessus, Nexpose, nmap Netsparker and Acunetix.
  • Experience in Penetration Testing using tools like Kali Linux, Metasploit, meterpreter, wireshark, password crackers, social engineering and client side attacks.
  • Experience in Web Application Penetration Testing using manual and automatic scanning tools like BurpSuite, Vega, OWASP ZAP, sqlmap and Beef - xss etc for detecting web attacks like XSS, SQLi and CSRF etc.
  • Wordpress Scanning and security.
  • Experience in Network Penetration Testing, wireless security using aircrack-ng suite.
  • Static Secure Code Analysis using HP Fortify, IBM Appscan.
  • Thorough understanding of OWASP Top 10, CWE/SANS Top 25, CIS Critical Security Controls, CWE and CVSS scoring system.
  • Comfortable working in Unix and Windows environment.
  • Experience in C, C++, SQL, JavaScript, HTML.

Confidential, Irvine, CA

Information Security Engineer

Responsibilities:

  • Experience in DLP (Data Loss Prevention) solution Symantec DLP, able to perform policy tuning, trigger Endpoint Response rules.
  • Knowledge of SIEM (Security Information and Event Management) solution Splunk, able to perform searches, create reports, alerts and dashboards.
  • Hands on experience in IDM (Identity Management) using the Oracle Identity Manager (OIM) tool for access provisioning, de-provisioning of the users.
  • Active Directory provisioning to manage the Active Directory groups, users and access.
  • Assuring system compliance by ensuring endpoint security for disk encryption using Bitlocker and port lock using DriveLock.
  • RSA Security Console Management.

Confidential

Security Engineer

Responsibilities:

  • Monitor alert logs triggered by the activities performed by individual resources on the UNIX & Windows Servers, Oracle and Sybase databases on daily basis.
  • Working experience in Alert Monitoring, Log Analysis and Unix Sessions Auditing using the tool Centrify Direct Audit Auditor.
  • Responding to security incidents and escalations, performing advanced analysis, containment, eradication of the intrusion.
  • Maintaining Endpoint Security by managing outdated AntiVirus Definitions, stolen/lost devices and OS Patch Management using JAMF.
  • Securing organization’s mobile devices using Airwatch for MDM (Mobile Device Management).

We'd love your feedback!