We provide IT Staff Augmentation Services!

It Security Consultant Resume

3.00/5 (Submit Your Rating)

PROFESSIONAL EXPERIENCE:

IT Security Consultant

Confidential

Responsibilities:

  • Designed and implemented a virtualized lab environment resembling a scaled down corporate network complete with external and internal routing protocols for use in testing custom security software as well as practicing and evaluating penetration tests.
  • Performed web application penetration tests and vulnerability assessments using a variety of tools including Burp Suite and the Browser Exploitation Framework.
  • Wrote and modified custom scripts in a Linux based environment using Python and BASH scripting.
  • Submitted recommendations to various security related projects.

Confidential, Fairfax, VA

Sr. IT Security Ops Engineer and Incident Response Technician

Responsibilities:

  • Conducted various vulnerability assessments and penetration tests within an enterprise environment utilizing industry standard commercial, non - commericial, and open-source projects including Tenable Nessus, CoreSecurity Core Impact, Burp Suite, Confidential Framework, nMap, metasploit, and multiple packet sniffers including Tenable PVS, Wireshark, and tcpdump. Targets ranged from individual users to multi-campus departments, and critical and point-of-sale systems.
  • Administrator and security operator for ArcSight SIEM solution (ESM, Connector Appliance, and Logger modules). Duties included SmartConnector and custom FlexConnector installations, rule creation and optimization, database maintenance, and security analysis.
  • Implemented use-cases from several departments within ArcSight based on need and requirements (i.e., a ruleset with correlation to match public IP, ports, and timestamps in order to more easily server copywrite violation notices for downloading pirated material.
  • Created general purpose centralized syslog server using rsyslog for use as a forwarder to various ArcSight Connectors to work within memory limitations and not overload ArcSight.
  • Installed and maintained several Redhat, CentOS, and FreeBSD servers for distributed vulnerability scanning, network tap monitoring and analysis, and other special purpose tasks including creating a multi VMware ESXi environment for lab and research purposes.
  • Monitoring and Analyzing IDS events using Nitro Security's NitroView and NitroGuard products, along with smaller targeted deployments consisting of both Snort and Securita products.
  • Created various web applications in Java for Confidential Security Office specific tasks, including an application to better find, filter, search, and sort through the National Vulnerability Database in order to encourage user awareness of vulnerabilities for relevantly used software.
  • Wrote several low-level programs for use in assisting in the analysis of network traffic at high-speed transmission rates using C and libpcap including a specific program created to analyze and remove MPLS headers for use with a device that did not understand the MPLS protocol.
  • Lead team to create university's Computer Incident Response framework, work flow, policies, and procedures along with verifying alignment with university's police requirements along with being an active member of the Incident Response Team.
  • Evaluated and made recommendations on several IT security related products for vulnerability scanning, penetration testing, and IDS/IPS devices.
  • Gave monthly talks about various security topics for server administrators. Topics included high-level and low-level information depending on audience requests.
  • Maintained all infrastructure belonging to Confidential Security Office by supporting a multitude of servers, along with racking and organized cabling.
  • Responsible for enforcing mandatory log book to describe any changes made within the racks.

Confidential, Fairfax, VA

Special Projects and Incident Response Technician

Responsibilities:

  • Technical lead for project based on migrating university systems from Novell to an Active Directory environment.
  • Responsibilities include working with individual departments to facilitate business needs, creating scripts to help migration process, and provide documentation on common troubleshooting tips.
  • Member of university's newly formed incident response team.
  • Created and maintained a Windows XP (Win32 - compatible) program for unattended installations of the Windows XP operating system and several computer applications.
  • Wrote operational support instructions for users and administrators of the software.

We'd love your feedback!