Information Security Officer Resume
SUMMARY
- Served as a liaison for stakeholders to translate requirements into highly specified project briefs and create Detail Functional Requirement Documents (DFRs )
- Formulates and defines systems scope through research and fact - finding combined with an understanding of applicable business systems and requirements.
- Elicits requirements, identify requirements to create process specification write detail functional requirements documents for information system processes: ensuring that requirements are complete and representative of stakeholders' needs .
- Coordinate with project teams and ensure projects are on schedule in SDLC in support of corporate strategy.
- Interact and contribute positively in multiple high-performance technologies and teams, and manage multiple projects
- Drive requirements gathering and documentation of projects, coordinates with project teams and ensure that projects are on schedule and within budget.
- Support system testing and system deployments - Conduct Independent Verification and Validation (IV&V) of Mainframe, mid-tier and DB2-based testing for business online services BOS application
TECHNICAL SKILLS
Technologies: Client server technologies, Internet Technologies, .Net.
Database: Oracle, DB2, MS Access, SQL,IDMS
Industry Standards: HIPPA, SOX, CFR 21 Part 11, CFR 21 Part 820, ISO, Six Sigma, CMM, EDI, 508, ICD- 10,CCD, CDA, C32,HL7.
Platforms: Windows NT/2000/XP/Vista, Mainframe ISPF/TSO ENDEAVOUR
GUI/Tools: Word, MS Visio, MS Excel, PowerPoint, Microsoft Share Point, IBM Documentum, Report Builder, Crystal Reports, DOORS 7.1, Track Wise. SharePoint, ASP.NET Web, MSDN (HTML, XML, CSS, AJAX, JSON, JavaScript, and JQuery.
Business Analysis Skills: Agile scrum SDLC, PM /EVM, Joint Application Development (JAD), Prototyping, Gap Analysis, Use Case Analysis, Data & Workflow, DMAIC methodology.
Tools: RequisitePro, Quality Center, MKS QC, Websphere Business Modeler, Test Director 6.x7/8.x.,WinRunner Load Runner, Remedy, ALM, QTP Quick Test Pro, Sharepoint.
Environment: Mainframe ISPF/TSO ENDEVOUR JCL IBMPCOM,COBOL CICS
PROFESSIONAL EXPERIENCE
Information Security Officer
Confidential
Responsibilities:
- Assign and activate UserIDs for authorized users.
- Adhere to Agency-mandated security policies, controls, and procedures as directed.
- Assist component management and project staff in assessing and resolving possible system security risks that may be associated with application development and local operational processes.
- Develop local guidelines to Agency-wide issuances pertaining to security awareness, training and education addressing unique local circumstances.
- Enforce the access control principles of “need to know” and “least privilege”, including assisting management to ensure that each user’s (including non-SSA personnel such as contractors) system access to data and transaction capabilities is limited and conforms to an authorized job function.
- Identify and communicate sources for security training.
- Maintaining a secure auditable file for user systems and remote access.
- Ensure potential internal controls and security weaknesses identify functional requirements and system specifications.
- Evaluate risks associated with systems developed by their component.
- Participate and support forums, workgroups, and committees established to address security awareness and training strategy.
- Provide input to Agency-wide policies, procedures, guidelines, controls, and planning documents.
- Review, validate, and authorize user applications for system access, including remote access.
- Retire systems, profiles and resources appropriately.
- Provide daily plan of the day and weekly status reports
Information Systems Security Engineer
Confidential
Responsibilities:
- Analyze, develop, and document business processes involving implementation of application control in the form of software whitelisting and blacklisting.
- Provide technical guidance for the implementation of software whitelisting and blacklisting tools.
- Develop documentation and procedures for both internal and external use.
- Provide Tanium systems administration support.
- Provide analysis and technical expertise to in corporate the security exceptions process into the agency’s whitelisting and blacklisting tool (e.g. Tanium)
- Develop business process for the evaluation of the security exceptions submitted and the security exceptions process as a whole.
- Develop criteria for evaluation of proposed hardware and software in the agency.
- Work with internal agency staff to document and develop processes and schedule to review existing methodologies for security exceptions.
- Assist internal agency staff with evaluating submitted security exception requests.
Senior Business Analyst
Confidential
Responsibilities:
- Develop Gap Analysis documentation to define various EIDM customers’ business needs.
- Develop business requirements for EIDM and OKTA systems.
- Translate business requirements into detailed user, functional and systems requirements, using agile methodology.
- Support the Portal team to ensure implementation meets specification and expectations.
- Facilitate Joint Application Development (JAD) sessions to generate use cases and context diagrams.
- Primary contact for Subject Matter Experts and assist with any issues across the software development lifecycle.
- Provide weekly, monthly and quarterly status reports.
- Present documentation for review by internal and external stakeholders.
- Communicate necessary changes to stakeholders in meetings.
