Vulnerability Management Analyst Resume
4.00/5 (Submit Your Rating)
EXPERIENCE:
Confidential
Vulnerability Management Analyst
Responsibilities:
- Writes Python scripts to interact with various APIs to automate tasks and integrate reporting functions of multiple security tools such as Tenable SecurityCenter, InfoBlox, and eService Desk into a custom Confidential solution.
- Analyzes penetration test findings and assigns validity, priority, remediation steps, and ownership.
- Monitors and tracks open penetration findings.
- Documents and confirms closure of penetration findings.
- Provides vulnerability evaluations and risk assessments and for enterprise risk exception process.
- Supports enterprise threat intelligence by identifying, detecting, analyzing, and communicating new security vulnerabilities.
- Supports platform engineering and application support teams with security consulting and vulnerability remediation guidance and solutions.
- Advises and ensures security concerns are met and align with PCI, internal, and industry standards.
- Compiles enterprise vulnerability metrics and penetration test results for weekly, monthly, and quarterly management briefings.
- Responsible for Tenable SecurityCenter administration and asset management.
- Performs vulnerability scanning, reporting, tracking, and analysis using Tenable SecurityCenter and QualysGuard.
- Determines priority of security patches for monthly and quarterly patch cycle reviews.
- Participates in penetration testing of the network utilizing Nmap, Metasploit, and Burp Suite.
- Reviews penetration test results and assigns tickets to system owners for remediation and manually verifies issue completion.
- Generates and analyzes Nipper reports for network device configurations.
- Provides security consulting and advice to other departments.
Confidential
Information Assurance (IA) Engineer
Responsibilities:
- Provided security consulting, vulnerability research and remediation, and security control documentation efforts required to insure system compliance with DoDI 8500.2 / NIST SP800 - 53 IA Controls.
- Managed and maintained Plan Of Action & Milestones for in progress IA Controls.
- Administered IA Controls through Security Technical Implementation Guide compliance, patching, and mitigation justification statements for RHEL and Windows systems.
- Reviewed and updated IA Control artifacts including system security plan and remote access policy.
- Oversaw Host Based Security System (McAfee ePolicy Orchestrator) implementation and policy.
- Utilized security auditing tools and reporting tools such as ACAS (Tenable SecurityCenter), Retina Network Security Scan, SCAP Compliance Checker, and DISA STIG Viewer.
- Maintained configuration management of system with creation and updating of system change request tickets.
- Updated system build plans and other documentation as appropriate with each system patch or release.
- Provided communication between DBA, Infrastructure, IA, and Certification and Accreditation teams.
- Designed, configured, updated, and maintained, HBSS (McAfee ePolicy Orchestrator) architecture for system compatibly testing within a secure lab environment.
- Responsible for creating and testing cumulative maintenance security patches Windows server and workstations.
- Researched and applied security patches and configuration changes for Windows workstation, Windows server, and Sun Solaris 8 systems.
- Automated the silent installation of application updates and system security patches through the command line, AutoIT, Visual Basic scripting, and Perl scripting.
- Edited and managed security related local group policy settings as well as registry settings on Windows systems.
- Created, maintained, administered, VMware Infrastructure and Workstation virtual machines and snapshots.
- Repackaged and tested software installations using Epsilon Squared InstallRite, Nullsoft Scriptable Install System, and Microsoft App-V.
- Documented and updated trouble report tickets within Rational Clear Quest.
- Functioned as technical team lead mentoring and supervising two employees.
- Integrated both ruggedized and commercial hardware with commercial and proprietary government software.
- Created, supported, tested, and updated custom laptop and server software builds with appropriate drivers.
- Authored and environmental and performance test architecture and plan.
- Designed, tested, and supported lab space and network.
- Provided engineering support to Project Management Office on Blanket Purchasing Agreement Requirements, environmental concerns, technology updates, and vendor specific hardware issues.
- Researched, authored, and maintained required documentation including test proposals, test plans, and technology white papers.
- Provided engineering and IT support for test team.
- Researched material and equipment requirements and contacts vendors for sales quotations.
- Acted as Configuration Management Representative and is solely in charge of checking materials in and out of change management.
Confidential
NOC Technician
Responsibilities:
- Provided proactive monitoring of production systems via AS400 operator console, IP Monitor, and Microsoft Operations Manager.
- Identified, troubleshot, and supported enterprise servers, network devices, applications, and production processes.
- Provided correct issue routing, escalation, and work order documentation through Track-It
- Provided and managed secure access to vendors and Confidential ’s associates relating to production systems.
- Cataloged and tracked backup media.
- Generated and distributed business and technology reports.
- Communicated status of issues with support team, MIS Management, and the business both verbally and in writing.
- Improved, streamlined, clarified, and documented nightly production processes.
- Ensured proper transition during shift changes.
Confidential
Network Administrator
Responsibilities:
- Independently operated as point of contact for Information Technology at Edison College of Naples.
- Managed all software and hardware configurations, installations, repairs, upgrades, and refreshes for 300 Windows XP machines and Windows NT 4.0/2000/2003 servers.
- Administered computers, user accounts, and group policies within Active Directory.
- Ensured proper network connectivity through server and network switch configuration of DHCP, DNS, and VLANs.
- Secured networked printers and storage devices through resources permissions.
- Navigated through proprietary Help Desk Online software in order to receive, create, update, and manage work tickets and ticket reports.
- Oversaw inventory control through asset tag placement, property reports and invoice sign offs.
- Directed machine backups and roll outs via Norton Ghost.
Confidential
Networking Specialist
Responsibilities:
- Provided computer and network support for small businesses and home users.
- Configured workstations and laptops for wireless networking, network printing, and synchronization with PDAs and Blackberries.
- Installed, configured and supported Microsoft Windows, Office, and Exchange.
- Created hard drive clones and backups using Norton Ghost.
- Managed server resources via remote desktop connections, terminal services, Citrix client and applications.
Confidential
Consultant
Responsibilities:
- Provided troubleshooting for Windows Operating systems hardware devices, software applications, and peripheral components.
- Use of corporate and home versions of Antivirus and spyware removal tools.
- Installed and configured network interface cards, network printers, hard drives, PCI sound cards, and Windows Operating System.
- Windows network client support and configuration of TCP/IP, DNS, and DHCP.
- Implemented structured network security through the setup and use of firewalls.
Confidential
Technical Support Representative
Responsibilities:
- Supported corporate and public customer base as a Level I Certified Confidential Desktop/Laptop Technician.
- Maintained and established proper customer relations as first point of contact.
- Provided step-by-step troubleshooting instruction to repair hardware/software and simple network problems via telephone.
- Navigated Proprietary Confidential Database to manage customers’ work history, service orders and parts shipping orders.
- Assisted customer support, sales, and theft departments by making appropriate suggestions to customers whenever appropriate.
