Security Analyst Resume Profile
Summary of Qualifications: Manage and merge all security determinations crosswise enterprise business units, together with internal and remote clients. Maintain Legal and Compliance requirements, including PCI standards and SSAE-16 reports. Recognize possible weakest points related to the security of the electronic data at all levels of the operation. Establish security measures to minimize risks, increase the consistency, confidentiality, availability, and integrity of the electronic data. Entrepreneurial and solutions-focused professional with validated responsibility for purposeful, business, and comprehensive company objectives. Effectively and proficiently incorporate and develop procedures, accomplish difficult subjects within functional area of expertise, create long-term planning, and contribute to the overall business strategy. Over 30 years in Information Technology and Information Security.
Technical Skills:
- Security Information and Event Management, SIEM
- Cloud designs, operations, and hardening
- CheckPoint R71.40, R75.45 GAIA , R75.46, R76.0, 77.0, and 77.20. IPsec, PKI, Proxy services
- Trip Log Wire TLC , RedSeal, Arbor PeakFlow
- Dell SecureWorks, SourceFire, AlertLogic, SilverTail,
- Imperva, Netwitness, ProofPoint, and Websense Triton
- RSA Adaptive Authentication and Identity Management. IBM Identity Management, SSO
- Microsoft ForeFront Identity Management
- VPNs' design, implementation, and strengthening strong background on different encryption methods
- VMware, SiteMinder, DataPower
- Multiple IDSs and IPSs
- WireShark, Nmap, Metasploit, Burp
- Server 2012 Enterprise, 2008 Enterprise, and 2003 Enterprise, Active Directory Administration
- Citrix Server 5.0 SQL 2000, 2005, and 2008
- Threat Management Gateway for Windows Server 2008, New ISA version
- dBase II, III, FoxPro, Fortran IV and 77, Cobol 85 and 2002, Turbo Pascal 5. 7.0, Delphi, Assembler, and C .
Information Technology Proficiencies:
- Penetration Testing, Computer Forensic, Data Recovery
- IT investigations and analysis of security breaches
- Skilled with electronic fraud detection and contention.
- System Administration
- Network Configuration, Troubleshooting and Maintenance
- Savvy on addressing the emerging threats to information security by developing and maintaining a strong information security strategy
- Knowledgeable with Identity Management Systems and Systems Administration.
- Secure wireless communications and mobile applications.
- Experienced with risk analysis, internal controls audit and testing, operations risk management, development of security systems and implementation of security protocols.
- Probed expertise complying with the laws and regulations, especially SOX, ISO 27001 best practices, OWASP, and SSAE-16 Reports
- Proficient on ITIL procedures and techniques, as well as PCI regulations
- Established and maintained technical infrastructure secure and administrative computer and network security safe.
- Pedagogical Skills: Taught classes for Florida National University, Everest University, ITT Technical Institute, The Academy South Florida, New Horizons, Fasttrain College, and The Training Associates. Courses taught: CISCO, Ethical Hacking, ITIL v.3, Computer Sciences, Digital Forensic, Algebra I, II, Capstone, Microsoft, C Programming, and others such as Network , Security , A , SQL, Database Management, Wireless Communications, Java, and Java Script.
Professional Experience:
Confidential
Chief Technology Officer
Oversee all issues related to security incidents from the technical and legal perspective throughout Central and South America. Develop and maintain a proper enterprise business continuity plan, and closely work and supervise the necessary measures to solve and prevent any security breaches that might occur. Manage security engineers and risks compliance analysts. Enforce security policies within the IT department. Propose, develop, manage, and audit the security policies to be implemented locally and in network environments. Prepare and control operational budgets for the security department and its personnel, training, and other activities related with the proper execution of the financial plan. Coordinate and manage day-to-day operations of the Information Security department in addition to managing a medium-size geographically dispersed team. Manage the companies auditing process and serve as the interface between external auditors and internal departments. Design security controls and policies to be implemented company wide. Revise existent security policies and procedures as well as propone new ways to get better data protection. Perform forensic analysis on daily tasks and advise of best practices to minimize security exposure and risks. Compile reports on security metrics, project status, and compliance. Define security policies, disaster recovery plans, and keeping it up-to-date. Foster an environment of regulatory awareness and guarantee regulatory compliance with SSAE-16 and PCI standards. Formulate, review and propose audit plans, classify, suggest and recommend mitigating process and controls oriented to minimize risks and vulnerabilities discovered during frequents system evaluations. Make sure all SSAE-16 and PCI compliance requirements are on place as for example, internal and external PCI scans, network segmentation, separation of duties, documentations, etc.
Confidential
Senior Security Analyst
Perform deep penetration testing oriented to find system's vulnerabilities, investigate the possible reasons and origins of the cyber-attacks, and create a plan to improve the electronic data protection. Execute forensic analysis on daily tasks, and suggest best practices to minimize security exposure and risks. Install, configure, maintain, and troubleshoot firewalls, proxy servers, network monitoring tools, authentication methods and technologies, and network intrusion detection systems. Triage inbound security events, monitor correlation metrics, update signatures on customer IDS devices, update policies on customer's firewalls, collect, analyze, and report anomalies detected during the security audits. Documented all tickets and request through a ticket system. Design, develop, and implement organizational plans to improve customer's portfolio and quality of the services.
Confidential
Information Technology Director
Responsible for the entire system administration such as: hardware/ software, installations, configurations, maintenance, troubleshooting and repair of Servers, PCs, Terminal Server, Printers, Projectors, TV and Audio Devices, Wireless Connections, Network Equipment's, Internet, System Backup, Telephone System, VoIP and user Accounts. Managed the WAN, LAN, and VPN connections. Completed inventory, accounts creation and maintenance. Accountable for the management of Help Desk issues, including incident definitions, tracking, escalation, resolution, and closure of all incidents. Managed and created the IT budget. Managed customer support from Tier I to Tier III.
Confidential
Professor Computer Science Mathematics
Planned, prepared and delivered classroom instructions in lecture and/or laboratory format while utilizing a variety of instructional methods. Evaluated and resolved student inquiries, issues, and problems. Ensured appropriate action was taken to the satisfaction of students while staying in compliance with company policies, procedures, and legal requirements. Participated in faculty meetings.
