We provide IT Staff Augmentation Services!

Cyber Security Analyst Resume Profile

5.00/5 (Submit Your Rating)

VA

SUMMARY OF QUALIFICATIONS:

  • Administration of Checkpoint, Cisco PIX Firewalls, configuration and log file analysis
  • Hands on experience with SPLUNK and SSIM Symantec Security Information Manager
  • Administration of Oracle 8i databases
  • Hands on experience with LINUX/UNIX
  • Hands-on experience with Network-Based Checkpoint IPS-1, ISS's RealSecure and Host-Based Tripwire Intrusion Detection Systems
  • Hands on experience with Mcafee epo/Intrushield
  • Hands on experience with HP's Tipping Point, Bro, Argus and Niksun NetDetector
  • Forensic tools: Netwitness Investigator 9.5, Sleuthkit Autopsy, Encase 6.0
  • Hands-on experience with Arcsight and NitroView SIEM from Nitro Security
  • Hands-on experience with SNORT IDS/IPS. Tuning, configuring and deploying sensors
  • Configured and maintained Cisco Catalyst 29xx-36xx series Switches
  • Experience with VLANs and CiscoWorks
  • Managed ACE Server/Secur ID Tokens
  • Administration with Bluecoat SG-810 and AV and Websense TRITON
  • Hands-on experience with Nessus and Nmap
  • Experience with Network Access Control CounterACT
  • Experience with Packet Sniffers Wireshark/TCPDump
  • Experience with Crime scene preservation, evidence handling, gathering and collecting including the Chain of Custody

EXPERIENCE:

Confidential

Cyber Security Analyst

Assists in running network scans with NESSUS and application/database scans with DBprotect. Apply and update patches. Maintain SNORT sensors, made sure they are working correctly and update rules. Worked with IBM'S Tivoli/BigFix to monitor and update patch systems.

Confidential

Cyber Security Analyst

Worked with Nessus scans and analyze and interpret the results. Created tickets and followed up with the Help Desk Team to remediate current Vulnerabilities and threats.

Confidential

Security Analyst Manassas,

Working at the Senate's SOC, intense monitoring of network traffic using Arcsight SIEM. Worked with and monitored variety of Channels in Arcsight from different security events. Correlated events with SPLUNK and Symantec SIM to weed out False positives and identify real threats and intrusions internal and external. Worked with the government Watch Officer WO to tackle intrusions, virus outbreaks and Incidents. Wrote up reports on Incidents or any harm inflicted upon the Senate's network including Malware/Spyware.

Confidential

Network and Host Based Intrusion Detection Consultant

Worked at the FBI NGInet Next Generation Identification project at Lockheed Martin.. Installation and maintainence of SNORT IDS on Linux Cent OS, monthly rule updates, working with SQL database to backup alerts. Monitored BASE and its alerts. Scrutinize network traffic .Take a snapshot of the NGInet 3 times week using TCP/Dump and analyze the captured packets with Wireshark and present the findings to the customer. Looking for any suspicious or malicious traffic internal or external. Make recommendation of the findings, what rules and which one to be turned on in the IDS. Testing of rules if they actually work or trigger alerts in BASE. Analyze data from Host-Based IDS AIDE Advanced Intrusion Detection Environment .

Confidential

Intrusion Detection/Prevention Engineer

Provided front-line analysis for defending and protecting Dept of the Interior BIA Bureau of Indian Affairs network. Supported the BIA's 24/7 CSIRT/SOC data center. Used ArcSight to Monitor, reading and interpreting Checkpoint IPS-1 alerts and console for suspicious/malicious activities. Tuned and filter out alerts/signatures to further reduce false positives. Identify and recognize attack signatures. Isolate, identify and contain incidents and prioritize them by the DOI's policies and standard procedures. Further investigated with ArcSight on incidents or attempted intrusions and network scans and prioritize them by critical, high, medium or low threat levels. Determine if it's a legitimate traffic, a reconnaissance, false positives, false negatives, false interpretation or a real attack on the network. Analyze traffic at the Packet-level using tools such as WireShark.. Monitor 19 Sensors deployed across BIA's WAN enterprise. Being able to recognize attack patterns and behavior on the network. Work with SNORT IDS/IPS, tuning, configuring and deploying SNORT sensors. Writing, creating and managing old and new rules to mitigate False positives. Constantly fine tuning and refining rules and testing them. Monitor and reacted to alerts using BASE Basic Analysis and Security Engine . Monitoring daily logs from Cisco's PIX firewall. Particularly looking for anything that is denied, failure or error.

Confidential

Intrusion Detection Analyst

  • Investigated computer breaches and crimes within different District Agencies: Fire Dept, Police Dept, Office of Latino Affairs, Office of the General Counsel, etc. Crime scene preservation, evidence handling, gathering and collecting including the Chain of Custody. Investigated cases such as Network/Resource abuses, Embezzlement, Pornography, Abuse of funds, Unauthorized Access, Suspicious Activities., etc. Conducted preliminary and interviews of personnel related to the investigations. Worked closely with FBI and other local authorities to obtain information during investigations. Ability to respond to minor and major computer security incidents. Ability to quickly adapt to customer incident response procedures working in a virtual team, creating and responding to tickets, attending conference call meetings, interacting with other groups such as Firewall and IDS teams. Set and follow District's protocols, rules and procedures. Prepare and support publishing of incidents, alerts, advisories and bulletins. Wrote and presented materials/reports on completed cases and investigations. Ability to write clear and concise reports to technical and non-technical personnel and being able to explain how the conclusion of investigations came about.
  • Monitored Network-based NFR and Host-based ISS's Site protector for suspicious activities. Recognized attack signatures and identify intrusions, viruses and other network anomalies. Ability to differentiate between False positives and real attacks.

Confidential

LAN Analyst

Set up new PCs, installed Novell Clients on students PCs and made sure that they are connected to the school's LAN. Troubleshoot network connection, login, internet, printer and email problems. Connected MAC users to the LAN. Worked and troubleshoot with all varieties of desktops and laptops, including MACs: HP, Dell, GW2, Hitachi, Sony, Toshiba, NEC, Acer, AST, Compaq, iMac, CompUSA. Assembled 100-Base-T, CAT 5 UTP patch cables for Ethernet network connections.

Confidential

Firewall Admin/Security Engineer

Responsible for the performance of day-to-day operational security-related activities. Worked with 20 Check Point firewalls running on Solaris. Wrote security policies, modified rulesets for customers. Maintained rulesets and policies. Analyze log files, responds to alerts and problems. Audited customer rulesets. Firewall rule design and maintenance. Assisted in installation of new Firewall-1s running on Solaris. Configured Firewall-1s. Acted as a first point of contact for Firewall related problems. Worked closely with the customer to ensure satisfaction and completed customers' request in a timely manner.

Confidential

Backup Recovery/JR Oracle Admin

Worked with 33 Novell servers 10 v3.1 20 v4.1 in 3 local and 30 remote sites being backed up by Arcserve 6.0. Remote sites included Seattle, Chicago, Los Angeles, etc. Ensure that they are all backed up. Troubleshoot/ analyzed problems. Sent out tickets to a tech as needed. Monitored and manipulated jobs running on NT, NOVELL, OS/2 servers, being backed up on NS.

We'd love your feedback!