Sr. Security Engineer Resume Profile
5.00/5 (Submit Your Rating)
VA
EXPERIENCE
Confidential
Security Consultant
- Perform Certification and Accreditation activities for Major Applications and General Support Systems e.g. Risk Assessments, System Security Plans, Contingency Plans and System Test and Evaluations .
- Develop and complete security plans based on the National Institute of Standards and Technology NIST Security Publications.
- Perform system vulnerability assessment scans using various web and application vulnerability scanners i.e., Nessus, Webinspect, Appdetect , analyze reports and provide remediation solutions.
- Perform physical walkthrough of facilities to ensure they meet NIST requirements.
- Proficient with Cyber Security Assessment and Management CSAM C A web application, Xacta IA Manager
Confidential
Security Architect
- Designed, implemented and supported integrated solutions for client engagements.
- Provided maintenance and technical support on services.
Confidential
Sr. Security Engineer
- Supported Certification and Accreditation C A of the Joint Personnel Adjudication System JPAS for the Defense Security Service DSS .
- Performed Security Readiness Review SRR scripts and eEye Retina scans on Windows and UNIX workstations/servers.
- Developed Systems Security Authorization Agreements SSAA , risk assessments, Security Test Evaluation ST E plans, and security policies.
- Provided Quality Assurance on technical documents to ensure content accuracy and grammatical consistency.
- Confidential
- Information Security Engineer
- Supported C A of systems within the Office of the Chief Financial Officer OCFO at the Department of Labor.
- Experience in performing security risk assessments and system self-assessments, and developing system security plans.
Confidential
Security Engineer
- Provided C A support for Military Health Affairs systems and its applications.
- Executed validation tests to assess the security posture of Windows NT/2000, Solaris/SunOS servers and workstations, Oracle databases, Web servers, Routers and Firewalls.
- Developed ST E plans and procedures, mitigation strategies, and vulnerability reports, and identified information security requirements for information system certifications in accordance with the DoD DITSCAP.
Confidential
Jr. Information Security Engineer
- Developed and performed ST Es on DoD and Defense Information Systems Agency DISA networks in accordance with the DoD DITSCAP. These tests involved using SRR scripts, vulnerability detection tools i.e., Internet Security Scanner , and other proprietary tools.
- Performed certification on applications and information systems as part of site certification teams. Performed SIPRNet and NIPRNet compliance validation visits to potential high-risk connections.
- Performed SRR and ISS scans on Windows and UNIX workstations/servers, Web servers, DNS servers, applications and databases.
- Certified to administer and operate the Defense Information Infrastructure DII Guard and STOP operating system. Performed Joint Vulnerability Assessment Process JVAP using checklists and DISA/NSA procedures to assess specific configurations, operations and administration of cross-domain solutions.
