Senior Information Assurance Engineer Resume Profile
VA
OBJECTIVE:
A Senior Information Technology Security management position where I can effectively utilize my expertise in certification and accreditation, risk management, personnel management, technical analysis, research and development of information systems.
SECURITY CLEARANCE: I have a current Top Secret security clearance.
SUMMARY OF SKILLS:
Over twenty eight years of experience in the Information Security CONFIDENTIAL
field. Professional INFOSEC experience consists of providing Information Security services to Department of Defense clients and other Federal Civil Agencies. Have experience with INFOSEC, Cyber, FISMA, DIACAP, DITSCAP Certification Accreditation C A , Common Criteria CC , DISA STIGs, Department of Defense, USMC, Army and Air Force, Department of Treasury, Department of Interior, Department of Justice, and NIST methodologies. Responsible for analyzing the technical and functional needs of a customer and then providing appropriate security recommendations so the customer can meet identified guidelines to ensure accreditation of computer systems. DoD IAM Level III qualified. I am a holder of the ISC2 Certified Information Systems Security Professional CISSP certification since 2001 and the SANS GIAC Security Leadership Certification GSLC since 2008.
EXPERIENCE:
CONFIDENTIAL
Senior Information Assurance Engineer
Providing Information Assurance support to the CONFIDENTIAL10 for the PM MCNIS for the Regional Support Services contract for the Quantico G-6. Providing support to the G-6 IA Manager during the transition from contractor operated to government operated network. Assisting in the development, implementation and management of IA policies, documentation, certification and accreditation process C A , standard operating procedures SOP and cyber assessment analysis. Provide internal IA SME support for SURVICE Engineering as required.
CONFIDENTIAL
Senior Information Assurance Engineer
- Working for the Prime Contractor Oracle as they develop the GCSS-MC system and helping their Information Assurance team review the program to ensure it meets the customers' requirements. Reviewing and commenting on IA policies, assisting in the correction of the IA policies and procedures. Also, duties included reviewing testing procedures and assisting in the testing of the GCSS-MC system.
- In Aug 2011, I was assigned as the IA Team Lead for a new sub-project of the GCSS-MC System. As the IA Team Lead I was responsible for ensuring the accreditation of a new sub-system that will include Automated Identification Technology AIT using Radio Frequency Identification RFID technology. Developing the C A packages and associated documents and policies that will all this AIT project to connect to the GCSS-MC Enterprise System. Working with the Oracle Database Designers and System Architects to help them understand the IA requirements so that IA is built-in rather than added-on later.
CONFIDENTIAL
Senior Information Assurance Officer
The Senior Information Assurance Officer responsible for leading and supporting the DIACAP C A efforts and FISMA compliance efforts for over 70 systems in accordance with Army Regulation 25-2, DoDI 8510.bb DIACAP DoDI 5200.40 DITSCAP , DoDI 8510.1-M, DoDI 8500.1 and DoDI 8500.2. I managed extensive evaluations of major information security networks, and as the Senior Government team lead, would prepare evaluations reports and present recommendations to Program Managers and Sr. PEO EIS Staff. I was the personal IA Subject Matter Expert for over 60 PM/PDs providing research and answers on a wide variety of IA subjects. I was in charge of developing, coordinating and reviewing IA policy for implementation by PEO EIS and PMs. Conducted trade off analyses of products to help PMs determine optimal information security solutions. Developed a milestone process that kept senior leadership apprised of all systems C A efforts. This enabled the leadership to step in when needed to get the C A effort back on track rather than waiting until the DAA had to approve extra time or they did not receive an accreditation.
CONFIDENTIAL
Principal, Information Security Specialist and On Site Manager for CACI
I was Senior Information Assurance Officer at the US Army's PEO EIS Office of Certification Accreditation responsible for an office of 6 people. Leads and supports DIACAP C A efforts for over 90 systems in accordance with Army Regulation 25-2, DoDI 8510.bb DIACAP DoDI 5200.40 DITSCAP , DoDI 8510.1-M, DoDI 8500.1 and DoDI 8500.2. Manages extensive evaluations of major information security networks, prepares evaluation reports and presents recommendations to Program Managers and Sr. PEO EIS Staff. Conducts trade off analyses of products to help PMs determine optimal information security solutions. I was the IA Subject Matter Expert for over 40 PMs providing research and answers on a wide variety of IA subjects. Develops, coordinates and reviews IA policy for implementation by PEO EIS and PMs. Improved the C A of PEO Systems from 60 to 90 . I received recognition from SES for my contributions. I was the On-Site Manager for Ft Belvoir, VA, responsible for managing CACI personnel, developing contracts and maintaining customer satisfaction.
CONFIDENTIAL
Principal Computer Systems Security Technologist
CONFIDENTIAL
Team Lead, responsible for the Certification and Accreditation C A effort including testing and certifying, a secure and global Ballistic Missile Defense System BMDS communications system, in accordance with of DoDI 5200.40 DITSCAP , DoDI 8510.1-M, DoDI 8500.1 and DoDI 8500.2. Duties include performing Certification Test and Evaluations and vulnerability audits in support of Type and Site accreditations. Lead Certifier using Nessus, NMap, Saint and other vulnerability assessment tools. Performed research, analysis and documented IA related vulnerabilities. I participated in site surveys, installation and checkout activities. I also developed, maintained and tracked System Security Authorization Agreements SSAA and Interim Authority to Operate IATO /Authority to Operate ATO documentation.
CONFIDENTIAL
Sr. Information Assurance Engineer
Responsible for providing information security and assurance, information assurance policy, risk management, vulnerability and threat analysis, and program management support to the federal government and commercial firms. I led program plan development, policy analysis, development of policy, implementation of guidance and DITSCAP Certification and Accreditation activities for DTRA Cyber Security and Counter Intelligence Division. He also led the effort at a Federal Government Agency, providing NIST 800-37 certification and accreditation of Information Systems, developed Contingency Plans and templates for future contingency planning and E-Authentication planning for agency systems.
CONFIDENTIAL
Information Assurance Engineer
I developed Information Assurance products for Federal Government clients. I also helped assess the security of automated information systems. Collaborated with Federal and Military clients to develop and implement security policies, plans, and strategies. Assisted Federal and Military clients in the design and development of integrated security system solutions, and recommended solutions that ensure systems are protected.
CONFIDENTIAL
Information Assurance Manager
I was responsible for the protection of information, processes and equipment in the automation and telecommunications environment. Formulated, published and disseminated information systems security policy and procedures. Advised and assisted commanders, staff officers, and security managers in all areas of information systems IS security. Conducted risk assessments to determine vulnerabilities and recommended countermeasures to be implemented based on DISA STIG requirements. I implemented the DITSCAP certification and accreditation process and ensured all systems were accredited prior to data processing and reaccredited in accordance with the DITSCAP policy.
CONFIDENTIAL
Numerous Locations
I developed security policies and procedures which helped improve the security environment of the Pacific Air Forces PACAF . I was the Team leader for the certification and accreditation of all Intelligence computer systems using the DITSCAP and DCID 6/3 process. I assisted branch offices in developing their yearly budgets along with their security policies and practices for the Special Security Offices. Lead and participated in numerous process action teams as the Intelligence, Security and Information Assurance expert. Researched new technologies and prepared reports detailing test results, vulnerabilities and strengths, and make recommendations on how to incorporate the new technologies into current networks. Performed site surveys prior to equipment installation and made suggestions to improve both security and installation. Set up PACAF IS based on DISA STIGs and NSA Security Configuration Guides. Configured and maintained the Cisco Routers on the base network. Installed and performed troubleshooting of fiber optic network cables. Performed System Admin duties on numerous versions of operating systems Windows, Unix, Sun, HP-UX, Linux from desktops to server farms and Tape Robots. Develop and instruct basic and advanced computer courses, developed interactive courses for self-study used to reduce the demand for Instructors. Mobile Training Team Leader responsible for the deployment and instruction of courses throughout the world. I was a Team Leader responsible for the development of self-discipline and basic military pride of young men and women upon entry to the US Air Force. I started my AF career as a Communications Security COMSEC Accountant for the third largest COMSEC account in Tactical Air Command. I was responsible for ensuring accurate receipt and delivery of COMSEC materials to all user accounts, both local and remote. Provided training on the storage, accounting and use of the COMSEC materials and equipment.
