Security Analyst Resume Profile
Blythewood, SC
Experience Summary
- Confidential has over twelve years experience in Information Technology and is certified in information systems auditing as well as risk and information systems controls. He has a strong foundation in Information Systems, Security, Compliance, Audit, and Management processes. He has conducted assessments, such as SAS70, NAIC MAR, HIPAA, and so forth, to determine that internal controls are compliant with industry best practices and government standards based on NIST, FISCAM, STIG and other regulations. He has implemented, interpreted and monitored security policies and procedures on various processes, such as business continuity, vulnerability scanning, and configuration management as well as system platforms, such as z/OS RACF , Windows Active Directory, Novell, UNIX and RSA SecurID to remain compliant with standards set by HIPAA, CMS, and the Department of Defense.
- Confidential is an Adjunct Instructor for South University in areas such as IT Security: Access and Protection, IT Security Information Assurance, and Applications of Management Information Systems. He possesses a Masters degree in Computer Resources and Information Management with an emphasis in security.
- Confidential is an active member of his local Information Systems Audit and Control Association ISACA chapter. He serves as the Communications Director as well as Webmaster in charge of maintaining the website for the chapter.
Employment History
Confidential
Security Analyst
Confidential supports the STC project management team and the CMS security officer in-charge of multiple, FISMA and non-FISMA, IT audit and security compliance engagements, such as A-123, CFOA, OIG, and self-assessments. He is responsible for ensuring that remediation efforts are completed to resolve any security-related issues noted during such audits and compliance engagements. He leads the effort to obtain an Authorization to Operation ATO for the STC tested systems by ensuring that all required CMS artifacts exist for the STC project and will lead efforts for maintaining ATO for the project.
Confidential
System Security Officer
Confidential was responsible for the delivery of system security activities for ESD task orders as outlined in the CMS Business Partners System Security Manual BPSSM . In his capacity as System Security Officer, he made sure that ESD system security requirements were considered during budget development and execution, reviewed compliance of the CMSRs and reported vulnerabilities with management upon release of draft and final documents publication. Additionally, he facilitated the completion of the ESD Information Security Risk Assessment, made sure that an operational IT Systems Contingency Plan was in place and tested for ESD task orders, made sure the ESD monthly Plan of Action and Milestones POA M were updated in CFACTS, and coordinated with appropriate teams to ensure implementation and compliance with DISA STIGs as well as other requirements as mandated by task orders.
Confidential
IS Auditor/IS Auditor II
Confidential conducted audits of I/S operations and data processing systems to verify that I/S plans and objectives are met and to verify that appropriate internal controls are present, functioning, and effective for all lines of business, including Corporate, Tricare and Medicare. He conducted security reviews to make sure that security systems are appropriately designed and effectively implemented, and conducted assessments to determine that internal controls are compliant with industry best practices and government standards based on NIST, FISCAM, STIG and other regulations.Confidential managed a staff of three that was responsible for monitoring network users for policy compliance and developing adequate audit records for oversight reporting to make sure that the company was operating at high security standards. He acted as a liaison for internal and external auditors, providing security reports and other pertinent information to complete in depth audits of company procedures and systems. In addition, he implemented, interpreted and monitored security policies and procedures on various operating system platforms, such as z/OS, Windows 2000/2003 servers, Novell servers and RSA SecurID to remain compliant with standards set by HIPAA, CMS, and Department of Defense.
Network Security Supervisor
Confidential managed staff of five responsible for system security administration functions to ensure security requests were processed in accordance to standard operating procedures and service level agreements. He supported I/S projects performing security assurance reviews for new and modified systems on various operating system platforms, such as Windows 2000/2003 servers, Novell servers and RSA SecurID.
Data Security Analyst
Confidential company's data security policy by administering security systems in order to protect the company's resources and adhering to audit requirements to ensure compliance with Department of Defense and HIPAA. He acted as a user accounts, groups and password administrator on Windows 2000 Active Directory , Novell Netware ConsoleOne and UImport , Citrix and RSA Ace, etc. He trained new employees on data security and audit procedures to ensure data integrity and confidentiality.
Information Resource Consultant
Confidential was responsible for administration, support, and management of Microsoft Windows NT/2000 workstation/server operating systems and Microsoft Windows 98 desktop operating systems, which included remote support utilizing SMS 2.0 and Terminal Services Client and administration tasks utilizing SQL queries and VBScript. He was responsible for the continuity of operations by managing backup and recovery processes for the organization.
Data Security Analyst II
Confidential enforced data security policy by administering security systems in order to protect the company's resources and adhering to audit requirements. He also acted as a liaison with internal auditors to provide reports and answers on controls and procedures.
