It Security Analyst Resume Profile
Rockville, MD
WORK EXPERIENCE
IT Security Analyst
Confidential
- Conduct meetings with the IT team to gather documentation and evidence about their control environment
- Perform comprehensive Security Control Assessment and write reviews for management, operational and technical security controls for audited applications and information systems.
- Prepare the Security Assessment Plans
- Develop, maintain, and communicate a consolidated risk management activities and deliverables calendar.
- Develop and conduct ST E Security Test and Evaluation according to NIST SP 800-53A.
- Apply current computer science technologies and Information Assurance IA requirements to the analysis, design, development, evaluation, and integration of computer/communication systems and networks to maintain an acceptable system security posture throughout the lifecycle of multiple national level mission system.
- Work with business process owners to ensure timely identification and remediation of jointly owned risk related issues and action plans.
- Manually review logs and provide documentation guidelines to business process owners and management.
Information Security Analyst
Confidential
- Conducted FISMA-based security risk assessments for government contracting organizations and application systems, including interviews, tests and inspections produced assessment reports and recommendations conducted out-briefings. Assessments conducted following NIST 800 processes and controls.
- Documented and Reviewed security plans SP , contingency plans CP , contingency plan tests CPT , privacy impact assessments PIA , and risk assessment RA documents per NIST 800 guidelines for various government agencies.
- Assisted with review of policy, security alerts, guidance, regulations and technical advances in IT Security Management
- Utilized processes within the Security Assessment and Authorization environment such as system security categorization, development of security and contingency plans, security testing and evaluation, system accreditation and continuous monitoring.
- Contributed to initiating FISMA metrics such as Annual Testing, POA M Management, and Program Management.
- Communicated effectively through written and verbal means to co-workers, subordinates and senior leadership
SKILLS:
Possess Secret Government Security Clearance, Working knowledge of NIST 800-53, NIST RMF, FIPS and FISMA guidelines to comply with federal and private agencies. Leading and managing network security, vulnerability management, intrusion detection, help desk, client or customer services. Experienced in the development of security plans SP , Contingency Plans, Disaster Recovery Plans, Incident Response Plans/Training, Configuration Management Plans, System Security Checklists, Privacy Impact Assessments, POA M, Authority to Operate ATO letters, FISMA Reports, Standard Operating Procedures SOP in accordance with Federal, Agency and Organizational policy, to include FISMA, NIST, OMB, FIPS instructions.
Possess in-depth ability performing information security risk assessments and analysis, risk mitigation in large-scale networked application environments. Performed risk analysis, assessment testing and analysis utilizing tools such as TAF, IDEA, XACTA IA MANAGER, Nessus vulnerability scanner and KALI LINUX penetration testing tool. Working knowledge of Network Infrastructures, Data Warehouses, Web Applications, Oracle Databases, Application Servers, Windows and Unix/Linux systems.
