Information Security Engineer Resume Profile
2.00/5 (Submit Your Rating)
OBJECTIVE: Obtain a challenging and rewarding position in the field of information security
WORK EXPERIENCE:
Confidential
Information Security Engineer
- Coordinated with IAO's regarding security control testing and FISMA compliance for over 100 Navy information systems
- Configured a secure, air-gapped workstation using a variety of system hardening tools including NIST's SCAP validation tool and Retina Network Security Scanner
- Experience using Navy C A tools including eMass, OCRS and DITPR-DON
- Used Google Skipfish to perform security scanning and reconnaissance
- Led the reaccreditation effort of a government system DOJ-OJP by implementing security controls, mitigating vulnerabilities, and updating accreditation documentation
Confidential
Information Security Engineer
- Supported the NIH National Institutes of Health vulnerability management program as a key member of the Incident Response Team
- Collaborated with members of the information security teams and app development teams from each of the 27 NIH Institutes and Centers IC
- Configured and executed vulnerability scans using IBM AppScan, validated the vulnerability findings, communicated the results to the client and assisted with the remediation effort
- Utilized Burp Suite to test and validate a variety of vulnerability issues found during scans
- Aggregated Tenable and AppScan data into various reports for management and clients
- Assisted with various security related projects such as implementing java whitelisting, writing password security policies, contributing to internal IT wikis and wireless war-driving
Confidential
Junior Information Security Engineer
- Developed a JavaScript web application that aggregates and maps database entities using an open source graphical modeling engine
- Created and deployed a Java filter capable of creating cookies as well as modifying HTTP request/response parameters based on an algorithm that analyzes browser cookie data
- Created a login page using JavaScript and AJAX which communicates with a LDAP authentication server and parses auto-generated XML responses
- Executed Retina scans in Windows 2003 Server and Windows XP environments then patched discovered vulnerabilities
SKILLS SUMMARY:
Scripting: Python, JavaScript, XML, AJAX, CSS, HTML, MySQL, Java
Security Tools: Retina Network Security Scanner, VMware, VirtualBox, IBM AppScan, Tenable Security Center, Nessus, Burp Suite, Skipfish, Kali Linux, NIST SP 853rev4, SCAP
