We provide IT Staff Augmentation Services!

Third Party Risk Specialist Resume

2.00/5 (Submit Your Rating)

SUMMARY

  • Seeking an Information System Auditor or Cyber Security Engineer position in a growth oriented organization with focus on FISMA, RMF, System Security Monitoring, Risk Assessments, Audit Engagements, Testing Information Technology Controls and the CDM processStandards
  • FIPS, FISMA, HIPAA, Security Assessment & Authorization (SA&A), OMB Circular A - 130 Appendix III, NIST 800-53A Rev 4, COSO/COBIT, Sarbanes-Oxley Act, SAS-70/SSAE 16, ISO 27001, FEDRAMP. Software, Tools and platform
  • SQL Server, Windows, IFISMA,Tenable Security Center, Big fix, Microsoft Word, Excel, Project, Access, Power Point,, SharePoint, Scorecards, CSAM, FIPS 199, E-Authentication, PTA, PIA, RA, ST&E, POA&M, SP 800-53A, ISA,MOUSUMMARY OF QUALIFICATIONS
  • I am specialized in areas such as Cyber security, Information Assurance (IA), Security Assessment & Authorization (SA&A), Risk Management, System Monitoring, Regulatory Compliance, Physical and environmental security, Project Management, Incident Response, and Disaster Recovery. I possess a strong managerial skill, excellent in relation building and developing strategic partnership.

PROFESSIONAL EXPERIENCE

Third party Risk Specialist

Confidential

Responsibilities:

  • Was a team member of the promesa group tasked with conducting Assessment on the Design of DHS’ DCAS R2 systems for the District of Columbia
  • Scheduled kick off meeting with Stakeholders to help identify assessment scope, system boundary, information types (information process, store or transmitted by the information system), and eventual categorize information system accordingly.
  • Developed test plans, testing procedures and request for evidence needed to validate implemented controls.
  • Ensured that system's security controls, policies and procedures examined, measured and validated against third party standards.
  • Conducted IT controls risk assessments that included reviewing organizational policies, standards and procedures, interview appropriate personnel, and provide recommendations on adequacy, accuracy and compliance with regulatory standards using NIST SP 800-53A. Responsible for the development of security control test plan and in-depth security assessment of NCI information systems in order to maintain HIPAA compliance by implementing guidelines and standards identified in the National Institute of Standard and Technology (NIST) 800-66.
  • Interviewed system owner/system administrators/network engineers/developers and review existing system documentations in order to define specific, measurable, relevant and theoretically sound audit objectives
  • Worked effectively with all levels of management, staff and cross-functional security teams within the organization to identify and implement information assurance controls authorized by NIST SP 800-53.

IT Security Analyst

Confidential

Responsibilities:

  • Conducted kick off meetings in order to categorize ERTIBs systems according to NIST requirements of Low, Moderate or High system
  • Developed a security baseline controls and test plan that was used to assess implemented security controls
  • Conducted IT controls risk assessments that included reviewing organizational policies, standards and procedures, interview appropriate personnel, and provide recommendations on adequacy, accuracy and compliance with regulatory standards using NIST SP 800-53A.
  • Performed follow up risk/vulnerability assessments to ensure identified vulnerabilities or weaknesses from previous assessment efforts are properly mitigated.
  • Assisted System Owners and ISSO in preparing SA&A packages that are handed over to the Authorizing Official (OA) to issue or deny an Authorization to Operate (ATO).
  • Coordinated with System Owners and ISSO in making sure management, operational and technical security controls are adhere to as established in NIST SP 800-53 R4.
  • Created, review, and update System Security Plan (NIST SP 800-18), Risk Assessment (NIST SP 800-30) Security Assessment Report (NIST SP 800-53A).
  • Created remediation plan to mitigate the vulnerabilities/ Weaknesses identified, Plan of Action and Milestones (POAM).
  • Led in the development of Privacy Threshold Analysis (PTA), and Privacy Impact Analysis (PIA) by working closely with the Information System Security Officers (ISSOs), the System Owners, the Information Owners and the Privacy Act Officer
  • Developed an E-Authentication report to provide technical guidance in the implementation of Electronic authentication.
  • Monitored controls post-authorization to ensure continuous compliance with security requirement
  • Analyze and update System Security Plan (SSP), Security Assessments report (SAR) and the Plan Of Actions and Milestones (POA&M) activities
  • Run Nessus scans and generate reports as part of NCI CDM program to identify system level vulnerabilities

IT Security Analyst

Confidential

Responsibilities:

  • Scheduled kick off meeting with Stakeholders to help identify assessment scope, system boundary, information types (information process, store or transmitted by the information system), and eventual categorize information system accordingly. Using NIST SP 800-60
  • Developed test plans, testing procedures and request for evidence needed to validate implemented controls.
  • Conducted IT controls Assessments that included reviewing organizational policies, standards and procedures, interview appropriate personnel, and provide recommendations on adequacy, accuracy and compliance with regulatory standards using NIST SP 800-53A.
  • Performed follow up risk/vulnerability assessments to ensure identified vulnerabilities or weaknesses from previous assessment efforts are properly mitigated.
  • Assisted System Owners and ISSO in preparing SA&A packages that are handed over to the Authorizing Official (OA) to issue or deny an Authorization to Operate (ATO).
  • Created, review, and update System Security Plan (NIST SP 800-18) and Security Assessment Report (NIST SP 800-53A).
  • Conducted Third party Assessment for various clients

HIPAA SECURITY ASSESSOR

Confidential

Responsibilities:
  • Performed HIPAA assessment and generates assessment reports to be shared with senior management using NIST SP 800-66 R1 and NIST SP 800 53 Appendix J as a guide.
  • Developed HIPAA compliance reports, documenting auditing findings and development of corrective actions plans using OCR protocol.
  • Developed test plan that included, controls/Safeguards to be assessed, method of assessment (examination, interview or testing), sampling method, sampling size, artifacts needed to satisfy control/safeguard requirements.
  • Track remediation activities to ensure the confidentiality, integrity and availability of Electronic Personal Health Information (EPHI).
  • Engaged and tracked priority issues with a responsibility for the timely documentation, and escalation.

We'd love your feedback!