It Security Resume Profile
SUMMARY
Used my experience in information technology and IT security management to serve the customer, build effective relationships, and shape their future. Managed contracts and teams, brought projects to successful completion on time and within budget, and helped build IT security organizations programs. My management, organizational, communications, and analytical skills have enhanced the organizations ability to: prevent problems and reduce risk uncover and resolve vulnerabilities and security events plot trends and eliminate threats ensure compliance to federal regulations and define security policies, procedures, guidance, and awareness programs. My skills and experience with the public and private sectors, and ability to understand the organization's mission have proven to be valuable in achieving their strategic goals and objectives.
CORE COMPETENCIES
IT Security Risk Management, A A, Contingency Planning, Cloud security, Training, Incident Response, Audit , Strategic Planning, Leadership/Management, Organizational Skills, Project Management, Systems Analysis
PROFESSIONAL EXPERIENCE
Confidential
Perform security assessments, write system-level policies, provide IT system security support, conduct annual training, monitor security compliance, wrote assessment documents following FedRAMP NIST SP 800-53 Rev. 4 standards, etc.
Confidential
Same work as ERT but also wrote Business Impact Analyses BIAs and Contingency Plans.
Confidential
Conducted system assessments/audits on systems Windows and Linux platforms and network architectures. Work included producing Risk, Security, Vulnerability, and Privacy Impact Assessments PIA . Write Business Impact Analysis BIA and Information System Contingency Plans ISCPs . Experienced with NIST and FIPS publications and processes, FISMA requirements, and development of Plan of Action and Milestones POA Ms . Provide IT security advice in the System Development Life Cycle SDLC . Provide training for Incident Response Plans and Contingency Plans and conductexercises.
Confidential
Department of Energy DOE - Managed of a team of six responsible for continuous network monitoring, Certification and Accreditation, incident response, malware analysis, and penetration testing. Also, advised on cloud security projects.
Confidential
Cloud Security: Provided input to update cloud security marketing documents. Developed Cloud Security presentations and related material for a DOD conference and a BAH forum. Part of a cloud support work group chartered to increase BAH cloud capabilities. Provided security input for the development of a Hadoop cloud indexing system training course.
Department of Energy DOE - Security professional that supported the cloud initiative assessment contract for National Energy Technology Laboratory NETL . Also, provided input to the IT Cyber Security strategy, Risk Management Process Guidance, and other DOE security documents.
Defense Intelligence Agency DIA - Updated C A documentation in support of Metadata Extraction and Tagging Service METS . Converted DCID documents to ICD 503 format, and created C A templates to support the transition to new standards and requirements.
Confidential
In addition to supporting IT security programs at NIH, DOJ, CMS, and DHS see below provided support to LM proposal writing teams.
