Sr. Product/application Security Analyst Resume
Alpharetta, Ga
SUMMARY:
- Intermediate understanding of JavaScript, its quirks, and workarounds
- Strong understanding of jQuery, HTML5, and CSS3
- Strong understanding of DOM manipulation with JavaScript
- Strong understanding of Reactjs and Redux
- Proficiency in PHP
- Proficiency in Java
- Proficiency in Python
- Familiar with front - end build systems technology
- Familiar with versioning tools such as Git
- Familiar with responsive design and popular web platforms / content management systems
- Knowledgeable of frameworks like Angular.js, Node.js, express.js
- Strong understanding with SQL / NoSQL databases (MySQL, PostgreSQL and Redis)
- Strong understand of usual web backend technologies such as MVC architecture, RESTful API, JSON, Singleton, PDO etc.
- Understanding of Networking (DNS, HTTP/HTTPS, Proxying, etc.)
- Strong interest in following technology trends as it relates to growing existing e-commerce offerings
- Strong analytical skills and the ability to troubleshoot issues
- Ability to research and understand technical documentation and understand how to apply
PROFESSIONAL EXPERIENCE:
Sr. Product/Application security Analyst
Confidential, Alpharetta, GA
Responsibilities:
- Performed manual assessments of applications, both dynamically and statically, produce reports and meet with development teams as required.
- Operated and maintained application security tool(s), such as Veracode for static application security testing (SAST) and dynamic application security testing (DAST) including tasks such as created and maintained user accounts, create application scans profile.
- Produced software composition analysis (SCA) assessment reports to outline the results of completed vulnerability assessments.
- Coordinated with business and technical contacts to obtain evidence to demonstrate compliance with specific technical standards including internet, cloud and mobile applications security standards, baseline security standards and audit logging and monitoring standards.
- Worked with both business and technical contacts to conduct vulnerability assessments which may include a business risk impact analysis, application assessments, or other activities to help ensure that applications and systems comply with Confidential Software Security Assurance policy and procedures in support of applicable laws, regulations /guidance, and industry standards.
- Presented assessment results and recommendations to upper management for acceptance. Worked on project teams to determine relevant security assessment processes and controls.
Sr. Security Analyst
Confidential, Atlanta, GA
Responsibilities:
- Created and maintained a control matrix to allow upper management provide status on security controls and to show the intended Enterprise security strategy as well as the security posture. Control gap Analysis against ISO 27002:2013
- Performed and participate in the Risk Assessment process (Enterprise wide including subsidiaries) providing metrics on identified risks to upper management.
- Performed a control gap analysis against on current policies and standard to identified control effectiveness and scope gaps with our policies and standards and being able to provide
- Participated in the implementation of the Enterprise (eGRC) system working closely with the consultant, performed QA (Quality Assurance) on newly created and implemented system modules (Policy review, Exception, Risk Assessment module), providing feedback and recommendations on how to customize the application to conform to our Risk Assessment process.
- Performed system updates as well as upgrades. Created users and groups accounts and troubleshoot minor issues.
- Served as the eGRC system administrator, responding to user’s inquiries, resolving minor problems or issues as well as to perform a more in details analysis on module performance to validate compliance with our Risk Assessment policy.
- Policies/Standards/Procedures/Guidelines review process
- Implementation & Compliance Audits system and process (eGRC system)
- Yearly Reviews and Amendments to policies and standards
- Performed the following Qualys system administrator functions:
- Configured and performed host vulnerabilities network scans
- Configured and performed Web application security scans and reporting
- Create new and maintain existing asset list
- Documented and tracked identify vulnerabilities
Information Security Engineer II
Confidential, Savannah, GA
Responsibilities:
- Served as the primary point of contact for all IT - related audits, including external (Cyber Security) and internal audits.
- Worked directly with external auditors to obtain a list of in-scope resources, documents, and personnel, and provides information and meeting invites in advance of the auditor's visit.
- Correctly identified subject matter experts for various systems or processes and works with those personnel to provide timely and accurate information to the auditors.
- Worked in the post-audit phase to assist stakeholders in preparing a response to audit findings.
- Prepared and presents status reports (metrics), risks, recommendations, and lessons learned to all levels of management.
- Performed periodic reviews of process controls and technical controls to ensure continuous adherence to General Dynamic corporate security policy.
- Conducted Cyber Security audits based on General Dynamic security policy and SOX 404 control to evaluate the established Security policy internal controls designed to manage the company's most significant risks and evaluate the operational effectiveness and compliance to formal process frameworks.
- Collected and analyzes relevant documentation, including risk assessments, past audit findings, remediation plans, policies and standards, business process flows, and technical diagrams.
- Performed audits for multiple Information System platforms such as Windows servers and Desktop, iPads (IOS) and IBM mainframes, Unix, and Linux.
- Advised and assisted the business to ensure that Gulfstream IT services were in compliant with General Dynamics corporate security policy and NIST 800-53 security standard and Risk Management Framework.
Information Security Engineer II
Confidential, Savannah, GA
Responsibilities:
- Evaluated the information security policies, standards and procedures for fullness and alignment with General Dynamic corporate security policies and NIST 800-53 security standards.
- Conducted periodic reviews of information systems to determine whether they continue to meet the organization’s objectives
- Evaluated the readiness for information systems for implementation and migration into production to determine whether project deliverables, controls and the organizations requirements are met.
- Evaluated the design, implementation and monitoring of system and logical security controls to verify the confidentiality, integrity and availability of information.
- Documented, and ensured communication of identified key risks.
- Recommended ways to control or reduce identified risk.
- Gathered and communicated risk-related reports from internal or external resources.
- Identified and analyzed areas of potential risk to the assets.
- Produced reports or presentations that outline findings, explain risk positions, or recommend changes.
- Created and validated Risk assessment, risk validation in the Application Environment.
- Attended to all Application Risk Assessments meetings where Application security is pertinent.
- Reviewed pre-existing Application Project, and technological documents associated with the listed projects.
- Communicated and reported issues, status, and results to IT Security Management and Project teams.
- Fostered relationships with development and technology teams to determine if additional Security requirements are needed during deployment of application projects.
- Participated in all change request meetings in respect to the listed application Projects and stay informed on any new updates with the project.
- Assisted IT Security in the capacity of a Senior Security Engineer in respect to Application Security.
- Performed static code analysis scans, and reporting and system administration using HP Fortify for new and existing applications
- Served as the project coordinator for the IT Security team.
- Attended Confidential CAB (Change Advisory Board) meetings
- Attended Gulfstream Aerospace VART (Vulnerability Assessment and Remediation Team) weekly meetings
- Performed application vulnerability assessments, security control validations,
- Performed the following Nessus system administrator tasks:
- Create and modify user accounts
- Create new and modify existing dashboards
- Create new and modify existing reports
- Create new and maintain existing asset list
- Documented and tracked identify vulnerabilities
- Provide bi-weekly metrics to the Gulfstream Aerospace ISO
- Provided guidance on and oversee secure application coding practices
- Participated in requirements reviews, meetings support, environments compliance support, ensuring vulnerability remediation is included in the builds when needed
- Managed other application security related projects, such as helping customers build security into their software development life cycles, configuring and tuning web application firewalls, performing application security design reviews, etc.
- Adhered to all corporate security policies and standards as they relate to job duties
Information Security Engineer I
Confidential, Savannah, GA
Responsibilities:
- Monitored information systems as directed to identify security intrusions, security breaches, and respond to cyber-attacks in accordance with General Dynamics corporate security policies and NIST 800-53 security standard
- Monitored the quarantine email queues for contents analysis in a daily basis and start an investigation if there was a violation on corporate policies regards email contents.
- Assisted the Human Resources, Legal and Ethics department in internal incident violation investigations gathering data and evidence to be used in prosecuting cyber-crime.
- Served as a security Advisor providing technical and non-technical advice to the Business Partner (BP) as they relate to information security related and enterprise projects.
- Served as a system administrator for the following systems and applications:
- Provided 24/7 support for (3500+) remote users and Cisco VPN client connectivity issues.
- Added, deleted users and servers to the RSA system
- Enabled or disabled soft token or key fobs
- Assigned new soft tokens and key fobs
- Site categorization
- Provided detailed information about a user’s Internet activity.
- Provided detail information about firewall activities, performance and a computer and Network Forensic tool as well.
Computer Forensic Analyst
Confidential
Responsibilities:
- Performed e-Discovery services in support of the Legal teams, both internal and external. Must be able to liaise with Legal staff efficiently and effectively, and participate in matter hearings.
- Assisted in computer and network forensic examinations in support of internal investigations and intrusion incidents.
- Followed forensic processes and procedures based on industry best practices. Maintains the necessary documentation to support the forensic and investigative processes and procedures.
- Researched and develop evidence collection, protection, and analysis techniques for company owned and maintained hardware and software.
- Participated in the development of additional evidence collection methods, technologies, and processes that support the need to detect and respond to unauthorized or unintentional activities.
- Exceled in communicating with internal customers in a professional manner while explaining technical information in easy to understand terms, and in helping them solve problems in a straightforward and efficient manner.
Information Security Specialist
Confidential, Jacksonville, FL
Responsibilities:
- Educated users and promoted security awareness training to ensure system security and to improve server and network efficiency.
- Developed and implemented internal controls to successfully resolve system performance and management.
Computer Support Specialist
Confidential, Jacksonville
Responsibilities:
- Responsible for the installation, troubleshooting, asset management, configuration and support of all computerized information systems for the Confidential activities.
- Administered network permissions and accesses for users and global accounts.
- Diagnosed and troubleshoot network, printer and connectivity issues.
- Resolved questions and problems related to PC hardware and software, LAN/WAN connectivity, mainframe hardware and software, and other technology-related devices.
- Assisted end users with step-by step technical instruction to resolve connectivity issues.
Cryptologist Technician
Confidential, MAYPORT, FL
Responsibilities:
- Responsible for operating equipment that receives and analyzes radio waves.
- Operated receiving and recording, identified call signs and encrypted call signs, typed messages received, knowing operating and procedure signals, identified natural and manmade radio interference, recognized and reported unusual radio wave activity, handled magnetic tapes and made recordings, maintained files, records, logs, and publications.
- Familiarity with various systems for direction findings, loads and operated data processing computers.
Technical Help Desk/Desktop Support
Confidential, Maryland
Responsibilities:
- Responsible for performing desktop support, network engineering and system administration networks assets, including classified and unclassified networks.
- Proactively identified and reported events through the use of an application for the recording and processing of trouble tickets that could adversely affect client’s network systems and user Application operations.
- Received training in the following fields: Communications Electronics, Computer Applications, Computer Systems and Organization, Database Management, Security Operations and Technical Mathematics, Computer Networking, Telecommunications, Electronics Communications Systems.
