Information Security & Audit Specialist Resume
5.00/5 (Submit Your Rating)
Houston, TexaS
SUMMARY:
- Proficient Cybersecurity & Audit Specialist with over 5 years of experience. Knowledgeable in information systems, cybersecurity, and project management.
- Information Assurance
- Service Level Agreements
- System Development Life Cycle
- Stakeholder Engagement
- Programming - Python
- PO&AM Management
- NIST 800/ SP800 series
- ITIL Methodology / Splunk ES
- Audit Support
- Security Policies & Procedures
- Vendor Management
- Vulnerability Testing / Assessments
TECHNICAL SKILLS:
Applications/Tools Used: SharePoint, ServiceNow, Nessus, WebInspect, RMFP,eGRC, RiskVision, CSAM, eMASS.
PROFESSIONAL EXPERIENCE:
Confidential ; Houston, Texas
Information Security & Audit Specialist
Responsibilities:
- Prepare Assessment and Authorization packages for IT systems, making sure management, operational and technical security controls adhere to a well-established security requirement authorized by NIST SP .
- Update and maintain System Security Plan, Risk Assessments, Business Impact Analysis, Contingency Plans and Incident Response Plans.
- Led a team of 3 people to ensure all Plans of Action and Milestone (POA&M) are completed and tested in timely fashion to meet client deadlines and provide continuous monitoring.
- Review and assess Vulnerability scan results and ensure that risks are assessed, and evaluated.
- Perform Security Categorization (FIPS 199) using NIST SP .
- Work with stakeholders to resolve computer security incidents and vulnerability compliance.
- Oversaw documentation, tracked progress, coordinated improvement efforts, and monitored process improvement effectiveness of a team of 6 people on a project worth $1.5million.
- Reviewed audit reports and coordinated audit remediation efforts in order to remediate findings within specified deadlines.
- Reviewed policies and procedures for compliance with applicable standards; and to identify areas of improvement for audit finding remediation.
- Facilitated meetings with third-party auditor staff to support IT-related audit engagements.
- Tracked artifacts and meeting requests and provided status reports on outstanding items to management.