Soc Lead Analyst Resume
3.00/5 (Submit Your Rating)
Washington, DC
OBJECTIVE:
To obtain a position which utilizes my skills and abilities to their fullest and to grow in an ever changing environment.
TECHNICAL SKILLS:
- WPM 53+
- Microsoft Office 2003/2007/2010/2 k13
- Server 2K3/2k8/2k12 Active Directory
- Cisco VoIP Systems Unity call manager & Polycom VoIP phone system/spherical call manager
- 98/2K/XP/Vista/Win7
- Exchange 2K3/2K7/2K8 familiarity
- CA - Server/Desktop management software
- Citrix XenApp server
- VM Ware ESX Servers
- Event Sentry monitoring tool
- WSUS 3.0
- Track-It 8.5
- Web Sense
- Lotus Notes; GFI Languard Network Security scanner 9.6
- Remedy AR System
- Belarc BelMonitoring Tool 8.0
- RSA Security Console 7.1
- Netback up 7.5
- Radmin 3.5
- Tenable Security Scanner 4.8.2
- EM7 Management System
- SolarWinds Orion IPAM web manager
- ZixAppliance 6.3.1
- McAfee Spam Filter and EPO/HIPS Services & AV Solutions 4.5
- FISMA/NIST compliance
- SIEM virtual appliance from Solar winds v6.3
- Forescout Counter act
PROFESSIONAL EXPERIENCE:
SOC Lead Analyst
Confidential
- Configure servers for ESXi hosts for security tools created for InfoSec teams
- Lead the team with tier 2/Tier3 escalation of security related events
- Managed SOC schedule for team to provide 24/7 support for clients
- Provided project management level support managing projects for SOC team to adhere to and follow on a timely basis
- Generate weekly reports of vulnerability assessments for several clients
- Other duties as assigned and to come
- Primarily responsible for scanning of all IDC Servers located within the U.S.A of specific court systems using Tenable System Scanner
- Provide execs with detailed status reports from scans generated along with remediation steps if needed
- Currently undergoing Splunk training to provide high level detail analysis of each courts IT Operations in depth
- Configured STIGS for custom in house application to allow stigging of specific servers seamless and easy (Windows 2k12,FireFox, Java, Adobe, Chrome, IE)
Security Sys Admin
Confidential
- Provided back up support with McAfee email gateway spam filters v7.6 by troubleshooting why specific emails were blocked and and adjusting custom policies as necessary. Added entries to the spam filter to block email address and domains that were deemed dangerous to TTB.
- Maintains McAfee ePolicy Orchestrator 5.1 to make sure DAT files are up to date and that all systems are reporting correctly. Made sure policies were in place to block specific .exe and other system process to NOT RUN in specific locations per request. Also made sure all client machines and servers were current and up to date with latest McAfee VSE and agent versions.
- Utilized Tenable( Nessus) Security Scanner v4.8.2 to perform system scans of the environment for patching status. Created custom scan reports to show latest vulnerability status and remediation’s using a custom dashboard showing daily, 30 - day & over vulnerabilities, and system status after patching.
- Create packages for SCCM 2012 for third party and Windows updates to address 0-day and current vulnerabilities. Created ADR to address patch Tuesdays and other custom application packages such as, Python, Chrome, Flash, Java, Firefox, and Wireshark just to name a few.
- Utilize a number of different web based applications such as ScienceLogic’s EM7 to review system status on high priority servers and to place systems in maintenance mode as well. Solar winds Orion IPAM web application is used to distribute IP’s and subnets for new or existing servers.
- Use of the SolarWinds SIEM to monitor and troubleshoot correlation events such as domain account lockouts, authentication failures and log on failures just to name a few.
- Monitored systems with Forescout to monitor, control, and orchestrate system wide threat responses within the TTB environment.
- Assisted with policy creation for enforcement and access controls for users to help reduce security gaps and to improve compliance for organization.
Systems Admin/Jr. Soc Analyst
Confidential
- Patched security systems and mobile devices using WSUS/SCCM and Device level encryption
- Performed vulnerability scans using GFI Languard to assist with my patch management and software audits
- Execute PowerShell cmds to create AD/O365&Lync2010 accounts for new users in Server 2k12
- Assist users with Junos Pulse VPN connectivity problems via SA 4500 SSL VPN Appliance by checking there connectivity status.
- Configure Polycom CX600 phones with Lync2010/13 Server control panel
- Manage and Configure Verizon & AT&T Nokia Lumia 822,922, 928, Galaxy S4, and IPhone for Corporate environment
- Basic server builds of 2k8R2 and 2k12
- Provide Tier 2&3 support for unresolved HD issues escalated
- Manage and configure Windows Surface Pro/2 8 tablets and Samsung Slates for VP users
- RSA Administrator 7.0 using RSA security console to administer RSA tokens for users for vpn access
- Utilized Belarc to audit agency’s software, security, and vulnerabilities on missing machines.
- Maintain desktop deployment images through Pxe boot through Dell for standard FHFA image
- Assisted with the implementation of a Citrix Presentation 4.0 Farm. This farm consists of two Citrix servers that will be serving the following applications: Microsoft Office 2003, Microsoft Project 2003, Adobe Acrobat, and Lotus Notes client
- Install, configure, and troubleshoot software and hardware for Windows Servers 2K3/2K8R2
- Supported and maintained an Active Directory 2003/2K8 environment for 500+ users and 6 satellite offices.
- Perform Monthly audits for Windows accounts, RSA, Local Server, and Remote desktop users accounts
- Maintains Symantec’s Netback 7.5 to maintain and monitor differential, Full, and Monthly Full backups running on (2) Dell ML 6020’s and a TL410
- Assisted with the implementation of VM Ware VSphere 4. /ESXi 4.1 cluster running on 2 Dell R910 servers
- Utilized Vsphere vCenter converter to migrate physical systems to virtual machines for infrastructure consolidation
- Manage McAfee’s ePop Orchestrator 4.5 to deploy updates and anti-virus updates/patches throughout the bank
- Configured users for Blackberry Enterprise Server 5.0 to deploy blackberry’s and configured Lotus notes on IPad, IPhone, and Droid based devices.
Assistant Network Administrator
Confidential, Washington DC
- Configured Event Sentry monitoring suite to monitor and control all 35 Windows servers for ping loss and disk space monitoring
- Used Backup Exec 11d to monitor and schedule daily, weekly, and monthly back ups
- Maintained SFTP Server by creating new user accounts and maintain existing user accounts and folders
- Assisted with tier 1/2 network support in a new Citrix environment implemented within ESX VM Ware over three Citrix farms making sure users had access to related desktop applications.
- Responsible for monthly maintenance of all 35 windows servers for windows updates and restarts
- Provided Tier 2/3 Tech support when Helpdesk became overwhelmed while using Track it 8.0
Systems Administrator
Confidential, Washington DC
- Created new user accounts for special projects persons in Active Directory and set permissions
- Installed and configured Polycom IP500 VoIP phone systems and configured the spherical desktop client for new users
- Acted as the Liaison for a 4-man team for WRAMC doing a base-wide pc system upgrade this consisted of data collecting and system backups and then transferring them over to their new PC’s. Replaced over three hundred outdated pcs with new ones.
- Assisted with the local Helpdesk when we were in downtime by connecting up local/network printers, Install/Uninstall applications for specific users, and also performed basic pc cleaning maintenance for those who were experiencing slow systems.
- Utilized Norton’s Ghost Cast server v 8.3 to image over 400 pc’s to new users
Tech Support Specialist/ Network Administrator
Confidential, Washington DC
- Assisted with the installation of a Confidential VoIP phone system throughout entire company and also utilized Confidential Call Manager to configure phones and voicemails for over 200 clients.
- Configured and managed a WSUS 2.0 & 3.0 server to the entire company updating over 200 +clients with Microsoft updates.
- Migrated entire company to the latest version of Symantec Antivirus v10.1 to the company and acted as the Symantec administrator as well.
- Managed and configured blackberry’s, smart phones, PDA’s, and pocket pc’s and also created documentation for activation/installation procedures. Provided hand’s on instructions and troubleshooting procedures as well.
- Managed bi-monthly server maintenance to over 30+ 2K3 server’s updating and applying the necessary upgrades and security patches as well as new installs.
- Created, maintained, and updated Active Directory for new user accounts for new employees and departed employees.
- Created several port maps for all 5 floors carefully labeling both Voice and Data ports using Paint.Net and Gimp programs.
- Created a custom server log on graphics that was applied to all 2k3 servers
- Deployed desktops and laptops to users using a custom RIS image created for the company
- Utilized Track-It 7.0 to view and edit tickets created by users needing assistance. Used the Admin’s console to also reset techs passwords and to also create custom ticket fields automatically assigned to users.
- Created a custom BartPE bootable disk that would allow us to boot into HDD’s that were failing.
- Performed Network troubleshooting to isolate and diagnose common network problems
- Responded to the needs and questions of users concerning their access of resources on the network
- Worked with the Sr. Network Administrator to maintain an available and secure computing infrastructure.
- Provided support for applications, email, and operating systems on users’ desktops that were beyond helpdesk level support
- Showed users how to access their emails via OWA Outlook Web Assist, by showing them how to log in and how they can also change their password.
Tech Support/ Office Manager
Confidential, Bethesda, MD
- Assisted WAN administrators based in Minnesota with basic level setup and configuration of new users accounts in local office of 12 users using Thin Client WYSE systems.
- Performed basic level LAN troubleshooting when problem arrived.
- Recommended and purchased all computer related equipment as needed for local office.
- Other administrative duties, scheduling, filing, MS Office specialist, organized meetings and setup phone conferencing and telecommuting.
- Persuaded local office Manager to upgrade from 15”crt to 17” LCD FP monitors instead explaining to him the benefits of doing so.
- Performed basic printer maintenance for networked HP & Konica Minolta printers.
- Made sure remote users had access to Shared Network files through a VPN tunnel that was configured only for Upper management and remote users. Installed local client on laptops and made sure they had access to all files as needed.
- Responded to Tier1/2 help desk tickets using TrackIT