Cyber Security Analyst Resume
4.00/5 (Submit Your Rating)
SUMMARY:
- A detailed oriented Army Reserve with MOS 17C (cyber operation) and over 4years experience in cyber security, managing information in federal systems using special publication as NIST and FIPS.
- Security Control Assessment (SCA), Risk Management Framework (RMF) and the remediation of failed security controls using POAM with compliance to FISMA.
TECHNICAL SKILLS:
- Knowledge on OSI/TCP model
- Understanding of VPN
- Understanding of transport protocols TCP/UDP
- Knowledge on FEDRAMP concept
- Knowledge on HIPAA Act
- Understanding of PCI/DSS
PROFESSIONAL EXPERIENCE:
Confidential
Cyber Security Analyst
Responsibilities:
- Perform Assessment and Continuous monitoring and authorization
- Extensive knowledge in categorizing information system using FIPPS 199 and NIST 800 - 60 as a guide
- Maintain follow-up reviews on system security plan, contingency plan, business impact analysis, Plan of Action and Milestone
- Participate in ST&E Kick-off Meeting and populate the Requirement Traceability Matrix (RTM) per NIST 800-53A
- Conduct onsite pre OIG audit by interviewing personnel, examining facts and testing of security controls/ screen shots
- Specializes in the entire FISMA, RMF, and SA, A&A/C&A and system control, assessment processes to ensure CIA triad is in compliance using FIPS 199/ NIST SP 800-60, NIST SP 800-53r4/53A.
- Implementing RMF through the SDLC process in addressing the risk posture
- Utilizes the Cyber Security Assessments and Management (CSAM) to record, manage, assess and remediate failed security controls.
- Interpret logs from IDS/IPS, Firewalls,
- Assisted end client to get RBD in order to get a temporal ATO
- Perform gap analysis by reviewing/assessment of my system
- Managed vulnerabilities with the aid of Nessus, Splunk, for vulnerability scanners to detect potential risk on a single or multiple asset across the enterprise network
Confidential, Dallas, TX
Information Security Analyst
Responsibilities:
- Categorized federal systems using FIPS 199 and NIST 800-60v1
- Initial Risk Assessment, reviewed SAR, SSP & POA&M
- Tracked NIST compliant vulnerability assessment, Plan of Action and Milestone (POA&M) and gives safeguard recommendation
- Conduct continuous monitoring and ensure system is up to date and operating within desired time period
- Managed vulnerabilities with the aid of NESSUS, Web Inspect as vulnerability scanning tools to detect potential risk on single or multiple asset across the enterprise.
- Knowledgeable on TCP/UDP
- Applied appropriate information security control for federal information system based on NIST 800-53, FIPS 199, FIPS 200