Information Security Analyst Resume
Collierville, TN
SUMMARY
- Technically sophisticated Programmer/Developer Analyst with 6+ years in Information technology offering expertise in Object Oriented and Web - based Enterprise applications using Java/J2EE and Client-Server technologies.
- Experience in complete Software Development Life Cycle and strong knowledge of Object Oriented Analysis, Design and Programming techniques.
- Strong ability to produce results within a team environment or independently.
- Played a key role in managing projects and resources and delivered as per the timeline. Proven ability to adapt quickly to challenges and changing global business environments while delivering consistent results.
- Demonstrated ability to guide requirements development, documentation creation, communications management, and implementation planning for business critical systems.
- Expert at gathering requirements on large, complex systems, writing functional requirements, use cases, and other supporting documentation, creating requirement traceability matrix, and designing test plans and test scenarios.
- Proven successes streamlining performance, reducing costs, and enhancing system stability.
- Conducting Integration, Functional, System, Regression, Smoke, GUI, Performance, UAT Positive and Negative testing for all the above projects.
- DevelopTest Plans, Test Cases as per Statement of Business Requirements (SoBR).
- Uploading the business requirements in Quality Center using Excel templates.
- Manage identified defects and reviewed with Quality center on daily basis.
- Executing the Test Cases and documented them as pass or fail in Test Analysis Report.
- Identifying errors and interacting with business users &IT team to resolve the issues.
- Design and develop tooling for automation solutions to meet testing requirements for Admin Roles in all themodules of the application and revising the existing test script automation architecture to increase test coverage and maintainability.
- Defines and tracks IT Test Metrics Reports on weekly basis such as IT Test Status Reports, Quality Center Reports, General Reports and Test Metrics Reports.
- Maintaining the Metrics Readiness Checklist at the beginning of each release.
- Work closely with DEV group (offshore/onshore) to track and troubleshoot the defects.
- Responsible for preparing of Test Data along with the business team for the UAT and working closely with user community to create UAT test cases and coordinate UAT testing and manage issues/bugs from UAT.
- Working extensively with UNIX servers for deploying the User Interface builds, watch the log files for fixing the errors accordingly.
- Automation of UNIX processes via environment aware shell scripting and cron jobs allowed for little to no user intervention for weekend runtimes.
- Providing aQA Sign off on code deployed in the QA/SIT versions and working as a Lead for all testing activities on given projects.
- Maintenance of all the servers in System Integration Testing (SIT) environment as part of Lead System Specialist duties (i.e., apache server, tomcat server). As per the issues, troubleshoot them andrefresh accordingly.
- On a regular basisdeploy builds in TEST environment for UI and Database.
- Working extensively on BPM admin console/web console, Portal web logic servers as part of routing rules, user credentials, manual builds etc.
- Working with DBAs to migrate reference data from master tables to TEST environments and validate them.
- Uploading/modifying the docs. in SharePoint portal on regular basis.
- Assist in creating and implementing security standards, policy, guidelines, and practices.
- Proven Customer handling, Client Interfacing skills and strong team player
- Provide assurance of confidentiality, integrity, privacy, and availability of information
- Production Support (24*7) environment exposure.
- Develop and implement customized security solutions and remediation strategies.
- Manage priorities, and prepare timely updates of project status.
- Adept at building relationships, gathering needed information, and negotiating successfully with people and groups that are potentially at cross purposes, in potentially political situations.
- Excellent verbal and written communication skills.
- Excellent interpersonal skills and takes initiative to find solutions.
- Skilled trainer and mentor to junior staff.
TECHNICAL SKILLS
Languages: Java 1.4/1.5/1.6, SQL and PL/SQL, HTML, XHTML, Unix Shell Scripting
J2EE Technologies: JSP, Servlets, JDBC, EJB, Java Beans
Frameworks: Struts framework, Spring, MVC architecture
Persistence layer: Hibernate 2/3.1
IDEs/tools: Rational Software Architect(RSA), Eclipse 3.4/3.5, Net-Beans
Design Modeling: OOA/OOD, UML
Web Tools: JavaScript, XML, HTML, XHTML, DHTML, WSDL.
Database: DB2 9.5/9.0, Oracle 10g/9i, MS SQL Server 2000/2005/2008 , MicrosoftAccess.
Documentation Tools: MS Office 2003/2007/2010 , Visio, MS Project, MS SharePoint
Web/Application Servers: WebSphere 5.1/6.1, WebLogic 6.1/7.0/8.1, Apache Tomcat 5x, JBoss 4.0/4
PROFESSIONAL EXPERIENCE
Confidential, Collierville, TN
Information Security AnalystResponsibilities:
- Streamlined code resulting in fewer server bounces and reduced maintenance costs.
- Implemented Oblix CoreID WSSO solution across all enterprise intranet applications providing single point login capabilities.
- Deployed LDAP directory-based authentication system and LDAP Groups retrieval system providing improved administration and access management capabilities.
- Simplified delegation assignment and approval by including compliance teams in broader range of work assignments.
- Established strengths in Confidential project management and implementation methods via hands-on planning, testing, and implementation support experience as Intern during summer 2006.
- Involved in the analysis, design, and development and testing phases of Software Development Lifecycle (SDLC)
- Designed Use Case Diagrams, Class Diagrams and Sequence Diagrams and ObjectDiagrams, using UML to model the detail design of the application.
- Developed the application front end: developed action classes, form beans and Java Server Pages.
- Perform the duties asaReleaseLeadby managing the entire release consisting of multipleprojects.
- Perform the duties asaBuildRepby reviewing and creating code patches for peers beforepushing any code to production.
- Training peers on the application usage and support it during its entire life span in a project.
Environment: Java, JDBC, Oblix CoreID, UNIX, Oracle 9i, SQL, MS Office (Word, Excel, Power Point) MS Project, CVS.
Confidential
Responsibilities:
- Developed and supported Delegation Framework forInformation security.
- The frameworkprovides registered and approved applications an application programming interface (API) to requestdelegationinformation. This service isimplemented as web service.
- Analyzed business requirements, external interfaces and documented the design using high-level, class and sequence diagrams.
- Participated and conducted code review meetings prior to pushing patches to next levels/environments.
- Fixed Defects in testing phase, supported corporate loads and provided production support 24/7.
- Followed SOX Procedures and guidelines.
Environment: Oracle 9i, Java, MS Visio, J2EE, Servlets, JDBC, Java Script, XML, SOAP, SQL, HTML, CVS, MS Project, Rational Rose, UML.
Confidential
Responsibilities:
- Collaborated with the Project requirements manager on the BRS rewrite to include enhancements.
- Self management tools to the application owners, necessitate de-provision through attestation, improve audit capabilities.
- Authored functional specifications and communicated them to development and testing teams.
- Facilitated review meetings to ensure that the project was implemented within the specifications.
- Effectively supported the use and enhancements of the SOX Quarterly Review Tool.
- Administered Quarterly Review process as scheduled each quarter.
- Developed a training session for application owners in the use of the QRT.
- Consistently maintained stringent coding and documentation standards, and assisted with quality control efforts.
- Improved code scalability to handle massive amounts of data with shorter runtimes.
- Earned merit awards for exemplary performance beyond normal responsibilities, excellent teamwork, and delivery of outstanding product.
Environment: Java, JDBC, HTML, UNIX, Java Script, XML, MS Office suite, SQL Server 2000, Oracle, Rational Rose, UML.
Confidential
Systems/Applications Analyst
Responsibilities:
- Served as Compliance Champion for enterprise SOX compliance efforts. Evaluated internal controls, identified gaps, and recommended procedural changes and created associated procedural documentation.
- Work with cross-functional stakeholders to assess needs, create business rules and requirements, and specifications documentation.
- Reviewed SOX Access Review Manager (ARM) tool used to verify compliance.
- Led tool rewrite efforts that relocated database to local environment, provided self-administration tools, and improved audit capabilities.
- Saved $150,000 by automating audit processes while improving access removal rates by 350%.
- Assessed systems security needs and created standardized information security procedures.
- Improved performance of single-source login capabilities across multiple platforms that streamlined account synchronization, automated account removals, and password change processes.
- Trained and mentored new hires in best-in-class Global Development Process (GDP).
- Earned merit awards and recognition for exemplary performance beyond normal responsibilities, excellent teamwork, and delivery of outstanding product.
- Earned prestigious Bravo Zulu award for exceptional service (In recognition of removing firewall barriers between Confidential operating companies, resulting in significant cost savings).
- As a part of audit procedures,facilitated meetings with auditors (E&Y) to review ARM automated process that determines if the system and process is operating as designed.
- Interviewed meetings with business users to gather requirements and analyzed the feasibility of their needs.
- Authored functional specifications and communicated them to development and testing teams.
- Facilitated review meetings to ensure that the project was implemented within the specifications.
- Draft Standard operating procedure (SOP) for ARM.
- Effectively supported the use and enhancements of the SOX AccessReview Manager.
- Administered Quarterly Review process as scheduled each quarter.
- Assisted new application owners in the use of the ARM.
Environment: Java, JDBC, HP QC, CaliberRM, iRise, MS SharePoint, MS Office suite, PL/SQL, UNIX, Rational Rose, Software Engineering (SDLC), and UML.
Confidential
Responsibilities:
- Interviewed business users to gather requirements and analyzed the feasibility of their needs by coordinating with the project manager and the tech lead.
- Prepared business requirements specification, conducted and participated in JAD sessions with stakeholders and system users to collect the software requirement specifications (SRS).
- Used RUP methodology to analyze and translate business requirements into system specifications.
- Used Rational Rose and UML to produce models like context, use case, sequence and activity etc.
- Created and managed project schedule ensuring on time, on budget deliverables completion adhering to qualitative requirements.
- Developed and assisted in designing test plans, test scenarios and test cases for integration, regression and user acceptance testing (UAT) to improve the overall quality of the Application.
- Facilitated communications through the full project lifecycle including testing, issues resolution, and implementation planning.
- Systematic approach for the accounts removal and streamlined new accounts synchronization process.
- Sync processes for Automated Account removal, Password changes, and Password expiration results.
- The Internal Control Function credits ARM for improvements in audit, noting the 350% increase in the average number of access removals.
- In addition to improvements, 3000 man-hours were saved ($150,000) in FY'08 due to automation of the review.
Environment: HP QC, CaliberRM, iRise, MS SharePoint, MS Office suite, PL/SQL, Rational Rose, Software Engineering (SDLC), and UML.
Confidential, Memphis, TN
Graduate Assistant
Responsibilities:
- Assisted in the administration and maintenance of Windows and UNIX SCO servers, and 145 windows 2000/XP workstations.
- Provided technical support for hardware and software for over 300 Physical Plant customers.
- Helped in ensuring information systems security through training and development of computer security procedures and resolved network problems.
- Worked on general troubleshooting and development and maintenance of web pages in the university libraries.
Confidential
Software Developer
Responsibilities:
- Involved in design and coding using ASP.
- Used JavaScript for client side validations like validating users input data, date formats.
- Extensively worked with Data Reports.
- Involved in the Design and coding of business components for the Middle Tier.
- Configured the components with MTS and created Export Package.
- Invoked components from Client machine using DCOM utility.
- Implemented print functionality using JavaScript.
Environment: ASP, ASP .net, HTML, Java Script, XML, MS Office suite, Unix, SQL, Oracle, Rational Rose.