Information Security Analyst Resume
0/5 (Submit Your Rating)
Richmond, VA
PROFESSIONAL EXPERIENCE:
Information Security Analyst
Confidential, Richmond, VA
Responsibilities:
- Conducted risk assessments for critical systems and applications.
- Presented Information Security Awareness to staff members; domestic and international.
- Supported KPMG during annual IT/Security audits.
- Worked with service owners to develop and document disaster recovery and backup plans.
- Assisted the Information Security Manager with the development of new Information Security policy and directives.
Zone Information Security Officer
Confidential, Richmond, VA
Responsibilities:
- Implement and oversaw Facility Information Security Program.
- Served as primary facility contact for all information security concerns.
- Monitored security compliance using existing tools as directed by Corporate Information Security.
- In conjunction with the Division IT&S staff, implemented Information Security policies, procedures, standards, and toolkits to ensure facility compliance with HIPAA and the Hitech Act.
- Ensured the facility had an ongoing Information Security and Awareness Program.
- Ensured a complete Information Security Incident Response Plan was developed and implemented.
- Ensured appropriate departmental security procedures are in effect which support Information Security requirements.
- Ensured appropriate physical security process for Information Security assets, including but not limited to, laptop and workstation security, appropriate access to controlled areas, and adequate environmental controls for equipment.
- Worked with the Facility Privacy Official to ensure alignment between information security and privacy practices.
- Worked with the Ethics & Compliance Officer to ensure alignment between information security and Company compliance requirements.
Information Security Officer/Vice President
Confidential, Las Vegas, Nevada
Responsibilities:
- Developed and maintained the Information Security Program, Policy, IT Risk Assessment, BCP/DRP Plans, and Incident Response Plan.
- Created an Information Security Awareness Program that was presented to all staff members annually and during new hire orientations.
- Project leader - Led group that created and implemented a compliant Red Flag/ ID Theft Prevention Program.
- The primary contact for Federal Examiners, Internal/External Auditors, and the FDIC for all onsite examinations relating to Information Security.
- Responsible for the company wide compliance with GLBA & SOX and adherence to FFIEC guidelines.
- Daily review of TriGeo and audit reports to ensure system integrity.
Information Security Analyst III
Confidential, Syracuse, New York
Responsibilities:
- Wrote Security Policies, Standards and procedures for multiple platforms.
- Provided support and for Security Analyst team.
- Supplied administration for RSA server,VPN clients, RACF, Active Directory, UNIX, Lotus Notes, Cisco Secure, CITRIX.
- HIPAA & SOX compliance projects.
- Acted as the key resource for supporting and resolving security-related problems and technical questions.
- Used all available resources to resolve security related problems and technical questions including technical staff, technical manuals, web-based documentation, and security tools.
Information Security Analyst
Confidential, New York, New York
Responsibilities:
- Project manager for RACF database clean-up project.
- Utilized system analysis skills to ensure proper configuration of RACF database.
- Involved in the definition of Secure ID’s for internal and external clients.
- Responsible for generating reports and analyzing possible violations, utilizing Vanguard Advisor and Vanguard Analyzer.
Data Security Analyst
Confidential, New Jersey
Responsibilities:
- Support and administration of CA-Top Secret databases.
- Reviewed and addressed violations using TSSUTIL.
- Created new Acids and modified existing Acids' access to resources.
Information Security Analyst
Confidential, Newark, New Jersey
Responsibilities:
- Project manager for new security product installations and existing product upgrades.
- Converted SDSF from ISFPARMS to RACF controlled Security.
- Implemented DB2 External Security Module.
- Configured the security for RACF, DB2, IMS, CICS, Endevor, etc.
- OS/390 security resource for CIS conversion from RACF to SAP.
Information Security Administrator
Confidential, New York, New York
Responsibilities:
- Responsible for the review of access requirements for various platforms including Mainframe(RACF), AS400, VAX and databases such as Sybase and DB2.
- Defined new IMS and CICS transactions to the RACF database.
- Auditing of multiple databases and review of access and violation reports for multiple platforms.