Tori Garrick
****.*********@*****.***
CLEARENCE
Currently cleared Top Secret, Sensitive Compartmented Information with Full-Scope Poly obtained in June
through Department of Defense
CERTIFICATIONS
Certified Ethical Hacker (CEH)
TECHNICAL COMPETENCIES
Software
• Wireshark, SNORT, Remote Desktop (RDP), Adobe Reader, FileZilla, Windows SysUtilities, Malicious Traffic
Analysis Toolset
Hardware
• Hard Drives, RAM, Ethernet, Switches, Linksys Wireless Access Points, Routers, Dell Power Edge (PE) Servers,
Network Printers, Network Cabling
Penetration Testing
• Metasploit, Nessus 4.4, eEye Retina, Netcat, Cain and Able, KisMac
Virtualization
• VMware Fusion, VMware Workstation, Vsphere, and Virtual Box
Telecommunications
• Wireless Technology
Traffic Analysis Tools
• Procmon, ProcessExplorer, AutoRuns, OllyDbg, IDA Pro, WinDiff, Regshot, NetStat
Programming Language
• C++, Perl
Operating Systems
• Microsoft Server 2003/2008 Installation and Configuration
• Microsoft Windows XP, Windows Vista, and Windows 7
• Red Hat Enterprise Linux
• BackTrack Linux
Security Standards/Controls
• National Institute of Standards and Technology (NIST)
• Federal Information Processing Standards (FIPS)
EXPIERENCE
Malware Triage Analyst Fort Meade, MD November 2012 – Present
Primary responsible for providing mission customer with malware triage and network analysis for cyber threats of interest to
derive at signature based characterization.
• Performed static and dynamic analysis through the use of various investigative techniques and tools to determine
security vulnerabilities as well as behavioral characteristics of malware.
• Conducted initial analysis to include, packet analysis and reverse engineering to determine the sophistications of
malware discovered.
• Assessed damages as a result of intrusion, and regularly documented findings in ticketing based system for viewing by
mission customer or further in-depth analysis.
Information System Security Engineer (ISSE) / Computer Networking, Department of Defense Feb 2012–Oct 2012
Fort Meade, MD
Chiefly accountable for leading Certification and Accreditation (C&A) process on behalf of SIGINT enterprise mission
customer. C&A process pertains to software solution providing command and control (C2) for corresponding hardware
solutions. Within mission, also accountable for installation, testing, and deployment of network infrastructure-enabling
customers to meet mission needs.
• Articulate security engineering activities associated with respective phases of an IT system’s life cycle.
• Analyze threat and risks related to mission critical SIGINT solutions, their operational capabilities, as well as
understand the relationship between operational capabilities and security requirements.
• Independently conducted vulnerability assessments via Agency tooling to determine a baseline for system
performance and security. Utilized Risk Management Framework (RMF) Process guidance to identify weakness
regarding configuration settings, user and administrator privileges as well as hardening system services. Documented
analysis and provided customer with changes as well as supporting justification. Efforts resulted in configuration
changes, operation system (OS) package enhancements, as well as customer willingness to accept mitigated risk of
mission dependant capabilities and functionality.
• Enhanced security posture of critical SIGINT communications systems by employing Agency hardening techniques
and tools to decrease the level of risk to mission systems. In an effort to complete the Security Authorization process
for telecommunications software solution, activities included conducting vulnerability scans, applying concepts of
least privilege, verifying system integrity against common vulnerability databases, mapping identified capabilities to
requirements documentation as well as adhering to guidance found in various National Institute of Standards and
Technology (NIST) publications.
• Identified product configuration inconsistencies in an effort to harden SIGINT solution to meet enterprise security
posture.
• Produced documentation detailing design, configuration, and sustainment procedures.
MAJOR ACHIEVEMENTS
• Built and maintained internal hardware components of SIGINT solution to sustain the integrity of deployed systems.
• Implemented re-architecture of test laboratory to include racking, configuration, and installation of test network.
Software Developer, Department of Defense Fort Meade, MD June 2011/Februrary 2012
Provided SIGINT mission customer with streamlined soft solution to effectively identify commonalities among
communications dynamically stored on a database or while in motion.
•Leveraged division-wide software modules to streamline development, testing, as well as maintenance of software
solution.
• Collaborate with subject matter experts (SME) and SIGINT analysts to provide a productive environment in
which ideas can be exchanged; modernized coding methods are established, as well as addressing inquiries and
providing feedback.
• Briefed division leadership and target analysts community in an effort to provide project status, coding
constraints, and development deltas.
• Authored documentation to provide guidance in functionality sustainment.
MAJOR ACHIEVEMENTS
• Developed database functionality to expand the depth in which data is captured, processed, as well as reported for
current and future analysis. Functionality serves as the current standard for identifying selectors, erroneous data, and
commonalities in SIGINT.
Information Systems Security Engineer (ISSE), Department of Defense Fort Meade June2010/January 2011
Primarily responsible for providing Information System Security Engineering guidance on various systems and tasked
projects, ensuring appropriate security features and safeguards are designed, integrated, and implemented by all information
systems through the System Development Life-Cycle (SDLC).
• Successful completion of Masters Level Engineering courses in the Information Systems Security Engineering
curriculum, at the Naval Postgraduate School (NPS).
• Collaborate with Security Engineering to establish a concise plan of action for the secure deployment and
implementation of communication solutions. Addressed scalability and potential vulnerabilities of perspective
encryption and authentication technologies.
• Measurably improve the security of critical IT systems through information assurance guidance in order to ensure
continued mission success for the National Security Agency.
• Regularly briefed team of engineers and senior management on project status, related tasks, as well as any associated
risk incurred during the Certification and Accreditation (C&A) process.
MAJOR ACHIEVEMENTS
• Lead a team of Junior ISSEs to determine the most applicable tool for real-time workflow management. Qualitative
analysis resulted in the implementation of new division-wide standard and use of workflow management tooling.
• Conceptualized and distributed a first of its kind Best Practices Statement for enterprise-wide implementation of
virtualization software solution. Further sustained and optimized Best Practices Statement as immerging technological
constraints arose.
EDUCATION
Bowie State University (Designated as Center of Academic Excellence (CAE) by National Security Agency )
Bowie, MD
B.S. Computer Technology/Networking Security, May 2010
RELATED COURSEWORK
Naval Postgraduate School (NPS) (Designated as CAE by Nation Security Agency) Monterey, CA
Network Security:
Explore principles in major topic areas to include the protection of legitimate network traffic via cryptographic mechanisms,
the detection and filtering of malicious network traffic via authentication mechanisms, attack signature recognition, as well as
filter mechanisms and strategies
Network Vulnerability Assessment and Risk Mitigation:
Grasp methodologies used to assess and mitigate organization related vulnerabilities through the employment of common
tools and resources. Classify and describe modern day vulnerabilities, potential threats, hacker motivations, and the means to
protect against them,
Secure System Principles:
Comprehend concepts and principles for secure systems construction to differentiate major categories of system policies,
secure component interconnection, trustworthiness, as well as how design choices affect system security.
Basic Malware Analysis
This course teaches students the fundamental requirements necessary to analyze malicious software. From simple
keyloggers to massive botnets this class covers a wide variety of current threats used on the Internet today with
actual samples being analyzed in the training environment.
Intermediate Malware Analysis
Student equipped with the behavioral Malware Analysis knowledge from the Basic Malware Analysis course, this course introduces more
advanced malware topics and utilizes Olly Debugger and IDA Pro debugger tools to better analyze assembly code.
Cyber Threat Detection and Mitigation
This course demonstrates how to defend large-scale network infrastructures by building and maintaining advanced
intrusion detection systems.
System Engineering Boot-camp
Course emphasizes cooperation between the security and engineering communities and instructs attendees on the joint development of design
criteria and protective measures to mitigate emerging threats to assets.
Internet Technologies
This course explores the basic introduction fundamentals to the technologies that underlie the Internet.
Networking Fundamentals
Course covers media types and standards and how data is encoded and transmitted. Students are also introduced to
the terminology and basic concepts of each network operating system.
Information Assurance Familiarization Course
Provides students an understanding of the information systems security policies, roles, responsibilities, practices, procedures, and concepts.
The lessons presented here will aid in developing an effective, overall security approach.
Wireless Ethical Hacking/ Penetration Testing & Defense
Utilizing different assessment and analysis techniques, this course will show you how to identify the threats that expose wireless technology
and build on this knowledge to implement defensive techniques that can be used to protect wireless system.
Level 1 Penetration Testing Course
Introduces students to different method of evaluating the security of a computer system or network by simulating an attack from malicious
outsiders.
CONFERENCES
BlackHat/Defcon 2011