LAWANDA EDMOND
***** ******** ******. *******, ******** 20148
********@*******.*** • 301-***-****
SECURITY & CONTINUITY CONSULTANT
Extensive record of success designing and implementing complex, enterprise-level security,
information assurance, disaster recovery (DR), and business continuity planning (BCP) solutions
HIGHLY ACCOMPLISHED, RESULTS-DRIVEN INFORMATION SECURITY AND CONTINGENCY PLANNING LEADER ADEPT AT
OVERSEEING ENTERPRISE-SCALE SECURITY, DISASTER RECOVERY, AND BUSINESS CONTINUITY PLANNING, TESTING, AND
IMPLEMENTATION INITIATIVES. EXEMPLIFY BEST-PRACTICE STRATEGIES FOR BUSINESS-FOCUSED EMERGENCY PREPAREDNESS
AND RESPONSE, LEADING CHANGE WHILE MITIGATING ORGANIZATIONAL RISK AND VULNERABILITY. VAST EXPERIENCE IN
BUSINESS ANALYSIS AND PROJECT MANAGEMENT, WITH PROVEN HISTORY OF EVALUATING AND DEVELOPING REQUIREMENTS,
SCOPE, SCHEDULES / BUDGETS, SOLUTIONS, CHANGE CONTROL PROCESSES, AND LAUNCH STRATEGIES. DEMONSTRATED
COMMUNICATION ASTUTENESS, COLLABORATING EFFECTIVELY ACROSS ALL LEVELS OF THE ORGANIZATION, ITS PARTNERS,
CUSTOMERS, AND REGULATORY AGENCIES.
CORE COMPETENCIES
DR / BCP Contingency Strategies Full Life Cycle Project Management
• •
Emergency & Crisis Response Backup & Recovery Best-Practices
• •
System Security Plans (SSP) Security Awareness Campaigns
• •
Disaster Recovery Testing Exercises Process Design & Documentation
• •
DITSCAP & NIST 800-34 Expertise Training, Coaching & Mentoring
• •
PROFESSIONAL EXPERIENCE
SRA INTERNATIONAL, INC., Fairfax, Virginia
Information Assurance Specialist, 2005 to 2014
Serve in client-facing consulting role, liaising across business units and functional areas of the
Federal Deposit Insurance Corporation (FDIC) to develop disaster recovery (DR) and business
continuity plans (BCP); conduct interviews with stakeholders and subject-matter experts (SME) to
develop mission-critical requirements for business recovery and continuity. Lead project plan of
action and milestone (POA&M) development; foster top client relations through insightful assessment
of key business needs / objectives.
Selected Contributions:
Second Shift Duty Manager responsible for overseeing and handling of the severity one (Sev-
1) incident according to the established guidelines for the severity one process.
Act as the facilitator of the Operations Schedule of Activities meeting to make sure
representatives present their maintenance based on the shift report for that day and it
includes a change request number and an approver from the client. Track the implementation
and ensure the maintenance was successful.
Monitor the critical alerts via NetCool, NetIQ, and Opsware and make sure the Surveillance
and Technology Engineers (STE) are working to resolve the issue in a timely manner.
Developed business impact analysis (BIA) questionnaires through SME / business process
owner interviews to define mission-critical functions, processes, systems, infrastructure, and
dependencies, as well as recovery point objectives (RPO) and recovery time objectives
(RTO).
Developed business impact analysis (BIA) questionnaires through SME / business process
owner interviews to define mission-critical functions, processes, systems, infrastructure, and
dependencies, as well as recovery point objectives (RPO) and recovery time objectives
(RTO).
LAWANDA EDMOND
PAGE TWO
Orchestrated DR plan testing in concert with FDIC Division of Information Technology’s
Infrastructure Services and Delivery Management Branches; track testing outcomes, present
results / results analysis, and provide recommendations for corrective actions and plan
improvements to senior decision-makers.
Instrumental to the creation and launch of the Security Awareness and Training Program,
including development of security awareness presentations and reference materials
concerning active protection of data integrity, security, and confidentiality.
Ensure compliance with federal requirements, including the National Institute of Standards
and Technology (NIST) 800-34 Contingency Planning Guide for Information Technology
Systems.
Lead DR plan testing exercise development and execution, supporting validation of business
continuity plans to meet NIST requirements.
Lead end-to-end biannual DR plan testing exercises full infrastructure test conducted in a
a
model production environment spanning 5 FDIC divisions test communication, data storage,
and recovery processes; orchestrate annual tabletop testing for major business applications
under Application Contingency Plan, developing testing scenarios, coordinating IT program
managers and testing schedules, and supporting required Federal Information Security
Management Act (FISMA) reporting development.
Instrumental in establishing Disaster Recovery Working Group (DRWG), leading monthly DR
discussions and sessions to continuously improve DR planning, positioning, and recovery
processes.
COMPUTER ASSOCIATES, Herndon, Virginia
Information Security Specialist, 2004 to 2005
Designed, implemented, and administered Access Control Facility (ACF2) security solutions onsite at
the Federal Deposit Insurance Corporation (FDIC); provided internal user and external customer
support.
Selected Contribution:
Played key role in segmenting and splitting the ACF2 database into two, ensuring compliance
with security administration regulatory requirements. Utilized CA eTrust Admin to grant user
access to Active Directory, Single Sign-On (SSO), and CA-ACF2.
TITAN SYSTEMS, Largo, Maryland
Consulting Security Engineer, 2001 to 2004
Engaged to consult on security aspects of the Department of Defense (DOD) Medical
Communications for Combat Casualty Care (MC4) initiative specific to US Army implementation;
designed comprehensive security solution and contingency / disaster recovery (DR) plan in
alignment with DOD requirements.
Selected Contributions:
Developed security and information assurance model well as all related certification /
as
accreditation documentation demonstrate alignment and compliance with DoD
to
Information Technology Security Certification & Accreditation Process (DITSCAP).
Performed post-implementation security monitoring to ensure top performance; liaised
extensively between the end-user community and DOD contract Designated Approval
Authority.
VERIZON TECHNICAL SERVICES, Arlington, Virginia
Consulting Security Engineer, 1999 to 2001
Oversaw networking and security function for the US Department of Transportation (DOT),
supervising the primary responsible Network Engineer performing security planning, user account
administration, access / permissions management, and incident investigation / reporting. Served as
primary internal and customer point-of-contact. Ensured data integrity via Access Control Facility
(ACF2).
Selected Contribution:
Performed investigation into non-repudiated digital certificates within public key infrastructure.
EDUCATION AND CREDENTIALS
Bachelor of Science in Computer Information Systems
STRAYER UNIVERSITY, Washington, DC
Associate of Science in Business Computer Programming
ARKANSAS COLLEGE OF TECHNOLOGY, Little Rock, Arkansas – Dean’s List
Certification: Certified Business Contingency Planner (CBCP)
TECHNICAL PROFICIENCIES
Platforms: Windows, Mac OS, UNIX, Oracle
Networking: LAN, VPN, TCP/IP, Routers, Switches, Firewalls, Intrusion Detection Utilities
Tools: Identity Access Manager Systems (IAMS), eTrust Administration, TSO/ISPF, ACF2, RACF,
CICS, RPGII, Assembler, IMS, VSAM, Microsoft Office Suite, Remedy