YUSUF FLUELLEN
CISSP; CISM; CEH V*; GIAC Systems and Network Auditor; MCITP: Enterprise Administrator on Windows Server® 2008; MCITP: Enterprise Messaging Administrator on Exchange 2010; ITIL V3, Foundation 130 New Sweden Rd.
Swedesboro, N.J. 08085
*****.********@*****-****.***
TELEPHONE
IT SYSTEMS OPERATIONS / INFORMATION SECURITY MANAGEMENT IT Professional with more than 20 years of Operations, Security Management, Telecommunications, Engineering, and Maintenance experience, in Highly Regulated Environments. Provide consultant level knowledge to clients and Information Assurance team personnel on industry, and DoD specific, IT Security topics. Manage projects from start to successful completion. Develop technical and user guidance. Lead individuals of diverse technical levels and backgrounds. KEY SKILLS / QUALIFICATIONS
PROFESSIONAL EXPERIENCE
JUL 2013 – Present Swedesboro, N.J.
Secur(IT)e – Principal IT Security Consultant
Deliver expert level, tailored on-site, and/or remote, IT Security consultative services to small and medium sized organizations.
Provide:
IT Security Policy Development, Implementation and Review IT Systems Secure Configuration Development, Implementation and Review IT Vulnerability Assessment, Review, and Remediation support IT Risk Management Assessment, Review, and, Mitigation Strategy Development IT Business Continuity Plan and Disaster Recovery Plan Development and Review Management of Anti-Malware and APT solutions
IT Security Solutions Engineering, Implementation and Review IT Security Incident Response Management Plan Development, and Implementation Oversight of IDS/IPS, SIEM, and Logging System Operations Management of IT Security Projects
NIST, SANS, HIPAA, PCI-DSS, DIACAP Assessment Reviews, and Compliance Report Preparation
Technical budget development.
Vendor negotiation coordination of pre-purchase, acquisition, Professional Services, and support services.
IT Security Training
Clients: SMART IMS – 9/2015 – Present
Thrupoint, Inc. – 7/2013 – 3/2014
MAR 2014 – SEP 2015 Philadelphia, Pa.
General Dynamics IT – Senior Manager, Information Security Utilize extensive knowledge of all areas of IT Security and IT Operations to establish IT Operations Management Goal Oriented Leader
Information Security Management Excellent Interpersonal / Written Communications
Strong Organizational Skills Project Management
operating standards and procedures for the IA Program. Ensure compliance with Federal, DoD and DoN Information Assurance policies. Conduct threat and vulnerability analysis to assess and determine effective measures to minimize risks and ensure IS is operational and secure. Coordinate Information Assurance Vulnerability Management (IAVM) program: Disseminate Information Assurance Vulnerability Alerts (IAVAs) to System Administrators (SAs) and Information Assurance Security Officers (IASOs) to ensure IAVAs are received and acknowledged as required; Monitor IAVA compliance and reporting, ensure IS and network security scanning are performed, completed and documented; Ensure patches, hot fixes, and system change packages and AV definition updates are applied utilizing the established change control process; Report program effectiveness to the program director; Ensure compliance of all program IS to ensure assets are properly reported and scans validated; Reduce vulnerability assessment tool data through the use of scripting, macros and functions (e.g. Excel macros). Create, submit, and validate Certification and Accreditation (C&A) packages in accordance with DIACAP (DoDI 8510.01). Create, submit, and validate Platform IT (PIT) Risk Approval (PRA) packages in accordance with NAVSEAINST 9400.2. Review risk analysis and accreditation documentation for timeliness, completeness and accuracy and insure that all necessary materials are forwarded for review. OCT 2012 – JUN 2013 Trevose, Pa
International SOS Assistance, Inc. – Information Assurance Manager Managed TRICARE Overseas Program’s comprehensive Information Assurance program, which covered operations in the United States, United Kingdom, Hungary, Singapore, Republic of the Philippines, and Australia. Managed reviews of security bulletins, and determined impact to program systems. Managed assessments of personnel policies and procedures, as related to IT Security and IT Operations. Lead internal technical security assessments, and took sponsorship role for external IT Security audit engagements. Oversaw and reviewed the use of compliance tools used to perform scans of technology platforms for vulnerabilities (e.g. Retina, HBSS, Gold Disk, SCAP). Documented remediation requirements for implementation by technical support organizations. Managed compliance Plans of Action and Milestones. Continually assessed best security practices for inclusion in the program. Lead system accreditation efforts. Ensured system logs from Intrusion Detection Systems, Firewalls, servers, and networking equipment, etc. are reviewed in accordance with documented procedures. Oversaw the creation of risk management plans, based on adherence to security controls. Leveraged comprehensive knowledge of DoD regulatory policies relating to Information Assurance (IA), HIPAA, DoD Information Assurance Certification and Accreditation Process
(DIACAP), National Institute of Standards and Technology guidance, Information Assurance Vulnerability Management (IAVM) products in determining regulatory requirements for systems under my influence. Managed Incident Response for all systems operated by or for the TRICARE Overseas program. Provided budget forecast for current and proposed IT Security functions. Coordinated efforts of Matrixed assets assigned to fulfill technical IT Security functions.
AUG 2008 – SEP 2012 Manama, Bahrain
STG, Inc. - Sr. Network Administrator
Provided dedicated, on-site, Tier III messaging Subject Matter Expert (SME) technical support for all OCONUS Navy Enterprise Network (ONE-NET) Bahrain MS Exchange 2003/2007 Enterprise servers, and BlackBerry Enterprise Server 4.1.x servers, which encompass six geographically separated sites and 12000+ user mailboxes. Supervised assigned Active Duty Military and contractor personnel in the operation of the messaging infrastructure. Participated in requirements analysis, design, engineering and build-out of the regional messaging infrastructure. Ensured that all assigned Windows 2003/2008 servers (physical and VMware virtualized), EqualLogic (PS6000, PS6500), Quantum Dxi 4500, and PowerVault NX3000, operated in accordance with ONE-NET Enterprise/SPAWAR standards, and US NAVCENT, CENTCOM, DoN and DoD IA guidance. Participated in the generation of local SOPs, and provided input for local and Enterprise-wide Request for Change (RFC) initiatives. Utilized DoD provided Security Technical Implementation Guides
(STIGs), checklist, and IA tools (Gold Disk, SCAP, RETINA, HBSS, Symantec Mail Security for MS Exchange 6.5, and Anti-Virus clients) to ensure that all assigned systems were properly configured, patched, and capable of minimizing the risk of malicious activity. Managed and coordinated the Microsoft Premier Support services for the ONE-NET Middle East Exchange Server Infrastructure. Coordinated trouble-shooting of CISCO CSIDS deployed at NCTS Bahrain. Assisted local Information Assurance personnel with certification documentation (DIACAP), compliance monitoring, compliance data research, inspections, and response to file and/or email data spills. MAR 2006 – JUL 2008 Manama, Bahrain
Science Applications International Corporation – Sr. Network Systems Administrator/Information Assurance Manager
Provided Sr. Level IT support to Military Sealift Fleet Support Command's (MSFSC), Ship Support Unit - Bahrain (SSU-Bahrain), and Military Sealift Command's (MSC), SEALOGCENT, organizations. Supervised a team of forward deployed MSC Afloat Systems Engineers. Ensured that MSC users and systems were able to fully employ the IT capabilities that were provided them by either the One-Net program or MSC. Responsible for all NIPR, SIPR, CENTRIXS and DMS technical support functions, regarding all LAN, PC and WAN issues. Ensured that all SSU-Bahrain Windows 2003 Small Business Servers (IIS, SharePoint Services, Exchange Server 2003, Windows Server Update Services, ISA Server 2004, SQL Server 2005), XP and Vista workstations, SonicWall appliances, CISCO switches, and network peripherals, were administered and secured in accordance with all applicable DoD, Navy and MSC guidance. Administered MS WSUS and Symantec Anti-Virus servers. Performed periodic network scans utilizing DoD's SCCVI (eEye Retina) to ensure MSC systems met DoD IAVA and recommended STIG requirements. Maintained all local MSC Active Directory and Share permissions on the ONENET networks. Provided technical coordination with MSFSC N6, ONE-NET Bahrain, NAVCENT N6 IAM, MSC Global Helpdesk and the MSC DMS Support Center. Represented SSU- BAHRAIN at all meetings involving SSU-Bahrain's IT issues at various NAVCENT, NCTS, and NSA Bahrain sponsored meetings. Ensured that current capabilities and future needs were assessed and planned for, as well as leveraged current equipment and future budgets to ensure the best possible technical solutions are available for SSU-Bahrain's mission. Coordinated escalation and response to ONENET, and or MSCGHD, for any IA incidents involving IT assets or personnel assigned to MSC in the CENTCOM area of responsibility. Provided IA awareness to all MSC staff and ensured that they complete all mandated IA training and certification requirements in a timely manner. Assisted NAVCENT IAM with IA issues and participated in all IA panels assembled within the NAVCENT organization.
OCT 2004 – MAR 2006 Manama, Bahrain
Computer Sciences Corporation - Sr. Information Assurance Representative
Responsible for providing senior level Information Assurance support to the DISA- CENT Field office and the CENTCOM J6 Staff (Forward). Focal point for vulnerability and incident response between the DISA IA staff and the DOD CERT, Central Regional CERT, Global Network Operations Support Center, and the Joint Task Force for Computer Network Operations. An integral working member of the DISA Information Operations Cell for the planning, coordination, and support between DISA and key elements within CENTCOM. Also responsible for the coordination and planning for DISA Information Assurance Readiness Review and Security Readiness Review processes, leveraging technical and operational support within DISA, to enhance DISA's IA posture. Coordinated installation and trouble- shooting of USCENTAF’s CISCO CSIDS deployed throughout the CENTCOM AOR. Assist CENTCOM with INFOSEC education, training, and security awareness to include IA tools and systems fielded by DISA network administrators, Information Assurance Officer (IAO), Information Assurance Manager (IAM) and the Designated Approval Authority (DAA). Work closely with the DISA staff on network life-cycle support, to include: configuration management, contingency plans, system requirements, architecture (Defense in Depth), engineering, design, integration, DoD Information Technology Security Certification and Accreditation Process (DITSCAP), Secret Internet Protocol Router Network (SIPRnet) connection security approval process, and installation, operation, and maintenance of CENTCOM's computer networks.
JUN 2003 - OCT 2004 Manama, Bahrain
Computer Sciences Corporation - Sr. Systems Administrator Performed System/Security Administration duties for all Windows 2000 servers, workstations and Windows XP workstations used by DISA-Central TNC, JDCS- INMS program. Administered various server applications: Internet Information Server 5.0, Microsoft SQL Server 2000, DNS Server 2000, WINS Server 2000, AI Metrix Neuralstar, Veritas BackupExec, Executive Software Diskeeper, and Symantec System Center. Determined and maintained overall security posture of all computer systems under the direct control of the JDCS program at DCR-TNC. Responsibilities include physical security, intrusion detection and intrusion prevention measures deployment. Utilized NSA (National Security Agency), DISA
(Defense Information Systems Agency) and DOD CERT security templates and baselines to secure JDCS systems. Ensured compliance with applicable DISA security standards utilizing, DISA FSO, Gold Disk and SRR scripts to verify security implementations. Maintained close communications with DCR-TNC CERT and IA representatives to ensure the highest adherence to applicable DOD and industry current security standards. Administered appropriate equipment configurations and implementation timelines in coordination with the JDCS-INMS Central Development Activity. Recommended equipment modifications and provided technical consultation and system requirements assessment. Supported: Dell PowerEdge 1650, 2650, 6650 server, StorageTek L20 Tape Library and various Dell Optiplex + Dimension workstations.
JAN 2000 - MAY 2003 Stuttgart, Germany
Northrop Grumman IT - Sr. Principal Analyst
Performed system/network administration duties for all UNIX/LINUX, Windows NT 4.0/2000 servers, workstations and networking equipment used by HQ, USEUCOM, ECCS-OR. Administered various Microsoft server applications: Internet Acceleration Server, Internet Information Server 4.0/5.0, Microsoft SQL Server 7.0/2000, Microsoft Systems Management Server 2.0, Exchange Server 5.5/2000, DHCP server NT4.0 /Win2k, DNS Server NT4.0/Win2k and WINS Server NT40/Win2k. Determined and maintained overall security posture of all computer systems/networks under the direct control of ECCS-OR. Responsibilities included physical security, intrusion detection and intrusion prevention measures deployment. Utilized NSA (National Security Agency), DISA (Defense Information Systems Agency) and RCERT-E security templates and baselines to secure ECCS- OR systems. Ensured compliance with applicable DISA security standards utilizing, DISA-FSO, SRR scripts to verify security implementations. Maintain close communications with DISA's EUR RCERT organization, HQ EUCOM J6 network personnel and security personnel to ensure the highest adherence to applicable DOD and industry current security standards. Specify computing equipment, hardware and software. Determined appropriate equipment configurations and implementation timelines. Recommended equipment modifications. Provided technical consultation, system requirements assessment, vendor sourcing and life cycle fiscal forecasting. Specified, design, implementation, configuration and maintenance of LAN equipment hubs, switches, routers, firewall applications and systems. Systems Supported: Silicon Graphics INDIGO2, SUN SPARCSTATION 5, 20, ULTRA SPARC 1, 2, 60, ULTRA ENTERPRISE 2 and ENTERPRISE 450 server, Dell PowerEdge 2300/2400/2500 servers, various Dell Optiplex + Dimension workstations, tape storage and backup systems, raid storage systems and CD storage systems.
JUN 1997 – JAN 2000 Stuttgart, Germany
Computer Sciences Corporation - Network/Security Manager Ensured all Joint Total Asset Visibility (JTAV) SUN servers were able to communicate via the LAN transmission facilities provided by HQ, US EUCOM, ECJ6 at Patch Barracks, Stuttgart, Germany, to and through the larger Defense Information Systems Agency (DISA), SIPR and NIPR networks to reach client as well as peer computer systems. System administration for Solaris UNIX and Netscape Suite Spot Web Server. Established UNIX user accounts and Netscape client accounts. Performed extensive diagnostic techniques to diagnose and take corrective actions for problems that arose with either element
(network/security/server hardware). Performed security evaluation, implementation and auditing to prevent unauthorized access to JTAV systems throughout the European operation. Utilized Omniguard/ESM, Axent, RAPTOR (firewall) and SUN Solaris ASET and Basic Security Module (BSM) programs. Worked with clients and remote technical staff personnel to assist in penetrations of firewalls and routers to enable access to the SUN server systems. Worked in close coordination with U.S. government clients, both in-theater and in the United States. Systems Supported: SUN Enterprise 5000 servers, SUN SPARC 1000 servers and several PC based systems of the system were included in tasking. OCT 1992 – MAR 1997 Stuttgart, Germany
Kajax Engineering, Inc. - Project Manager
Selected candidates for open positions. Coordinated employee overseas transitions. Formulated start-up and shutdown procedures for a 2400 user, Novell Ethernet LAN, maintenance and repair facility. Manage a six-man team of technician and engineers. Designed, installed, configured, modified and maintained all user work- stations (PCs, Printers, etc.), network transmission equipment (Cabletron, Cisco, Modems, etc.), fiber optic and copper cabling systems, and various other office ADP items (Secure + Non-Secure Fax Systems, High Speed Printers, etc.). Installed and configured DOS, Windows, Word Perfect and various other PC based applications. Major projects include re-engineering Secret and Unclassified, Ethernet and Fiber Optic, cable plants at HQ, US, EUCOM. Developed monthly budgets that focused on ensuring consumable items were sufficiently stocked to handle predicted workloads. Worked in close coordination with U.S. government clients, both in- theater and in the United States.
EDUCATION
Installing and Configuring Windows 7, Koenig Solutions, Goa, India, June 2012 Deploying Windows Server 2008, Koenig Solutions, Goa, India, June 2012 Configuring and Troubleshooting Internet Information Services in Windows Server 2008, Koenig Solutions, Goa, India, June 2012
Configuring and Troubleshooting Windows Server 2008 Terminal Services, Koenig Solutions, Goa, India, June 2012
Designing a Windows Server 2008 Network Infrastructure, Koenig Solutions, Goa, India, June 2012
Designing a Windows Server 2008 Active Directory Infrastructure and Services, Koenig Solutions, Goa, India, June 2012
Threat Management Gateway, Koenig Solutions, Goa, India, June 2012 Implementing a Microsoft SQL Server® 2008 Database, New Horizons, Manama, Bahrain, April 2011
Maintaining a Microsoft SQL Server® 2008 Database, New Horizons, Manama, Bahrain, April 2011
Dell EqalLogic PS Series Business Continuity and Disaster Recovery, NCTS Bahrain, Manama, Bahrain, February 2011
Dell CommVault Training, NCTS Bahrain, Manama, Bahrain, February 2011 VMware vSphere: Manage for Performance, ESX 4.0, ESXI 4.0, and vCenter Server 4.0, NCTS Bahrain, Manama, Bahrain, February 2011
VMware vSphere 4.1: Install, Configure, Manage, ESX 4.1, ESXI 4.1, and vCenter Server 4.0, NCTS Bahrain, Manama, Bahrain, February 2011 Microsoft Exchange Server 2010, MCITP Certification tract, Koenig Solutions, Goa, India, January 2011
Windows Server 2008, MCITP Server Administrator tract, Koenig Solutions, Goa, India, January 2011
BlackBerry Enterprise Server Administrator’s course, Research In Motion, Singapore, August 2010
EC-Council, SANS, GSNA course, On-line, February 2010 Project Management International, PMP Preparation seminar, NovoTech Seminars, Manama, Bahrain, July 2009
Office of Government Commerce, ITIL V3 Foundation Course, Global Knowledge, Manama, Bahrain, June 2009
CISCO CCNA Prep Course, New Horizons, Manama, Bahrain, February 2008 DISA, FSO, DoD IA Boot Camp (DITSCAP, DIACAP), Manama, Bahrain, February 2008
DISA, FSO, McAfee, Hercules 4.0 Operator Training, BAE Systems Information Technology, Manama, Bahrain, March 2007
DISA, FSO, eEye Digital Security, eEye Retina 5.X.X/REM 3.0 Operator Training, BAE
Systems Information Technology, Manama, Bahrain, March 2007 DISA, FSO, Auditing and Monitoring Windows 2003 Server, JET Computer Services Inc., Manama, Bahrain, March 2006
Auditing Perimeters, Systems and Networks, the SANS Institute, Self Study Course, March 2005
Microsoft Windows Server 2003 MCSE Track, New Horizons, Manama, Bahrain, June 2004 - April 2005
DISA, FSO, Securing Your Windows 2000 Server, JET, Manama, Bahrain, March 2004
WEBSEC 2003 Conference, MIS Training, London, England, March 2003 DISA, IATAC, Introduction to Cryptology, Booz-Allen-Hamilton, Kaiserslautern, Germany, November 2002
DISA, IATAC, Network Intrusion Fundamentals, Booz-Allen-Hamilton, Kaiserslautern, Germany, November, 2002
(ISC), CBK Review Seminar, Tech Train Institute, Vienna, VA., November 2001 DISA, Global Networks Operations and Security Center, UNIX SA Level II Security Course, Stuttgart, Germany, August 2000
Introduction to Network Security and Intrusion detection, GTE, Stuttgart, Germany, October 1999
Department of Defense, Operational Information Systems Security, Stuttgart, Germany, February 1999
Global Command and Control System (GCCS), Security Administrator, Air Force Training Command, Stuttgart, Germany, February 1999 Audit and Security of Unix-Based Operations Systems and UNIX Workshop, MIS Training Institute, Stuttgart, Germany, June 1998
DISA UNIX Security Procedures, Defense Information Systems Agency, Stuttgart, Germany, May 1998