Joseph Boateng (Top Secret Clearance)
********@*****.***
Alexandria Va 22309.
Skills
• Network Security • Cyber Security • Information Assurance • Security Assessment and Authorization • Risk Management • System Monitoring • WebInspect • e-policy orchestrator (ePO) console • Nessus • Symantec Endpoint • Security Technical Implementation Guide (STIG) Checklists • Center for Internet Security (CIS) Benchmark • Incident Response Planning • Identity and Access Management (IAM) • Plan of Action and Milestones (POA&M) • Compliance
Experience
Security Control Assessor,
Dept Of State, Washington D.C. December 2022- Present
● Conduct comprehensive security assessments and evaluations of information systems, ensuring compliance with relevant security policies, standards, and guidelines.
● Collaborate with Information System Security Officers (ISSOs) to document and remediate audit findings, develop security plans, and report on security vulnerabilities.
● Perform incremental Webapp scanning using WebInspect to identify and address potential vulnerabilities.
● Manage and monitor servers using the e-policy orchestrator (ePO) console, effectively detecting and responding to security vulnerabilities, intrusions, and attacks.
● Conduct periodic on-site security testing using Nessus and Symantec Endpoint to proactively identify and mitigate risks.
● Expertly configure and manage Security Technical Implementation Guide (STIG) Checklists and Center for Internet Security (CIS) Benchmark to ensure compliance.
● Prepare and document quarterly Incident Response Plans & Tests to establish effective incident response procedures.
● Identify security incidents and provide actionable recommendations to protect the network and enhance overall security posture.
● Conduct technical client interviews related to Identity and Access Management
(IAM) investigations with application owners.
Joseph Boateng (Top Secret Clearance)
********@*****.***
Alexandria Va 22309.
Cybersecurity Analyst
New York Life, Edison NJ February 2018 - November 2022
● Evaluate system security plans and procedures, and assist in managing and directing the operations and functions of the office support contractors, addressing IT out-of-compliance issues, preparing, implementing, monitoring, and updating the project plan
● Develop Plans of Actions and Milestones (POA&Ms) to correct findings of non-compliance
● Initiate, direct and participate in the full life cycle of cyber security appraisals and network penetration testing of geographically dispersed and operationally diverse agency facilities
● Develop and recommend new and/or revised inspection, evaluation, and penetration testing methodologies for cyber security appraisals
● Provide recommendations on implementation strategies and policy recommendations based on industry best practices and governing directives
● Assist the Division by conducting research, conducting investigations of cyber events to include those that potentially violate regulatory requirements
● Collaborate with senior leadership, departmental and contractor managers and staff in scheduling, planning, coordinating, and implementing the Independent Oversight Cyber Security Appraisal Program.
Certifications
CASP+ (Cybersecurity Advanced Security Practitioner) CompTIA Security+
Education
Bachelors in English – Rutgers University (2017)
Associate Degree in English – Middlesex County College (2015) Associate Degree in Education - Middlesex County College (2015)