Post Job Free
Sign in

Information Security Risk Management

Location:
Atlanta, GA
Salary:
90000
Posted:
December 13, 2023

Contact this candidate

Resume:

Wilfred Nkondock

Cyber Security Analyst

Norcross, GA (470) – 461 – 1469 *********@*****.*** LinkedIn PROFESSIONAL SUMMARY

• Senior Cybersecurity Analyst with 5+ years of experience, having worked as a cybersecurity analyst specializing in the areas of

(GRC) - Governance, risk management, and Compliance.

• Good Knowledge of Risk Management Framework (RMF), System development life cycle (SDLC), and Vulnerability Management using FISMA, and applicable NIST standards and adaptations

• Applied in-depth knowledge of NIST SP 800-53, and NIST SP 800-37 to perform a detailed security assessment of all FISMA- categorized information systems

• Assist the Program Management team in the delivery of multiple ATO packages and managing extended ATOs due to exceptions and waivers ignited by open POA&MS

• Applied knowledge of ISO 27001 to contribute to the development and maintenance of an Information Security Management System

(ISMS)

• Tested compliance with policies, and procedures to ensure conformity with industry standards, such as HIPAA, and PCI DSS frameworks

• Managed and maintained compliance with the Federal Risk and Authorization Management Program (FedRAMP) for cloud computing systems

• Ensured compliance with regulatory frameworks such as the Federal Information Security Management Act (FISMA), Federal Information Processing Standards (FIPS) 199, and the NIST SP 800 Series

• Utilized tools such as NESSUS and Web Inspect to perform vulnerability assessments and penetration tests.

• Developing, enforcing, and monitoring security policies to ensure compliance with industry standards and regulations

• Assisted in the development, and maintenance of IT Governance, and compliance Frameworks for managing IT improvement initiatives

• Ability to translate technical concepts for non-technical stakeholders

• Performed Federal Information Security Management Act (FISMA) audit reviews

• Communicated complex security concepts and compliance requirements clearly to various stakeholders

• Collaborated with cross-functional teams to implement and maintain security controls SKILLS

EDUCATION

Master of Science

University of Douala, Cameroon

Certification

CompTIA Security+ (In Progress)

EXPERIENCE

Senior Cybersecurity Analyst

Dell Technologies, NY March 2021 - Present

• Develop and update Security Assessment Reports (SAR), System Security Plans (SSP), Contingency Plans (CP), and Plans of Action and Milestones (POA&M).

• Assist in creating and maintaining security documentation, including policies, procedures, and incident response plans, ensuring compliance with regulatory requirements.

• RMF process

• FISMA

• FIPS 199

• NIST SP 800 Series

• Fed Ramp

• Cybersecurity Fundamentals

• Incident Response and Management

• Security Monitoring and Intrusion Detection

• Network and System Security

• Meet deadlines

• Strong written and verbal communication skills

• Security Awareness

• Compliance monitoring and reporting

• Risk Assessment, Risk Management

• Threat modeling

• GDPR, HIPAA, PCI DSS

• NESSUS and Web inspect

• ISO 27001

• Vulnerability Assessment and Penetration Testing

• Security Policies and Compliance

• Analytical and Problem-Solving Skills

• Team player

• Participate in penetration testing and vulnerability management activities, identifying weaknesses and recommending remediation strategies.

• Timely completion of tasks and projects within the GRC domain

• Coordinate and maintain Security Assessment and Authorization (A&A) process documentation for each system.

• Assist in conducting assessments of information systems in adherence to FISMA, FIPS, and NIST requirements.

• Conduct risk assessments, identify potential threats, vulnerabilities, and impacts on organizational assets and operations

• Implement and maintain compliance with PCI DSS for secure handling of credit card information

• Provide attestation of compliance for SOC 1 and 2 audits, demonstrating effective controls over financial reporting and information security

• Develop and execute incident response plans to mitigate the effects of security breaches or disruptive events

• Understand and adhere to Federal Risk and Authorization Management Program (FedRAMP) requirements for cloud computing systems

• Identify security controls and construct a compliance matrix for tracking purposes

• Review and update privacy documents such as PTA and PIA as part of compliance reports

• Perform risk assessments for new projects to ensure alignment with regulatory requirements and industry standards.

• Evaluate processes and controls for compliance with laws, regulations, and established policies

• Manage information security risk management activities and internal/external audit initiatives

• Communicate with company workers on security awareness topics and foster a culture committed to information security best practices

• Assist in selecting and tailoring third-party cyber risk management approaches, methods, and tools

• Facilitate root cause analysis, assess the impact and likelihood of issues, and support metrics and reporting

• Manage security policies, standards, procedures, and exceptions

• Plan and engage business stakeholders with quarterly and targeted Security Awareness programs

• Review and remediate ticketing systems, coordinate with clients and engineers to resolve issues

• Update and develop information security policies for ISO 27001 compliance Cybersecurity Analyst

Epsilon, GA Feb 2018 – Mar 2021

Helped guide system owners and ISSOs through the Certification and Accreditation (C&A) process, ensuring that operational, management, and technical control securing sensitive security systems are in place and followed according to the Federal Guidelines (NIST SP 800-53).

• Conducted meetings with internal and external partners to gather documentation and evidence about their control environment.

• Performed risk assessments to ensure alignment with regulatory requirements, industry standards, and corporate information security and privacy policies for new projects and deployments.

• Managed ongoing project programs for information security risk management, including risk treatment plans and external audit/certification initiatives like SOC2 and FedRAMP.

• Planned and executed internal security and privacy audits to assess control design and effectiveness.

• Reported compliance activity status and developed metrics for the risk remediation program.

• Communicated with company workers on security awareness topics.

• Supported, exhibited, and promoted a corporate culture committed to information security best practices.

• Reviewed Nessus scans from assigned systems as part of SOC2 audit preparation.

• Reviewed test evidence from ISCP as part of SOC2 audit response on PBC.

• Assisted in selecting and tailoring third-party cyber risk management approaches, methods, and tools.

• Assisted clients in developing third-party risk management programs.

• Performed validation of sub-controls with third parties as per the validation process.

• Provided periodic updates about the work status assigned to the project manager.

• Reviewed client's processes and controls against industry framework, identifying gaps, and communicating issues and recommendations.

• Stayed abreast of new technology, emerging risk areas, and related control techniques.

• Appraised the adequacy of corrective actions to remediate deficiencies identified during audits.

• Reviewed and updated the System Security Plan (SSP).

• Developed, maintained, and communicated a consolidated risk management activities and deliverables calendar.

• Contributed to initiating FISMA metrics such as Annual Testing, POA&M Management, and Program Management.

• Worked with System Owners to categorize systems using FIPS 199 and identified information types using NIST SP 800-60 Vol. 1&2.

• Reviewed Plan of Action and Milestones (POAM).

• Selected applicable Baseline Security Controls from NIST SP 800-53 Rev4 based on systems' categorization and documented them in the SSP.

• Worked with Assessors and ISO to close Plan of Action and Milestone (POA&M) entries.

• Ensured compliance with security standards and regulations such as HIPAA, PCI DSS, and GDPR.

• Created and maintained backup and disaster recovery plans to address system failures or data breaches.

• Provided security awareness training and education to employees to promote best security practices.

• Investigated and responded to security incidents, breaches, and exposures, determining the cause and extent of the problem and taking corrective action.

• Performed regular system log monitoring and analysis to detect potential security incidents.

• Participated in security audits and assessments conducted by external auditors and regulatory bodies, providing recommendations for security improvement.



Contact this candidate