Wilfred Nkondock
Cyber Security Analyst
Norcross, GA (470) – 461 – 1469 *********@*****.*** LinkedIn PROFESSIONAL SUMMARY
• Senior Cybersecurity Analyst with 5+ years of experience, having worked as a cybersecurity analyst specializing in the areas of
(GRC) - Governance, risk management, and Compliance.
• Good Knowledge of Risk Management Framework (RMF), System development life cycle (SDLC), and Vulnerability Management using FISMA, and applicable NIST standards and adaptations
• Applied in-depth knowledge of NIST SP 800-53, and NIST SP 800-37 to perform a detailed security assessment of all FISMA- categorized information systems
• Assist the Program Management team in the delivery of multiple ATO packages and managing extended ATOs due to exceptions and waivers ignited by open POA&MS
• Applied knowledge of ISO 27001 to contribute to the development and maintenance of an Information Security Management System
(ISMS)
• Tested compliance with policies, and procedures to ensure conformity with industry standards, such as HIPAA, and PCI DSS frameworks
• Managed and maintained compliance with the Federal Risk and Authorization Management Program (FedRAMP) for cloud computing systems
• Ensured compliance with regulatory frameworks such as the Federal Information Security Management Act (FISMA), Federal Information Processing Standards (FIPS) 199, and the NIST SP 800 Series
• Utilized tools such as NESSUS and Web Inspect to perform vulnerability assessments and penetration tests.
• Developing, enforcing, and monitoring security policies to ensure compliance with industry standards and regulations
• Assisted in the development, and maintenance of IT Governance, and compliance Frameworks for managing IT improvement initiatives
• Ability to translate technical concepts for non-technical stakeholders
• Performed Federal Information Security Management Act (FISMA) audit reviews
• Communicated complex security concepts and compliance requirements clearly to various stakeholders
• Collaborated with cross-functional teams to implement and maintain security controls SKILLS
EDUCATION
Master of Science
University of Douala, Cameroon
Certification
CompTIA Security+ (In Progress)
EXPERIENCE
Senior Cybersecurity Analyst
Dell Technologies, NY March 2021 - Present
• Develop and update Security Assessment Reports (SAR), System Security Plans (SSP), Contingency Plans (CP), and Plans of Action and Milestones (POA&M).
• Assist in creating and maintaining security documentation, including policies, procedures, and incident response plans, ensuring compliance with regulatory requirements.
• RMF process
• FISMA
• FIPS 199
• NIST SP 800 Series
• Fed Ramp
• Cybersecurity Fundamentals
• Incident Response and Management
• Security Monitoring and Intrusion Detection
• Network and System Security
• Meet deadlines
• Strong written and verbal communication skills
• Security Awareness
• Compliance monitoring and reporting
• Risk Assessment, Risk Management
• Threat modeling
• GDPR, HIPAA, PCI DSS
• NESSUS and Web inspect
• ISO 27001
• Vulnerability Assessment and Penetration Testing
• Security Policies and Compliance
• Analytical and Problem-Solving Skills
• Team player
• Participate in penetration testing and vulnerability management activities, identifying weaknesses and recommending remediation strategies.
• Timely completion of tasks and projects within the GRC domain
• Coordinate and maintain Security Assessment and Authorization (A&A) process documentation for each system.
• Assist in conducting assessments of information systems in adherence to FISMA, FIPS, and NIST requirements.
• Conduct risk assessments, identify potential threats, vulnerabilities, and impacts on organizational assets and operations
• Implement and maintain compliance with PCI DSS for secure handling of credit card information
• Provide attestation of compliance for SOC 1 and 2 audits, demonstrating effective controls over financial reporting and information security
• Develop and execute incident response plans to mitigate the effects of security breaches or disruptive events
• Understand and adhere to Federal Risk and Authorization Management Program (FedRAMP) requirements for cloud computing systems
• Identify security controls and construct a compliance matrix for tracking purposes
• Review and update privacy documents such as PTA and PIA as part of compliance reports
• Perform risk assessments for new projects to ensure alignment with regulatory requirements and industry standards.
• Evaluate processes and controls for compliance with laws, regulations, and established policies
• Manage information security risk management activities and internal/external audit initiatives
• Communicate with company workers on security awareness topics and foster a culture committed to information security best practices
• Assist in selecting and tailoring third-party cyber risk management approaches, methods, and tools
• Facilitate root cause analysis, assess the impact and likelihood of issues, and support metrics and reporting
• Manage security policies, standards, procedures, and exceptions
• Plan and engage business stakeholders with quarterly and targeted Security Awareness programs
• Review and remediate ticketing systems, coordinate with clients and engineers to resolve issues
• Update and develop information security policies for ISO 27001 compliance Cybersecurity Analyst
Epsilon, GA Feb 2018 – Mar 2021
Helped guide system owners and ISSOs through the Certification and Accreditation (C&A) process, ensuring that operational, management, and technical control securing sensitive security systems are in place and followed according to the Federal Guidelines (NIST SP 800-53).
• Conducted meetings with internal and external partners to gather documentation and evidence about their control environment.
• Performed risk assessments to ensure alignment with regulatory requirements, industry standards, and corporate information security and privacy policies for new projects and deployments.
• Managed ongoing project programs for information security risk management, including risk treatment plans and external audit/certification initiatives like SOC2 and FedRAMP.
• Planned and executed internal security and privacy audits to assess control design and effectiveness.
• Reported compliance activity status and developed metrics for the risk remediation program.
• Communicated with company workers on security awareness topics.
• Supported, exhibited, and promoted a corporate culture committed to information security best practices.
• Reviewed Nessus scans from assigned systems as part of SOC2 audit preparation.
• Reviewed test evidence from ISCP as part of SOC2 audit response on PBC.
• Assisted in selecting and tailoring third-party cyber risk management approaches, methods, and tools.
• Assisted clients in developing third-party risk management programs.
• Performed validation of sub-controls with third parties as per the validation process.
• Provided periodic updates about the work status assigned to the project manager.
• Reviewed client's processes and controls against industry framework, identifying gaps, and communicating issues and recommendations.
• Stayed abreast of new technology, emerging risk areas, and related control techniques.
• Appraised the adequacy of corrective actions to remediate deficiencies identified during audits.
• Reviewed and updated the System Security Plan (SSP).
• Developed, maintained, and communicated a consolidated risk management activities and deliverables calendar.
• Contributed to initiating FISMA metrics such as Annual Testing, POA&M Management, and Program Management.
• Worked with System Owners to categorize systems using FIPS 199 and identified information types using NIST SP 800-60 Vol. 1&2.
• Reviewed Plan of Action and Milestones (POAM).
• Selected applicable Baseline Security Controls from NIST SP 800-53 Rev4 based on systems' categorization and documented them in the SSP.
• Worked with Assessors and ISO to close Plan of Action and Milestone (POA&M) entries.
• Ensured compliance with security standards and regulations such as HIPAA, PCI DSS, and GDPR.
• Created and maintained backup and disaster recovery plans to address system failures or data breaches.
• Provided security awareness training and education to employees to promote best security practices.
• Investigated and responded to security incidents, breaches, and exposures, determining the cause and extent of the problem and taking corrective action.
• Performed regular system log monitoring and analysis to detect potential security incidents.
• Participated in security audits and assessments conducted by external auditors and regulatory bodies, providing recommendations for security improvement.