Nathnael Yared
Dallas, TX – *************@*****.*** – C: 972-***-****
SUMMARY
Familiar with Authority to Operate (ATO) process for all systems, NIST special publications (SPs) regarding the Security Authorization process, including SP 800-53, SP 800-137, SP 800-171, & SP 800-37 Sound knowledge of business management and knowledge of information security risk management and Cyber Security technologies
SKILLS
• NIST / FISMA
• Vulnerability Management
• Security Incidents
• Monitoring & Analysis
• Assessment & Authorization
• POA&M Management
• Continuous Monitoring
• Cloud Security
• Audit Compliance
• FIPS 199/ 200 NIST 800 Series
CERTIFICATIONS
Sec + and CEH (in progress)
PROFESSIONAL BACKGROUND
ProSec Solutions, Washington, DC 03/2022 - Present Information System Security Analyst
• Coordinate with system owners, program managers, and other stakeholders to determine the overall control effectiveness through documentation review, inspections, testing and interviews and identify potential vulnerabilities or weaknesses.
• Conduct assessments of existing and new systems, including subsystems in the respective system boundary, and communicate the results and potential implications of identified control weaknesses.
• Review and analyze, packages to include system security plans, risk assessments, contingency plans, incident response plans, configuration management plans, hardware/software inventory, vulnerability scan reports and plan of actions & milestones for completeness, accuracy, and document effectiveness of controls, plans and procedures implementation.
• Perform security reviews, identify gaps in security, and develop a security risk management plan with recommendations for inclusion in the risk mitigation strategy.
• Plan and conduct security authorization reviews to confirm that the level of risk is within acceptable limits for each system.
• Execute vulnerability/compliance scans through Tenable interface and perform analysis of scan results.
• Collaborate with stakeholders and system owners to elucidate findings, offer mitigation recommendations, and advocate for addressing vulnerabilities.
• Work closely with other IT teams, vendors, and statewide partners to analyze and remediate incident response issues.
• Conducts research and analysis of incident response, threat and vulnerabilities related to significant cyber events.
TECHNICAL PROFILE
Tools: Archer, CSAM, Nessus, Fortify WebInspect, RiskVision, Splunk, SharePoint, LogicGate, OneTrust, Azure DevOps, Remedy, ServiceNow, Jira