Post Job Free
Sign in

SiEM admin, security analyst/engineer.

Location:
United States
Posted:
March 27, 2020

Contact this candidate

Resume:

Andrew Maguhn, CISSP

*** *** ******* ****, ********, FL 32579

******.******@*****.***

407-***-****

WORK EXPERIENCE

IBM, Sandy Springs, GA

SIEM Administrator, July 2019 - Present

●Handled alerts and issues arrising from monitored customers.

●Troubleshot high events per seconds, memory errors, errors with various log sources (Windows, Unix/Linux)

●QRadar SIEM appliances, QRadar on cloud, QRadar apps

Beast Code, LLC, Mary Ester, FL

Windows System Administrator, December 2018 - June 2019

●Recommended and purchased all server, SAN, and network hardware

●Installed, configured, and managed Palo Alto firewall 850

●Setup 2 node Hyper-V Windows 2016 Data Center cluster

●Setup 2 node VMWare ESXI cluster

●Purchases, racked, and configured 32TB Nexsan SAN

●Configured, managed, and patched 18 Hyper-V Windows 2016 Data Center Servers, Ubunutu, and Red Hat servers

●Administered O365, Active Directory, DNS, IIS, File and Print Server, Atlassian products (Jira, BitBucket, Confluence), and Jenkins in an Agile environment.

●Performed STIG scan and configured associated GPO settings per NIST standards

Eglin Federal Credit Union, Fort Walton Beach, FL IT Specialist, December 2017 - December 2018

Managed IBM QRadar SIEM creating rules, reports, and alerts

Respond to potential security incidents

Managed Symantec Endpoint Manager, StealthBits software and Windows SCCM

Participated in Information Technology Security Committee

Performedr vulnerability scanning using Nessus

Performed STIG hardening on Windows servers per NIST standards

Participated in NCUA audits

Managed and patched Windows 2012 / 2016 Data Center servers

Odyssey Systems Consulting Group, Eglin Air Force Base, FL

Computer Engineer 3, October 2014 - August 2017

Worked as a Functional System Administrator (FSA), installing, managing, maintaining, and patching Windows Server Data Center 2008/2012, centOS virtualized under Citrix XenServer and Microsoft Hyper-V

Managed Microsoft SQL, Backup Exec, DFS, WSUS, File and Print Servers

Managed Dell PowerEdge, EqualLogic, and NetApp SANs

Led Windows 2008 to 2012 Data Center migration from bare metal to virtual servers

Led Citrix XenCenter migration to Microsoft Hyper-V

Led project to consolidate 47TB of storage and server roles

Administered enclave networks in compliance with JSIG

Patched servers for compliance and security per IAVAs/STIGs

Produced artifacts for DoD accreditation of NIPR/SIPR systems

Worked as a Client Service Administrator (CSA), end user support for Windows 7/10

Managed user accounts, groups, and GPOs in Active Directory

Install configure approved software on servers and workstations

Managed, ordered, setup and configured department IT equipment; printers, desktops, laptops, routers, Blackberry and iPhones

LOCKHEED MARTIN, JSF F-35 ALIS Support Team, Eglin Air Force Base, FL

System Administrator Senior/Security Administrator Technical Lead, Sept 2013 – Oct 2014

Led team of security administrators across multiple sites

Improved compliance by coordinating audits with internal and external agencies

Increased log monitoring efficiency by developing security content for NetIQ

Increased workstation maintenance efficiency by installing timely updates (IAVAs, SPARS), reimaging PCs, and new PC setup

Decreased user downtime through account creation, unlocks, and password resets

Used NISPOM and JAFAN 6/3 requirements to increase applied knowledge

Cyber Intel Analyst SOC, Orlando, FL 2006 – 2013

Performed all duties using the Lockheed Martin Cyber Kill Chain methodology

Increased auditing quality and response time for Windows 2003/2008/2012 Data Center and UNIX/LINUX/Red Hat/AIX servers by developing content for HP ArcSight SIEM

Performed log monitoring of Windows, UNIX, and mainframe (RACF) servers using a variety of tools, LogParser, Visual Basic (VB) scripts, PowerShell, shell scripting, batch files, IBM Tivoli, Quest InTrust, and Microsoft System Center Operations Manager (SCOM)

Provided initial triage and analysis of malware

Provided incident handling and incident response

Worked on the Insider Threat team

Investigated policy violations, and employee misuse cases with host and network based forensics with EnCase, Spector, and Clearwell

SME for McAfee DLP roll out

Increased response time for end user calls and emails from days to minutes

Reduced and eliminated vulnerabilities on Windows Server 2003/2008 and UNIX/LINUX/Red Hat/AIX/IBM Mainframes with McAfee Foundstone vulnerability scanner

Improved log monitoring performance; Cisco routers, Checkpoint firewalls, SourceFire IDS, AirDefense, Juniper Net Screen, Tripwire IPS, and PGP appliances

Provided oversight for Sarbanes-Oxley (SOX) and HIPAA audits

EDUCATION

University of Central Florida, Management Information Systems, BS, Orlando, FL 2011

CERTIFICATIONS

(ISC)2 Certified Information Systems Security Professional, CISSP (329694)

CompTIA Network+ (COMP001005969605)

CompTIA Security+ (COMP001005969605)



Contact this candidate