Andrew Maguhn, CISSP
*** *** ******* ****, ********, FL 32579
******.******@*****.***
WORK EXPERIENCE
IBM, Sandy Springs, GA
SIEM Administrator, July 2019 - Present
●Handled alerts and issues arrising from monitored customers.
●Troubleshot high events per seconds, memory errors, errors with various log sources (Windows, Unix/Linux)
●QRadar SIEM appliances, QRadar on cloud, QRadar apps
Beast Code, LLC, Mary Ester, FL
Windows System Administrator, December 2018 - June 2019
●Recommended and purchased all server, SAN, and network hardware
●Installed, configured, and managed Palo Alto firewall 850
●Setup 2 node Hyper-V Windows 2016 Data Center cluster
●Setup 2 node VMWare ESXI cluster
●Purchases, racked, and configured 32TB Nexsan SAN
●Configured, managed, and patched 18 Hyper-V Windows 2016 Data Center Servers, Ubunutu, and Red Hat servers
●Administered O365, Active Directory, DNS, IIS, File and Print Server, Atlassian products (Jira, BitBucket, Confluence), and Jenkins in an Agile environment.
●Performed STIG scan and configured associated GPO settings per NIST standards
Eglin Federal Credit Union, Fort Walton Beach, FL IT Specialist, December 2017 - December 2018
Managed IBM QRadar SIEM creating rules, reports, and alerts
Respond to potential security incidents
Managed Symantec Endpoint Manager, StealthBits software and Windows SCCM
Participated in Information Technology Security Committee
Performedr vulnerability scanning using Nessus
Performed STIG hardening on Windows servers per NIST standards
Participated in NCUA audits
Managed and patched Windows 2012 / 2016 Data Center servers
Odyssey Systems Consulting Group, Eglin Air Force Base, FL
Computer Engineer 3, October 2014 - August 2017
Worked as a Functional System Administrator (FSA), installing, managing, maintaining, and patching Windows Server Data Center 2008/2012, centOS virtualized under Citrix XenServer and Microsoft Hyper-V
Managed Microsoft SQL, Backup Exec, DFS, WSUS, File and Print Servers
Managed Dell PowerEdge, EqualLogic, and NetApp SANs
Led Windows 2008 to 2012 Data Center migration from bare metal to virtual servers
Led Citrix XenCenter migration to Microsoft Hyper-V
Led project to consolidate 47TB of storage and server roles
Administered enclave networks in compliance with JSIG
Patched servers for compliance and security per IAVAs/STIGs
Produced artifacts for DoD accreditation of NIPR/SIPR systems
Worked as a Client Service Administrator (CSA), end user support for Windows 7/10
Managed user accounts, groups, and GPOs in Active Directory
Install configure approved software on servers and workstations
Managed, ordered, setup and configured department IT equipment; printers, desktops, laptops, routers, Blackberry and iPhones
LOCKHEED MARTIN, JSF F-35 ALIS Support Team, Eglin Air Force Base, FL
System Administrator Senior/Security Administrator Technical Lead, Sept 2013 – Oct 2014
Led team of security administrators across multiple sites
Improved compliance by coordinating audits with internal and external agencies
Increased log monitoring efficiency by developing security content for NetIQ
Increased workstation maintenance efficiency by installing timely updates (IAVAs, SPARS), reimaging PCs, and new PC setup
Decreased user downtime through account creation, unlocks, and password resets
Used NISPOM and JAFAN 6/3 requirements to increase applied knowledge
Cyber Intel Analyst SOC, Orlando, FL 2006 – 2013
Performed all duties using the Lockheed Martin Cyber Kill Chain methodology
Increased auditing quality and response time for Windows 2003/2008/2012 Data Center and UNIX/LINUX/Red Hat/AIX servers by developing content for HP ArcSight SIEM
Performed log monitoring of Windows, UNIX, and mainframe (RACF) servers using a variety of tools, LogParser, Visual Basic (VB) scripts, PowerShell, shell scripting, batch files, IBM Tivoli, Quest InTrust, and Microsoft System Center Operations Manager (SCOM)
Provided initial triage and analysis of malware
Provided incident handling and incident response
Worked on the Insider Threat team
Investigated policy violations, and employee misuse cases with host and network based forensics with EnCase, Spector, and Clearwell
SME for McAfee DLP roll out
Increased response time for end user calls and emails from days to minutes
Reduced and eliminated vulnerabilities on Windows Server 2003/2008 and UNIX/LINUX/Red Hat/AIX/IBM Mainframes with McAfee Foundstone vulnerability scanner
Improved log monitoring performance; Cisco routers, Checkpoint firewalls, SourceFire IDS, AirDefense, Juniper Net Screen, Tripwire IPS, and PGP appliances
Provided oversight for Sarbanes-Oxley (SOX) and HIPAA audits
EDUCATION
University of Central Florida, Management Information Systems, BS, Orlando, FL 2011
CERTIFICATIONS
(ISC)2 Certified Information Systems Security Professional, CISSP (329694)
CompTIA Network+ (COMP001005969605)
CompTIA Security+ (COMP001005969605)