JAMES H. KIM
MONROVIA, MD 21770
**********@*****.***
SUMMARY
-Over 6 years of experience in technical support, systems administration, network operations and security operations
-Strong research, collaboration, and communication skills
-CERTIFIED: Cisco CCNA, CompTIA Sec+, Splunk Core Certified Power User, Splunk Core Certified User, CompTIA Net+
SKILLS
TECHNICAL:
OS: Windows 7, 8, 10, Server 2016/2019, Linux, Cisco IOS
Applications / Software: Active Directory, SIEM, Splunk Enterprise, Splunk Phantom, Tanium, EMC SMARTS Service Assurance Manager, Wireshark, CAPRS, MS Office 365, Citrix Receiver, Quickbase, Atlassian Confluence, BMC Remedy, MS SCCM, MS Active Directory, ActivClient, MS BitLocker, PuTTY, PKI, Forescout CounterACT, Forcepoint Email Security, Cisco Anyconnect VPN, Cisco Webex, Cisco Jabber, Cisco IP Communicator, Cisco Finesse, Cofense Triage, IBM Maas360, SIEM, Oracle OIM, Oracle Opera Cloud PMS, FireEye AX/CX/EX/NX, VirusTotal, Cisco SourceFire/FirePower, IBM Resilient, McAfee ePolicy Orchestrator, Akamai WAF, Palo Alto Firewalls, Zeek (BRO), Suricata, ServiceNOW, Slack, AWS cloud, Sysmon, PowerShell
Protocols: TCP / IP, EIGRP, OSPF, BGP, DHCP, DNS, LDAP, RADIUS, TACACS+, Kerberos, OSI Model, TFTP, FTP, SSH, Telnet
OTHER:
OWASP Web App Security Risks, Common Weakness Enumeration (CWE), MITRE ATT&CK, NIST 800-30, US-Cert, excellent organizational, administration, multi-tasking, communication, interpersonal, collaboration, presentation, documentation, troubleshooting and writing skills. Bilingual – Korean, US Citizen
EXPERIENCE
April 29, 2020 – Present
Iron Vine Security, LLC
Windsor Mill, MD
Security Operations Center Analyst- Mid-Level
Conducts continuous monitoring in enterprise / AWS cloud networks for malicious activity / policy violations threats via SIEM (Splunk ES), IDS systems, Splunk Phantom, logs (Firewall, Bro, IDS, Active Directory, Windows, Sysmon, Suricata, McAfee ePo, Cisco, etc.) and other security operation tools
Analyzes PowerShell scripts and raw data sources to extract, institutionalize, and document actionable events
Investigates incidents (web applications attacks, malware, denial of service, phishing, etc) both from a network and host/application level and develops a timeline documenting attacks
Investigates and identifies the root cause behind security incidents using the Mitre ATT&CK framework and relevant tools
Conducts forensic investigations and analysis of artifacts (prefetch, autorun, memory, etc.) for malicious activity
Collaborates and communicates with US-Cert, Forensic Analysis, Cyber Threat Intelligence, Incident Management teams and other relevant groups
October 31, 2019 – April 24, 2020
Akimeka, LLC
Woodlawn, MD
Security Operations Center Analyst
Performed operational security analysis / investigations of proxy logs, network traffic (packet analysis), endpoints, malware, rogue activity, policy violations/misuse, phishing activity, making true/false positive determinations, and making escalation decisions / severity determinations
Utilized SIEM for monitoring and acting upon alerts, developed reports and other capabilities to support the needs of the SOC and agency.
Analyzed logs and event sources including proxy / web server traffic logs, firewall logs, PCAP/Flow data, DNS, audit and authentication logs, VPN, IDS, and other relevant tools and technologies
May 20, 2019 – October 30, 2019
Akimeka, LLC
Woodlawn, MD
Network Operations Center Analyst
Monitored network health of critical LAN / WAN infrastructure devices including routers, switches, servers, virtual devices, firewalls, load balancers, modems and cloud / web applications using network tools including Splunk and SNMP for performance and availability issues for over 1700 field offices worldwide
Accessed and configured router / switch configurations via Cisco IOS scripting using SuperPutty
Coordinated incident response with vendors and escalation teams while documenting all incident response support through Change Asset Problem Reporting System (CAPRS)
March 23, 2019 – May 19, 2019
NCR Government Systems, LLC
Germantown, MD
PS Technical Consultant
Diagnosed, troubleshooted and documented application, software, authentication, identity / access management, and data integrity / transmission issues to resolution for 240 Department of Defense Commissaries worldwide on a 24/7 basis
Coordinated technical support services with vendors and escalation teams
Trained other Technical Support Specialists in application support / troubleshooting procedures
Assisted in documenting new application features in Knowledge Base for training of Technical Support staff
August 28, 2017 – March 22, 2019
Optomi, LLC Atlanta, GA
PS Technical Consultant
Diagnosed, troubleshooted and documented application, software, authentication, identity / access management, and data integrity / transmission issues to resolution for 240 Department of Defense Commissaries worldwide on a 24/7 basis
Coordinated technical support services with vendors and escalation teams
Trained other Technical Support Specialists in application support / troubleshooting procedures
Assisted in documenting new application features in Knowledge Base for training of Technical Support staff
July 11, 2016 – August 25, 2017
SpectraTech, LLC
Washington, DC
IT Service Desk Analyst
Installed, configured and troubleshooted hardware (laptops, desktops, monitors, docking stations, printers, scanners, mobile phones), network connectivity, authentication and authorization issues including PIV cards, PKI, PII and VPN for over 5,000 on-site and remote end-users
Performed password resets and unlocked accounts for LAN accounts, multi-factor authentication, VPN, Citrix, and proprietary application accounts while administering user permissions, policies and groups in Active Directory
May 2016 – July 2016
Oracle Corporation
Columbia. MD
Customer Support Analyst
Provided technical support for Opera Cloud PMS including server services management via phone, email and remote support tools for post-sales operational and distribution issues including product hardware / software compatibility, connectivity, access controls, configuration, load balancing, licensing, invoicing / shipping and product availability
Served as point of contact for customers, dispatched open service requests and wrote case notes in tracking system to resolution in accordance with service level agreements
March 2007– February 2016
Kangnam University
Yong-in, Korea
Academic English Instructor
Taught English discussion, reading comprehension, writing, grammar, presentation and Business English skills to undergraduates and business professionals\
Administered online e-learning program with tasks including creating user accounts / permissions and scheduling of assignments
March 2006 - December 2006
Chung Dahm Learning
Seoul, Korea
Online E-Tutor
Evaluated and edited student TOEFL practice essays for grammar and writing errors using online educational software, leading to greater writing proficiency and higher test scores
May 2005 – February 2006
Poly Returnee Education Institute
Goyang, Korea
Academic Coordinator
Led a group of six academic English instructors and two administrators to provide exceptional educational leadership and service to learners
Developed curriculum, testing and evaluations utilized by 8 Poly REI campuses
May 2002 – February 2005
Kangnam University
Yong-in, Korea
Conversational English Instructor / Trainer
Taught English discussion, reading comprehension, writing, grammar, presentation, American History / Culture and Business English skills to undergraduates and business professionals
Trained hundreds of Korean public school teachers in the effective utilization of English in the classroom
October 2001 – January 2002
Sapphire Technologies
Herndon, VA
Product Support Representative (Contractual)
Effectively resolved users’ issues and requests with web-based mortgage loan applications, third-party applications and connectivity / transmissions while documenting in Remedy ticket system
March 2000 – April 2001
Qwest Communications, Inc.
Arlington, VA
Network Provisioner III
Delivered and documented network data services from reception of order to completion for business clients based on requested service specifications
Configured and routed Frame Relay/ATM engineering circuit orders for bandwidths DS0 through DS3
Ordered services and maintained strong relationships with external vendors and local exchange carriers
Trained other Provisioners in order management process, circuit design/routing, and software applications
September 1999 – March 2000
The Jaeger Group
Gaithersburg, MD
Junior Quality Assurance Analyst (Contractual)
Developed test plans for discovering bugs and anomalies in a web-based human resources application
Analyzed and documented bugs and anomalies while executing manual testing
Trained other Analysts and recommended feature enhancements that added value to applications
EDUCATION / TRAINING
July 2022 (expected)
University of Maryland Global Campus
Adelphi, MD
Master’s of Science – IT – Information Assurance
July 1999
University of Maryland
College Park, MD
Bachelor of Arts - American History
CERTIFICATIONS
July 2020
Splunk Core Certified Power User
San Francisco, CA
Splunk Core Certified Power User (SPLK-1002)
License #: Cert-298652
March 2020
Splunk Core Certified User
San Francisco, CA
Splunk Core Certified User (SPLK-1001)
License #: Cert-293657
September 2019
Cisco CCNA
San Jose, CA
CCNA – Cisco Certified Networking Associate (200-125)
Credential ID: 437365527118BPWK
October 2018
CompTIA Security+ CE
Downer’s Grove, IL
Security+ (SY0-501)
Credential ID: BM63MTLPF341QD92
August 2018
CompTIA Network+ CE
Downer’s Grove, IL
Network + (N10-006)
Credential ID: ZK5WD07PPGVQQM3C