Afia Owusu Akyaw
** ******** **, *********, **, *1758 Phone: 301-***-**** Email: ********@*****.***
US Citizen
PROFESSIONAL SUMMARY
Highly motivated female Cyber Security Professional with over 5 years hands-on experience and exposure in performing Information Systems Risk Assessments, System Security Monitoring, Auditing and Evaluation, and Security Assessment & Authorization (SA&A). Detailed knowledge of FISMA Security Standards and Guidelines for Compliance, Risk Management Framework (RMF) as defined in NIST SP 800 Series. Also experienced with common security tools, and knowledge of protocols, such as TCP/IP, UDP, ICMP, unauthorized access, malwares, and a wide range of vulnerabilities and threats.
SKILLS
Experience with guidelines and regulations including NIST SP 800 Series, FIPS, and FISMA, FedRAMP, HIPPA and PCI-DSS
Experience with Security Assessment and Authorization (SA&A) processes.
Sound knowledge of Vulnerability Assessment tools including Nessus, Wireshark, Splunk, OSI Model
Working knowledge of Windows OS, MS Office Suite, and McAfee Virus Scan Enterprise.
Sound knowledge of network security including threat and vulnerability analysis, malware, and intrusion detection and prevention.
Knowledge and understanding of networking including but not limited to TCP/IP, OSI model, LAN/WAN, cabling and data transmission types, network topologies, routing protocols, and remote access methods.
Possess excellent oral and written communication skills, as well as excellent time management and analytical skills.
PROFESSIONAL EXPERIENCE
Cyber Security Risk and Compliance Analyst Jan 2017– Present
Xoreta Technology Solutions, Middletown, MD
Implement and monitor a comprehensive information security and technology risk management program to ensure the integrity, confidentiality and availability of information.
Ensure proper access controls are implemented for both system access and physical access to data processing facilities per NIST SP 800-37 and NIST SP 800-53.
Ensure Configuration Management is appropriate for all Information Systems (IS) software and hardware, including documentation and tracking of change control actions.
Prepare and review Authorization to Operate (ATO) packages (System Security Plan (SSP), Plan Of Action And Milestone (POA&M), Security Assessment Report (SAR), Information Security Contingency Plan ISCP, Disaster Recovery Plan (DRP), Incidence Response Plan (IRP).
Create System Security Plans (SSP), Plan Of Action and Milestone (POA&M), Privacy Threshold Analysis (PTA), Privacy Impact Assessment (PIA), E-Authentication, FIPS-199, Business Impact Analysis (BIA) for assigned information systems.
Facilitate the definition of project scope, project management/SDLC approach, milestones, tasks, deliverables, and resource requirements of A&A activities.
Validate system requirements, security policies and procedures, contingency plans, incident response plans, personnel security, access control mechanisms and identification and authentication mechanisms.
Ensure all information system and applications are certified and accredited and that RMF packages were processed, reported, and coordinated in a timely fashion with the organization.
Information Security Specialist Jun 2013 – Dec 2017
Carey International, Frederick, MD
Performed network traffic analysis using raw packet data, network flow, Intrusion Detection Systems (IDS), and custom sensor output from communication networks.
Assisted the Cyber Security Manager with the development of the IA related Procedures, and Work Instructions
Researched and updated emerging threat databases and communicate same revisions with the IT security team.
Monitored, reviewed and integrated IoC’s into SIEM’s, IDS’s, sniffers and malware analysis tools.
Assisted with the development of processes and procedures to improve incident response times, analysis of incidents, and overall SOC functions.
Collaborated with the IT Risk Department to have suspected malicious local IPs blocked on the company’s firewall.
Detected, scrutinized and resolved network and host-based security events.
Analyzed a variety of network and host-based security appliance logs (Firewalls, NIDS, HIDS, System Logs, etc.) to determine the correct remediation actions and escalation paths for each incident.
EDUCATION
Bachelor of Science May 2004
University Of Ghana, Accra, Ghana
Associates Degree- Respiratory Therapy May 2013
Frederick Community College, Frederick MD
PROFESSIONAL CERTIFICATION
CompTIA Security+
Certified Authorization Professional (CAP)- Exams Passed, Certification in Progress