Post Job Free
Sign in

Security Administrator Threat

Location:
Pompton Lakes, NJ
Salary:
145-160k
Posted:
July 09, 2021

Contact this candidate

Resume:

Data Protection

As an Information Systems Security Administrator/Engineer /Lead I have 12 years experience in Incidence Resonponse, vulnerability and risk management quantitative, Compliance and Reporting, Access management, Identity Management, System architecture design, Data Loss Prevention, Cyber Alert monitoring. Proficiency in and

understanding of data privacy regulations (PCI, HPAA,PII etc.) and compliance

industry/federal standards and guidelines such as (NIST sp 800-30 (NIST 270**-***-**, CIS, ISO27002.

I have an extensive knowledge of data protection and privacy enabling technologies and IT security tools Proofpoint,Symantic DLP, OneTrust, Microsoft Compliance or Information Protection. I have expertise to conceptualize and develop Data Protection solutions to address customer's data and security needs.

As an IT security operations lead I trained security analysts in investigating incidents and the policy to respond,

I also created policies and procedures. Managed the data loss prevention department lowering false positives, determining severities training DLP analysts working closely with the director reporting and keeping documentation.

Acted as a subject matter expert for the team and attending weekly meetings and hosted weekly training meetings.

Lead and managed various projects involving migrations upgrades etc.

Areas of Experience

Valued Skills in Network Environments Employing various Arenas

Discipline

Description

Data Protection and Monitoring Tools

McAfee, Symantec, Crowdstrike, Digital Guardian, Pece,Peca, Olympic, Instinct, arcsight. Splunk

Network Protocols & Tools

Servers, Routers, Switches, Load balancers TCP/IP, HTTP/HTTPS,SMTP, SSH, DNS

Servers

Exchange Servers, Application Servers, Development Server

Cloud platforms

AWS, Microsoft Azure

Ticketing Systems

Remedy, Service Now, Landesk

Data analysis tools

Splunk, Peca, Pece,AppHQ,BICs, Instinct,Permit to Send,vendor list

Networking Environments

VPN, LAN, AWS, WLAN, Cloud

Operating Systems

Windows Server 2003-2008,2016, Linux, Windows 7,8,10,Win9X thru 10, Win2K/Win2K3 Pro/Win2008/2012 Server, Microsoft Office 97,2000,20008, thru 2010, VMware vSphere Clientk

Penn Testing and Code Review Tools

Kali,Linux, Nessus, HPE Fortify

Risk Assessments

Brain Storm

Vulnerability management

Qualys, Burp suite,

Scripting Languages

Python, Powershell

Professional Experience

Western World an (AIG company) October 2018- Present

Data Loss Prevention Engineer III

Performed continuous monitoring data in motion resolving various incidents

Analyzed vulnerability scan results, system audits, log events and troubleshoot software issues

Configured Tenable to operate and discover security, application and operating system related items

Processed and enhanced the security operations of applications and software

Utilized data protection methodologies to resolve unstructured data incidents

Established data standards and processes/workflows, providing recommendations for privacy and data governance programs, processes and controls and supporting data breach response planning and playbook development

Supported implementation of data privacy compliance processes, risk management and control implementation efforts, including data inventory and mapping tasks

Reported any updates of projects exceptions to policies, new authored policies procedures, and added processes to the CISO in a timely manner

Utilized Qualys to run vulnerablility scans on endpoints and worked with owners to remediate the vulnerability and ran a demand scan to validate the fix.

Developed targeted playbooks for L1 response

I initiated the threat management processes, to ensure that every aspects of an event is documented,remediated, and and reported to the Director in a timely manner

Implemented, established, developed and maintained an efficient vulnerability,access management, data loss prevention and incident response process

Initiated the use of information and Digital Rights Management (DRM)

Created various groups and applied policies

Performed deep data analysis using various tools

Reviewed asset management documentation for all, hardware, and software changes that may impact the firms standard information security posture; security technology policies, procedures, processes, and technologies

Provided quality assurance,appraisal and approval of security deliverables, to include revising and drafting test plans, security specification reviews and standards, and technical documentation

Worked with relevant stakeholders within the various Technology groups and business units to guarantee security awareness and issues were communicated effectively with documentation and verbal communication

Conducted the reviews of applications from a security and privacy perspective; review and contribute to the client's IT Standards used in the solution security review process and provide security recommendations and better practices regarding secure software development.

Initiated the use of Exact Data Match (EDM)

Provided recommendations to protect the business against industry known threa

Interacted with IT and vendor auditors, both internal and external, including coordination of interviews and walkthroughs and outlining key risks and controls. Understands risk impact and likelihood to business goals and objectives.

I could guarantee the accuracy and timely completion of audit tasks within established guidelines

Performed general control oversight and reviews to verify compliance with McAfee, Qualys and PCI.

Developed a working relationship and Coordinated with IT departments and financial, operations

I was instrumental in remediating issues found from the compliance reports.

Followed compliance procedures and Best Practices for internal operational risk Assessments and controls in accordance with the national standards, requirements, and policies.

Made recommendations after the review of systems to assess the adequacy of management controls, efficiency, and compliance with policies, regulations.

Constantly monitored performance of assets and performed risk assessments

Ran Queries and Reports Daily and emailed to management in regards to the progress of the remediation of issues found as a result of the compliance scan

Food and Drug Administration May 2017-October 2018

Data Protection Engineer

Provided recommendations information to protect the business against industry known threats by utilizing Tenable

Ensured all Cyber security threat response strategies are integrated with governance and compliance processes.

Performed execution of security root cause analysis and forensics as part of the enterprise’s Cyber Incident Response Plan.

Initiated monitoring/reporting and developing processes and procedures.

Analyzed incidents to solve issues and improved incident handling procedures

Configured Qualys to report and alert through external systems

Initiated the use of information and Digital Rights Management (DRM)

Analyzed vulnerability scan results, system audits, log events and troubleshoot software issues

Configured Qualys to operate and discover security, application and operating system related items

Supported multiple Information security projects as assigned

Performed Data Protection solution rollout or operations support

Performed automated and manual run-time assessments

Established governance and operating model for large scale organizations

Designed and implemented Cyber Threat hunting for organizations, including threats and enacting identification, containment, and eradication measures while supporting recovery efforts

Developed, reviewing, updating data protection policies for a large scale enterprise

Technical knowledge of Active Directory including user account and security groups creation and maintenance process

Implemented a Data Protection solution (e.g., DAG, DLP, Data Classification) and integrating it with other technology solutions such as Identity and Access Management and Security Information and Event Monitoring for in-depth security

Developed application security standards and policy documentation

Gathered Data Protection solution specific requirements and assist with framework development, policy development and design governance and operating model

Performed log Correlation Security monitoring by using tools such as Splunk

Acted as subject matter expert to provide insight, guidance and engaging in the discussion to adopt various methodologies, processes and policies.

Developed requirements, designed, built an operational documentation for Data Protection solution roll out and support

Identified, reduced, and reported on unstructured data risk

Conducted periodic integrity checks for Process Control equipment power supplies, control processors and analyze their performance to continuously drive improvements

Participated in site investigations, self-assessments, risk assessments, and audits providing information evidence of the local compliance to cyber security requirements.

Performed detailed source code of old and new application

Utilized Qualys to run vulnerablility scans on endpoints and worked with owners to remediate the vulnerability and ran a demand scan to validate the fix.

Researched, initiated the evaluation of tools, technologies, processes to enhance the security of application software produced

Received Tier 2/3 incident escalation from detection operations and assist with realtime, continuous (24x7) security event monitoring, response, and reporting

I was the automation subject matter expert in the development and implementation

Deployed new products, product upgrades, patches

Analyzed incidents to solve issues and improve incident handling

Performed risk assessments and/or threat modeling to articulate the levels and types of security controls appropriate application/product initiatives

Performed Search and Reporting with Splunk and License management

Conducted the reviews of applications from a security and privacy perspective; review and contribute to the client's IT Standards used in the solution security review process and provide security recommendations and better practices regarding secure software development.

Provided recommendations to protect the business against industry known threa

Interacted with IT and vendor auditors, both internal and external, including coordination of interviews and walkthroughs and outlining key risks and controls. Understands risk impact and likelihood to business goals and objectives.

I could guarantee the accuracy and timely completion of audit tasks within established guidelines

Performed general control oversight and reviews to verify compliance with McAfee, Qualys and PCI.

Developed a working relationship and Coordinated with IT departments and financial, operations

I was instrumental in remediating issues found from the compliance reports.

Followed compliance procedures and Best Practices for internal operational risk Assessments and controls in accordance with the national standards, requirements, and policies.

Made recommendations after the review of systems to assess the adequacy of management controls, efficiency, and compliance with policies, regulations.

Constantly monitored performance of assets and performed risk assessments

Ran Queries and Reports Daily and emailed to management in regards to the progress of the remediation of issues found as a result of the compliance scan

Bed Bath and Beyond, Union, NJ June 2016- May 2017

Data Loss Prevention ANalyst/Engineer

Analyzed data in motion incidents to resolve issues

Utilized data protection methodologies to resolve incidents involving unstructured data

Performed scanner configuration, asset inventory, triage of output and remediation guidance, workflows, continuous monitoring

Worked hand in hand with development teams to remediate application vulnerabilities detected through security scanning tools

Configured Qualys to report and alert through external systems

Analyzed vulnerability scan results, system audits, log events and troubleshoot software issues

Configured Qualys to operate and discover security, application and operating system related items

Provided remediation guidance to partners, and recommended appropriate measures to manage and mitigate risk.

Provided leadership regarding best practices for vulnerability scanning, configuration baselines, security designed reviews.

Guided a team in the completion of security assessments, vulnerability scans, penetrated testing, and continuous monitoring activities

Managed the security activities associated with Secure Software Development to address existing and evolving risks and threats appropriately

Leveraged enterprise standards for data domains and data solutions, focusing on simplified integration and streamlined operational and analytical uses

Guided high level data architecture design (functional, non-functional) and ensures teams adhere to data architecture standards

Developed information processes for data acquisition, data transformation, data migration, data verification, data modeling, and data mining

I was Accountable for cost viability and technical estimation of data platform usage

Designed data solutions for data distributions and partitions, scalability, disaster recovery and high availability

Designed security for data policies and standards

Monitored and optimizes data solutions

Actively governed and automated standard data architecture patterns and blueprints

Partnered with architecture, security, infrastructure, and application teams to design and implement the automation of data, data platforms, and tools

Created and updates automation to eliminate routine management processes

Articulated the need for scalability and understand the importance of improving quality through testing

Provided and/or organize appropriate application security training and awareness for technical and non-technical staff

Orchestrated the requirements determination, threat modeling, and security vulnerability assessments on new and existing systems, products, product updates, patches, operating systems and databases

Performed automated and manual run-time assessments

Created vulnerability reports on spreadsheets, detailing the security requirements, risks, business impacts, and remediation guidance to the customer and to my CISO

Performed code review and threat modeling

Established attack baselines and using threat research results to operationalize findings into security analytics and detections for our clients advanced Security Analytics and Threat Detection platform.

Contributed to the Security efforts of our clients cutting-edge Threat Research & Labs team

Developed ways to detect threat activity using security analytics, machine learning, behavioral analysis.

Analyzed latest threats in the lab.

Reproduced real-world attacks.

Analyzed security log data to identify adversary activity

Discovered vulnerabilities in System Architectures, Builds, infrastructure configurations, and 3rd-party product deployments

Cyber Security System Plus, Inc. @ AIG April 2012- June 2016

Information Systems Security Engineer

Configured, deployed, monitored, operated, secured, and maintained two (2) central ePolicy Orchestrator (ePO) servers, and numerous Enterprise Super-Agent Distributed Repositories

Initiated a Custom workflow and developed Feature additions and improvements to the Aspera Orchestrator,

Prepared, developed and maintained organizations best practices; Responsible for installing, patching and maintaining Servers

Utilized the use of VMware Configured VLANs and Administrated VDI accounts

Responded to threats and incidents and acted independently of the team as well as working with the team to analyze and react to events

Performed security patching and updates on servers; Initiated Backups for endpoints nightly

Collaborated with Service Vendors by conducting meetings for planning security solutions

Performed automated and manual run-time assessments

Conducted the reviews of applications from a security and privacy perspective;

Reviewed and contributed to IT Standards used in the solution security review process and provide security recommendations

Provided recommendations to protect the business against industry known threa

Interacted with IT and vendor auditors, both internal and external, including coordination of interviews and walkthroughs and outlining key risks and controls. Understands risk impact and likelihood to business goals and objectives.

Guaranteed the accuracy and timely completion of audit tasks within established guidelines set in place

Performed general control oversight and reviews to verify compliance with McAfee, Qualys and PCI.

Developed a working relationship and Coordinated with IT departments and financial, operations

I was instrumental in remediating issues found from the compliance reports.

Followed compliance procedures and Best Practices for internal operational risk Assessments and controls in accordance with the national standards, requirements, and policies.

Made recommendations after the review of systems to assess the adequacy of management controls, efficiency, and compliance with policies, regulations.

Constantly monitored performance of assets and performed risk assessments

Ran Queries and Reports Daily and emailed to management in regards to the progress of the remediation of issues found as a result of the compliance scan

Performed network traffic monitoring and log analysis

Managed Splunk apps performed configuration files, index management Users roles, and authentication.

Performed System modifications to meet official requirements

I was a liaison with the stakeholders within the IT groups and business units to ensure security awareness and issues are communicated effectively

Performed Secure Development Lifecycle process assessments

Provided technical direction, leadership, and training to staff and remote users and engineers

Worked closely with developers to remediate applications and vulnerabilities detected through security scanning tools

Initiated the use of risk assessments and/or threat modeling to articulate the levels and types of security controls appropriate application/product initiatives

Managed the security activities associated with Secure Software Development

Performed Threat Intelligence Exchange server installation and implementation

Identified threats, vulnerabilities and exploitations using Security Tools to remediate them

Utilized Threat Intelligence Exchange to protect against network Threats

Defined project scope and objectives, involving relevant stakeholders and ensuring technical feasibility

Cisco Systems, Richardson, TX June 2010- April 2012

Information Systems Administrator

HBSS Administrator in a Multi-Security Enclave supporting a 1100+ customer base Enterprise

Investigate IT security incidents and issues to identify root cause, assess impact and to make specific recommendations for containment, mitigation and future improvements to security posture

Configure, deploy, monitor, operate, secure, and maintains three servers, and eight (8) Enterprise Agent Distributed Repositories

Receives daily Anti-Virus (VSE) and periodic Host Based Intrusion Prevention System (HIPS) (Block High, Medium, and Low) signature updates from Support.

Conducted Benchmarks and File Integrity Monitor checks through Policy Auditor

Implemented, managed and deployed the Security Software on Citrix Servers master image.

Perform SQL Server administration and management;

Perform System modifications to meet official requirements

Provide Tier 3 support to remote sites as well as, troubleshooting, planning, and upgrade implementation

Assist other departments, directorates, and agencies with –related Security questions and issues

Conducted the reviews of applications from a security and privacy perspective; review and contribute to the client's IT Standards used in the solution security review process and provide security recommendations and better practices regarding secure software development.

Provided recommendations to protect the business against industry known threa

Interacted with IT and vendor auditors, both internal and external, including coordination of interviews and walkthroughs and outlining key risks and controls. Understands risk impact and likelihood to business goals and objectives.

I could guarantee the accuracy and timely completion of audit tasks within established guidelines

Performed general control oversight and reviews to verify compliance with McAfee, Qualys and PCI.

Developed a working relationship and Coordinated with IT departments and financial, operations

I was instrumental in remediating issues found from the compliance reports.

Followed compliance procedures and Best Practices for internal operational risk Assessments and controls in accordance with the national standards, requirements, and policies.

Made recommendations after the review of systems to assess the adequacy of management controls, efficiency, and compliance with policies, regulations.

Constantly monitored performance of assets and performed risk assessments

Ran Queries and Reports Daily and emailed to management in regards to the progress of the remediation of issues found as a result of the compliance scan

FEMA May 2005-June 2010

System Administrator

FEMA Site-Admin for a 3000+ Multi-Security Enclave customer base Domain\Experience in managing, updating, and deploying antivirus updates and software

Initiated Intrusion Detection System/Intrusion Prevention System device administration for malware detection

Deployed Endpoint Encryption to manage machines; Responded to malware threat events

Constant Monitoring of server/storage related processes and performance insured server uptime

Analyzed and resolved faults, such as major system crashes; Initiated distributed patches using Servers

Schedule reports, extract data, review for errors/incidents and troubleshoot to resolve

Used an Intrusion Detection System to help track and provide advice on critical emerging threats

Performed Patch auditing with Policy Auditor

Initiated Systems Support which included vulnerability scanning and monitoring by using

Performed Malware Analysis in response to alerts

Installing, supporting and maintaining new server hardware and software infrastructure

Analyzing and resolving of faults, ranging from a major system crash to a forgotten password

Undertaking routine preventative measures and implementing, maintaining and monitoring of systems

Monitoring of server/storage related processes and performance to insure server updates

Education and Certifications

ITT Technical Institute: BA– Cyber Security

NJIT: Cyber Security (BootCamp)

Certification: Security + CISSP



Contact this candidate