PROFESSIONAL SUMMARY
Information Systems Security Officer – Experienced professional providing information security assurance and systems security support to clients and private sector organizations for classified and unclassified Information Systems (IS). Strong background in developing information security policies, procedures, and plans in a clear, concise manner for individual customer environments. Proficient in generating Certification and Accreditation/Assessment and Authorization (C&A/A&A) packages using Risk Management Framework (RMF) processes for Security Assessment and Authorization (SA&A) by Security Control Assessors (SCA’s) and approval from Authorizing Officials. Experienced in Authority to Operate (ATO) compliance activities such as Continuous Monitoring, Risk and Security Control Assessments, Control Identification and Security Controls Traceability Matrix (SCTM) generation.
Able to effectively collaborate and negotiate problem resolutions to provide quality service for a wide variety of customer
TECHNICAL SKILLS:
Knowledge of the entire RMF process and its compliance using NIST publications and standards,
Working knowledge of NIST […] 18, 115, 137, 128, 30, 34, 37, 63, 200, 53Ar4, 60 vol 1&2, NIST 37 RMF, FIPS 199, FIPS 200, and FISMA guidelines to comply with Federal and private agencies.
acquainted on vulnerability scanning tools and penetration testing
Experienced in the development of System Security Plans (SSP), Contingency Plans, Disaster Recovery Plans, Incident Response Plans/Training, Memorandum of understanding and Configuration Management
Skilled in Privacy Impact Assessments, POA&M, Authority to Operate (ATO) letters,
Possess in-depth ability performing information Security Risk Assessments and Analysis, Risk Mitigation in large-scale networked application environments.
Knowledge of MS Excel Spreadsheet and other FISMA tracking systems/tools to implement six steps NIST RMF aim at managing, monitoring and tracking ATO, POA&M, continuous assessment and ongoing authorization.
Excellent at FISMA Reports, Standard Operating Procedures (SOP) in accordance with Federal, Agency, and Organizational policy, to include FISMA, NIST, OMB, FIPS instructions
Knowledge of IT security architecture (Firewalls, Intrusion Detection Systems, Virtual Private Networking, and Virus Protection Technologies
EDUCATION AND IT CERTIFICATION
CompTIA Security + Ce Certification
Scrum Master Certification
CISM
Potomac State College of West Virginia University Keyser, West Virginia
WORKING EXPERIENCE
EVOKE CONSULTING LLC ISSO WASHINGTON DC, MAY 2017 – PRESENT
* Performed Security Categorization (FIPS 199), Privacy Threshold Analysis (PTA), E-Authentication with business owners and selected stakeholders.
* Documenting and reviewing security plans (SP), contingency plans (CP), contingency plan tests (CPT), privacy impact assessments (PIA), and risk assessment (RA) documents per NIST 800 guidelines for various government agencies.
* Supporting client and creating findings as part of POA&M remediation efforts
* Reviewing of security and privacy compliance aspects of Cloud Customer contracts and inquiries
* reviewing cloud security control documentation
* Reviewing and updating ATO package documents such as SSP, SAR, POA&M, IR and MOU
* Review audit logs and provide documentation guidelines to business process owners and management
* Conduct Risk Assessments regularly, ensured measures raised in assessments were implemented in accordance with risk profile, and root-causes of risks were fully addressed following NIST 800-30 and NIST 800-37.
* Provide input to management on appropriate FIPS 199 impact level designations and identify appropriate security controls based on characterization of the general support system or major applications
* Conducting Risk Assessment (RA) and completing Risk Management Framework (RMF) process to obtain ATO.
* Perform vulnerability scanning and penetration testing in accordance with NIST 800-115, using tools like Nessus, Web Inspect and Found stone.
* Perform specific quality control for packages validation of Risk Assessment, (RA), FIPS-199 Categorization, PTA, PIA, SORN, E-authentication
* Assist in developing NIST Compliant vulnerability assessments, technical documentation, and Plans of Action and Milestone (POA&M), and address system weaknesses
* Documenting and reviewing System Security Plan (SSP), Security Assessment Plan, Requirements Traceability Matrix (RTM), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M), Authorization letter/memorandum (ATO).
FEDERAL SYSTEM CONSULTING LLC- ISSO MARYLAND MAY 2015 TO DEC-2017
Provide input to management on appropriate FIPS 199 impact level designations and identify appropriate security controls based on characterization of the general support system or major applications.
* Assist in establishing an Ongoing Authorization (OA) program design to review the security posture of designated systems on a continual basis.
* Determine security controls effectiveness (i.e., controls implemented correctly, operating as intended, and meeting security requirements).
* Conduct risk assessments regularly; ensured measures raised in assessments were implemented in accordance with risk profile, and root-causes of risks were fully addressed following NIST 800-30 and NIST 800-37.
* Develop NIST Compliant vulnerability assessments, technical documentation, and Plans of Action and Milestone (POA&M), and address system weaknesses.
* Perform Information Systems Security Audits and Certification and Accreditation (C&A) Test Team efforts.
* Generate, review and update System Security Plans (SSP) against NIST 800-18 and NIST 800-53requirements.
* Determine security controls effectiveness (i.e., controls implemented correctly, operating as intended, and meeting security requirements).
* Conduct risk assessments regularly; ensured measures raised in assessments were implemented in accordance with risk profile, and root-causes of risks were fully addressed following NIST 800-30 and NIST 800-37.
* Assess existing security policies, processes, and templates against NIST guidance.
* Perform on-site security testing using vulnerability scanning tools such as Nessus.