GlORIA UDENGWU
************@*****.*** 832-***-****
Houston Texas United States.
PROFESSIONAL SUMMARY
Multi-talented IT professional with 5 years of experience developing and implementing security solutions in fast paced environments. Self-motivated and goal-oriented cyber security professional with rich experience in Governance, Risk, and Compliance (GRC) in both private sector and federal government environments. A result-driven professional with a track record developing, reviewing, and updating ATO package documents to get systems authorized. Excellent team player with a strong technical background, excellent oral and written communication skills, and a rich experience interacting with both technical and non-technical audiences. Professional in development of security plan, contingency plan, incident response plan and disaster recovery plan. In-depth knowledge of plan of action and milestones (POAM) management.
SKILLS
·Skilled in security and privacy control assessment with a proven history of developing exceptional risk management support.
·Solid experience working with NIST 800 series.
·Experience with Nessus Vulnerabilities scanning tools.
·Experience with Fed RAMP System.
·Rich experience in assessment and authorization process.
·Strong experience with the RMF.
·Risk Mitigation Strategies.
·Penetration Testing/Nessus/Splunk
·Implementing Security Programs.
·Vulnerability Assessment
·Case Management
·Policies and Procedures
·Customer Support
WORK HISTORY
Johns Hopkins Hospital
February 2020 - Present
Information System Security Officer
·Implement, document, and update RMF process for various information systems in accordance with NIST special publications
·Identify accreditation boundaries and categorize information systems based on impact evaluations of confidentiality, availability, and integrity
·Effectively develop and establish baseline security controls and overlays based on categorization of data types with each computer system
·Analyze and define security requirement for computer systems which include servers, cloud platforms, networks, databases, and applications.
·Protect and maintain availability, integrity, confidentiality and accountability of information system resources and information processes throughout system ‘s life cycle.
·Independently put together variety of security authorization deliverables including system Security Plans, Security Assessments Report, Risks Assessment plans POA&Ms.
·Create system security plans and keep current with updates of any changes made to information systems.
·Demonstrate efficiency in RMF package development, including but not limited to, FIPS 199, POA&Ms, control implementations, risks assessments, architecture diagrams, hardware/software inventories, and system/site policies, procedures, and processes
·Create and update Authorization to operate (ATO) packages draft, finalize, and submit privacy Threshold assessments (PTAs), privacy impacts analysis (PIAs),E-authentication assessment, system of record Notice (SORNs) for annual review and recertification, monitoring compliance, conducting periodic scans, and scans, and conduct audit logs reduce.
·Continuously monitor security controls effectiveness using NIST SP 800-137 as a guide.
NM-2 Consulting LLC
May 2017 - February 2020
Security Control Assessor
·Scheduled kickoff meetings with system owners to help identify assessment code, system boundary, information system category and attains any artifacts needed in conducting assessment.
·Developed security assessment plans (SAPs) and conducted assessments of security control systems to ensure compliance with NIST SP 800-53A, Rev 4
·Created Requirement Traceability Matrix (RTM) to document initial assessment findings.
·Conducted security control interview meetings and artifacts gathering meetings with various stakeholders using assessment methods of interview, examination, and testing.
·Developed Test Procedures and Plans for Assessing Security controls and security Assessment Reports (SARs) using NIST SP 800-53A Rev 4
·Conducted risk assessments that include reviewing organizational policies and providing recommendations on adequacy, accuracy, and compliance with regulatory standards.
·Documented assessment findings in Security Assessment Reports (SARs) and recommended remediation actions for controls that failed and vulnerabilities. Reduce A&A package items using NIST guidance for FISMA compliance such as system FIPS 199 categorization E-authentication assessment, PTA, PIA, contingency plan (CP) and contingency plan test (CPT).
·Performed vulnerability assessment of information system to detect deficiency and validate compliance using the POA&M tracking tool (CSAM)
·Planned and worked with POA&M teams remediate vulnerabilities in information system and close POA&Ms.
·Participated in the development of information security continuous monitoring strategy to help agency in maintaining ongoing awareness of information security, ensure continuous excessiveness of all controls, vulnerabilities, and threats to support organizational risk management decisions.
·Established effective communication, good working relation with all stakeholders to identify goals and expectations.
EDUCATION
University Of Central Oklahoma
Bachelor Of Science.
Certification:
Security +