Post Job Free
Sign in

Support Analyst Security

Location:
Stafford, VA, 22554
Posted:
February 19, 2023

Contact this candidate

Resume:

Akua Amponsem

Phone: 571-***-**** E-Mail **********@*****.***

TS/SCI Clearance

OBJECTIVE

I am seeking a challenging and rewarding growth position in the cyber security and technology field where I can continue to utilize my expertise to support the business and technology goals of the company.

Possess an in-depth ability in performing information security risk assessments and analysis, risk mitigation in large-scale networked application environments. Performed risk analysis, assessment testing. I am a fast learner, have the ability to multi-task. I can also work independently and as a contributing team member. I have a strong verbal and written communication skills. I have over 10 years of experience in information security

EDUCATION/ CERTIFICATIONS

Strayer University

Master of Science in Information Systems: Computer Security Management - March 2020

Bachelor of Science: Computer Networking - March 2008

Northern Virginia Community College - General Courses September 2003-July 2004

ISACA – CISM

CompTIA Security+

Certified Ethical Hacker (CEH)

CompTIA CASP

HDI Certification -Help Desk Customer Service Certification

PROFESSIONAL EXPERIENCE:

BeSpoke Technology April 2020 - Present

Security Control Assessor II

Fairfax, VA

Perform and lead Risk Management Framework (RMF) assessments, authorizations, and monitoring steps for systems following NIST standards and best practices.

Work in close coordination with all system stakeholders to create and maintain existing information system security documentation, including System Security Plan (SSP), Security Controls Matrix and/or Assessment, POA&M and Security Configuration Guide in order to control changes to the system.

Modify implementation and design documents describing how security features are implemented. Prepare system documentation for assessment in accordance with the Risk Management Framework (RMF) and NIST Special Publications (800-37, 800-53 and others); identify deficiencies and provide recommendations for solutions.

Performs host, network, cloud, application based security control assessments

Create security policies and maintain existing information system security documentation

Conduct comprehensive assessment of the management, operation, and technical controls to determine overall effectiveness of controls

Conduct periodic and continuous reviews of the system to ensure compliance with the authorization package through continuous monitoring.

ASM Research January 2016 – Jan2020

Cyber Security Engineer

Chantilly VA

Guided System Owners and ISSOs through the Certification and Accreditation (C&A) process

Test, assess, and document security control effectiveness. Collect evidence, interview personnel, and examine records (SSP, SOP) to evaluate effectiveness of controls.

Post all required security artifacts for Authorization and Accreditation (A&A) in the VA Governance Risk

Collect evidence to support security controls and revise VA implementation details inputs Interconnection Security Agreement (ISA)/Memorandum of Understanding

(MOU) for external connections, IAW NIST SP 800-47 and VA Handbook 6500.

Review and update remediation on plan of action and milestones (POA&Ms), work with system administrators to resolve POA&Ms.

Conduct security assessment interviews to determine the security posture of the System and to develop a Security Assessment Report (SAR) in the completion of the Security Test and Evaluation (ST&E) questionnaire using NIST SP 800-53A required to maintain Company Authorization to Operate (ATO), the Risk Assessment, System Security Plans, and System Categorization.

Assisted in the developing risk assessments, security plans and risk mitigation plan to identify security risks for systems and architectures using the 6550 and MDS2 documentations

Maintain and updated all ATO packages and system security documentation including, but not limited to the following: the SSPs, IRPs, ISCPs, Privacy Threshold Analysis (PTA), Privacy Impact Assessment (PIA), Business Impact Analysis (BIA), SOPs and E-Authentication.

Ensure vulnerabilities and risks are efficiently mitigated in accordance with the organization monitoring plan

Review POA&M and enforced timely remediation of audit issues, and update system security plans (SSP) using NIST SP 800-18 guidelines.

Determine Risks and Priorities and review current incidents and determine appropriate threat levels through NWET Tool

Mansa Holdings-Ghana September 2013-June 2014

System Security Analyst

Support, monitor, test and troubleshoot hardware and software problems.

Perform and coordinate effective installation and performance of advanced operating system hardware and software on servers.

Install new software releases as Microsoft office 365 and windows 10, system upgrades, evaluate and install patches and resolve software related problems.

Plan and perform appropriate procedures, documentation, inventory assessment, and other procedures related to IT with tools such as Microsoft excel sheets.

Analyze and advise on the risk and remediation of security issues based on Nessus Scan reports from vulnerability assessment scanners, patch management tools, and emerging threat information.

Participates in multiple large-scale concurrent projects that include enhancement, migrations, additions, and upgrades to existing devices and reconfiguring existing devices. Install communication devices such as PC’s, printers, wireless devices, switches, and routers at customer sites.

Identify and escalate business and technical challenges as appropriate.

University of Maryland University College October 2012- June 2013

Information Assurance Analyst

Collaborated with system stakeholders to develop and maintain security documentation required for Authority to Operate (ATO) approval.

Supported the tracking, reporting, and remediation of agency Plan of Action and Milestone (POA&Ms).

Performed incident response, as defined by FISMA, in support of all security incidents related to customer information or information systems.

Ensured information systems are assessed, integrated, accredited, operated, maintained and disposed of in accordance with applicable security policies and practices outlined in NIST SPs and customer directives.

Investigated system security incidents to determine the extent of compromise to information systems, assess implemented security controls to determine their effectiveness and efficiency as well as review the system dependency matrix needed for system interconnections.

Provide recommendations, guidance to program management and insight into the overall management and evaluation of the system security posture include migration of systems to the cloud.

Ensured that all deficiencies and vulnerability scans are addressed in a Plan of Action and Milestones (POA&M), track remediation actions and report status to senior management.

American Public University System Sept 11- June 2012

Information Assurance Analyst

Performs analysis on access control list ACLs and ensures configuration meets baseline standards

Performs vulnerability assessment and proposes solutions on mitigating security risks

Analyzes, troubleshoots, and maintains network infrastructure devices (routers, switches, etc.)

Determine Risks and Priorities and review current incidents and determine appropriate threat levels

Works in a team environment that is deadline driven

Ensured information systems are assessed, integrated, accredited, operated, maintained and disposed of in accordance with applicable security policies and practices outlined in NIST SPs and customer directives

Research verify and document information security controls using Federal Certification and Accreditation (C&A) processes to “accredit” the "systems".

Communicate and enforce security policies, procedures and safeguards for all systems and staff, based upon NIST Compliance

Analyze and advise on the risk and remediation of security issues based on Nessus Scan reports from vulnerability assessment scanners, patch management tools, and emerging threat information.

Kosvic Company LTD (Ghana) Dec 2010- August 2011

Network Support Analyst

Provide support in the installation of new computers, network printers and connecting to company network using switches and routers.

Assist sites in development of basic and more advanced diagnostic routines to be used to perform first and second level troubleshooting

Account for time by documenting every support request in Remedy and Magic for all related activities

Create logon scripts and standard computer images using ghost system including Desktop Image and Patch Management

Resolve, refers, tracks, dispatches or escalates incidents according to agree upon service level agreement

Fairfax County Public Schools March 2007 - August 2010

Information Technology Specialist

Provide support to over 236 schools and about 20,000 employees.

Diagnoses and troubleshooting problems associated with LAN/WAN networks, servers and printers and manage users accounts by creating and resetting passwords with Active Directory System

Provide support in the installation of new computers, network printers and connecting to company network using switches and routers.

Assist sites in development of basic and more advanced diagnostic routines to be used to perform first and second level troubleshooting

Account for time by documenting every support request in Remedy and Magic for all related activities

Create logon scripts and standard computer images using ghost system including Desktop Image and Patch Management

Resolve, refers, tracks, dispatches or escalates incidents according to agree upon service level agreement

Backup and Restore files using VERITAS Exec and Symantec

Management of group policy GPO

TECHICAL SKILLS:

FISMA and FEDRAMP compliance, Security controls and operations, System Security Planning (SSP) RMF, NIST Special Publications, MS Exchange 2000, 2003 & 2010 server, Splunk Ladder, CompTIA, Network +, Symantec Web Security, Nessus Enterprise Web Tool NEWT, Risk Vision, Wireshark, Nmap, GRC



Contact this candidate