Sadiq Odusoga
Information Systems Security Officer
Contact
Jessup, MD 20794
*****.*@*****.***
Objective
As an information systems security officer with 10 years of experience, my primary objective is to lead security teams in safeguarding sensitive data, implementing cybersecurity measures, conducting risk assessments, and developing effective security strategies in accordance with industry standards.
Education
University of Maryland
College Park, MD
BS in Information Systems
Management
Key Skills
Cybersecurity Strategy
Risk Management
Security Auditing
Incident Response
Compliance
Management
Team Leadership
Communication
Certifications
Certified Information
Security Manager (CISM)
CompTIA Security+
Certified Information
Systems Security
Professional (CISSP) in
Progress.
Experience
MAY 2021 – JUNE 2023
Information System Security Officer Unisys, Herndon, VA
Managed and led the security team to implement security controls and ensure operational governance.
Lead a team of security professionals in designing and implementing security policies and procedures.
Implemented risk management framework for compliance resulting in 100% compliance with regulatory standards.
Conducted regular security audits, vulnerability assessments, risk assessments and recommended mitigation strategies and implemented controls, reducing data loss incidents by 30%.
Managed relationships with 3rd party vendors, ensuring adherence to security policies and procedures.
Managed end-to-end delivery of security practices and processes, ensuring operational governance and regulatory compliance.
Developed and implemented security policies and procedures, resulting in 25% reduction in security incidents.
Developed and delivered security awareness training to employees, reducing security incidents by 20%.
Collaborated with IT teams to ensure timely patching and updates of systems and applications.
Played a key role in achieving ISO 27001 certification. FEBRUARY 2013-MAY 2021
Operations Manager Nature Island Global, Bowie, MD
Assisted in the management of construction projects, providing support in project planning, budgeting, and scheduling. Also, conducted research and analysis to optimize project processes and improve cost-effectiveness, assisted in vendor and subcontractor selection, contract negotiation, and procurement.
OCTOBER 2007- FEBRUARY 2013
Senior Consultant Booz Allen Hamilton, McLean, VA
Provided systems support in information assurance.
Developed systems and application security control questionnaire for civilian client: USDA Forest Service.
Assisted in the Certification and Accreditation (C&A) process for civilian client: USDA Forest Service.
Interacted with clients to develop information systems boundary scope and system security plans.
Conducted NIST 800-53 guide for assessing the security controls in federal information systems and building effective security assessment plans.
Implemented selected security products into existing customer networks and provided planning and implementation support during new network design and deployment.
Helped ensure compliance with statutory, regulatory, and industry best practices through periodic monitoring and enforcement activities.
Participated in Information Technology’s contingency planning effort while assisting in plan development, maintenance, and testing.
Developed and verified system security plans, security policies, and procedures.
Worked closely with accreditation and certification personnel to ensure adherence to customer security directives and provided guidance on security configurations to mitigate concerns. SEPTEMBER 2005-OCTOBER 2007
Security Analyst Apex Systems
Supported the certification and accreditation (C&A) for the Interim/Final Authority to Operate (IATO/ATO) for DOD Military Healthcare System.
Performed baseline scanning, manual checklists, and review mitigation strategy reports.
Performed and manages monthly Gold disk, Retina, SRR and AppDetective scans on all applicable systems.
Conducted C&A risk assessment scans using tools such as Retina, AppDetective, and the DISA Production Gold Disk
Performed Security Technical Implementation Guide (STIG) activities. Reports vulnerability findings and remediate findings as necessary.
Produced POA&M as applicable for findings and tracks mitigations to completion.
Assesses configuration changes for security impacts; assists in the development of alternate courses of action or implementation of resultant measures.
Performed functions as required in support of the DITSCAP, DIACAP, HIPAA and other TMA IA supporting documentation.
Knowledge and experience providing security accreditation support under the DITSCAP and DIACAP.
References
Available upon request.