Terrence J Bacchus
Alexandria, VA ***** (C) 860-***-**** ******@******.***
LinkedIn: http://linkedin.com/in/terrence-bacchus-084a57a
EDUCATION
Master of Science, Cyber Security
American Military University, Charles Town WV
Bachelor of Science Degree in Industrial Technology, Network Administration
Central Connecticut State University, New Britain CT
Splunk System Administrator Training
CompTIA Boot camp
PROFESSIONAL EXPERIENCE
WMATA Cyber Security Engineer / Analyst 2024 – present
Weekly reporting of assigned duties such:
oCyber tools tuning and objectives to aligns tools, that resulted in significant reduction of tickets
oDaily report for morning stand-up om all tools that included health checks
oWeekly report of projects status to senior level management
Realign tools via tuning to reduce ticket queue utilizing Splunk.
oIncident tickets
oTenable Scanning
oArmis Alerts
Daily Responsibilities:
oLog into Servers to ensure compliance and latest hardenings were successful
oManaged projects for WMATA such as Assisted in the implementation of migrating Splunk, Service Now and Tenable into a private cloud network. Other duties were included but not limited to:
oSplunk Cloud Migration
oUser Analytics Behavior – UBA
oService Now and Splunk Integration
oTripwire
oCrowdStrike
Attend weekly Security Services meeting
Stakeholder with PCI SS team to ensure compliance of the current assets
oHost quarterly meetings with Assets owners to ensure assets meets or exceed PCI Compliance
Unisys Cyber Security Analys / Network Engineer 2022 – 2023
Completed Unisys contract including performing the onboarding and off boarding of individuals and their RSA tokens, Windows Server Update Services, (WSUS), Patch approval, daily review of CISA reports and Security training. Responsibilities included:
Weekly approval of Engineering changes that were reviewed at bi-weekly Change Advisory Board meetings (CAB)
oWhich included but not limited to access to ports, firewalls and servers.
Worked to reduce ticket queue utilizing Service Now Portal which included.
oEnabling and disabling of RSA token
oIncident tickets
oTenable Scanning
Quarterly review of latest software versions via Center of Internet Security (CIS) portal
Produce software vulnerability reports via Tenable and determined acceptable risk.
Managed the RSA Token portal as well as built an excel spreadsheet to maintain true inventory of RSA tokens.
Access Active Directory to verify user’s information.
Attend weekly Security Services meeting
The Walt Disney Company (TWDC) Engineer, Network 2020 – 2021
Completed TWDC contract including Network Firewalls fundamentals that encompassed monitoring of various network traffic, allowing and or denial of traffic to and from the Enterprise via Palo Alto Panorama and Splunk. Other responsibilities included:
Firewall discoveries of existing rules to be migrated to the new servers and data centers conducted via Palo Alto and Splunk
Worked to consistently reduce ticket queue utilizing Jira Software that tracked, manages and journalized incidents and issues
Conducted audits in ServiceNow to remove dated changes, while following up with stakeholders and approvers
Built monitoring of international traffic logs that collected data from the Internet Provider using PRTG Network Monitor
Extensive use of Splunk Boolean’s capabilities to resolve source and destinations of traffic, firewall blocks and rules
Resolved F5 firewall issues concerning staging new pool members, nodes and loading balancing of Global/Local managed traffic
oUsed Infoblox to determine Internet Protocol (IP) classification
Cleaned and refreshed token distribution software (SafeNet) when additional enterprise tokens were required
Aetna Engineer, Security Control 2014 - 2019
Successfully converted over 50k employees over to Microsoft Bitlocker To Go encryption, Project lead for implementation of Bit Locker to Go throughout enterprise that yielded savings more than $500k, Support and manage End-point protection software – Checkpoint Media Encryption Port Protection removal and replacement to Bitlocker To Go for remote and overseas employees
Deployed Tanium to over 50k systems for the purpose of identifying, detecting and removing the old Checkpoint Media Encryption Port Protection Code Go via the registry key and hashes that would otherwise hinder the proper execution of Microsoft Bitlocker To Go
Incident response team member that managed Symantec VIP Enterprise Gateway and used Splunk to investigate incidents in real-time
Currently supported engineers for Anti-virus protection Symantec and McAfee which includes performing daily monitoring of updates and manage policies via McAfee ePolicy Orchestrator, and administer system and application upgrades as required
Secondary SME for Symantec Enterprise Gateway and Token VIP Administration being responsible for entire enterprise
Project lead for currency plan to upgrade Servers to 2016 platform which will mitigate security issues as well as allow for scheduled patching.
SME for Microsoft TEAMS and hosted training Security Engineering as well as developed pathways for department to use TEAMS.
Azure which included:
oManaging of Azure dashboard
oMonitoring of BYOD devices as well as support directly to employees via Mobile Device Management of (MDM)
Aetna Associate Engineer, Technical Training Program 2014 – 2016
Enrolled in the TTP (Technical Training Program) for two years; rotational placements included Aetna Networks, Engineers, Security Controls and Global Security. Following graduation, worked on Security team.
Conducted best practices through RSA Archer Governance, Risk, and Compliance
Reviewed and revised over 500 Global Security policies and related procedures
Updated Server Inventory for entire security team
Completed training on Checkpoint Media Encryption Port Protection
Performed daily routine security checks, hosted meeting for developers to acknowledge erroneous codes
Application Development – supported HR move to new Ultipro payroll solution
Aided in writing archival script from SonarQube to repository
Identified software that were sunset to gain clear path to Asset Inventory
Support Engineers with the F5 Load Balancer
Created VIP (Virtual IP) spreadsheet in Excel to perform comparison checks for the Data centers
Analyzed and changed errors on the F5 to ensure seamless failovers to various Data Centers, in both Development and Production areas, which include verifying Pool Members, Load Balancing Methods, i.e. Round Robin versus Global Availability
Piloted Documentation Program using Aetna Stream and Word procedure documentation to correct F5 Load Balancer errors
Working with Mobile Engineering to re-design changes from Cisco Netscaler to F5 Load Balancer of all Aetna’s Mobile Devices
Collaborate with On-call Engineers to troubleshoot issues and respond to escalated tickets in an afterhours environment
Working knowledge of SIEM
Identity and Access Management for internal clients
Microsoft Azure, including Azure dashboard management, BYOD device monitoring, and Mobile Device Management support
Working knowledge of Federal Information Security Management (FISMA) and National Institute of Standards and Technology (NIST) while supporting Aetna’s Global Security, including extensive research for Master’s degree in Cyber Security Thesis
United States Navy Aviation Support Equipment Technician (AS-7609)
Performed various duties as set forth by the Uniform Code of Military Justice, which included developing self-management skills, teamwork, following detail instructions, reporting all foreign and domestic issues to appropriate authority.
Repaired and operated various Aviation Support Equipment, such as Electrical Power Plants, hydraulic and pneumatic units, air-conditioning systems, forklifts varying from 2 to 15-ton systems
Flight deck troubleshooter for at sea deployment, hosted daily ‘FOD’ walk on both flight and hanger deck areas of the ship
Component Repair shop supervisor, implemented positive tool control as set for by mil-spec
Coordinated and support ship wide con-rep, vert-rep operations, provided support for the pilots to test avionics of aircraft
EDUCATION
Master of Science, Cyber Security
American Military University, Charles Town WV
Bachelor of Science Degree in Industrial Technology, Network Administration
Central Connecticut State University, New Britain CT
Splunk System Administrator Training
CompTIA Boot camp