Michael L. Hutchison
Allen, TX 75013
********@***.***
Security Clearance: Active Top Secret (SCI eligible)
EDUCATION
M.S. Management, Information Systems Security, Colorado Technical University, Colorado Springs, CO, Nov 2008
B.S. Technical Management / Digital Forensics, DeVry University, Colorado Springs, CO, Oct 2007
B.S. Information Systems Management, Colorado Technical University, Colorado Springs, CO, Sept 2005
Honors: Summa Cum Laude
CERTIFICATIONS
Certified Information Systems Security Professional (CISSP), (ISC)2 06/2008
Certified Ethical Hacker, EC-Council 04/2007
TECHNOLOGY SKILLS:
Applications: Microsoft Office Suite, Microsoft Visio, Retina and REM Scanning tools, DISA Gold Disk.
EXPERIENCE
Information Assurance Officer 05/2011 – Present
US Falcon, Colorado Springs, CO
Oversee the overall security, integrity and operations of the Space Innovation and Development Center (SIDC) systems and networks IAW Air Force Instruction (AFI) 33-203, AFI 33-115V2, AFI 33-119, AFI 33-210, AFI 33-230, AFI 33-501 and local policies and procedures.
Perform certification and accreditation, patching, monitor, managing and testing of systems.
Develop and review technical solutions to provide network, computer system, financial, installation, outside agency coordination, information assurance and customer assistance.
Review systems and network design for technical solutions and work plans that are consistent with architectural and information system security guidelines.
Support the Government in the development of certification and accreditation (C&A) packages, IAW Air Force Policy Directive (AFPD) 33-2, DoD Directive 8500.1, DoD Instruction 8500.2, DoD Instruction 8510.01, Director of Central Intelligence Directive (DCID) 6/3, Joint DoDIIS/Cryptologic SCI Information Systems Security Standards (JDSISSS) and supports SIDC customers/users with their specific network and stand-alone system accreditations.
Investigate, mitigate and report all security incidents or events in accordance with established procedures.
Maintain and update Trusted Facility Manuals, system descriptions, security policies, user guides, system architectures, and security-related documentation IAW DCID 6/3 and JDCSISSS.
Prepare and present training tailored for initial and periodic Information Awareness (IA) to include threat neutralization and prevention.
Support system administrators, network managers, users, and security personnel with intrusion detection and prevention plans.
Configured Comodo firewall, installed various anti-malware and anti-virus programs on Windows 7 platform
Ensure access controls meet complexity requirements, age requirements and reuse requirements.
Perform internal and external vulnerability assessments, implement and report on all security/configuration patches/changes.
Perform a weekly review of the audit trail for SIDC systems IAW Air Force Policy Directive (AFPD) 33-2, DoD Instruction 8500.2, AFI 33-202V1, DCID 6/3 and JDCSISSS.
Experienced in performing internal and external vulnerability assessments of systems to ensure they meet Air Force and DoD security standards through the use of approved security tools and techniques such as the DISA Gold Disk, Linux scripts and eEye Retina network analysis tools.
Conduct vulnerability testing, risk assessments and security audits as part of the overall accreditation process on all networks and systems as determined by the Government
Lead IAO for the SIDC Information Assurance Assessment Program.
Provide management with up-to-date information concerning Information Assurance Vulnerabilities.
Information Assurance Officer 07/2009 –05/2011
Wyle Information Systems, Colorado Springs, CO
Developed security architectures to meet established baseline requirements; identified deficiencies and recommended mitigations/countermeasures.
Investigated, mitigated and reported all security incidents or events in accordance with established procedures.
Subject Matter Expert (SME) for ensuring product(s)/system(s) meet the criteria for Certification and Accreditation
Performed security review of systems and network design, implementation, monitoring, managing, testing, and documentation for DoD programs in accordance with the DoD Information Assurance C&A Process Guidance (DIACAP).
Investigate, mitigate and report all security incidents or events in accordance with established procedures.
Experienced in performing internal and external vulnerability assessments of systems to ensure they meet Air Force and DoD security standards through the use of approved security tools and techniques such as the DISA Gold Disk, Linux scripts and eEye Retina network analysis tools.
Verified that access controls met complexity requirements, age requirements and reuse requirements.
Developed system security policy and plans, secure network architectures, requirements, intrusion detectors, operational concepts, and security accreditation plans and procedures.
Developed security policies and procedures.
Prepared and presented training tailored for initial and periodic Information Awareness (IA) to include threat neutralization and prevention.
Conducted vulnerability testing, risk assessments and security audits as part of the overall accreditation process on all networks and systems as determined by the Government
Configured Comodo firewall, installed various anti-malware and anti-virus programs on Windows 7 platform
Information Security Specialist 04/2009 – 07/2009
Boecore Professional Services, Colorado Springs, CO
Develop System Security Authorization Agreement (SSAA) for Certification and Accreditation of Air Force systems IAW the DoD Information Assurance Certification and Accreditation Process (DIACAP).
Developed test procedures in order to verify and validate systems' functional requirements.
Perform vulnerability assessments and mitigate any findings.
Configured Comodo firewall, installed various anti-malware and anti-virus programs on Windows 7 platform
Investigate, mitigate and report all security incidents or events in accordance with established procedures.
Computer System Security Analyst 05/2006 – 04/2009
Northrop Grumman Corporation, Colorado Springs, CO
Support the security monitoring, design, development, evaluation, and accreditation of large-scale, distributed Enterprise-level computer systems.
Ensure product(s)/system(s) meets the criteria for Certification and Accreditation including vulnerability testing, risk assessments and security audits.
Configured Comodo firewall, installed various anti-malware and anti-virus programs on Windows 7 platform
Perform vulnerability assessments of systems and network designs through the use of approved security tools and techniques such as the DISA Gold Disk, Linux scripts and eEye Retina network analysis tools.
Implement, monitoring, managing, testing, and documentation for DoD programs in accordance with the DoD Information Assurance C&A Process Guidance (DIACAP).
Investigate, mitigate and report all security incidents or events in accordance with established procedures.
Develop, publish, and maintain validation documentation and development artifacts for the MILSATCOM sustainment office specifically for the Consolidated Logistics Assistance and Advisory Support Services (CLASS) contract.