WORK HISTORY
I.T INFRACTURE, Houston, TX
Cybersecurity Analyst 01/2019 - Current
- Developed and maintained incident response protocols to mitigate damage and liability during security breaches.
- Performed threat identification and mitigation activities using industry-leading security controls and tools sets.
- Support advancement of Company's cyber threat and vulnerability management program to ensure consistent identification, analysis and response
- Monitored of cyber security threats, events, and vulnerabilities.
- Assess threats to business and deploy countermeasures for those threats.
- Performed vulnerabilities testing using Nessus (Tenable), Kali Linux, wire shack, , STIG solution
- Designed company-wide policies to bring operations in line with Center for Internet Security (CIS) standards.
- Reviewed violations of computer security procedures and developed mitigation plans.
- Monitored computer virus reports to determine when to update virus protection systems.
- Documented and mitigated vulnerabilities in the POA&M
- Applied technical knowledge to protect Company against cyber threats (e.g., knowledge of firewalls, intrusion detection, and prevention systems, data loss prevention solutions, endpoint protections, log aggregation technology, and other leading-edge security technologies).
- Participated in cross-team coordination to achieve defined security goals as well as meet technical requirements in support of detailed implementation plans for security projects.
- Participated in creation of device hardening techniques and protocols.
- Managed relationships with third-party intrusion detection system providers.
- Spearheaded Bring Own Device program, defining necessary security parameters and designing complementary security deployments
- Developed plans to safeguard computer files against modification, destruction or disclosure.
- Collaborated with third-party payment card industry (PCI) compliance partners.
- Authored Monthly security incident reports, highlighting breaches, vulnerabilities and remedial measures.
- Recommend improvements in security systems and procedures.
- Conducted security audits to identify vulnerabilities.
EMBUK DIGITAL INC, Houston Tx
Information Security Analyst 01/2015 - 12/2018
- In-depth understanding of professional knowledge in providing support and guidance to System Owner's through the NIST Risk Management Framework & Systems Assessment and Authorization processes.
- Participated in FIPS 199 process in which Security Categorization takes place, and selecting Technical, Operational and Managerial Controls using NIST SP 800-60 guidelines
- Ability to provide support and guidance through the phase of FISMA SA&A, including Monitoring of the SA&A artifacts compliance, annual self-assessment (NIST SP 800-53A) guidelines and quarterly self-assessment completion using NIST SP 800-26 guidelines.
- Reviewed and updated System Security Plan (SSP) using SP 800-18 guidelines.
- Reviewed and updated Risk Assessment (RA) using NIST SP 800-30 guidelines.
- Reviewed and updated Contingency Plan (CP) using NIST SP 800-34 guidelines.
- Ability to develop POA&M (Plan of Action & Milestone) document to take corrective actions resulting from ST&E (System Test & Evaluation).
- Performed comprehensive Security Assessment Controls and write reviews of management, Operational and technical security Controls for audited applications and information systems.
- Compiled data to complete Residual Risk Report and to insert contents into the POA&M
- In-depth knowledge of penetration testing and intrusion detection on systems
CSAT SOLUTION, Houston Tx
Desktop Support Analyst 11/2013 – 12/2014
- Investigated and corrected problems with printers, copiers and other peripheral devices
- Maintaining inventory of installed software, managing software licensing, and creating policies and procedures for upgrades
- Working with hardware and software vendors to verify timely product delivery and ensuring that new equipment is installed and ready to operate on schedule
- Analyzing and making recommendations for hardware and software standardization
- Creating user accounts and managing access control based on company policies
- Diagnosed and executed resolution for network and server issues.
- Performed network security design and integration duties.
- Improved overall user experience through support, training, troubleshooting, improvements and communication of system changes.
- Diagnosed network problems involving combination of hardware, software, power and communications issues.
- Supported users in setup and configuration of wireless bridge networks.
- Oversaw patch testing and deployment, script network software pushes and uninstalls.
- Provided faculty and staff with security software and network configuration support.
- Investigated and corrected problems with printers, copiers and other peripheral devices.
- Monitored network hardware operations to evaluate proper configuration.
- Utilized source code control for tracking configurations and changes.