Information Security Architect @ Currently serving as the Information System Security Officer (ISSO) for a government agency as the ISSO on several classified systems, including cross domain solutions and an unclassified public facing program. My specific duties include:
• Provides strategic focus, leadership, and presides over client engagements to elicit, document, analyze and validate IT security compliance by applying the latest Security Frameworks such as: Federal Risk and Authorization Management Program (FedRAMP), Federal Information Security Management Act (FISMA), NIST 800-53, Department of Defense Enterprise Cloud Service Broker (ECSB) and Risk Management Framework (RMF).
• Extensive experience in conducting Privacy Impact Assessments (PIAs), writing/performing security categorizations, Risk Assessments (RAs), System Security Plans (SSPs), Security Control Assessments (SCAs)/Security Test and Evaluations (ST&Es), Security Assessment Reports (SARs), Incident Response Plans (IRPs), Configuration Management Plans (CMPs), Information System Contingency Plans (ISCPs), and Plans of Action and Milestones (POA&Ms).
• Perform vulnerability assessments utilizing Nesuss, AppDetective, and Hail Storm.
• Advise the system owner regarding security considerations in applications systems procurement or development, implementation, operation and maintenance, and disposal activities (i.e. life cycle management).
• Act as the Change Management Manager, the Configuration Management Manager, and the Incident Response Coordinator for my assigned systems.
• Determination of an appropriate level of security commensurate with the impact level.
• Participate in risk assessments to periodically re-evaluate sensitivity of the system, risks, and mitigation strategies.
• Notify the responsible parties, (i.e. System Owner, Program Manager, and ISSM) of any suspected incidents in a timely manner, and assist in the investigation of incidents, as necessary. From July 2014 to Present (1 year 6 months) IAVM Compliance Manager @ As a Theater level Information Assurance Vulnerability Management (IAVM) Compliance Manager, I supervise IA engineers and IAVM compliance engineers the Camp, Regional and Theater levels and also have the responsibility of acting as an escalation point for all IAVM related incidents. I acted as a senior level Auditor to ensure DoD regulation compliance is met for all information assets across several different security enclaves or classification levels, including preparation for annual Command Cyber Readiness Inspections (CCRI).
-PROMOTED FROM IAVM ANALYST
• Audit and provide feedback to customers on weekly vulnerability scans using Retina, Nessus, Security Center, ACAS, Gold Disk, SCAP, and SCCVI for routine operations and CCRI (Cyber Command Readiness Inspection).
• Serving as a subject matter expert by managing, disseminating, interpreting, and tracking compliance with IAVM associated messages including Alerts (IAVA), Bulletins (IAVB), Technical Bulletins (IAVT), as well as Common Vulnerabilities and Exposures (CVE), and DISA Security Technical Implementation Guides (STIG) compliance
• Survey network diagrams and other artifacts, utilize network visualization tools and assist in determining if vulnerability scans are being conducted on all network assets; identified gaps in vulnerability scanning.
• Prepare and assist in the preparation of vulnerability scanning reports to commanders and high headquarters; liaison with IAVM manager and IAPM regarding vulnerability and remediation issues.
• Develop plans and recommend tools for the vulnerability scanning of all network assets, regardless of type.
• Monitor INFOCON status and maintain awareness of all INFOCON requirements; assess current architecture and computer assets for INFOCON compliance.
• Responsible for approximately 30,000 assets throughout the theater. From October 2013 to June 2014 (9 months) US Army Positions as listed @ IAVM Compliance Manager
IAVM Vulnerability Analyst
Information Assurance Analyst - Lead
VTC Technician From September 2011 to June 2014 (2 years 10 months) Lead Information Assurance Analyst @ I am responsible for ensuring and documenting that all systems are regularly scanned and audited in accordance with applicable DoD policy and procedures, and that incidents are documented and accounted for as necessary by using network scanning tools such as REM/Retina/ACAS to detect system and network vulnerabilities/deficiencies, as part of a proactive network security policy.
• Acting IA Lead, Camp Buehring
• Utilizing skills to determine if requisite cyber security patches and remediation procedures have been applied per IAVA requirements.
• Maintain a database to track trends, unauthorized activities, and common practice procedures and remedies to be followed by subordinate units in correcting deficiencies identified during information assurance vulnerability compliance visits.
• Ensure system security by scanning and patching over 6000 computers to keep them compliant in accordance with DoD policy
• Provide weekly reports of IAVA to insure that systems are compliant
• Provide guidance and assistance to IMO and Systems team on compliancy
• Maintaining virus / security requirements by the US Army
• Army Training And Certification Tracking System (ATCTS) Manager for the Camp
Promoted from:
VTC Technician - Camp Arifjan, Kuwait From September 2011 to October 2013 (2 years 2 months) IT Manager - VTC Engineer @ I engineered, managed and maintained the company-wide IT infrastructure and related services, including maintaining the server, network, desktop, and blackberry/cellular infrastructure, VPN, custom in house software suites, as well as both consulting and acting as Project Manager.
• Fulfilled the roles of: Network, Server and Security Engineer, Incident Responder, Desktop Technician, VTC Engineer, Blackberry Enterprise Server Administrator and Exchange Admin
• Served as Project Manager for all in-house upgrades and on IT Related customer installations including equipment selection, service calls, to include consulting on project bidding.
• Responded to and resolved IP Based e-mail blacklisting within 1 month of hire. Corrected by implementing policies on failure-responses and a company wide email spam filtering. From August 2010 to September 2011 (1 year 2 months) Tampa/St. Petersburg, Florida AreaIncident Management Technician @ Promoted from Service Desk Analyst
I provided second level IT support and was responsible for the restoration of normal services as quickly as possible while minimizing the adverse impact on business operations, including beginning to end management of all issues affecting both assigned and unassigned regions of restaurants, regional offices, and Home Office Users.
• Night Lead for all after hours support staff including being a technical point of reference.
o Senior Analyst responsible for directing an incident response team of 8 people to respond to any outages and incidents.
• Certified Trainer – OSI Support: Facilitated new hire training by conducting side-by-side coaching, and call visioning.
• Troubleshot Frame Relay WAN connections for over 1500 Restaurants and Regional Offices as well as VPN Connectivity for remote users
• Used basic scripting to implement a disaster recovery process utilized by the support team.
o Scripting reduced the average down time from 1 hour to fewer than 10 minutes, minimizing lost sales
• Dedicated Technician for Evergreen, and T-Bird Franchises, the Hawaii market and 90+ additional locations. From May 2007 to August 2010 (3 years 4 months) Tampa/St. Petersburg, Florida AreaSenior Customer Service Representative @ Promoted from Research and Adjustments Rep. II
I supported customers, banking center associates and clients with all service issues including posting and encoding errors, missing deposit or payments, missing items, service charges or fees, ATM and check card issues including: lost/stolen, declined transactions, and general activity, return items, holds and uncollected funds, loans, lien releases, lines of credit, and a multitude of other tasks related to checking and savings accounts, errors in processing, and the banking industry.
• Trained a new hire class during their OJT transition (Coaching), including side by side quality monitoring, handling on phone escalations (supervisor calls) and other various tasks to ensure a smooth transition. From December 2005 to May 2007 (1 year 6 months) Tampa/St. Petersburg, Florida AreaHelp Desk Associate @ Assist merchants, clients and sales agents with issues related to credit card processing equipment, transactions, and processing policies by providing phone based technical support. From August 2003 to December 2005 (2 years 5 months)
Master of Science (MS), Information Security Assurance @ Western Governors University From 2013 to 2015 Bachelor of Applied Science (BASc), Technology Management - Information Security Assurance, 3.311 @ St. Petersburg College From 2010 to 2012 Associate of Applied Science (AAS), Criminal Justice Technology @ Hillsborough Community College From 2003 to 2005 Koenig