INFOSEC Specialists/ISSM - PERATON
(2023-01)
INFOSEC Specialist/ISSM serve as a directorate level resource. INFOSEC Specialist/ISSM shall provide comprehensive Information Security (INFOSEC) assistance and oversight to customers throughout the mission space in their role supporting Sponsor Information Systems Security Managers (ISSMs). The INFOSEC Specialists coordinate with the ISSOs, who are collocated with Sponsor's Office Departments, or Programs, to ensure that INFOSEC policy and ISSM guidance is appropriately followed and documented, and deliver outcomes as follows:
- Review and analyze systems architecture diagrams and networks.
- Assess security system needs and provide corrective actions into a coherent security strategy.
- Support Assessment and Authorization (A&A) requirements and process and apply ICD 503, NISPOM, and other federal guidelines in support of systems used at contractor facilities.
- Help in the creations of new processes to support Sponsor and partners to advance security and lower risk: Cyber Reset – binning and profile system initiative. This is a major initiative to completely change the way assessments are conducted, and risks are presented in Sponsor system.
- Pilot and enhance Sponsor Front Office initiatives based on direct requests.
- Create custom documentations and step-by-step processes to streamline cyber risk reduction, security relevant changes, and help maintain the current understanding of Sponsor systems.
- Assist Sponsor systems owners and/or service providers throughout the risk management framework (RMF), including the assessment and authorization (A&A) processes.
- Provide advice to Sponsor system owners and/or service providers on the creation of required system documentation or body of evidence; review and provide recommendation for approval or disapproval, as appropriate.
- Assess security and privacy controls and data protection in sponsor information systems and environments of operation as part of the initial security assessment and during operational changes affecting information systems' security posture.
- Assist the security control accessors (SCA), as appropriate, in performing security systems assessments and reviewing risk elements in the executive Risk System (ERS) report.
- Create plans of action & milestones (POA&Ms) and/or request risk acceptance through a security assessor (SA), who will certify the ERS report to the appropriate authorizing official (AO) or designated AO.
- Provide oversight and guidance to ensure compliance with Sponsor information security regulations and policies on processes and request, such as Data Transfer Request; Access Request; Service/Change Request; Purchase Request; Accountable Property Management; Waivers, including medical devices and introduction (use) of equipment /devices into SCIF; and Equipment Transport.
- Build relationships, to include Interagency, with system owners and stakeholders.
- Review and approve requests to include but not limited to Sponsor system access system, crypto, hardware orders, and Sponsor portal waivers (SCIF 705, IT, DTO, medical devices, and Sponsor Certs.
- Facilitate development, maintenance and security review of AIS security plans for computers, networks, and information systems deployed and used at contractor facilities, ensuring that sponsor and program approving signatures are acquired and documented.
- Conduct technical exchange meetings to facilitate AIS security solutions for both industrial contractors and government systems; and produce comprehensive solutions to technically complex systems and challenges.
- Advise and answer questions regarding Sponsor's AIS policies, including providing recommendations on waivers and mitigations as appropriate to meet mission requirements.
- Ensure documentation is complete and accurate in accordance with Sponsor AIS policies and requirements.
- As necessary, support the investigation of virus/malware alerts/incidents to determine root cause, entry point of code, damage risk, and report this information.
- Write reports based on technical analysis of sponsor or industrial partners systems, and as applicable provide recommendations for mitigating issues in the future.
- Participate in project review meetings and provide technical cyber security advice/expertise to Sponsor personnel.
- Review complex sponsor and industrial partners system designs for security risk and compliance with sponsor policy and regulations; propose resolution and preventive strategies.
- Communicate complex technical concepts, project information, and security policy clearly and concisely to both technical and non-technical audiences.
ISSE - ATS
(2022-10 - 2023-01)
- Support customer through ASSESSMENT & AUTHORIZATION (A&A) process from obtaining ATO from ATD.
- Process the system SSP ASSESSMENT & AUTHORIZATION (A&A) in GreenLight to obtain ATO
- Scanned the system for vulnerability assessment on Rapid 7
- Update all system activities on RoadRunner for agency to easily assess at their end
- Worked with system Owner and ISSM in accepting risk in system as part of the ATO process.
- Act as a technical management resource for information system security matters
- Provides technical and programmatic Cyber Security and Information System Security Management Services to internal and external customers in support of network and information security systems
- Ensures the development and implementation of information security policy, requirements, and procedures within an organization's business processes.
- Reviews documentation from information obtained from customer using accepted guidelines such as RMF (Risk Management Framework).
- Conducts complex vulnerability assessments to include; development of risk mitigation strategies with the customer adjudicating based on assessing the vulnerabilities, threats, and risk associated with assessment.
- Reviews system configurations and scan tool results in order to determine system compliance and report results.
- Analyzes policies and procedures against Federal laws and customer regulations and provides recommendations for closing gaps.
- Develops strategies to comply with privacy, risk management, and e-authentication requirements
- Provides cyber security and information system security support for the development and implementation of security architectures to meet new and evolving security requirements.
- Evaluates, develops and enhances security requirements, policy and tools.
- Performs vulnerability assessments including development of risk mitigation strategies
Cybersecurity Analyst - UTILIQUEST, LLC
(2015-01 - 2022-10)
- Execute security control assessment from start to finish on all NIST 800-53 control families.
- Identify, communicate, and mitigate system vulnerabilities by leveraging vulnerability management tools such as Tenable Nessus.
- Contribute to system security plans, security risk analysis, and vulnerability assessments.
- Leverage Security Incident & Event Monitoring (SIEM) appliances to monitor event logs, system intrusion, unauthorized access, and misconfiguration.
- Assess IT security architecture including databases, servers, firewalls, Intrusion Detection System (IDS), Virtual Private Network (VPN), and host-based security technologies.
- Evaluate configuration of network devices such as DNS, VPN, TCP-IP, DHCP.
- Apply and enforce standards of the entire System Development Lifecycle (SDLC).
- Perform testing of security controls for various enterprise applications.
- Use Azure Active Directory to verify mandatory security compliance.
- Serve as liaison among various teams to coordinate security changes and attain A&A approval.
- Brief customers and management by providing regular status updates on security incidents.
Asset Management Coordinator - OMNIFICS INC.
(2006-06 - 2015-10)
- Install, configure, test, maintain, and troubleshoot end-user workstation hardware and software.
- Serve as lead customer engagement liaison for project status updates.
- Triage, diagnosis, and isolate faults with various desktop systems.
- Install CPUs and NIC cards, hard disks, hard drive, RAM, memory chip and software updates.
- Managed IT assets to receive, track, and tag products for ad-hoc help desk inquiries related to ongoing operations and logistics being transported out of w