Research to acquire more knowledge
A US ARMY Reservist, with DOD active Secret Clearance and prolific information system security officer with deep experience in Privacy and Data Security Management and Operations, Vulnerability Scanning, Assessment and Authorization (A&A), NIST 800-60, NIST 800-53 Rev.1 and Rev.4 and NIST 800-37 Rev.1, NIST 800-18, NIST 800-53 Rev.3 and NIST 800-34, FIPS, FISMA Security Content Automation Protocol, NIST Family of Security Control, FedRAMP Security Assessment Framework, POA&M, Incident and Contingency Planning, Information Architecture and IT Security activities. Used Splunk and other technical testing tools such as Nmap, NESSUS for monitoring logs, alerts, and aggregations. Information Security Specialist with passion for aligning security architecture plans and processes with security standards and business goals. Extensive experience developing and testing security framework for cloud-based software. Versed in robust network defense strategies. COMPTIA security+,CYSA. and CISM. Certified
• CompTIA Cybersecurity Analyst (CYSA) 2026
• CompTIA Security Certification (Security+) 2026
CISM
• Identified trends and root causes of system failures or vulnerabilities using NESSUS Vulnerability Scanner, NMAP to scan ports, weak configuration, and missing patches.
• Performed installations, upgrades, and troubleshooting for 70+ users and 120 devices, including laptops, desktops, printers, and smartphone devices.
• Defined and executed Cybersecurity Maintenance Plans and activities such as application of Security Template Implementation guides, Information Assurance Vulnerability Management (IAVM) remediation actions, System and Software Security Patches.
• Configured and installed local servers, executed hardware and software upgrades, and supported disaster recovery and backup procedures Install firewalls and anti-virus software and deploy 2- factor authentication to ensure data integrity and cybersecurity for highly sensitive legal documentation.
• Installed, operated, and maintained state-of-the-art IT Infrastructures including local and wide area network (LAN & WAN), Mainframe, Mini and Microcomputers, and peripheral devices.
• Attended meetings with the IT department to identify continuous improvement opportunities and enhance the delivery of IT services to users
• Collaborated with the Corporate Information Security and IT Audit teams to review Information Security policies, standards, procedures, and guidelines.
• Conducted regular internal penetration testing and Investigated IT security incidents.
• Researched the latest information technology (IT) security trends.
• Continuing education on security issues in the oil and gas industry.
• Worked with Security Operation Center (SOC) Analyst in making sure Intrusion detection and prevention systems (IDS/IPS) such as SNORT to analyze and detect worms, vulnerabilities exploit attempts, IDS monitoring and management using Security Information and Event Management (SIEM) by Tenable to collect and analyze large volumes of logs and network traffic and alerts to assess, prioritize and differentiate between potential intrusion attempts and false alarms.
• Developed security standards and best practices for the organization.
• Recommended security enhancements to management or senior IT staff.
• Reviewed third-party application security vulnerabilities and recommended updates.
• Coordinated and executed IT security projects.
• Coordinated and executed IT security assessments and managed remediation of findings.
• Researched, assessed, and deployed added security processes and products in response to identified vulnerabilities.
• Investigated Desktop PC issues submitted through ticketing system; Identify and apply solutions for common computer problems.
• Created & modified new and existing Microsoft Access Database queries for account manager reporting and reconciliation.
• Installed updates for windows-based server operating systems.
• Created/disabled Active Directory user accounts for new hires and terminating employees.
• Loaded electronic claim and eligibility files, from clients and carriers into benefits system, ensure system contains the most current data; Investigate error reports generated and review with team managers to correct any issues.
• Documented and maintained all technical procedures in easy-to-follow how-to guides
• Reviewed support tickets and assigned them to the correct technical resource to ensure timely response to all IT related requests.
• Ensured HIPAA regulations are followed. Ensures file transmissions follow encrypted protocols, staff are following guidelines for disclosure of PHI and ePHI, participates in team HIPAA risk assessment and training.
CompTia is a leading provider of vendor-neutral IT certifications that validate the skills and knowledge of IT professionals. CompTia offers certifications in various domains, such as security, networking, cloud computing, project management, and more
Active DoD Security Clearance
Research to acquire more knowledge