Summary
Overview
Work History
Education
Skills
Certification
Timeline
Work Availability
Hi, I’m

Ali Amadu Sorgho

BRONX,New York
Ali Amadu Sorgho

Summary

Mission-driven and highly motivated Information Security Analyst. Protect and support enterprise organizational assets, organizational processes and data privacy critical to organizational and national security through the Assessment and Authorization (A&A) process. Attentive to details with the ability to work under pressure without compromise to quality of results. A result-oriented team player with awesome problem solving and time management skills. Experienced in successfully executing the rigorous Risk Management Framework (RMF) compliance program as stipulated by FISMA, OMB Circulars, NIST SPs, and related industry standards to support organizational mission and business operations. Hands-on experience with assessing information systems for risk, identifying, mitigating and recovering from vulnerabilities to a more secured security posture.

Overview

4
years of professional experience
1
Certification

Work History

Byte-Path LLC

Information System Security Officer (Contractor)
07.2021 - Current

Job overview

  • Work directly under the Authorizing Official to review system security assessment package and Vulnerability Scans and make recommendation to the Authorizing Official the length of ATO to be granted for initial systems, systems with conditional/temporal ATO and systems with full ATO coming for their yearly review. Using FISMA Compliance guidelines, Assessment and Authorization Compliance guidelines and Information Assurance Vulnerability Management Compliance guidelines as a guidance tool.
  • Actively involved in ATO decision meetings.
  • Performed periodic audits on continuous monitoring of system’s security artifacts, Scans, and POAMs before they are due ATO review using FISMA Compliance guidelines, Assessment and Authorization Compliance guidelines and Information Assurance Vulnerability Management Compliance guidelines.
  • Guided System Owners and ISSOs through the Re-categorization process and how to utilize the internal tool for Re-categorization.
  • Prepared Quick Reference Guide on security issues that will come up.
  • Ensured that all systems under the organization’s enclave obtain and maintain an ATO.
  • Ensured that Information Assurance and vulnerability Scan metrics are reported accurately. Using FISMA Compliance guidelines, Assessment and Authorization Compliance guidelines and Information Assurance Vulnerability Management Compliance guidelines as a guidance tool.
  • Actively involved in migrating traditional systems into the Cloud. Using FedRAMP Compliance guidelines as a tool.
  • Conducted CDM meeting to discuss vulnerabilities and potential remediation actions with system and application owners
  • Ensured identified weaknesses from vulnerabilities scans are remediated in accordance with NCI defined time frames
  • Involved in NCI security awareness program to educate employees and managers on current threat and vulnerabilities

CVS Pharmacy

Information Security Analyst
02.2019 - 06.2020

Job overview

  • · Perform comprehensive Security Assessments as part of Assessment and Authorization process to determine if controls are being implemented correctly, operating as intended and meeting the desired objectives.
  • · Prepare Assessment and Authorization (A&A) packages, which includes but not limited to SSP, SAP, RTM, RA, SAR and POA&M.
  • · Review the A&A Packages to ensure they remain current and security operations are in compliance with NIST 800-53 standards, FISMA and organization’s policies and procedures.
  • Assist in developing, defining and maintaining information security policies, standards and procedures relating to Management, Operational and Technical controls.
  • Provide assessment reports on the severity of findings/weaknesses and recommend corrective actions for mitigating vulnerabilities and exploits to the information and information system.
  • Review the POA&M in order to validate the items uploaded in the POA&M tracking tools support the closed findings and coordinate promptly with stakeholders to ensure timely remediation of security weaknesses.
  • Conducted assessment kick-off meetings, provide expert analysis and advice on systems and programs related to IT security problems and provide recommendations.
  • Perform vulnerability scans for Database, Network and Web Application for clients using Tenable Nessus.SC and gather information necessary to maintain system security.
  • Provide routine support of IT security programs to ensure that security objectives of Confidentiality, Integrity and Availability are met.
  • Perform Assessment and Authorization on General Support Systems (GSS) and Major Applications to ensure environments are operating within strong security posture.

Education

University of Ghana
Accra, Ghana

Bachelor of Business Administration from Accounting
06.2010

The Cloud Bootcamp

from Multicloud And DevOps Bootcamp
11.2023 - Current

University Overview

MultiCloud Specilization Program. The MultiCloud Bootcamp prepares Technology Professionals to work with Cloud (AWS, Microsoft Azure, Google Cloud and Oracle Cloud) by providing the practical experience needed through the implementation of more than 30 projects based on real scenarios, requested by the largest companies in the world.

Skills

  • Good Work Ethic
  • Risk Mitigation
  • Tenable Nessus
  • Reporting and Documentation
  • Cloud (AWS, Google Cloud, Microsoft Azure)
  • Training & Development
  • Disaster Recovery Management
  • Privacy and Confidentiality
  • Data Security
  • Business Operations
  • Risk Management
  • Vulnerability Assessment
  • Vulnerability Management
  • Policy Development
  • Risk Identification
  • Risk Assessment
  • Documentation Skills
  • Audit Documentation
  • Payment Processing
  • Access Control

Certification

ISACA Certified in Risk and Information Systems Control (CRISC), 11/22/2023 - 01/01/2027

Timeline

The Cloud Bootcamp

from Multicloud And DevOps Bootcamp
11.2023 - Current

Information System Security Officer (Contractor)

Byte-Path LLC
07.2021 - Current

Information Security Analyst

CVS Pharmacy
02.2019 - 06.2020

University of Ghana

Bachelor of Business Administration from Accounting
Availability
See my work availability
Not Available
Available
monday
tuesday
wednesday
thursday
friday
saturday
sunday
morning
afternoon
evening
swipe to browse
Ali Amadu Sorgho