Summary
Overview
Work History
Education
Skills
Languages
Timeline
Generic

Amara Camara

Upper Marlboro,MD

Summary

Detail-oriented Cybersecurity Analyst with over 10 years of experience in implementing cybersecurity measures, conducting risk assessment, and enhancing network security for diverse organizations. Skilled in risk management, in-depth knowledge of FISMA and enterprise information systems using, NIST SP 800-18, SP 800-53 Rev5, NIST 800-37, POA&M, and FedRAMP.

Overview

18
18
years of professional experience

Work History

Cybersecurity Analyst

Lunarline, Inc
Silver Spring, MD
03.2016 - Current
  • Experience in information system security management, performing monitoring, auditing, and analyzing information.
  • Ensuring information systems reliability and accessibility.
  • Prevention and defense against unauthorized access to systems, networks, and data.
  • Knowledge, understanding, and compliance using the risk management framework process for certification of DOD and federal civilian agencies systems.
  • Assist in conducting on prem and cloud-based information systems assessments
  • Helping in updating IT security policies, procedures, standards and guidelines according to department, local and federal requirements
  • Supporting cyber security analysts in conducting vulnerability management, security engineering, policies examination, assessment and accreditation process (A&A) and computer network defense.
  • Performing risk assessments, review system security plan (SSP) and make recommendations to update the (SSP) using NIST 800-18 (Guide for developing security plans for federal information systems), Plans of action and milestones (POAMs), security control assessments, configuration management
  • Creating Plan of actions and milestones (POAMs) for review and approval by the Authorizing Official (AO) formerly known as the designated approving authority (DAA).
  • Performing vulnerabilities scans and monitoring continuously using NIST 800-137 as a guide and Nessus enterprise for recommending improvements in security systems and procedures.
  • Monitoring confidential agency's data and mitigating hacking through network systems updates.
  • Monitoring computer virus reports to determine when to update virus protection systems and continually performing risk analyses to identify appropriate security countermeasures.
  • Proving and meeting successful tight deadlines and a fast-paced environment.
  • Using critical thinking to break down problems
  • Evaluate solutions and make decisions.

Security Control Assessor

Fidelis Security Systems
Bethesda, MD
03.2014 - 04.2016
  • Provided technical support for secure software development and integration tasks, including reviewing work products for correctness and adhering to the design concept and to user standards.
  • Performed risk analyses, which included assessment using tools such as STIGs, ACAS and Endpoint Security Solutions (ESS).
  • Knowledge of Security products such as PKI, VPN, firewalls and IDS/IPS (intrusion detection and prevention systems).
  • Knowledge, understanding and compliance with DOD 8140, 8500 (Cybersecurity), 8510 (RMF), 8551 (PPSM), CJCSI 6510.01f (IA & CND).
  • Set Up VMware, Installed and configured virtual machines
  • Monitored, Kept an eye on VM performances, and fixed issues
  • Supported, troubleshooting any problems that came up backed up and Recovered data
  • Reviewed violations of computer security procedures and developed mitigation plans.
  • Developed, reviewed, and updated information security system policies, and established security baselines under NIST, FISMA, FIPS, and industry best security practices.
  • Performed vulnerability scanning with the support of Census the scanning tool to detect potential risks on a single or multiple asset(s) across the enterprise network.
  • Updated IT security policies, procedures, standards, and guidelines per the agency's local and federal requirements.
  • Performed risk assessments to help assess the risk, review and update, the plans of action and milestones (POAMs) Analyzed and examined prior security control assessments, configuration management plans (CMP), contingency plans (CP), incident response plans (IRP), and other tasks and specific security documentation.
  • Conducted security assessment and Authorization using NIST SP 800-53 rev5 and FIPS 200 (Security Controls) and NIST 800-53 Rev 5.
  • Monitored controls post-authorization to ensure constant compliance with the security requirements.

Junior Security Control Assessor

NTT DATA Services
Washington, DC
09.2008 - 02.2014
  • Performed multiple IT security support services associated with security functional testing, vulnerability assessments, and penetration testing. Including Vulnerability, Database, web server testing, and scanning of the Network
  • Conducted ongoing security functional requirements testing and security assessments of federal agency's information systems hardware, software, applications, and overall system architecture to: Verify and validate that the system security technical and operational controls are under established security policies, requirements, plans, standards, processes, and procedures.

Education

Bachelor of Science - Information Technology

University of Youkon
Alaska
05-2009

Skills

  • FIPS 199 and FIPS 200,
  • Authorization to Operate (ATO),
  • Privacy impact assessment (PIA),
  • Privacy threshold analysis (PTA) & Business impact assessment (BIA),
  • CSAM, ACAS,
  • Vulnerability Scanning: Nessus, Nmap, Burp Suite, Wireshark

Languages

English
Full Professional
French
Full Professional

Timeline

Cybersecurity Analyst

Lunarline, Inc
03.2016 - Current

Security Control Assessor

Fidelis Security Systems
03.2014 - 04.2016

Junior Security Control Assessor

NTT DATA Services
09.2008 - 02.2014

Bachelor of Science - Information Technology

University of Youkon