Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic
DAVID  OPOKU-MENSAH

DAVID OPOKU-MENSAH

FREDERICKSBURG,VA

Summary

Goal-Oriented Information Technology Professional with over 8 years of expertise in Risk Management Framework and NIST methodologies. Well organized and excellent in technical writing and communication skills.

Overview

8
8
years of professional experience
1
1
Certification

Work History

Security Control Assessor

ASG
Baltimore, MD
05.2020 - 05.2023

· Conducted Kick-off meetings with system owners, security staff and other stakeholders in efforts to understand the established information system

· Documented and conducted a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an information system

· Created/updated security assessment plan to present the intended schedule, outline the control being evaluated and acknowledge rules of engagement during assessment

· Coordinated with team on reviewed assessment procedures in order to develop a symmetric overall company system

· Determined the overall control effectiveness through documentation review, inspections, testing and interviews. Provide an assessment of the severity of weakness or deficiencies and recommend corrective actions to address identified vulnerabilities

· Drafted and validated plan of action Plan of Action & Millstone to ensure non-compliant controls are identified, updated and addressed within an accepted timeframe

  • Managed user authentication and authorization of data access.

RMF Analyst, Lead

CYLOC SOLUTIONS
Lanham, MD
08.2017 - 04.2020

· Leveraged Risk Management Framework to assign impact levels to systems, selected applicable controls, assessed controls effectiveness and performed continuous monitoring activities

· Categorized Information system using NIST 800-60 and assigned the appropriate impact levels as required

· Performed required adjustments of impact levels of the information system using FIPS 199 to align with the overall systems objectives

· Selected appropriate security controls as per NIST 800-53 for the information systems and collaborated with engineering teams to implement the selected controls

· Developed System Security Plan to capture system purpose, security requirement and outlined systems interconnections and all implemented security controls

· Prepared required documentation for Information System including Contingency Plan, Configuration Management Plan and Risk Assessment in collaboration with System Owner

Cybersecurity Specialist

Stechs Solutions LLC
Quantico, VA
10.2015 - 08.2017

· Analyzed and reviewed evidence of implemented controls to ensure each assessment objective was achieved

· Prepared for and conducted in-person interviews and witnessed implementation to ascertain control effectiveness

· Evaluated exposed threats and vulnerabilities to assess whether further safeguards are recommended.

· Collaborated with Information System Security Officer to evaluate Security System report and develop Plan of Action & Milestone that highlights the assessed controls including the satisfactory and unsatisfactory controls with suggested remediation

· Supported and documented security controls tests and assisted in remediation to ensure that POAMs are being appropriately managed

DESKTOP SUPPORT

A-COTE COLLECTIONS
ACCRA
09.2015 - 07.2017
  • Managed user authentication and authorization of data access.
  • Supported users with in-person and remote technical assistance.
  • Provided training and support to users for both hardware and software needs.
  • Promoted security awareness among employees and clients to alleviate risks and breaches.
  • Learned about latest security threats from blogs and online publications.
  • Designed, implemented and maintained security systems and controls.

Education

High School Diploma -

BCS
LONDON
12.2016

High School Diploma -

BCS
LONDON
12.2014

Bachelor of Arts - INFORMATIONS STUDIES AND PSYCHOLOGY

UNIVERSITY OF GHANA,LEGON
ACCRA
05.2007

Skills

  • Risk Mitigation
  • Reporting and Documentation
  • Critical Thinking
  • Problem Resolution

Certification

  • CompTIA Security+
  • Professional Scrum Master 1
  • High School Diploma, D2 THE BUSINESS CONTEXT OF IS
  • High School Diploma, INFORMATION SYSTEMS DEVELOPMENT
  • Higher National Diploma, MANAGEMENT INFORMATION SYSTEMS

Timeline

Security Control Assessor

ASG
05.2020 - 05.2023

RMF Analyst, Lead

CYLOC SOLUTIONS
08.2017 - 04.2020

Cybersecurity Specialist

Stechs Solutions LLC
10.2015 - 08.2017

DESKTOP SUPPORT

A-COTE COLLECTIONS
09.2015 - 07.2017

High School Diploma -

BCS

High School Diploma -

BCS

Bachelor of Arts - INFORMATIONS STUDIES AND PSYCHOLOGY

UNIVERSITY OF GHANA,LEGON
  • CompTIA Security+
  • Professional Scrum Master 1
  • High School Diploma, D2 THE BUSINESS CONTEXT OF IS
  • High School Diploma, INFORMATION SYSTEMS DEVELOPMENT
  • Higher National Diploma, MANAGEMENT INFORMATION SYSTEMS
DAVID OPOKU-MENSAH