SUMMARY HIGHLIGHTS am an Information Security Specialist with proven experience in Risk Management Framework (RMF), Systems Development Life Cycle (SDLC), and Risk Assessment using industry frameworks such as FISMA and applicable NIST special publications. Some areas of experience include, Nessus, Tenable, CSAM, McAfee, and MS Office Suite and Outlook. Adequate understanding of Federal and international regulatory bodies such as Office of Management Budget (OMB),PCI DSS and ISO. Risk Assessment and Security Assessment and Authorization process (SA&A). Experience reviewing and interpreting vulnerability scanning reports from Nessus etc. Experience in the development of ATO Package Documents such as System Security Plans (SSP), SAR, POAM, and security documents such as Contingency Plans, Incident Response Plans, PIA, and Configuration Management. Expertise in developing security artifacts to support the organizations program to include System Security Plans (SPP), Security Assessment Reports (SAR), Risk Assessment Reports (RAR), Security Control Traceability Matrix (SCTM), System Design and Installation. Procedures, System User Guides, Privileged User Guides, Security Test Procedures, and other documents as needed. Attends meetings and communicates status with stakeholders regarding vulnerabilities discovered, trends, and mitigations. Performs vulnerabilities discovered, trends, and mitigations.