- Provided safety reports and data analysis to building managers to inform security processes.
- Completed vulnerability scans to identify at-risk systems and remediate issues.
- Outlined and maintained security patching schedule to efficiently address ongoing system issues.
Risk Compliance Analyst
- Investigated incidents and wrote reports.
- · Develop templates and tools to support risk and compliance frameworks
- · Ensure accuracy and timely completion of required information for regular reports
- · Risk monitoring – assisting with identifying risk and establishing risk management strategies
- · Using IRS Publication 1075 to assess security controls for State agencies, contractors
- · Develop and update Authorization to Operate (ATO) packages such as the SSPs, SAR, and POA&Ms for information systems to ensure they comply with the organization's information security requirements.
- · Reviews, monitors, and reports Plan of Action and Milestone (POA&M) status to all stakeholders and follows up with appropriate personnel to ensure that POA&Ms are remediated and written promptly to the POA&M Manager
- · I worked with the Security Control Assessors (SCA) team to determine the effectiveness of current security controls and a path forward to implement future security controls where potential weaknesses might exist.
- · Responsible for researching and evaluating relevant information security policies, guidance, and best industry practices, including NIST and FISMA, for applicability to IT systems security.
- · Develop and review system security artefacts such as contingency plans (CP), incident response plans (IRP), privacy impact assessments (PIA), MOUs/ISAs, and risk assessment (RA) documents for compliance with NIST 800 guidelines and agency’s security requirements.
- · Monitor controls post-authorization to ensure continuous compliance with the security requirements by evaluating threats and vulnerabilities through Nessus scan results and working with the IT staff for mitigation actions. Created and implemented security network framework across
Joined Okta team in January 2023 to date
Using Okta to support end users for single sign-on, multifactor Authentication, Deactivate and activating user accounts when needed, sending activation emails, viewing user system logs to find the problem and troubleshoot, resetting user authenticators, helping users with their group assigned application, Using okta directory to find the user name and email to troubleshoot State agencies, contractors, Pensioners, non-State workers