Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic

Mercy Barnes

Dumfries,VA

Summary

Qualified Information System Security Analyst with expertise in ensuring the organization's IT systems and networks are secure and compliant with industry regulations. Proven ability to implement and monitor security control assessments, and vulnerability management. Proficient in FISMA, HIPAA, NIST, and RMF compliance frameworks. Skilled in the documentation of System Security Plans, Risk Assessment Plans, Continuity of Operations Plans, Incident Response Plans, and Security Test and Evaluation Standards. Enjoy creative problem-solving and prioritizing high-quality results in deadline-driven environments.

Overview

8
8
years of professional experience
1
1
Certification

Work History

Information Security Analyst

Johnson & Johnson
10.2020 - Current

Coordinate kick-off meetings with system owners to identify assessment scope, system boundary, and information system category; leveraged artifacts to conduct assessment and reduce compliance issues

  • Led FIPS 199 process in which security categorization takes place, and select technical, operational, and managerial controls using NIST SP 800-60 guidelines.
  • Assist in the documentation of System Security Plans, Risk Assessment Plans, Continuity of Operations Plans, Incident Response Plans, and Security Test and Evaluation (ST&E) standards.
  • Establish internal control procedures by examining reports, records, documentation, and operating practices.
  • Support assessors, system owners, and engineers in developing, categorizing, implementing, assessing, and monitoring security controls.
  • Ensure security awareness and training materials are regularly reviewed and updated required.
  • Planned and led POA&M teams to remediate system vulnerabilities and prepare authorization packages for ATO (Authorization to Operate).
  • Conduct security risk assessment methodology for system development.

Information Security Analyst

Dun & Bradstreet
06.2018 - 09.2020
  • Collaborated with system stakeholders to develop and maintain security documentation required for Authority to Operate (ATO) approval.
  • Supported the tracking, reporting and remediation of agency Plan of Action and Milestone (POA&Ms).
  • Performed incident response, defined by FISMA, in support of all security incidents related to customer information or information system.
  • Assessed effectiveness of subset of implemented controls on ongoing basis to inform AO's decisions regarding continued use and operation of system.
  • Led in development of Privacy Threshold Analysis (PTA) and Privacy Impact Analysis (PIA) by using NIST privacy handbook and working closely with Information System Officers (ISSO's) System Owners (SO) and information owners (IO).
  • Assisted Security Assessment and Authorization (SA&A) activities, by preparing the complete ATO package for the authorization official to make accreditation decisions.
  • Reviewed and Updated System Security Plans using NIST 800-18 as guide.
  • Developed, tested and implemented security policies, plans and procedures for organizational protection.

IT Compliance Analyst

Penske Truck Leasing
07.2017 - 05.2018
  • Coordinate process control remediation for PCI, NIST, and ITGC standards and attend annual training to keep aware of IT Control changes and requirements, communicate changes to Management team and support changes to processes to remain compliant.
  • Ensured all IT activities are closely aligned with business objectives while ensuring information security policies programs and systems are compliant with business and legal/regulatory requirements.
  • Managed and coordinate risk assessment and compliance efforts.
  • Conducted 3rd party security assessments, track, and follow-up on issues, report out results to management team.
  • Provided regular reports to IT Director, Management and company regarding status of IT Compliance with group.
  • Facilitated monthly and quarterly report reconciliations between trustees and Third-party Administrator.
  • Monitored metrics that measure IT and information security framework.
  • Worked with process owners as well as security administration team to ensure all reviews are done in timely basis, all changes are processed, and all activity is documented in secure repository.
  • Participated in IT Audit Remediation meetings with Senior Management monthly.

Customer Service Representative

TD Bank
08.2016 - 06.2017

• Handled customer inquiries, complaints, billing questions and payment extension/service requests.

  • Maintained good working relationship with clients to enhance customer satisfaction.
  • Provided accurate and appropriate information.
  • Commended for initiative, enthusiasm, tenacity, persuasiveness, intense customer focus and dependability in performance evaluations.

Education

Bachelor of Science - Health Administration

Lehman College of The City University of New York
The Bronx, NY

Skills

  • Good written and verbal communication skills for report-written technical policies and methodology documentation ▪ In-depth knowledge of RMF, NIST Special Publications, FISMA and HIPPA compliance framework ▪ Advanced Microsoft Office skills (Excel, Word, PowerPoint) and Teams
  • Work effectively in a team environment and participate in collaborative initiatives which foster the mutual exchange of knowledge and expertise
  • Ability to communicate effectively to build and maintain customer satisfaction and express conclusions in a clear, technically sound manner on matters associated with IT security

Certification

  • Active Secret Security Clearance
  • CISA - Certified Information Systems Auditor
  • CompTIA Security+

Timeline

Information Security Analyst

Johnson & Johnson
10.2020 - Current

Information Security Analyst

Dun & Bradstreet
06.2018 - 09.2020

IT Compliance Analyst

Penske Truck Leasing
07.2017 - 05.2018

Customer Service Representative

TD Bank
08.2016 - 06.2017

Bachelor of Science - Health Administration

Lehman College of The City University of New York
Mercy Barnes