Summary
Overview
Work History
Education
Skills
Certification
Project
Timeline
Generic

Michael Ogolo

Los Angeles,CA

Summary

Experienced Information Security Analyst with over 7 years of experience in Security Engineering, specializing in Risk Management Framework (RMF), Systems Development Life Cycle (SDLC), and Security Life Cycle. Proficient in vulnerability management, regulatory compliance (FISMA, HIPAA, HITECH, NIST, ISO 27001), and development of formal Security Programs. Strong in customer service, communication, and IT security assessments for government and commercial clients. Skilled in Python scripting and XQL for data management.

Overview

7
7
years of professional experience
1
1
Certification

Work History

Sr. IT Security Analyst

PANTHERGON IT & CYBERSECURITY SOLUTIONS,
07.2020 - Current

- Designed, documented, and implemented a global enterprise Security Program, Security Framework (based on CIS), and formal Security Processes and Procedures.

- Assisted with the evaluation, implementation, and utilization of Vulnerability Management, SIEM, SOAR, Incident Response, IDS/IPS, and Endpoint Security Tools.

- Led the research and implementation of Azure Cloud Security Solutions.

- Collaborated with Information Technology, Network Engineering, Operations, and Executive Management regarding the implementation and execution of Security Program and Strategy, Security Initiatives, and Security policies, procedures, and best practices.

- Streamlined communication channels between IT staff members during critical incidents by developing clear escalation paths based on severity level classification.

- Managed vulnerabilities utilizing Nessus Vulnerability Scanners to identify potential risks across single and multiple assets within the enterprise network.

- Revised and examined A&A Packages to encompass Core Documents, Policies & Procedures, Operations, Maintenance Artifacts, SSP, SAR, FIPS 200, FIPS 199, POA&M, CPTPR, BIA, PTA, PIA, and additional components.

- Developed comprehensive System Security Plans (SSPs) in accordance with NIST Special Publication 800-53.

- Conducted security assessments to evaluate the effectiveness of implemented security controls.

- Educated and trained users on information security policies and procedures.

- Developed and implemented IT security policies, ensuring compliance with industry standards and best practices.

- Performed risk analyses to identify appropriate security countermeasures.

- Supported all Assessment and Authorization (A&A) phases and processes.

- Implemented and managed Endpoint Detection and Response (EDR) solutions like McAfee, ensuring proactive threat detection and rapid incident response.

- Utilized XQL for database manipulation and employed Python scripts to correlate and standardize data.

IT Security Engineer

VINDS LLC
09.2017 - 06.2020

- Designed company-wide policies to bring operations in line with Center for Internet Security (CIS) standards.

- Drafted security reports and metrics to track security performance and strategize improvements.

- Enhanced network security by implementing advanced threat detection and prevention systems.

- Authored security incident reports, highlighting breaches, vulnerabilities, and remedial measures.

- Provided cybersecurity expertise during internal and external audits, offering valuable insights and guidance.

- Conducted regular vulnerability assessments to reduce the risk of cyber-attacks.

- Supported in technical writing to simplify complex technical terms for clients.

- Developed Python scripts for gathering and correlating data.

Education

Bachelor of Science - Computer Science

Unical University of Calabar
Cross River, Nigeria

Associate of Science - Nursing

El Camino College
Torrance, CA

Skills

  • Skilled in diverse technical tools and platforms, including Nessus, Splunk, McAfee EDR, Trend Micro, Wireshark, and proficient in Python scripting and XQL
  • Experienced with Active Directory, ServiceNow, and SIEM tools
  • Strong in Windows, Linux, and macOS environments, with expertise in Arange of other specialized security tools
  • Expertise in Vulnerability Management, Penetration Testing, Asset Management, Incident Response, SIEM, SOAR, IDS/IPS, and Endpoint Security
  • Experience with security frameworks such as CIS and NIST

Certification

  • CISA - Certified Information Systems Auditor

Project

MARCH 2023

- Overview: Implemented automated vulnerability scanning and reporting using Nessus Vulnerability Scanner and Python scripting to streamline identification, analysis, and remediation processes.

- Objectives:

- Configured Nessus for scheduled scans.

- Developed Python scripts for data collection and reporting.

- Established centralized tracking for prioritizing and monitoring remediation efforts.

- Team: Information Security Analyst (Lead), IT Security Engineers

- Outcome: Enhanced efficiency in vulnerability management, ensuring compliance with NIST standards and improving overall security posture.

Timeline

Sr. IT Security Analyst

PANTHERGON IT & CYBERSECURITY SOLUTIONS,
07.2020 - Current

IT Security Engineer

VINDS LLC
09.2017 - 06.2020

Bachelor of Science - Computer Science

Unical University of Calabar

Associate of Science - Nursing

El Camino College
  • CISA - Certified Information Systems Auditor
Michael Ogolo