Highly experienced Cyber Security Engineer with an excellent understanding of technology and utilization of Firewalls (Security Groups), VPNs, Data Loss Prevention (DPS), IDS/IPS, Web-Proxy, Security tools, and Security Audits. Worked directly work with Team leads, developers and operations personnel throughout a DevSecOps life cycle both on policy and technical implementation of technologies. Detail-orientated team player with a results driven mindset.
Actively lead and contributed to the security planning, assessment, risk analysis, risk management, ATO accreditation, and monitoring of various DOD Information Systems (5 years of experience). Provided day-to-day support to systems engineers in baseline security audits. Attended and participated in weekly vulnerability and risk management TEMs to ensure that all services, operational systems, devices and applications sustained compliance with the most current DISA STIGs, DISA SRGs, IAVM requirements, ICD 503 RMF guidance, and approved security updates. Developed experience using various DOD security tools such as XACTA360, HBSS (Trellix), ACAS (Tenable Nessus), and ArcSight Kibana. Provided security subject matter expertise at all engineering, change,configuration control and other TEMs. Demonstrated leadership in coordinating and implementing cyber security policies, standards and processes.
Developed knowledge of the program's functional capabilities including system and derived requirements. Understood how software components implemented the requirements. Collaborated with product owners and software developers to develop and manage requirements. Managed system requirements to achieve epic goals. Independently created and updated systems engineering artifacts including but not limited to: ConOps, Requirements Analysis, User Guides, and System View Diagrams. Developed and managed requirements and ensured traceability. Understood and interpreted system requirements to ensure procedures satisfy verification of the functionality.
Carefully surveyed the surroundings and actions of uncleared personnel working in USG facilities. Escorted uncleared individuals throughout SCIFs. Secured classified working areas containing sensitive materials. Delivered accurate verbal and written reports to key stakeholders.