Information Security Professional with a passion for aligning security architecture plans and processes with security standards and business goals. Extensive experience developing and testing security framework for all system/application or environment in a growth-oriented organization with focus on conducting security control assessments for Federal and Non-Federal Organizations using NIST SP 800-53 Rev4 and NIST documentation Series. Knowledge and management of Federal Government C&A practices and policies, particularly FISMA, Fed Ramp NIST SP 800-53, 800-171 and ability to analyze technical outputs and recommend process improvements at an enterprise level and testing of Security controls and and security framework.
Analyzed and updated System Security Plan (SSP), Risk Assessment (RA), Privacy Impact Assessment (PIA), System Security test and Evaluation (ST&E) and the Plan of Actions and Milestones (POA&M).
Training attended: