Senior Information Technology Security Officer
CurrentCoordinated and documented an annual risk assessment as well as ad hoc project risk assessments.Reviewed risk assessment documentation for completeness and appropriate selections of controls.Coordinated and led efforts to execute an agency-wide security awareness program that is tailored to the needs of specific roles within the agency and is measurable and auditable.Designed and implemented a program to collect and report information security related performance metrics and key risk indicators.Worked collaboratively with all NOAA office lines to ensure that their practices are consistent withcorporate information security policies and standards.Identified compliance objectives and mapped program deliverables to the requirementsAssessed agency-wide compliance with NOAA's policies and standards and take action to remediate non-compliance.Recommended controls to reduce risks to levels that align with the organization's risk tolerance.Ensured that NOAA is properly evaluating security risks through the NIST framework that assesses the potential impact of threats to the agency’s information systems.Provided updates to senior management concerning any policy or documentation required for compliance to FISMA guidelines.