Information Security Analyst
Current• Update and analyze System Security Plan (SSP), Risk Assessment (RA), Privacy Impact Assessment (PIA), System Security test and Evaluation (ST&E) and the Plan of Actions and Milestones (POA&M)• Support System Owners and ISSO in preparing Certification and Accreditation package for companies IT systems, making sure that management, operational and technical security controls adhere to a formal and well-established security requirement authorized by NIST SP 800-53 • Designate systems and categorize its C.I.A using FIPS 199 and NIST SP 800-60• Perform Self-Annual Assessment (NIST SP 800-53A)• Perform Vulnerability Assessment• Make sure that risks are assessed, evaluated and a proper action have been taken to limit their impact on the Information and Information Systems• Create standard templates for required security assessment and authorization documents, including risk assessments, security plans, security assessment plans and reports, contingency plans, and security authorization packages• Performing I.T controls risk assessments that included reviewing organizational policies, standards and procedures and provided advice on their adequacy, accuracy and compliance with the Payment Card Industry Data Security Standard (PCI DSS)