Information System Security Officer
•Analyzed and updated the System Security Plan (SSP), Risk Assessment (RA), Privacy Impact Assessment (PIA), System Security Test and Evaluation (ST&E), and the Plan of Action and Milestones (POA&M)•Assisted System Owners and ISSO in preparing certification and Accreditation packages for companies IT systems, making sure that management, operational, and technical security controls adhere to formal and well-established security requirements authorized by NIST SP 800-53 R4•Designated systems and categorized its C.I.A using FIPS 199 and NIST SP 800-60•Conducted Self-Annual Assessment (NIST SP 800-53A)•Performed Vulnerability Assessments to make sure that risks were assessed, evaluated, and proper actions were taken to limit their impact on the Information and Information Systems •Created standard templates for required security assessments and authorization documents, including Risk Assessments, Security Plans, Security Assessment Plans and Reports, Contingency Plans, and Security Authorization Packages.