Professional Summary:• Information Security Analyst with 6+ years skilled in Security Control Assessment with proven history of delivering exceptional risk management support. Self-motivated and deadline-oriented with a track record of on-time deliverables. Clear understanding of the RMF process. • Good understanding of most of the Special publications used as a guide during an ATO process such as: SP 800-18, SP 800-53rev.4, SP 800-137, FIPPS 199/200 and much more.• Experience with FISMA, NIST family of security controls, POA&M Management, A&A Package (SSP, SAR, CP, CP TEST, PTA, PIA, RAR, ISA/MOU,• Schedule kick off meetings with system owners to help identify assessment scope, system boundary, the information system’s category and attain any artifacts needed in conducting he assessment.• Create Requirement Traceability Matrix (RTM) and document failed/passed controls using NIST SP 800-53A as a guide.• Develop Security Assessment Plans (SAPs) and conduct assessment of security controls selections on various Moderate impact level systems to ensure compliance with the NIST SP 800-53A Rev 4.• Conduct security control interview meeting and Artifact gathering meeting with various stake holders using assessment methods of interview, examination and testing.• Document assessment findings in a Security Assessment Report (SAR) and recommend remediation actions for controls that failed and vulnerabilities.• Request scans and review scan results for common vulnerabilities such as missing patches, weak password settings, unnecessary services not disabled and weak configurations.• Created and updated Authorization to Operate (ATO) packages.• Continuously monitored security controls effectiveness using NIST SP 800-137 as a guide• Knowledge of ISO 27001 and ISO 2702 Security Standards and Controls.• Highly motivated, productive and versatile team player with strong analytic skills and the ability to independently and under mentor ship, learn and apply modern technologies in a short time.• Knowledge of STIG viewer
Listed skills include Network Administration, Technical Support, Troubleshooting, Tcp/Ip, and 44 others.