Senior Information Security Engineer
Current• Responsible for managing and executing the vulnerability management process including remediation efforts and the creation of scans within Nessus and Qualys per CIS, DISA STIG, FISMA, and PCI DSS compliance standards for multiple enterprise customer. This includes both internal and external vulnerabilities. • Evaluated and verified accuracy of client’s scope, which included assessing the accuracy of the scans, network segments covered, scoring the security posture of endpoints, and providing detailed risk assessments of the environment.• Lead client discussions regarding vulnerability risk assessments including Zero Day attack communications, time to resolution discussions, and vulnerability priority within client’s environment. • Provide best practices and recommendations for clients under the guidelines of NIST for their System Security Plans including but not limited to, Access Control (Account Management, Wireless Access, Remote Access, Session Locks and Session Terminations), Incident Response (Incident Handling, Monitoring, and Reporting), and Risk Assessment (Vulnerability).• Audit client environments to evaluate the effectiveness of internal controls regarding the IT security posture such as Monthly AV and Patch Management, Quarterly Cryptographic Key Check, and CHD Retention. • Responsible for creating and implementing security policies, procedures, and system hardening standards across a multitude of endpoints, including but not limited to all windows server and workstation OS’s, ESXi and HyperV hypervisors and hosts, linux based operating systems such as Red Hat, Centos, and Ubuntu, and bare metal bios and software, for enterprise clients.• Responsible for selecting, implementing, and then managing numerous software and hardware solutions, including Endpoint security, AV, SIEM, patching, scanning, virtualization and Backup solutions.