Lead Cybersecurity Engineer
Current• Lead a team of 5 Cybersecurity Engineers in securing a financial management system that processes over 60 billion dollars of government funds• Create, update, and maintain servers including Nessus scanners, Security Center, Splunk, Security Onion, Symantec Endpoint Manager, Symantec Endpoint Agents, and Burp Suite application scanner servers• Create, analyze, and respond to SEIM alerts in Splunk, Security Onion, and Kibana• Monitor and investigate Symantec Endpoint Protection HIDS alerts for windows and OSSEC HIDS alerts for Linux • Engineer Suricata IDS rules and Yara rules to detect malicious and unauthorized network activity utilizing tcpdump, wireshark, and scapy • Conduct web application scanning utilizing Burp Suite for 10 environments as part of the software development life cycle• Conduct OS scanning utilizing Nessus for 10 environments including Windows 2022, Oracle Enterprise Linux, Oracle Databases, F5 Load Balancers, ESXi clusters, Cisco Firepower, routers, and switches as part of the software development life cycle • Utilize Python, Powershell, and SQL scripts for automating patching tasks, account anomaly detection, and server management • Maintain compliance with the NIST SP 800-53 Rev 5, and FISMA by leading audit evidence gathering and interviews with auditors • Coordinate patching and mitigation of audit findings across multiple teams including Database, Network, System Admin, and Application Development• Create POA&Ms to track patches and requirements that require a larger timeline for completion • Maintain cybersecurity documentation deliverables including system access, network processes, patch management, PII data management, and change control SOPs• Provide guidance for cybersecurity initiatives such as implementing zero trust, IPv6 transition, FISMA assessments, and role based trainings