Information Security Consultant
CurrentAs a Certification Analyst contracted to support USCG TISCOM project:Responsible for perform Security Control Assessor (SCA) responsibilities; this include review, evaluation and resolution for new systems, major applications and decommission systems. Utilize NIST Information Security Publications and Standards (SP-800 series and FIPS), DISA Security Technical Implementation Guides (STIG)s and Assured Compliance Assessment Solution (ACAS) vulnerability scans to identify security weakness… Show more As a Certification Analyst contracted to support USCG TISCOM project:Responsible for perform Security Control Assessor (SCA) responsibilities; this include review, evaluation and resolution for new systems, major applications and decommission systems. Utilize NIST Information Security Publications and Standards (SP-800 series and FIPS), DISA Security Technical Implementation Guides (STIG)s and Assured Compliance Assessment Solution (ACAS) vulnerability scans to identify security weakness and non-compliance. Use Enterprise Mission Assurance Support Services (eMASS) process tool. Provide program level discussions with project leads to determine a recommended path forward for accreditation. Coordinate with the team lead and ISSO/ISSM members to discuss situational awareness on emerging vulnerabilities, associated with possible exploits. Manage daily workload assignment of General Support System (GSS), Major Application (MA) or Request for Modification (RFM) with quality results Track and review Plan of Actions and Milestones (POA&M), Contingency Plans/Contingency Plan Test (CP/CPT), and annual security control assessment as part of system continuous monitoring Perform Risk Analysis/Risk Assessment for networks and major applications Review vulnerability scan and STIG checks to determine potential security impact and discuss resolution Show less