Cyber Security Consultant
CurrentSpearhead risk mitigation efforts. Handle IAM and SIEM tool incident monitoring and response, JumpCloud administration and continuous monitoring. Presented on CIS Controls and Cybersecurity current events. Develop written policies and procedures based on NIST. •Track and organize NIST SP 800-53A Rev 5, CMMC, ISO and CIS controls to meet governance and regulatory compliance. Achieved risk mitigation reduction of 85% across the organization, in all areas of cybersecurity risk, and business compliance. •Perform vulnerability assessments using the Defense Information Systems Agency (DISA) and Security Technical Implementation Guide (STIG).•Conduct risk assessments using NIST RMF, SP 800-37 Rev 2, to prepare, categorize, select, implement, and monitor information systems and environments. •Develop findings, remediation and plans of actions and milestones and policy and procedure development. Conducted a cost-benefit analysis to assist in implementing a VPN solution. •Analyze logs, identify indicators of compromise, respond to incidents, provision, and monitor 270 users and devices. •Applied DLP in Cyvergance.AI’s production environment, handle vulnerability management, change management, incident response, configuration management and IT configuration control board access. •Conduct enterprise impact assessments and security impact analyses, patch and technical policy management, software license management. Employed MFA, disaster recovery/COOP planning and procedures and applied encryption technologies. •Created SharePoint sites to centralize data and streamline processes. •Conduct helpdesk role and close Zendesk tickets. •Brief leadership on ways to improve Cybersecurity Capability and Maturity through incident response and patch management policies.•Possesses a High-level understanding of FedRAMP controls compliance. •Consistently provides recommendations through weekly After-Action Reviews in support of continuous quality improvement.