It Security Analyst
Current• Responsible for compliance scanning of company infrastructure through use of python scripts, and Tenable security center. Created and updated Audit files resulting in 75% of compliance scans being automated, with a 0 high finding track record and saving 300 man hours per audit.• Conducted advising of subject matter experts, platform owners, and executive leadership of new programs, compliance requirements, and changes in regulatory frameworks. Researched and proposed adopting NSA’s DIB Cybersecurity Services, which resulted in full adoption for WPS and all other CMS Contract holders.• Created and managed policy and procedure documents. Verified through review by external auditors every 6 months. Proper implementation of policies and procedures has resulted in awards of 75% of possible bonus from CMS.• Established training for subject matter experts on compliance requirements for NIST 800-53, DISA STIGs, CMMC, FIPS 140-2, FEDRAMP, and MAC ARS. Created and maintained training documents, presentations, and lectures to be provided to new SME’s and platform owners on an annual basis or upon hire, resulting in an increase of 60% awareness, as measured by time savings of 90 man hours per audit.• Researched FEDRAMP requirements for CSP’s and as CMS contract holders. Briefed ISSO’s, and assisted in creating a SSP for CSP’s to utilize for authorization and compliance within our environment.