Information Systems Security Administrator
CurrentConfigure and oversee monthly automated vulnerability scans of ~8000 devices withRapid7 InsightVM. Use results to identify attack surface of worldwide business network.Whitelist and blacklist domains with Cisco Umbrella based on user requests. Blacklist malicious IP addresses with Cisco Firepower.Blacklist malicious email addresses and domains in Cisco Ironport.Design policies in CyberArk EPM to prevent malicious software from running, or to giveadmin access to users for simple tasks such as changing their clocks and adding printers.Administrate and update Splunk instance for entire enterprise, created internal Splunkapp consisting of relevant dashboards and search queries. Generate non-securityrelated alerts, reports, and dashboards for company business groups that request them.Investigate malware events originating from company SentinelOne console, as well asusing their deep visibility search tool to aid in security events that occur. Orchestrate test phishing email campaigns in KnowBe4 to send to entire company toincrease phishing email awareness, using results to identify users susceptible tophishing.Use Mandiant Redline to gather forensic data from devices involved in security events.