Information Security Analyst
Current● Reviewed, maintained, and ensured the inclusion of all Assessments and Authorizations (A&A) documentation in the system security package, enhancing compliance with industry standards.● Collaborated with system administrators to remediate Plan of Action and Milestones (POA&Ms) findings, gathering artifacts and creating mitigation memos and corrective action plans to facilitate closure.● Conducted comprehensive security assessments, developed Security Assessment Reports (SARs), and executed Security Test and Evaluation (ST&E) questionnaires using NIST SP 800-53A to maintain Authorization to Operate (ATO).● Performed information security risk assessments and internal audits, evaluating threats and vulnerabilities while identifying necessary mitigation strategies in alignment with established policies.● Developed and maintained training materials on data protection, ensuring organizational awareness and adherence to security protocols across all departments.