Information Security Analyst
Current- Reviewed, maintained, and ensured the inclusion of all Assessments and Authorizations (A&A) documentation in the system security package, enhancing compliance with industry standards.
- Collaborated with system administrators to remediate Plan of Action and Milestones (POA&Ms) findings, gathering artifacts and creating mitigation memos and corrective action plans to facilitate closure.
- Conducted comprehensive security assessments, developed Security Assessment Reports (SARs), and executed Security Test and Evaluation (ST&E) questionnaires using NIST SP 800-53A to maintain Authorization to Operate.
- Performed information security risk assessments and internal audits, evaluating threats and vulnerabilities while identifying necessary mitigation strategies in alignment with established policies.
- Developed and maintained training materials on data protection, ensuring organizational awareness and adherence to security protocols across all departments.