Senior Security Engineer
CurrentLed all projects from the security perspective for a large scale USG FISMA high rated critical infrastructure system using NIST 800-53 controls; Led program through annual SA&A audits and POAM resolution; built Vulnerability Management Program and reduced vulnerabilities by 3/4's using Tenable Nessus and HP Fortify to identify system and programmatic vulnerabilities; Implemented Splunk queries for reporting; Implemented 2FA utilizing MS Active Directory and privilege management with Centrify and CyberArk; Transitioned Symantec Endpoint Protection to Crowdstrike. Implemented change control for security controls on all networking changes including firewalls, routers, switches, protocols, etc. Strengthened environment by eliminating high risk protocols in use; Implemented MS jump servers to force 2FA where software did not support 2FA authentication. Worked with SOC on Splunk alerts and triaging events in order to implement standardized event management and response.Mentored junior staff on a regular basis to build team strength. Implemented warm hand-offs in order to ensure proper resolution on identified weaknesses and ensure correct deliverables.