Information System Security Officer
Washington D.C. Metro Area
Information System Security Officer
Washington D.C. Metro Area
Information Assurance, Information Security, Teaching.
(Information Technology and Services industry)
August 2009 — Present (5 months)
DoD) Information Assurance Certification and Accreditation Process (DIACAP) for TISCOM. Assist the government in system identification and requirements, evaluate system architecture including external connections, data flow, vulnerabilities, and countermeasures. Evaluate system security including data classification, controls and countermeasures, lifecycle maintenance, roles and responsibilities, and design features for all software, hardware, and peripheral system interfaces. Identify and assist the government in identifying requirements for system certification, evaluate and assist with the development of contingency plans and risk management. Coordinate with program and project managers throughout the accreditation process. Update and maintain certification-tracking database, create adhoc report, and perform other duties as assigned.
(Educational Institution; 1001-5000 employees; Education Management industry)
January 2009 — Present (1 year )
Maintain a teaching assignment for each module and plan course instruction based upon approved syllabus/outline provided, to assure course content and objectives are met. Distribute a copy of the module calendar to all students at first class meeting. Utilize a variety of teaching styles and methods to accommodate diverse learning styles of students. Design, administer and grade examinations to assess achievement of course objectives as identified in the syllabus. Actively work to maintain retention in all classes taught, by maintaining accurate attendance records daily, calling all students who are absent, and recording absentee information in roster after each class meeting and communicating attendance concerns to the Program Director.
(Information Technology and Services industry)
June 2009 — August 2009 (3 months)
Under contract to the US Patent and Trademark Office (USPTO), supported the Facilitation Services program management department in managing the security aspect of network operations by performing NIST-based systems certification and accreditation, vulnerability scan analysis, mapping and scoping of security controls, review vulnerability reports, and provide guidance to the team regarding security issues. Review current security policies, laws, regulations, and directives; identify personal identifiable information, map/scope security controls, and recommend changes as needed to keep up with changing security needs. Provide weekly status report on tasks and projects; coordinate and attend system certification kick-off meetings, and attend other program management meetings as requested. Update certification document templates, and create certification documentation and letters for accreditation. Create Plan of Actions and Milestones (POAM) in CSAMS. Additional duties consist of project management and leadership to include performing independent validation and verifications, peer review, and the assembly of certification packages of information systems for accreditation.
(Information Technology and Services industry)
January 2009 — June 2009 (6 months)
Supports the Dept of the Navy NAVSEA CIO Headquarters Office with the certification and accreditation of Department of Navy (DON) classified and unclassified information systems and circuits. Perform validation and verification of Naval operational program packages for accuracy and compliance. Coordinate weekly collaboration team meetings to discuss DITSCAP/DIACAP requirements to obtain interim authority to operate (IATO) or three-year authority to operate (ATO). Train new reviewers and assist in the maintenance and management of FISMA information systems. Perform other duties as assigned.
(Information Technology and Services industry)
April 2008 — January 2009 (10 months)
Supported NOAA program management in managing the security aspect of government information systems by reviewing current security policies, and recommending changes as needed. Performed independent validation and verification, performs interviews, and system scans to include NMap and Nessus. In addition, developed departmental information system security policies, disaster recovery plans, and analyzed and prepared certification and accreditation packages. Currently is the lead in the Governance effort of the Cyber Innovation Center project whereas process flow is determined, rules of behavior, policies, procedures, and change request documentation is established. Performed forensic analysis and additional duties as assigned to include the coordination of the annual division Cyber Security Forum and Executive Dinner, and attendance at quarterly Information Security Privacy Advisory Board meetings.
(Privately Held; 1-10 employees; Information Technology and Services industry)
February 2007 — March 2008 (1 year 2 months)
Under contract to the US Dept of Transportation , supported program management in managing the security aspect of network operations by performing systems certification and accreditation, vulnerability scans, security testing, reviewed vulnerability reports, patch systems and provided guidance to the team regarding security issues. Reviewed current security policies, test, and recommend changes as needed to keep up with changing security needs, provided weekly status report on tasks and projects, and acted as representative of network team in security meetings with Federal Motor Carrier security team or other meetings as requested, developed organization policies and procedures, procedures, and created configuration management templates. Provided annual security awareness training for departmental personnel. Updated Enterprise Security Portal (ESP) for Plan of Actions and Milestones (POAM), and performed contingency planning tabletop testing, and system scanning using Gold Disk 2.0. Additional duties consisted of project management and leadership to include performing independent validation and verifications, and the preparation certification and accreditation packages of information systems.
(Information Technology and Services industry)
January 2006 — January 2007 (1 year 1 month)
Reviewed cryptographic and information security related patent applications to assess if in compliance with formatting, rules, and legal requirements. Determined the scope of protection claimed by the inventor, researched relevant technologies to compare similar prior inventions with the invention claimed in the patent application, and communicated findings to the patent practitioner/inventor with reasons on the patentability of the applicant's invention.
(Information Technology and Services industry)
July 2004 — September 2005 (1 year 3 months)
Under contract to the US Dept of Transportation, was responsible for the understanding of DOT system accreditation and security regulations and procedures using NIST, Department of Transportation Departmental Continuity of Operations Planning, Security Program, and DOT Templates as methods of reference and guidance of Independent Verification and Validation for the DOT System Certification and Accreditation process. Coordinated with system owners, users, system developers, and operational support staff to assist in the resolution of system vulnerabilities based on action items from system security test and evaluation findings, developed specific procedures for system operational support, user guides and system documentation, and a variety of technical writing deliverables associated with system development and support. Assisted the program manager with coordination of technical services for user incident reports (service requests), configuration and change management, and updated the Remedy tracking system to reflect current status of technical services. Served as an integral part of the development and operational support team to perform quality assurance of applications, conducted user assistance and technical support with web enabled applications, developed training guides, conducted user training, and performed periodic application testing to ensure applications met user requirements prior to production implementation. Additional duties included assisting with Section 508 testing to ensure application accessibility standards are met in relation to application development and ongoing life cycle management support.
(Information Technology and Services industry)
December 2003 — July 2004 (8 months)
DOT), Provided regulatory support for the Office of the Secretary of the Department of Transportation which entailed maintaining the regulatory management system database; coordinating with DOT legal staff to obtain and validate data; producing standard and ad-hoc reports, assisting users and staff with operation of application, troubleshooting of technical problems, and coordinated with the DOT technical support team. Additional duties included processing system change requests; testing new application releases, assisting with documentation, procedures, and user guides and providing dedicated administrative and technical support for the Rulemaking Management System application.
(Information Technology and Services industry)
February 2003 — May 2003 (4 months)
Responsible for setting up and maintaining the middle school's computer lab. Additional duties included tutoring, coordinating, and system maintenance. Other duties were performed as requested.
(Information Technology and Services industry)
September 1998 — March 2001 (2 years 7 months)
Under contract to the US Dept of the Army, responsible for the administration and maintenance of the Hazardous Material Management Program which included direct interface with customer, attending briefings, and compiling reports to US Army personnel. Configured and maintained user NT workstations, managed and supported the Oracle database, end users manipulated database tables, ran ad-hoc reports for the Environmental department as requested, and trained and assisted users on the Hazardous Substance Material System (HSMS). Other duties included site manager, inventory management, computer security, and supervision of data entry clerks.
(Information Technology and Services industry)
April 1997 — July 1998 (1 year 4 months)
Responsible for configuration management and the maintenance of source code library for utility software which entailed direct contact with software developers, reserving source code, troubleshooting, running reports, and the replacement of source code into the configuration management library. Modified access to source code as necessary, and compiled and generated source code for Quality Assurance analysis. Additional duties included the preparation of release notes and source code for distribution to include burning CDs and packaging of software and release notes and mailing product to clients.
(Information Technology and Services industry)
June 1996 — February 1997 (9 months)
Under contract to the US Dept of the Army, created, enforced and followed operating procedures, and developed and maintained Composite Health Care System integrity to include database and user routines, troubleshooting and resolving user problems. Maintained Composite Health Care System external interfaces and software configuration; loaded new versions, updates, and quick fixes, created, added and extended volumes, tracked changes to site software configuration; updated and maintained VMS files, and provided user assistance with Ad-Hoc reports. Additional duties included modification of documentation, daily and weekly tape backups and computer system inventory.
(Information Technology and Services industry)
March 1992 — May 1995 (3 years 3 months)
Under contract to the US Dept of Energy, Managed systems which included analysis, modification, maintenance, and other administrative tasks to create and maintain an efficient computing environment. Configured and tested new and existing systems, performed software upgrades, application software installation, problem solving and resolution which entailed troubleshooting, establishing, creating and maintaining system and network print queues, system support, system backups, user accounts and privileges, training, modifying procedures, recovery planning, licensing, system security and property management.
(Information Technology and Services industry)
January 1991 — March 1992 (1 year 3 months)
Under contract to the US Dept of Energy, Reviewed procedures, drawings, test requirements, estimates and other pertinent data to assist in the conceptual planning of departmental activity. Helped to establish work sequencing for a specific discipline and assisted in the implementation and maintenance of work plans into schedules for the P, L, C and K Reactors.
(Information Technology and Services industry)
August 1989 — December 1990 (1 year 5 months)
Instructing college-level students on the basic concepts of mathematics in day-to-day and analytical operations.
(Information Technology and Services industry)
August 1988 — March 1989 (8 months)
Responsible for accounts payables, generating reports and the part time sales of chemicals and petroleum products to the City of Detroit.
(Insurance industry)
May 1987 — August 1988 (1 year 4 months)
Rate Calculator/New Business Processor
Responsible for the calculations of small group insurance premiums to include the processing and modification of new and existing group benefit plans for the Georgia Port Authority and Coca Cola.
Cetificate , Certificate with Honors in Disaster Recovery and Continuity Planning , 2008 — 2008
MS , Master of Science, Information Security and Assurance , 2005 — 2007
BS , Bachelor of Science, Computer Science and Mathematics , 1981 — 1986
for Doctorate , Information Security and Assurance
Certificate with Honors in Disaster Recovery and Continuity Planning