Westbrook, Maine, United States
With over four years of progressive experience in security systems, software, threats, and vulnerabilities management, I have made significant contributions in the IT field. My strong analytical and leadership skills demonstrate my ability to be a successful engineer and a dynamic leader with clear vision and effective personnel supervision and guidance. By obtaining a Bachelors of Science in Software Development from the Husson University, I have proved my mettle in software architecture, human/computer interaction, and project management that has resulted in effective data protection for the organization. As an Information System Security Engineer at Science Applications International Corporation, I facilitated the existing security architecture and worked on the enhancement and automation of security systems on the user end. I was also in charge of Risk Management Framework packages submissions and the development of action plans for security programs. My expert domain knowledge always enabled me to articulate an innovative plan that focused on enhancing effectiveness and yielding constructive improvements.
• Led technical risk assessments of new technologies, such as SaaS and AIML solutions, determining alignment with the firm's security control standards. • Developed risk syntheses that communicated key risk points to other security professionals, technologists, and executive stakeholders that reduce practical security risk and enabled informed risk decisions. • Mentored and provided technical guidance to more junior technology risk analysts on the team. Improved the design, led the implementation, and oversaw with other members of the Technical Risk Analysis team, the firm's controls assurance program. • Collaborated with other security professionals and technologists to refine or build standardized methodologies for technology risk evaluation, documentation, and the systemized collection of security risk data.
• Led the successful implementation of SOC2 compliance across multiple business units, enhancing data security and trust with stakeholders. • Developed and managed a Unified Consent Management system, ensuring compliance with global privacy regulations and improving user trust. • Championed Privacy Rights initiatives, including the development of user-friendly privacy policies and procedures. • Designed and implemented comprehensive Data Privacy and Classification frameworks, safeguarding sensitive information and ensuring regulatory compliance. • Architected scalable Data Schemas to support privacy-by-design principles, facilitating efficient data management and protection. • Conducted Privacy Impact Assessments (PIA) for new projects, identifying potential privacy risks and recommending mitigation strategies. • Performed Data Protection Impact Assessments (DPIA), ensuring compliance with GDPR and other international privacy laws.
• Function as Security Domain Architect for Virtual Security Architecture Team. • Design network boundary controls and encryption standards for SaaS products. • Implement FedRAMP security controls for SaaS platforms • Lead the design and implementation of unified access management for customer facing SaaS application • Facilitate product security incident response activities and assist with identifying and driving the resolution. • Evaluate and recommend new and emerging techniques and technologies for building and operating secure applications. • Conduct formal tests on web-based applications, networks, and other types of computer systems quarterly • Identify, monitor and remediate vulnerabilities, patches and application security defects within SaaS products. • Support security compliance controls, systems, and processes for cloud, SaaS services. • Participate in continuous monitoring and incident response for SaaS services. • Verify adherence to company security policies and procedures. • Consult with business groups and provide guidance on security-related topics. • Conduct pre-engagement security analysis of third-party application integration.
• Participate in product security incident response activities and assist with identifying and driving the resolution. • Evaluate and recommend new and emerging techniques and technologies for building and operating secure applications. • Conduct formal tests on web-based applications, networks, and other types of computer systems on a regular basis. • Simulate attacks on networks, firewalls, operating systems and web applications. • Contribute to creating reports of vulnerability and penetration test results • Identify and monitor vulnerabilities, patches and application security defects. • Track the remediation & mitigation of known vulnerabilities, and drive them to resolution. • Support security compliance controls, systems, and processes for cloud, SaaS services. • Participate in continuous monitoring and incident response for SaaS services. • Verify adherence to company security policies and procedures. • Design and develop product security controls, best practices, and documentation to support a FedRAMP operating environment. • Design and develop security controls and processes that align with company policies and satisfy compliance requirements. • Evaluate, recommend, and implement security controls to protect cloud services and information assets. • Consult with business groups and provide guidance on security-related topics.
While working in the US Army National Guard, I responsibly train 25 members of Infantry Rifle Platoon. I ensure their readiness for deployment within 24 hours. Also, I maintain platoon weapons and equipment with a value of $500K+.
As a Cyber Defence Analyst, I performed IRIS security scans and system vulnerability mitigation. I also developed Microsoft PowerShell scripts and hardware for testing. I effectively liaised with state cyber defense officials when communicating analysis results.
• Independently perform collection, analysis, and research of system, network and application vulnerabilities and threats • Analyze and respond to relevant security alerts from multiple sources • Conduct formal tests on web-based applications, networks, and other types of computer systems • Simulate attacks on networks, firewalls, operating systems and web applications • Create reports of vulnerability analysis and penetration tests, and present them to key stakeholders, system owners, architects and product managers • Track the remediation / mitigation of known vulnerabilities, and drive them to resolution • Perform Incident Response tasks as part of a Product Security Incident Response Team (PSIRT) • Continuously improve the management and incident response procedures, practices and tooling