True Information AssuranceSecurity Analyst
Jun. 2012 - Sep. 2016Lanham, Maryland, United StatesSecurity Testing: • Supported FISMA Assessment & Authorization testing for 34 SB/SE FISMA Reportable applications in production • Gathered application artifacts/ evidence to satisfy control test cases • Performed preliminary analysis using the Risk Management Framework and NIST SP800-53 Rev 4 on controls to be tested on each application to validate testing pool • Tracked all security findings from the Security Assessment Report (SAR) resulting in a POA&M in the Treasury FISMA Inventory Management System (TFIMS) • Supported SPMO and Application POC during POA&M mitigation meetings ensuring proper remediation milestones are set according to RMF • Tracked all findings from the Security Assessment Report resulting in a POA&M in the Treasury FISMA Inventory Management System (TFIMS) Support and Training: • Assisted the business unit (BU) in updating System Security Plans, Contingency Plans, and developed incident response and audit plans for all applications going through continuous monitoring • Provided a monthly POA&M progression dashboard for SB/SE Leadership • Documented Assessment & Authorization, Contingency Plan, Training, and POA&M progress for SPMO Program Manager • Provided weekly status reports to Leadership on FISMA related activities • Provided support and training to all new SB/SE SPMO government employees and contractors • Trained Application Stakeholders on A&A and ISCP assessment process which also included documenting/ tracking POA&M entries within TFIMS.