freiberufler IT Senior Security Consultant and Auditor auf freelance.de

IT Senior Security Consultant and Auditor

zuletzt online vor 10 Tagen
  • 85€/Stunde
  • 71083 Herrenberg
  • Weltweit
  • en  |  de
  • 01.09.2024

Kurzvorstellung

CISO-Ass.,Strategieber.,Compliance/GRC (NIST Framework, PCI-DSS, ISO 27001:2022)Technologieber.,Projektleitung, ISMS (PCI-DSS, ISO27001,KRITIS, NIST AI Trustw/OWASP AI TOP10, NIS-2, DORA, CIS, BSI), Audits,Awareness,Cyber Sec./SOC,EU-DSG

Qualifikationen

  • Certified Information Systems Security Professional (CISSP)
  • CISSAP
  • Compliance management
  • Cyber Security
  • Datenschutz
  • DIN EN ISO 27001
  • PCI-DSS6 J.
  • Risikoanalyse3 J.
  • Schulung / Training (IT)
  • Schwachstellenmanagement
  • Security Operations Center (SOC)9 J.

Projekt‐ & Berufserfahrung

Security Analyst
Freelancer, Herrenberg
1/2024 – offen (9 Monate)
IT & Entwicklung
Tätigkeitszeitraum

1/2024 – offen

Tätigkeitsbeschreibung

Meine Geschäftsgelegenheit:
•Überprüfung von Scans, die über den PCI-Scanning-Service von Qualys eingereicht werden, um eine Bescheinigung zu erhalten.
•Überprüfung der Gültigkeit der vom Kunden eingereichten Scans durch Überprüfung aller erforderlichen Nachweise, unabhängige Analyse und Nachstellen bestimmter Szenarien in einer Laborumgebung
•Unterstützung der Kunden bei der Einreichung von PCI ASV-Scans
•Zusammenarbeit mit den Ingenieuren des technischen Supports, um die ordnungsgemäße Bearbeitung von PCI-Fragen sicherzustellen
•Identifizierung von Bereichen für Workflow- und Prozessverbesserungen innerhalb der PCI ASV-Aufgaben
•Aufrechterhaltung der PCI ASV-Zertifizierung
•Andere PCI ASV-Aufgaben nach Bedarf (z.B. „Business as Usual“ compliance checks.)

Eingesetzte Qualifikationen

PCI-DSS, Risikoanalyse

Security Professional
IBM, Ehningen
10/2021 – 12/2023 (2 Jahre, 3 Monate)
IT & Entwicklung
Tätigkeitszeitraum

10/2021 – 12/2023

Tätigkeitsbeschreibung

Member of the IBM Garage team working along with the client CISO and/or Security Subject Matter Experts to ensure security and compliance requirements are integrated into Minimum Viable Solution (MVS). Worked as a thought leader in DevSecOps practices and have hands on expertise with security practices across the infrastructure, applications, and networks.

Utilized the IT risk management discipline to define relevant policies, standards, & controls for the solution.

Ensured requirements for security & data privacy controls are integral throughout all phases of the solution lifecycle.

Designed the innovative security architecture; ensure the security, reliability & integrity requirements are met as a part of the overall solution architecture. Ensure inter-dependencies with other functions are addressed.

Lead security component integration and delivery via hands-on experience addressing security issues for cloud-based applications, containers, infrastructure, and networks.

Forged strong working relationships with the client, IBM Garage teams, and Product Owners.

Interviewed Clients on the current IT security risk landscape; helped articulate security requirements, issues, and solutions in business terms for C-Level Executives.

Applied consulting methodologies, problem-solving techniques, and industry knowledge to determine and address client's security needs.

Translated client business driver requirements to help define the structure of solutions and architectures, including systems, applications, and process components.

Eingesetzte Qualifikationen

Cyber Security Practitioner (CSP), Requirement Analyse, Risikoanalyse, System Analyse

Qualified Security Assessor, Payment Card Industry
SecureTrust, Herrenberg
7/2016 – 9/2021 (5 Jahre, 3 Monate)
IT & Entwicklung
Tätigkeitszeitraum

7/2016 – 9/2021

Tätigkeitsbeschreibung

Customer engagement and project execution providing information security consultation and assessment services (Compliance Validation and Gap Assessments), helping clients meet compliance obligations by evaluating their business, technology, and processes against the PCI DSS security Standard. Shared experience with clients and colleagues to aid in making decisions on topics like strategy and scoping as well as deep and highly technical projects like web application architecture and security. Provided clear, organized findings and recommendations to clients and tracked progress towards resolution and compliance. Produced detailed, high-quality reports on compliance for clients and industry third parties like payment card brands and the PCI Security Standards Council. Worked with clients to implement practices to procure secure applications and identify and eliminate security vulnerabilities. ISO 27001 certified Internal Auditor. Completed over 50 Reports on Compliance and Gap Analysis reports on acquiring banks, payment service providers and e-commerce companies.

Eingesetzte Qualifikationen

PCI-DSS, Auditor

Security Analyst
Defense Intelligence Agency, Vahingen
7/2011 – 7/2016 (5 Jahre, 1 Monat)
IT & Entwicklung
Tätigkeitszeitraum

7/2011 – 7/2016

Tätigkeitsbeschreibung

Develop data graphs based on audit log records and defined how the log records are mapped into a visual representation. Calculated statistical upper and lower probability boundaries of specific administrator actions. Created charts relating to Perimeter threats - visualizing service traffic flow of destination ports vs. time, service anomalies using tree maps, worm outbreaks visualized in link graphs, large email delays using a box plot graph of sender vs delay. Successfully created Insider Threat visualizations measuring documents accessed vs. username, date charts measuring the number of added or deleted cron jobs by user.
Implemented workflows for Security Operations Center Tier 1 and Tier 2 staff though a process of event annotation and escalation procedures based on specific tiered threshold levels within the console. Developed metric dashboards for security operations center managers that show personalized grids where each analyst can add a sub-tab that shows their events only. Created a semi-automated process where a tiered-triage methodology suppressed incoming events to limit noise. Developed reports and metrics that provide a way to measure events received versus events reviewed and subsequently helped meet audit review requirements. Established a process for reviewing events that need to be filtered from the console which also helped eliminate noise. Accurately modeled network IP address space information. Incorporated vulnerability scan data into the SIEM for a higher model confidence calculation. These actions have tuned incoming events to focus specifically on interesting threat traffic.
Applied methodology to the chaos of reviewing hundreds of events per second. Defined responsibilities for each of the security operations tiers which shared event review responsibilities.

Eingesetzte Qualifikationen

Incident Management, Prelude Live Logger, Security Operations Center (SOC)

ArcSight Security Analyst
SRA International, Vahingen
3/2010 – 6/2011 (1 Jahr, 4 Monate)
IT & Entwicklung
Tätigkeitszeitraum

3/2010 – 6/2011

Tätigkeitsbeschreibung

Responsibilities included tier 3 security engineering services for the European Command Security Operations Center (SOC). Installed operated and maintained consolidated logging solution (ArcSight Logger/Connector appliances) for all network, and server devices. Engineered open-source threat intelligence lists into ArcSight logger (-Hyperlink entfernt-) to provide SOC staff automated alerts on potential security threats. Delivered daily intelligence reports based on Ad-Hoc Logger reports. Delivered to network administrators daily reports on problem areas in the network based on router and switch logs. Provided data leak prevention solutions, enabled Denial of Service (DoS) thresholds, Intrusion Prevention Services, Spam detection and rejection, Greyware/Malware checking and Anti-Virus services. Trained Tier 1 & 2 SOC staff in incident response procedures, firewall debugging, trace flows and interface dumps. Engineered data leak stops for classified information in Fortinet appliances.

Eingesetzte Qualifikationen

Fortigate Firewalls, McAfee AntiVirus Plus, Security Operations Center (SOC)

Senior Security Engineer
Science Applications International Corporation, Fort Collins
8/2008 – 2/2010 (1 Jahr, 7 Monate)
IT & Entwicklung
Tätigkeitszeitraum

8/2008 – 2/2010

Tätigkeitsbeschreibung

Cyber Security Engineer supporting various aspects of security operations including SAIC's MSSP, by solving complex challenges across the Cyber Security spectrum. Primary role includes assisting in advanced incident response, resolving engineering challenges, assessing, enhancing, and developing operational capabilities, technical writing and marketing demonstrations, assessing new technologies, developing new operational concepts, security event management and correlation content development, first to deploy new services, providing technical demonstrations of MSS capabilities.
Commercial Managed Security Services branch out of San Diego California. Lead representative for six major commercial accounts generating revenues totaling $1.3 million annually. As Tier 3 lead engineer my responsibilities included event collection, log management, event management, using ArcSight Enterprise Security Management 4.0. Created filters, trends, asset modeling etc based on my customers’ network traffic flows. Ensured events flowed 24x7 into the ESM. Additional responsibilities included: handling architecture changes (VPN, New Virtual IPs for terminating IPSEC, device monitoring, performance trending, graphing, firewall changes, content filtering), policy and procedure, documentation, high profile incidents (event monitoring, zero-day attacks, policy violations, vendor bug issues), be the last engineer of tier escalation in all contract matters and overall customer satisfaction. Special project to install EMC Clariion CX4-480 model storage area network to archive security events. Configured two fibre channels to ESM ArcSight server at secondary warm site. Provided help was needed but also directed/delegated once assistance has been provided. FortiGate 300A, 1000A and Cisco ASA administration experience. ArcSight Certified Security Analyst 4.0.

Eingesetzte Qualifikationen

Cisco Firewalls, Security Operations Center (SOC), VPN (Virtual Private Network)

Information Assurance Network Engineer
Kundenname anonymisiert, Fallujah
4/2007 – 5/2008 (1 Jahr, 2 Monate)
IT & Entwicklung
Tätigkeitszeitraum

4/2007 – 5/2008

Tätigkeitsbeschreibung

Operated and maintained Multinational Forces-West Iraq (MNF-W) for II MEF, G6 network security architecture throughout the Al Anbar province to include Cisco PIX ASA firewalls and IDS systems, Content Engines, routers and switches. Developed, maintained and updated network diagrams for NIPR, SIPR, and CENTRIXS networks. Operationally assisted the MNF-W IA Commander in managing a team of network security professionals throughout the Al Anbar Province. Assisted the Theater Information Assurance Manager (TIAM) in gathering the data necessary to Certify and Accredit Department of Defense Information Systems (DIACAP/DITSCAP). Scanned US Marine networks with eye Digital Security Retina scanner and managed the central repository server eEye Digital Security REM from other MNF-W subordinate scanners.

Eingesetzte Qualifikationen

Security Operations Center (SOC)

Security Architect III
Unisys, Fort Collins
5/2005 – 4/2007 (2 Jahre)
IT & Entwicklung
Tätigkeitszeitraum

5/2005 – 4/2007

Tätigkeitsbeschreibung

Perform technical security reviews of United States Department of Agriculture Web Farm security initiatives. Manage and execute vulnerability scans of Web Farm environments and perform ad-hoc vulnerability scans for certification and accreditation of new and existing server application deployments. Worked with application hosting staff to address remediation for vulnerabilities found. Tools used were ISS Site Protector, Cisco IDS/IPS and Cisco PIX ASA firewalls.
Serve as lead security contact for ongoing XML appliance deployment and ISS Site protector, Real Secure host-based agent administration and Proventia Intrusion Prevention operations.
Produce documentation deliverables including security waiver requests, architecture documents, and weekly status reports. Mentor junior OpSec staff and share knowledge of assessment, remediation, and
IT security best practices. I also ensured the security plans, risk assessments, System Test and Evaluation (ST&E), and completed Certification and Accreditation process (C&A) using NIST 800-53 as the basis and structure for USDA C&A Policy. Ensured Plan of Action and Milestones (POA&M) have been completed.

Eingesetzte Qualifikationen

Cisco Firewalls, Cisco Router, Cisco Switch

Information Assurance Analyst
Science Applications International Corporation, Vahingen
2/2002 – 4/2005 (3 Jahre, 3 Monate)
IT & Entwicklung
Tätigkeitszeitraum

2/2002 – 4/2005

Tätigkeitsbeschreibung

Contracted to enforce Joint Task Force (JTF) security policies at the Standardized Tactical Entry Points (STEP) in Europe. Remotely managed sixteen routers and four firewalls in geographically separate
locations. Lead JTF Information Assurance personnel in developing security policy for deployed networks. Administered Lucent Brick 201 packet filtering firewalls and Cisco 3620 firewall feature-set routers. This program saves 20-30% bandwidth by implementing security policy at the earth-terminal satellite site. Solid troubleshooting methodology efforts on congested IP network traffic flows improved deployed network services. Established baselines and documented bastion hosts for statistical anomaly detection. Coordinated a distributed security policy between satellite downlinks in two geographically separate theatres. Perform technical security reviews of USDA Web Farm security initiatives. Manage and execute vulnerability scans of Web Farm environments and perform ad-hoc vulnerability scans for certification and accreditation of new and existing server application deployments. Worked with application hosting staff to address remediation for vulnerabilities found. Tools used were ISS Site Protector, Cisco IDS/IPS and Cisco PIX ASA firewalls.

Eingesetzte Qualifikationen

Cisco Firewalls

Ausbildung

Computer Resources and Information Management
Ausbildung
Webster University
1998
Bachelor Economics
Ausbildung
Colorado State University
1993

Über mich

Nach Meinung meiner Kunden zeichnen mich neben meinen beruflichen Qualifikationen folgende Eigenschaften aus: Unternehmerisches Denken,
Praxisnähe, Problemlöser und Innovator.

Weitere Kenntnisse

IT-Sicherheitsmanagement, Governance, Risk & Compliance (PCI-DSS, ISO27001:2022, NIST-Standards, OWASP) Technologieberatung/Produkttests (IPSEC, TLS, Architektur-Review, Rechenzentren, Internet-/Intranetportale, Databases, PKI/Smartcards/HSM, Verschlüsselung) Ethical Hacking/Penetrationstests (Netz- und Applikationstests), Proprietäre Systeme CERT, Schwachstellenmanagement, Forensik Erstellung von Security Policies, Standards, Guidelines Prozessdesign, Aufbau eines ISMS/IKS

Persönliche Daten

Sprache
  • Englisch (Muttersprache)
  • Deutsch (Fließend)
Reisebereitschaft
Weltweit
Arbeitserlaubnis
  • Europäische Union
  • Vereinigte Staaten von Amerika
Home-Office
bevorzugt
Profilaufrufe
93
Alter
54
Berufserfahrung
22 Jahre und 7 Monate (seit 02/2002)
Projektleitung
13 Jahre

Kontaktdaten

Nur registrierte PREMIUM-Mitglieder von freelance.de können Kontaktdaten einsehen.

Jetzt Mitglied werden