In Michael Hannah’s tenure, his goal and interests as a Cybersecurity Manager will be to lead engagements and assist his customers with test planning, execution, reporting, and evaluating their technical and operational risks within an operational Cybersecurity program, and being a conduit between the business and technology, and managing Digital Security Strategies/Portfolio and to create governance.
Cyber Security Consultant | Endcap Technology Solutions
ACCOMPLISHMENTS: Led the Cyber Security team in analyzing security log data, leveraging tools and technologies including:
- Access Control, Network Security, Intrusion Detection / Prevention Systems, Identity Governance and Administration, Malware Protection, Email Security, Data Loss Prevention, Cloud Security Solutions, and Security Information and Event Management (SIEM) tools, project management support and for four major commercial and government businesses (Hensel Phelps, DCS Corp., City of Hope, and Softek International, Inc.).
- Architected Lab testing LAN environment simulating actual Classified Real-Time, Pilot-in-the-Loop, Reconfigurable Flight Simulator (RFS) Systems. IPV4, IPV6 routing setup of RIP, OSPF, and BGP configurations.
- Assigned as the Project Management, SDLC (Waterfall-Model), and central point of contact throughout the project, and telecommunication Client work with Customer to schedule a kick-off meeting to initiate the Project.
- Conducted Compliance Assessments under GDPR, CCPA, PCI, NIST RMF, HIPAA/HITECH, DAAPM, NISPOM, GLBA, PCI, FERPA, ISO 27001 ISMS regulatory requirements.
CYBER SECURITY SKILLS:
- Agile and Six Sigma Framework HIPPA, HACS SIN - Oral Tech. Evaluation
- BIA, Assessment, Strategy, Framework Kill Chain, MITRE ATT&CK Framework
- C2/C&C Vulnerability Analysis Management and Exploits Network Analysis Tools (Wireshark)
- CIA Triad for Information Systems Assets ISO 27001 ISMS
- COMSEC/Shonan.io Real-world - Contingency Planning Pen-Testing (Metasploit, Kali), NGFW
- Cloud Security Strategy and Migrations (AWS / GCP / Azure) FedRAMP Compliance, SOX, PCI DSS
- Digital GRC (Teneable.sc / Teneable.io) SIEM, SPLUNK, ATP, AEP, NGAV
- Full-Stack DevSecOps knowledge of IT Infrastructure IAM Regulatory Regimes NIST SP 800, JSIG