Ivan Lopez

Sr Security Engineer/Senior ISSE/Senior Cyber Security Engineer/Security Control Assessor (System Owner Support- Master)/GRC Analsyst

Role
a Isso, Sr Security Engineer, Cyber Grc Analyst Sr Principal at SAIC
Location
Fredericksburg, VA, US
LinkedIn followers
500 followers

About Ivan Lopez

Experienced professional with 41 years of in-depth experience and demonstrated competency in Cyber Security initiatives; specializing in application security, information security (INFOSEC), network security, disaster recovery/business continuity (continuity operations) planning [DRP/BCP (COOP)], end-user education, security audits, system and facility certification and accreditation (C&A), connection approval processes (CAP), critical infrastructure security, and independent verification and validation (IV & V). Extensive background in program, project, technical management, and team leadership functions. Developed and implemented technical and non-technical policies, standards, procedures, and guidelines based on Federal laws, regulations, and standards; conducted risk analysis and risk management, penetration testing, and security audits and assessments through vulnerability testing and program reviews of networked and individual security infrastructure components. Performed business process re-engineering (BPR) and excelled in planning and implementing processes to improve the effectiveness of business teams and systems. Determined quickly how business processes operated, identified opportunities for improvement, and facilitated the development of streamlined procedures. Responsible for ensuring high quality service, serving as the contractor/customer liaison, and implementing prompt action to correct any service problems.Specialties: • Security Program Management• Information Systems Security• Risk Analysis & Management• Investigation and Audit • Education & Awareness Training • Firewalls & Internet Security• Certification & Accreditation• Security Process Innovation• Industrial Security• Physical Security• Disaster Recovery/Business Continuity/Continuity of Operations• SCIF Management

Experience

  1. a Isso, Sr Security Engineer, Cyber Grc Analyst Sr Principal

    SAIC

    Feb 2019 — Present · Springfield, VA, US

    Responsible for protecting an organization\'s computer systems and networks from cyber threats and vulnerabilities, which involves designing, implementing, monitoring, and upgrading security measures to safeguard sensitive data and prevent unauthorized access; overseeing and managing the governance, risk, and compliance (GRC) functions within an organization. This role involves ensuring that the organization adheres to regulatory requirements, industry standards, and internal policies to mitigate risks and maintain compliance. Develop organizational Security Assessment and Authorization documentation for unclassified and classified systems.Key Responsibilities:Develop and implement security strategies, policies, and procedures.Perform vulnerability assessments and penetration testing to identify potential weaknesses.Monitor and analyze security alerts and incidents to determine the root cause and mitigate risks.Collaborate with IT and other departments to ensure security best practices are followed.Conduct regular security audits and compliance checks.Develop and implement GRC strategies and frameworks to align with organizational goals.Conduct comprehensive risk assessments and audits to identify and mitigate potential risks.Ensure compliance with relevant Federal regulations (e.g, OMB, CISA, DHS, NIST, FISMA, GSA) standards, and best practices (e.g, GDPR, ISO 27001, HIPAA, PCI DSS).Lead and mentor a team of GRC analysts and other relevant personnel.Collaborate with senior management and other departments to integrate GRC practices into business operations.Develop and maintain policies, procedures, and controls to enhance the organization\'s security posture.Monitor and report on GRC metrics and key performance indicators (KPIs).Stay updated with the latest industry trends, regulatory changes, and emerging threats.Provide expert advice and guidance on GRC matters to stakeholders and management.

Education

  • Case Western Reserve University

    Bachelor of Science (BS), Management Information Systems, General

    1984

  • University of Maryland (European Division)

    Master of Science (MS), Computer Science

    1988

Skills

  • Comptia Security
  • Diacap
  • Network Security
  • Networking
  • Pci Dss
  • Malware Analysis
  • Comptia Security+
  • Security Awareness
  • Intrusion Detection
  • Security Architecture Design
  • Defense
  • Fisma
  • Information Assurance
  • Security+
  • Information Security
  • Comptia Security
  • Disaster Recovery
  • Cissp
  • Computer Forensics
  • Integration
  • Dod
  • Pki
  • Ceh
  • Program Management
  • Incident Response
  • Ids
  • Web Application Security
  • Vulnerability Scanning
  • Nist
  • Ips
  • Security Management
  • Internet Security
  • Firewalls
  • Management
  • Security Audits
  • Security
  • Penetration Testing
  • Enterprise Architecture
  • Information Technology
  • Security Clearance

Find verified contacts for anyone on LinkedIn

Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.

Free plan included · No credit card required

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

Ivan Lopez — a Isso, Sr Security Engineer, Cyber Grc Analyst Sr Principal at SAIC in Fredericksburg, VA, US | Unifers