
Rodney Penny
Information System Security Officer (ISSO) @ Tunuva Technologies, Inc.
United States
Hyattsville
Information Technology & Services
Government, Vulnerability Management, Risk Management Framework (RMF), U.S. Federal Information Security Management Act (FISMA), NIST 800-53, DoD, Security, Security Clearance, Network Security, System Administration, Program Management, Computer Security, Troubleshooting, Active Directory, U.S. Department of Defense, Integration, Networking, Network Administration
Experience

Information System Security Officer (ISSO)
Chantilly, VA
• Executed full Risk Management Framework (RMF) lifecycle (Prepare through Continuous Monitoring) for federal information systems • Assessed and validated NIST 800-53 security controls, improving system compliance and security posture • Conducted DISA STIG and SCAP vulnerability scans, identifying and tracking security findings • Developed and maintained Plan of Action & Milestones (POA&M), supporting remediation efforts • Prepared and delivered security status reports to senior leadership and system stakeholders • Supported Authority to Operate (ATO) documentation and accreditation processes

Information System Security Engineer
Washington, District of Columbia, United States
Ensure that assigned information systems are operated, maintained, and disposed of in accordance with approved security policies and practices. Ensure that system security requirements are addressed during all phases of the IS lifecycle. Developing and maintaining the SSPs and all other system security documentation, reviewing and updating them at least annually for all assigned systems. Author or coordinate the development of other required system security plans: Configuration management (CM), Contingency Plan (CP), Continuity of Operations (COOP), Disaster Recovery Plan (DR) and Incident Response Plan (IRP). Support risk assessment activities throughout the system's lifecycle. Implement a strategy for continuous monitoring for assigned systems including: Establishing system audit trails and ensuring their review, reporting all identified security findings and initiating the periodic review of security controls. Request required information system vulnerability scans in accordance to establish policy; develop system POA&Ms in response to reported vulnerabilities. Ensure compliance with annual FISMA deliverables and reporting. Monitor and analyze security functional tests. Prepare C&A documentation such as SSP, SCONOPS, ST&E reports, etc.

Associate ISSO
Washington D.C. Metro Area
- Ensure that assigned information systems are operated, maintained and disposed of in accordance with approved security policies and practices. - Ensure that system security requirements are addressed during all phases of the IS lifecycle. - Developing and maintaining the SSPs and all other system security documentation, reviewing and updating them at least annually for all assigned systems - Author or coordinate the development of other required system security plans: Configuration management (CM), Contingency Plan (CP), Continuity of Operations (COOP), Disaster Recovery Plan (DR) and Incident Response Plan (IRP). - Support risk assessment and evolution activities throughout the system's lifecycle. - Implement a strategy for continuous monitoring for assigned systems including: Establishing system audit trails and ensuring their review, reporting all identified security findings and initiating the periodic review of security controls. - Request or conduct required information system vulnerability scans in accordance to establish policy; Develop system POA&Ms in response to reported vulnerabilities - Ensure compliance with annual FISMA deliverables and reporting. - Investigate any information technology or system security incidents - Assesses and mitigates system security threats/risks throughout the program life cycle; determines/analyzes and decomposes security retirements at the level of detail that can be implemented and tested; reviews and monitors security designs in hardware, software, data, and procedures; performs system certification and accreditation planning and testing and liaison activities; supports secure systems operations and maintenance. - Perform security engineering analysis, risk and vulnerability assessment, etc. - Monitor and analyze security functional tests. - Prepare C&A documentation such as SSP, SCONOPS, ST&E reports, etc.

Public Key Infrastructure Engineer
National Reconnaissance Office (NRO)
Chantilly, VA
Maintain and operate the Public Key Infrastructure as per the FIPS-140 Level 3 operating standard and as per the CP/CPS ensuring general availability, performance, and usability. Integrate certificates into Enterprise infrastructure like VPN, LDAP, various web servers and applications like Adobe, SAP etc. Provide technical assistance to protect enterprise data and infrastructure using certificates and security protocols like SSL, IPSEC etc. Perform day to day CA operations and certificate life cycle management activities of issuance, revocation and restoration of client private key from key escrow. Maintain and operate Card Management system integrated with enterprise PKI. Perform day to day card management functions like issuance and revocation of certificates on smartcards. Perform administrator functions on the Card Management system like integrating CMS with CA's , creation of roles, card profiles etc. Plan and execute software and/or infrastructure upgrades with minimal service disruption. Providing problem analysis following any service issues to prevent recurrence. Performing product evaluations and making product recommendations. Identifying security risks to systems and suggest mitigations. Developing and updating systems documentation. Excellent MS-Windows Server administration & maintenance. Familiarity with PKIs and related technologies (LDAP directories, HSMs, OCSP) and security practices. Excellent oral and written communication skills. Excellent analytical and troubleshooting skills. Working knowledge of Entrust suite of PKI products (Security Manager, Administration Services, Security Manager Proxy) especially in a government setting. Hands-on experience with Hardware Security Modules (HSMs). Experience with directory products (LDAP), such as Critical Path or Active Directory. Network infrastructure diagnostics (TCP/IP general networking knowledge, network monitoring tools)

Tier I - Technical Support
Department of Justice
Chantilly, VA
Answers incoming phone calls on behalf of client. Provides accurate and appropriate information to callers. Uses probing and listening skills that support effective telephone communication. Places outbound customer service or customer satisfaction calls, as required by client. Correctly completes call guides; gathers and verifies required information. Attends training sessions. Adheres to established levels of service. Remains current on program changes including content information and application changes. Adheres to established customer service and documentation standards within required time frames. Adheres to contact center scheduling, and ensures telephone coverage during contact center hours of operation. Performs clerical or administrative duties as assigned. Monitors center service level performance. Assists supervisor(s) with daily, weekly and monthly reporting. Provides leadership and work guidance to less experienced personnel. Improves team performance and facilitates communication among the members of the team. Unlock and reset passwords via Active Directory. Remote desktop connections to Manage services on user workstations; perform software installs via Bigfix Web console, basic troubleshooting and resolution.

Technical Support Engineer
Department of Justice
Chantilly, VA
Supported the Department of Justice in providing desktop and application support service to clients at undisclosed government contracting site. Provides Tier 2 support for desktop and server applications across 2 separate networks in a Windows server environment. Used active directory to create user profiles, used power shell to create the user's mailbox, assisted with password resets when notified by the user, removed users from organizational units, and disabled accounts when authorized. Mapped printers on the network, replaced printer cartridges, and resolved most printer malfunctions. Configured Microsoft Windows Exchange and Outlook 2003/2010/XP/Windows7. Shared knowledge and experience with other team member to increment a group knowledge base. Documented network outages and system maintenance. Attended group meetings discussed new problem and solutions with the team via email. Installed new hardware on user workstation which includes KVM switch boxes, headsets, keyboards, mouse, speakers, CAC readers, VOIP phones, dual monitors, dual video cards, NIC's for Cat5 and Fiber cables, and metrobilities. Reimaged desktops when faced with BSOD "blue screen of death" and other fatal malfunction within the system. Assisted with VTC connections for conference rooms. Experience supporting four primary and extensive databases. Responsible for annual STAS auditing of hard drive on issued desktops and laptops for the express purpose of identifying elicit and inappropriate material for government attention. Updated spreadsheets and email reports with laptop findings from annual laptop audit report. Monitors the state of networked devices via IPMonitor. From a security standpoint, Tier I & II are expressly responsible for verifying clearance level and appropriate access for STAS users requesting account creation or repair. User Call Manager to setup/configure VOIP phones and resolves all VOIP phone issues. Experienced installing and configuring MAC workstations.

Information Technology Specialist
Department of Justice
Chantilly, VA
IT software specialization with the express position description of providing Tier I technical support to STAS users at undisclosed government contracting site. Responsible for preparing troubleshooting response tickets and coordinating Tier I & Tier II support for resolution. Support services include, but are not exclusive to, basic phone response, the repair and installation of hardware/software along with associated system peripherals, computer wares acquisition, delivery, imaging and account set up/reset. Experience in the servicing of platforms: Windows '07, Windows XP- with repair and installation support for both desktop and laptops issued. Experience supporting four primary and extensive databases. Experience troubleshooting for VOIP phones and ensuring constant and secure communications. Tier section responsible for annual STAS auditing of hard drive on issued desktops and laptops for the express purpose of identifying elicit and inappropriate material for government attention. From a security standpoint, Tier I & II are expressly responsible for verifying clearance level and appropriate access for STAS users requesting account creation or repair.

Technical Support Security Engineer
Department of Agriculture (USDA-OCIO)
Washington D.C. Metro Area
Provides support for monitoring IDS and IPS system tools FireEye, Fidelis, Sourcefire, Nagios, Netwitness, and Trustwave used by analysts to assess threats to the USDA network. Assist in the hardware maintenance of devices that hosts security applications. Provides daily reports of general system health. Generates weekly reports of user activity on security appliances. Digipass administrator and Active Directory administrator of security tools server.

Network Engineer I
Department of Army – Pentagon
Pentagon, VA
Function as a Tier 1&2 Help Desk Technician support for unclassified and classified workstations for over 500 VIP customers including personal in the SCIF. Respond to telephone, electronic mail, and/or walk-in requests for support for all systems and equipment within the AOC Service Desk environment. Exercise daily knowledge of Microsoft Office 2003-07, Adobe Professional, DoD CAC, DoD (PKI), and Virtual Private Network (VPN), Active Directory. Test and create NIPR and SIPR hard drive images utilizing the ghost server. Troubleshoot problems encountered using microcomputer software. Provide limited one-on-one desk side training for customers requiring assistance on standard software applications and or IT equipment. Perform network and desktop-based detection of viruses to counter/eliminate/control. Input user information creating trouble tickets in Remedy 7.1. Utilizing excellent customer service with client request by telephone, electronic mail or walk-ins. Provide limited one-on-one desk side training for customers requiring assistance on standard software applications or IT equipment. Perform desktop-based detection of viruses and contain and eliminate virus infestations. Configure ghost image on hard drives to swap out old imagery on classified and unclassified workstations. Load software and update patches required. Reset passwords and update user accounts on unclassified and classified networks in Active Directory. Install Blackberry Desktop Manager, Blackberry CAC Software, create Blackberry accounts, activate, configure and setup Blackberry handle devices. Swap out power supplies, motherboards, RAM on Dell OptiPlex 745, 755 and Dell OptiPlex 680 computers. Change toner cartridges, fuser, imaging unit to network Xerox 7300 and 7400 printers. Replace maintenance kit and print cartridges replacement on Xerox 4500 printers.

PKI Registration Authority
Department of Army
Crystal City, VA
Experienced in the usage of PKI software-based certificates and registration process. Verify the identity and information for each software certificate subscriber; issue software certificates; and revoke software certificates. Manage the alternate smart card process for both NIPR and SIPR nets; issue alternate smart cards to Systems Administrators and all other communities as required. Initialize, configure, and revoke alternate smart cards. Responsible for recovering escrowed private encryption keys. Responsible for complying with all Army policies related to software certificates. Responsible for preparing all, group, and role based PKI certificates. Provide subject matter expertise for the Registration Authority (RA) Certificate Practice Statement (RACPS) and the Local Registration Authority Certificate Practice Statement (LRACPS). Assist in development of certification and accreditation documentation in accordance with AR 25-2 and DODI 8510.01; scheduled and trained 15- 20 Trusted Agents for the SIPRNet IOT&E using teleconference and pre-distributed Microsoft PowerPoint-graphs. Developed daily production reports; acted as lead when team lead was absence and produced team reports.

Information Technology Specialist
Department of Army – MWR
Fort Belvoir, VA
Responsibilities included establishing best practices and techniques to plan/develop operational tests and evaluation plans for systems impacting local operation of dependent service installations. Researched, evaluated, and provided feedback on trends and patterns in customer support requirements. Configure, install, troubleshoot, and maintain hardware and software providing information system security. Develop and implement data and system recovery plans for hardware and software system failures. Troubleshoot all software issues. Troubleshoot client and network hardware issues. Unlock and reset user accounts. Services are provided in a timely manner with 80% accuracy. Assist with server, workstation, printer, scanner and all network device configuration and deployment. Run system backups, file restoration and systems recovery. Member of large-scale deployment team. Provide technical instruction, procedure, and assistance to activity personnel. Experienced in rapid deployment of Windows 2000 Professional and Windows XP at the desktop level using disk imaging and unattended setup files. Experienced with Windows 2000 Active Directory design, installation, users and groups management deployment of enterprise-wide Group Policies using Active Directory components. Redesigned Active Directory's Organizational Units to facilitate management of computers and users through Group Policies.

Support Assistant (Office Automation)
Dept. of Army - USACFSC-IM
Alexandria, VA
Responsibilities included serving as Support Assistant and Office Automation for the Headquarters Community and Family Support Center, (CFSC), under the direct supervision of the Network and Automation response Center supervisor. Resolved network problems for all Departments of the Army/DOD personnel, and contractors. Responded to incoming technical trouble calls from CFSC/MWR personnel, Department of the Army/DOD agencies serviced by the Network Response Center. Monitor trouble tickets in the system to ensure resolution. Configure and install and troubleshoot internal and external personal computer, laptop and printer components and related software. Receive and review incoming mail, and make proper distribution of mail ensuring the integrity of sensitive or secret documentation and correspondence.
Rodney Penny's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.


