Summary
Overview
Work History
Education
Skills
Certification
Securityclearance
Personal Information
Timeline
Generic

Orane Dixon

Gaithersburg,MD

Summary

Security Assessor with a proven track record in evaluating, testing, and ensuring compliance with various security frameworks including NIST, ISO 27001, PCI-DSS, HIPAA, and FedRAMP. Skilled in conducting risk assessments, vulnerability scans, penetration testing, and security audits to identify weaknesses and provide effective remediation strategies. Strong expertise in governance, risk, and compliance (GRC), security policies, and technical controls to safeguard organizational assets. Collaborative team player adept at working with cross-functional teams, IT security professionals, and senior management to enhance security postures and meet regulatory requirements. Proficient in utilizing security tools such as Nessus, Qualys, Burp Suite, and Splunk to assess risks and strengthen security defenses. Exceptional analytical abilities combined with excellent communication and report-writing skills ensure clear documentation and presentation of findings to stakeholders. Committed to continuous learning and staying updated on cybersecurity trends and best practices as demonstrated by certifications including CISSP, CISA, CEH, or Security+.

Overview

6
6
years of professional experience
1
1
Certification

Work History

Security Control Assessor

DLH
01.2024 - Current
  • Company Overview: National Institutes of Health
  • Conduct security control assessments (SCA) for 5 System Security Plans (SSPs) in compliance with NIST 800-18 & FISMA, reducing ATO approval time by 15%
  • Lead 15+ risk assessments, identifying security gaps and aligning remediation strategies per NIST 800-53 Rev 5 guidelines
  • Perform security audits and control testing on 10+ external services, ensuring compliance with FedRAMP, SOC2, and NIST frameworks, leading to successful Authorization to Use (ATU) approvals
  • Validate federal information system readiness via FIPS 199 and NIST 800-60 control categorizations
  • Develop Security Assessment Plans (SAPs), execute security interviews, documentation reviews, and control testing, ensuring compliance with NIST SP 800-53A Rev 5
  • Collaborate with system owners to complete and manage 30+ Plan of Action and Milestones (POA&M) items, ensuring compliance with continuous monitoring policies
  • Liaise with Security Operations Center (SOC) teams to validate vulnerability scans and ensure tracking consistency for security weaknesses
  • National Institutes of Health

Vulnerability Remediation Specialist

DLH
04.2023 - 01.2024
  • Company Overview: National Institutes of Health
  • Spearheaded 100+ vulnerability remediations, reducing high-risk security gaps by 30% across NIH systems
  • Implemented data sanitization (NIST 800-88, DoD 5200.28) for 200+ devices, ensuring full compliance with government data destruction policies
  • Provided security awareness training to 400+ employees, reducing security incidents by 10% and improving enterprise-wide cyber hygiene
  • Deployed device images integrated with EDR/XDR solutions, strengthening NIH’s threat detection capabilities
  • Managed Active Directory user access, ensuring efficient provisioning, de-provisioning, and access controls aligned with security policies
  • National Institutes of Health

Information Security Analyst I

Daly Computers Inc.
07.2022 - 04.2023
  • Conducted phishing analysis on suspicious emails, enhancing email security for users
  • Conducted network traffic analysis using Wireshark, investigating malicious activity and anomaly detection
  • Assessed and prioritized vulnerability risks based on CVSS scores and CISA guidance, aiding proactive patch management

IT Support Engineer

Daly Computers Inc.
09.2021 - 06.2022

• Change and reset passwords using Active directory.

• Create, manage and delete users and groups in Active directory.

• Provide Office 365 and other software application support.

• Troubleshoot and resolve basic networking issues.

Computer Field Technician

Worldwide Technical Services
05.2019 - 01.2021

• Diagnose and repair computer hardware and software issues.

• Image computers using a variety of methods.

• Install computer peripherals for users (monitors, keyboards, mouse, docking stations).

Education

Bachelor of Science - Information Technology

Towson University
Towson, MD
12-2019

Skills

  • NIST RMF, FedRAMP, Archer GRC, CSAM, SIEM, Nessus, Risk Recon, Prevalent, Virtual Machine, Service Now, Azure, Firewalls, Access Control Lists, AWS, Cloud Computing, Active Directory, Windows 10, Windows 11, Mac OS, Python, Microsoft Office, TCP/IP, FTP, SSH, HTTPS, SSL, DNS, DHCP, ICMP, OWASP, KnowBe4, Elastic, CVE, CVSS, IDS, IPS, Metasploit, Nmap, Burp Suite, A&A, SCA, POA&M

Certification

CompTIA Security

Securityclearance

Public Trust

Personal Information

Citizenship: U.S. Citizen

Timeline

Security Control Assessor

DLH
01.2024 - Current

Vulnerability Remediation Specialist

DLH
04.2023 - 01.2024

Information Security Analyst I

Daly Computers Inc.
07.2022 - 04.2023

IT Support Engineer

Daly Computers Inc.
09.2021 - 06.2022

Computer Field Technician

Worldwide Technical Services
05.2019 - 01.2021

Bachelor of Science - Information Technology

Towson University
Orane Dixon