{"id":138,"date":"2021-09-15T17:32:51","date_gmt":"2021-09-15T17:32:51","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/cyberimpact1\/?page_id=138"},"modified":"2024-08-01T15:03:18","modified_gmt":"2024-08-01T15:03:18","slug":"cyse-368","status":"publish","type":"page","link":"https:\/\/sites.wp.odu.edu\/xavierlesane\/cyse-368\/","title":{"rendered":"CYSE 368"},"content":{"rendered":"\n<h1 class=\"wp-block-heading\">Cybersecurity Internship<\/h1>\n\n\n\n<p>This course allows students to volunteer to work in an agency related to cybersecurity. Students must volunteer for 50 hours per course credit and complete course assignments.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Course Material<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Reflection #1<\/h2>\n\n\n\n<p>Reflection #1<\/p>\n\n\n\n<p>Xavier Lesane<\/p>\n\n\n\n<p>This summer marked the beginning of my first IT internship. The company I was interning for was Dephiant Consulting Inc. Unlike a traditional internship my peers may have taken, my work is being done virtually in an online environment. This is great as it alleviated concerns I had with balancing this internship with my real-life job and has become great practice in workload balancing. When I started I was set up with my own corporate email and immediately put in contact with who would be my supervisor for the remainder of my time here.<\/p>\n\n\n\n<p>I chose to work for this company because they are relatively small and are willing\/allowing me to immerse myself in many aspects of cybersecurity, helping me build a personal connection and discover what I want to see myself doing in IT in the future. The first task assigned to me was reading and becoming familiar with industry standards such as the NIST Cybersecurity Framework 2.0 and the HIPAA privacy rules just to name a couple. I combined these documents with the services my company provides on its website to get an idea of how these standards are applied throughout the company.&nbsp;<\/p>\n\n\n\n<p>During my first 50 hours, I was also introduced to SIEM dashboards, a software I did not know existed during my time in college classrooms. I was given hands-on experience with reading\/navigating device logs and I was shown how to organize events using the Splunk software. So far this internship is inspiring me to continue learning all I can in IT and is ensuring I have made the right career choice.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Reflection #2<\/h2>\n\n\n\n<p>Reflection #2<br><\/p>\n\n\n\n<p> Xavier Lesane<\/p>\n\n\n\n<p>For the previous month of my internship, I have been shadowing a Security Engineer and a SOC Analyst. During this time I have been given assignments in relation to Kusto Query Language and how to use it when completing Azure active directory tasks. Before this internship, my college courses only familiarized me with Structured Query Language so everything was more of a learning experience, but I did find KQL statements much easier to grasp.<\/p>\n\n\n\n<p>Many of the assignments that I have completed involved Splunk SOAR (security orchestration, automation, and response). I learned about playbooks (manual vs automatic), SOAR artifacts, and the VPE (visual playbook editor) and how I could configure the VPE to run automated tasks that SOAR playbooks could use to gather and parse information from events such as phishing alerts. One of my favorite aspects of seeing SOAR in practice was how it was able to automate tasks that I was previously given such as scanning URLs and files for malicious activity and performing reputation checks. I also liked how it gave more information than a typical SIEM program.<\/p>\n\n\n\n<p>Besides observing SOAR at work I was also given assignments on SIEM log management and using EDR. I handled simulated incidents and was able to view how an incident report would be generated after I investigated the alerts; such as SQL injections in Apache log files. Most of the simulated incidents I was given involved familiarizing myself with VirusTotal, scanning files and URLs in Any.Run, and learning how the company network was configured as so I wouldn\u2019t flag false positives as legitimate threats.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Reflection #3: An interview with the Director of Cybersecurity<\/h2>\n\n\n\n<p>Xavier Lesane<\/p>\n\n\n\n<p>Reflection #3<\/p>\n\n\n\n<p>Interview with Mentor<\/p>\n\n\n\n<p>This week in my internship I got the chance to interview my mentor Socorro Diaz-Perry on her role and thoughts on the company and cybersecurity industry. Below is the interview.<\/p>\n\n\n\n<p><strong>What are your responsibilities?<\/strong><\/p>\n\n\n\n<p>I am responsible for overseeing protection and governance of Dephiant Consulting\u2019s technical assets, including information\/data, computer systems, and Point of Sales systems, to ensure components meet security and regulatory requirements.&nbsp; I develop the vision and strategies while managing the implementation of global security policy, guidelines, and procedures in collaboration with IS leaders and stakeholders.<strong>&nbsp;<\/strong><\/p>\n\n\n\n<p>My day-to-day responsibilities are to build and lead multiple teams of various levels of security professionals to deliver exceptional security solutions and operational processes designed to protect our clients from internal and external threats through the prioritization and implementation of project-related activities. I also prepare IT Security Briefings &amp; information regarding new risks, threats, trends and laws periodically to the Cyber Security Steering Committee and clients.<\/p>\n\n\n\n<p><strong>What are the most important skills needed by someone in your field?&nbsp;<\/strong><\/p>\n\n\n\n<p>Excellent problem-solving skills and the ability to work under pressure during high-stress situations. Strong interpersonal and written and verbal communication skills, capable of interacting with both technical and non-technical stakeholders. Basically be really good at customer service; and the reason why I say that is, you can have all the knowledge in the world but when you\u2019re trying to relay information to a customer, but if they feel like you\u2019re belittling them then they won&#8217;t receive the information that you&#8217;re trying to give them. Our group includes experienced employees and consultants located throughout the country dedicated to helping clients with preventing, detecting, and responding to security threats that may affect their critical systems and data. We serve a diverse client base within a variety of industries, and we are relied upon to provide expertise within areas of security testing, architecture, governance, compliance, and digital forensics. You must have a deep understanding of cybersecurity concepts, frameworks, and standard methodologies. The ability to analyze threat landscapes, identify vulnerabilities, and develop mitigation strategies.<\/p>\n\n\n\n<p><strong>What are good entry-level jobs that will help you gain experience in your field?<\/strong><\/p>\n\n\n\n<p>Help desk. You get everything at a help desk, people come in with a wide range of issues. While working in this role, volunteer to shadow or assist with other tasks in other IT and Cybersecurity departments. Familiarize yourself with the various domains within cybersecurity, such as network security, ethical hacking, incident response, and risk management. Understanding these areas and staying up-to-date on the latest trends, publications, and developments will help you identify your specific interests and choose the right path for your career transition.<\/p>\n\n\n\n<p><strong>What attracted you to this career path?<\/strong><\/p>\n\n\n\n<p>I worked in telecom and during that time there were mass layoffs in the late 90\u2019s &#8211; early 2000\u2019s. I went to Johns Hopkins University to be an admin assistant because I figured everyone needs an admin assistant in the IT department. I asked the techs to teach me how to do basic things and from there stemmed my IT career from admin assistance to basically helping people do password resets and from there it went on. All of my training I got basically on the job so I went the unconventional route pivoting into a different career from telecom and wanting to help people get to do the things they need to do to be productive in their jobs.<\/p>\n\n\n\n<p><strong>What are the biggest challenges you face in your typical workday?<\/strong><\/p>\n\n\n\n<p>Sometimes people and communicating with teams and stakeholders could be seen as a challenge. There could be the issue that everyone is not on the same page about a project and it\u2019s your job to try to get everyone on the same page to complete projects on time. Another is when there are limited resources such as budget constraints where we are not able to afford the latest tech, toys, and gadgets.<\/p>\n\n\n\n<p>Another may be some occasions where we may need to work evenings or weekends, or when there are unexpected security problems, such as the recent Crowdstrike denial of service event or other deadlines to meet.<\/p>\n\n\n\n<p><strong>What are the biggest rewards of your job?&nbsp;<\/strong><\/p>\n\n\n\n<p>Helping people, the clients, and departments within the organization be able to achieve the things they need to do, to be productive, and knowing I was an element to that. I definitely enjoy having amazing cohesive teams within my sector and being able to provide a welcoming environment that allows you to have autonomy and self-direction when creating solutions.<\/p>\n\n\n\n<p><strong>What is the culture like at Dephiant Consulting?<\/strong><\/p>\n\n\n\n<p>DCI allows us the freedom to build a workplace that is challenging, inspiring, and motivating. I would say it is a team environment because we work to support the country, so everything and everyone plays a part in that be it if someone is coming to us for assistance then we must be sure our network is up to par, that our applications and software programs are working properly, and that everything is in tip-top shape and if not that we find viable solutions. From the top down, it\u2019s shown by leadership that we\u2019re valued here and positive results come from working together to overcome challenges, making each employee grow in their knowledge and skill.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Final: Internship Reflection<\/h2>\n\n\n<a href=\"https:\/\/sites.wp.odu.edu\/xavierlesane\/wp-content\/uploads\/sites\/26046\/2024\/08\/CYSE-368-Final-Paper.pdf\" class=\"pdfemb-viewer\" style=\"\" data-width=\"max\" data-height=\"max\"  data-toolbar=\"bottom\" data-toolbar-fixed=\"off\">CYSE-368-Final-Paper<br\/><\/a>\n<p class=\"wp-block-pdfemb-pdf-embedder-viewer\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity Internship This course allows students to volunteer to work in an agency related to cybersecurity. Students must volunteer for 50 hours per course credit and complete course assignments. Course Material Reflection #1 Reflection #1 Xavier Lesane This summer marked the beginning of my first IT internship. The company I was interning for was Dephiant&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/xavierlesane\/cyse-368\/\">Read More<\/a><\/div>\n","protected":false},"author":21876,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/xavierlesane\/wp-json\/wp\/v2\/pages\/138"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/xavierlesane\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/xavierlesane\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/xavierlesane\/wp-json\/wp\/v2\/users\/21876"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/xavierlesane\/wp-json\/wp\/v2\/comments?post=138"}],"version-history":[{"count":5,"href":"https:\/\/sites.wp.odu.edu\/xavierlesane\/wp-json\/wp\/v2\/pages\/138\/revisions"}],"predecessor-version":[{"id":328,"href":"https:\/\/sites.wp.odu.edu\/xavierlesane\/wp-json\/wp\/v2\/pages\/138\/revisions\/328"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/xavierlesane\/wp-json\/wp\/v2\/media?parent=138"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}