Summary
Overview
Work History
Skills
Certification
Timeline
Generic

Alex-Michael Eddings

Forney,TX

Summary

Accomplished cybersecurity professional with over 13 years of experience specializing in risk management and compliance while possessing a broad skill set across multiple areas of the cybersecurity domain. Demonstrated expertise in configuring systems, developing robust security policies, and conducting comprehensive audits to ensure adherence to industry standards and regulations. Proven ability to manage cross-functional teams, fostering collaboration to enhance security practices and mitigate risks effectively. Committed to continuous improvement in security posture and risk management processes, leveraging a wealth of knowledge to drive organizational success.

Overview

17
17
years of professional experience
1
1
Certification

Work History

IT Consultant

Microsoft
07.2021 - 06.2024

Served as an IT Consultant specializing in NIST and RMF compliance within Azure cloud environments, supporting clients across DoD, Federal, and Commercial sectors. Led the development of Authority to Operate (ATO) packages in the cloud, executing thorough risk assessments, policy configurations, and security compliance evaluations. Created an organizational process that reduced ATO package creation time by up to 50% and increased success rate. Established an in-house training program to promote knowledge transfer and consistent ATO support across teams. Leveraged extensive expertise with Azure tools and Azure FedRAMP documentation to ensure effective control inheritance and compliance.

Classified Cyber Security Senior

Lockheed Martin
07.2020 - 04.2021

Managed Special Access Program (SAP) security for compliance with NIST 800-53 Rev 4 and JSIG. Successfully researched, configured, and implemented a cost-effective SIEM system for centralized logging and event management. Developed and delivered comprehensive SAP training programs to site personnel, ensuring both technical and non-technical staff maintained compliance awareness. Authored organizational policies, architectural documentation, and project tracking tools to streamline RMF and project compliance efforts.

Senior Advanced Information Assurance Engineer

Acara Solutions
01.2020 - 05.2020

Proficient Information Assurance Engineer with extensive experience managing security operations and ensuring regulatory compliance. Fine-tuned and maintained an IBM QRadar SIEM for over 1,000 hosts, enhancing threat detection and response capabilities. Developed a comprehensive Organizational Contingency Plan and coordinated an enterprise-wide functional exercise in line with NIST 800-37, reinforcing organizational resilience. Conducted detailed reviews of NIST 800-53 Rev 4 controls for compliance, and performed system hardening and technical security assessments across Windows 10, Windows Server 2016, and Red Hat Enterprise Linux environments. Leveraged advanced Excel power queries and macros to streamline data analysis for more efficient decision-making.

Intermediate Cybersecurity Engineer (Security Control Assessor)

Netizen Corporation
12.2018 - 12.2019

Performed over 30 Authority to Operate (ATO) audits for Department of Defense (DoD) System raging in Security Classifications. Conducted in-depth technical configuration reviews of over than 500 devices, including workstations, servers, and networking equipment, to validate security posture and compliance. Diligently assessed organizational policies, such as Incident Response, Continuity of Operations, and System Security Plans (SSPs), for risk and adherence to standards. Evaluated system and architectural documentation to ensure security accuracy and operational effectiveness, and produced management reports detailing risks and recommending mitigation actions.

Cybersecurity Engineer (Security Control Assessor)

BreakPoint Labs
12.2017 - 12.2018

Conducted comprehensive RMF Security Assessments and authored Security Assessment Reports (SAR) for over 18 DoD enterprise systems and networks. Utilized Security Content Automation Protocol (SCAP) and Secure Technical Implementation Guidance (STIG) standards to enhance security across multiple platforms, including Windows workstations and servers, McAfee Host-Based Security System (HBSS), Layer 2/3 network infrastructure, and SQL/Oracle databases. Provided on-site support to OCONUS clients and delivered high-level security briefings to executive leadership.

Information Assurance Specialist

Arctic Slope Regional Corporation
05.2017 - 10.2017

Served as the primary security officer for multiple networks across various classification levels, ensuring comprehensive security management and compliance. Developed critical documentation, including network architecture diagrams, Memorandums of Understanding (MOU), Functional Support Agreements (FSA), Memorandums for Record (MFR), and Plan of Action and Milestones (POA&Ms), to accurately represent and maintain the security posture of Information Systems (IS) and networks. Configured, updated, and managed the vulnerability management program using Assured Compliance Assessment Solution (ACAS) to identify and mitigate security risks. Acted as Alternate Network Administrator, supporting System Administrators with technical tasks and network maintenance as needed.

Information Systems Security Officer

ManTech
09.2016 - 04.2017

Conducted Certification and Accreditation (C&A) activities in alignment with NIST 800-37 standards for multiple systems, utilizing Governance, Risk, and Compliance (GRC) Tools like Xacta to streamline compliance processes. Responded promptly to Information Security Vulnerability Management (ISVM) notifications, ensuring that information systems adhered to TSA and DHS MD 4300 IT policies. Developed detailed architectural diagrams in accordance with DHS guidelines to accurately represent system security configurations. Collaborated with third-party service providers and leveraged FedRAMP standards to ensure compliance of cloud services, enhancing the overall security posture of the organization.

Information System Security Officer/Network Administrator

Janus Research Group
07.2014 - 08.2016

Served as the Senior ISSO and Network Administrator for the Battle Lab at Fort Huachuca, overseeing the security and operational integrity of network systems. Configured and managed various Cisco switches and routers, implementing VPNs, VTP, ACLs, VLANs, DHCP, multicast, port security, and routing protocols (EIGRP/OSPF). Utilized tools such as Wireshark and Multicast Hammer to analyze and inspect network traffic effectively. Acted as the incident response manager, conducting Continuity of Operations (COOP) and incident response training and exercises to prepare teams for potential security incidents. Led a team of seven ISSOs, providing guidance, mentorship, and oversight to ensure compliance with security standards and consistency across operations. Played a pivotal role in the acquisition of multiple Authorities to Operate (ATOs), significantly enhancing the organization’s security posture.

U.S. Army Reserve, Transportation Management Coordinator/Information Technology Specialist

U.S Army Reserve
04.2007 - 04.2015

Conducted automation systems support for the 80th Training Command, ensuring the seamless operation of information technology systems. Supervised, installed, operated, and performed unit-level maintenance on multi-functional and multi-user information processing systems, as well as peripheral equipment and associated devices in both mobile and fixed facilities. Simultaneously executed analyst and information assurance functions to maintain system integrity and security. Deployed and redeployed system images in accordance with the Army Gold Master program, ensuring compliance with Army standards. Analyzed unresolved trouble tickets to identify and resolve system problems effectively. Managed over 800 information systems valued at more than $860,000 in Active Directory, demonstrating strong responsibility for critical IT assets.

Skills

  • System Hardening (STIGs/SCAP, CIS, BBPs)
  • EMASS/ Xacta/ CSAM
  • Zero Trust Architecture
  • Vulnerability management (ACAS/Nessus/Nexpose)
  • DoDI 851001 (RMF), NIST, JSIG
  • Security Information and Event Management (SIEM) (QRadar, FireEye, etc)
  • Network Security
  • Security Auditing
  • Microsoft Azure
  • Compliance Management
  • Vulnerability Assessment
  • Security Architecture

Certification

  • Certified Information Systems Security Professional (CISSP)
  • Security+ Certified
  • Network+ Certified
  • Active Top Secret (TS) DoD Security Clearance
  • SC-100: Microsoft Cybersecurity Architect

Timeline

IT Consultant

Microsoft
07.2021 - 06.2024

Classified Cyber Security Senior

Lockheed Martin
07.2020 - 04.2021

Senior Advanced Information Assurance Engineer

Acara Solutions
01.2020 - 05.2020

Intermediate Cybersecurity Engineer (Security Control Assessor)

Netizen Corporation
12.2018 - 12.2019

Cybersecurity Engineer (Security Control Assessor)

BreakPoint Labs
12.2017 - 12.2018

Information Assurance Specialist

Arctic Slope Regional Corporation
05.2017 - 10.2017

Information Systems Security Officer

ManTech
09.2016 - 04.2017

Information System Security Officer/Network Administrator

Janus Research Group
07.2014 - 08.2016

U.S. Army Reserve, Transportation Management Coordinator/Information Technology Specialist

U.S Army Reserve
04.2007 - 04.2015
Alex-Michael Eddings