Information security professional with proven track record in safeguarding digital assets and ensuring compliance with security standards. Known for strong focus on team collaboration and consistently achieving results. Reliable and adaptable, with expertise in risk management and threat mitigation.
Overview
15
15
years of professional experience
1
1
Certification
Work History
Information Systems Security Officer
Joint Chiefs of Staff (J7)
07.2023 - Current
Conducted vulnerability assessments to identify security risks in information systems.
Collaborated with cross-functional teams to address cybersecurity incidents effectively.
Plans and reports to J7 Chief Information Security Officer, DoD and JS CIO / J6 as appropriate and required, regarding management, control, coordination, and execution of the J7 Joint Training Enterprise Systems accreditation projects and services.
Administer the JTE accreditation project management process to ensure IT Specialist and system owners are successful in achieving accreditation and communicating needs and developing planning roadmaps and strategies.
Administer and monitors the application of the Enterprise Mission Assurance Support Service (eMASS) for J7 Risk Management Framework Portfolio. Assist, facilitates, maintains, monitors and update system entries to ensure compliance with RMF standards.
Performs a variety of JTE accreditation technical support, advisory duties and consultant support for the entire JTE portfolio and regular interfaces with DoD CIO program managers, Joint Staff program managers, and other partners/stakeholders (CCMD's, Services, DoD Agencies). Reviews DoD and JS policy and enforces command policies and procedures for implementation of CS laws, regulations, polices and guidelines.
Develops and coordinates training programs that ensures J7 JTE system staff have an appropriate level of awareness and understanding of their accreditation requirements and responsibilities
Oversees the execution of the accreditation program, ensuring the accreditation records for J7 JTE system under JS/J7's areas of responsibilities are properly maintained.
Assists in representing J7 on assessment, authorization, and accreditation matters.
Attends various technical and functional meetings where there are diverse viewpoints, goals or objectives and represents the J7 CISO position on cybersecurity issues to consultants, contractors, vendors, professional associations, and other agencies.
Make decisions and develops alternative solutions based on obtaining J7 Joint Force Development mission goals / objectives.
Participates in DoD meetings or presentations to discuss problems and procedures of considerable importance.
Writes, edits, reviews, and publishes cybersecurity documents to include regulations, polices, procedures, and memorandums.
Performs technical, analytical and advisory functions pertinent to the development of policies, plans and processes, ensuring work accomplished is in compliance with the laws.
Interprets and explains Cybersecurity laws, regulations, policies and guidelines.
Identifies ways to provide greater effectiveness and efficiencies. Works on special projects such as performing analysis on complex cybersecurity business issues, identifying quality control metrics and preparing highly techinical briefs.
I am the Liaison with other cybersecurity professionals to identify gaps in data and processes.
Incident Response Mgr./RMF Practitioner/ISSO.
US Navy - NAVFAC Midlant
01.2018 - 07.2023
Assists the command ISSM in ensuring that the command security posture is implemented and maintained for command information system programs.
Implemented confidentiality, integrity and availability of systems, networks and data through planning, analysis, development, maintenance and enhancement of information system security program, policies, procedures and tools.
Advise Command ISSM on cyber security incidents, risks, or policy changes that affect the command mission, systems or program.
Provide support for multiple components or CISP, Command Cybersecurity Program, Architecture, requirements, objectives and polices, cybersecurity personnel and cybersecurity processes and procedures; drafting, modifying and maintaining command core cybersecurity policies.
Coordinating of security issues with other commands and higher echelon and external organization to address cybersecurity requirements.
Reviewing IT and control systems programs to assess overall compliance with cybersecurity plans, policies and alignment with business and mission requirements, while modifying IT plans and policies to respond to changes in the commands business or mission processes or change in legislation or regulatory requirements.
I apply information system security measures and procedures, including reporting incidents to the Commander, Command ISSM and appropriate reporting chains and coordinating system-level responses to unauthorized disclosures in accordance with DoD Controlled Unclassified Information (CUI).
Execute the administration of Command Cyber IT/Cybersecruity Workforce (CSWF) Program.
Ensure that information ownership responsibilities are established for each system, to include accountability, access approvals, and special handling requirements, ensuring all cybersecurity components have completed the appropriate evaluation and configuration process prior to integration or connection to an IS or PIT system in accordance with DoD Instruction 8510.01, Risk Management Framework for DoD information Technology and OPNAV Instruction 5239.ID, Navy Cybersecurity Program.
Developed project documentation; including statement of work business case analyses charter, scope, schedule, cost, risk stakeholder and communication management plans.
Work with manager and users to scope and define project requirements and deliverables that are necessary to meet the business and cybersecurity needs of the organization development of plans of action and milestones, complying with policies, directives, guidelines standards and budgets; coordination of multiple related project activities and resources, monitors progress and resources to mitigate risk and to properly manage customer expectation, institute quality assurance processes, initiate and facilitate regular project reviews, establish metrics to be used in evaluating success and in identifying follow-on corrective measure to be employed as well as compiling documentation in historical repository for future organizational use an reference.
Cyber Warfare Info. Systems Mgr./Systems Security
US Navy - Commander Afloat Training Group (ATG)
11.2013 - 08.2017
Navy Sustainment and Basic Phase Communications and Cyber Security Assessments, Training and Certification Program Scheduler for over 350 Atlantic fleet units.
Type Commander's agent for conducting pre-deployment training and evaluation of Atlantic Fleet Crew proficiency in all warfare areas and required shipboard competencies.
Maintained and participated in continuous learning program as described in SECNAVINST 1543.2 a Cyber IT/CSWF related continuous learning annually documented in a current individual development plan.
Inspector for all DoD sea based facilities to evaluate their effect on the security posture of the Department of Defense Information Networks (DoDIN).
Evaluated information systems security features and settings against security requirements utilizing Security Technical Implementation Guide (STIG) checks as released by DISA and DOD information Assurance Vulnerability Alerts (IAVA).
Applied Information Assurance (IA) expertise in preparation and review of system accreditation documentation for base level communication systems as well as plan and execute techinical cyber assessments.
Preformed training, support and assistance with tactics, techniques and procedures for site assist visits on DoD network security unclassified and classified assets.
Brief inspection results threat validation and reporting incidents and threats to the site's leadership to include Flag level Officers in reference to certification and accreditation.
Provided leadership and direction to IT and ET personnel.
Performed information technology related tasks that required attention to detail, customer service, oral communication and unique problem solving skills referencing Operational Risk Management and concept and application.1
Maintains required Information Technology (IT) and DISA qualification while traveling to alternate CONUS/OCONUS locations for inspections.
Coordinate the modification, and utilization of multiple network, and integrate all phases of projects and programs.
Commo/IA Mgr./ISSM Mgr./COMSEC /EKMS Mgr.
US Navy HSV-2 (SWIFT-GOLD)
12.2010 - 11.2013
Created the DoD Information Assurance Certification and Accreditation Process (DIACAP) package necessary for Unclassified/Classified Network operations to include all command directives, instructions, contingency plans, and required policies for over 25 systems.
Drafted and implemented networked security policies that protected all onboard information systems and data while also ensuring their availability, authentication, confidentiality, reliability, and integrity.
Evaluated, disseminated, and monitored IT security tools, products, services and procedures IAW DOD/DON regulations.
Coordinated the collection and preservation of data for investigations of misuse or abuse. Conducted internal investigations with Senior Leadership to ensure the implementation of corrective actions have been taken.
Conducted more than 50 Anti-terrorism drills, entry/exit inspections and over 200 hrs. of training to ships force to enforce access control and maintain the integrity and physical security of secure sites.
Apply knowledge of diverse concepts, relationships, principles, and theories to plan, design solutions, evaluate and install network and telecommunications equipment, systems, and network based on requirements analysis, topologies and protocols.
Recommend resource allocation; Performed daily security audits and random security inspections development and utilization of testing methodology for networked systems.
Assisted, review and recommended the implementation of security policy statements and operational orders.
Conducted over 50 inspections to ensure proper handling and stowage of classified material and spaces.
Performed duties as Information Assurance Officer. Ensured the enforcement of Information Systems security procedures and all relevant documentation was updated.
Developed, published, and maintained Information Assurance plans, policies and procedures.
Evaluated and ensured Information Systems Security controls and procedures were IAW all Federal Law, DOD, DON and NATO government policies, directives and other regulatory materials governing information security programs for personnel, physical, emanations, encryption, hardware, software, telecommunications and procedures for operational information systems capabilities.
Conducted System Security reviews for vulnerability and assessments.
Enhanced existing networks through risk assessments; advised senior leaders on best practices for all networks.
Led 5-member team in network and systems administration of multiple unsecured and secure network circuits; conducted network maintenance, administration, infrastructure management, circuit control, data systems management and managed internet protocol systems across radio, network and VoIP platforms.
Provided command personnel contract input for required IT systems, ensuring contracting support personnel were IA compliant and contract requirements were met as agreed.
Education
BA of Science Info. System Mgmt. And Cybersecurity
ITT Technical Institute
Norfolk, VA
12-2011
Skills
Exceptional skills in troubleshooting complex technical problems with consideration for cost-effective standard operating procedures, management goals, and client satisfaction
Team builder and critical thinker with great technical writing experience
Effective Oral and Research experience
Interprets and applies IA and IT policies, processes and guidelines
Experienced in IT resource planning, management, technical oversight and services delivery.
Experience with Information Assurance theories, practices, methods and techniques in order to operate network equipment
Experience working extensively with IT security certification and accreditation requirements in order to provide security awareness training
Experience in applying Information Technology (IT) network security operation principles, as well as the ability to develop new methods and procedures to protect data and networks from becoming compromised
Certification
CompTIA Security+ CE Certified (Aug. 2018)
ISC2 Certified in Cybersecurity (Sep. 2026)
CompTIA CySA+ (Testing in the near future)
ISACA CISM Certified Information Security Manager (Testing in 6 Months)
Qualifications
Security Clearance: TS/SCI (active)
Department of Defense 8140 CSWF Qualified Cyber
Personnel/Security Inspection Reviewer Certified
Defense Information Security Agency (DISA) Windows Security Readiness Review Training
DISA Host Based Security System (HBSS) Security Readiness Review Training
DISA EXCHANGE Security Readiness Review Training
DISA MOBILITY Security Readiness Review Training
Timeline
Information Systems Security Officer
Joint Chiefs of Staff (J7)
07.2023 - Current
Incident Response Mgr./RMF Practitioner/ISSO.
US Navy - NAVFAC Midlant
01.2018 - 07.2023
Cyber Warfare Info. Systems Mgr./Systems Security
US Navy - Commander Afloat Training Group (ATG)
11.2013 - 08.2017
Commo/IA Mgr./ISSM Mgr./COMSEC /EKMS Mgr.
US Navy HSV-2 (SWIFT-GOLD)
12.2010 - 11.2013
BA of Science Info. System Mgmt. And Cybersecurity
Associate Chief Security Officer/Information Systems Security Officer at Federal Bureau of Investigation, FBIAssociate Chief Security Officer/Information Systems Security Officer at Federal Bureau of Investigation, FBI
Senior Information Systems Security Officer (ISSO) and Security Subject Matter Expert (SME) at Interim Business Solutions, LLCSenior Information Systems Security Officer (ISSO) and Security Subject Matter Expert (SME) at Interim Business Solutions, LLC