Summary
Overview
Work History
Education
Skills
Certification
Military Service
Timeline

Calvin Pan

Haymarket,VA

Summary

Cybersecurity solution architect with top-secret clearance, adept at aligning policy with practical implementation. Combines technical expertise and enterprise architecture to design compliant and effective security solutions. Demonstrated success in delivering security transformations for federal agencies by integrating technical capabilities with mission objectives. Experienced in infrastructure management, technical solution oversight, and proposal review, contributing significantly to product development lifecycles.

Overview

11
11
years of professional experience
1
1
Certification

Work History

Cybersecurity Solutions Architect

Booz Allen Hamilton
McLean, VA
01.2019 - Current

Deliver advanced cybersecurity solutions for federal agencies in implementing and maturing CDM, end-to-end, with implementation solutions, ensuring proper integration of security tools, and validation of data ingestion pipelines from sensors to dashboards. Manages cross-functional teams to deliver asset management, vulnerability scanning, NAC, and IdAM capabilities to align with DHS/CISA requirements. Provides technical oversight for Treasury, HHS, and VA programs, bridging tool deployment with operational security needs to meet RFS deliveries.

Delivered Projects:

National Institutes of Health (NIH) - Asset Management Analysis of Alternatives (AoA)

  • Supported the National Institutes of Health (NIH) in conducting an enterprise-wide analysis of alternatives (AoA) to evaluate potential replacement options for existing asset management tools and business processes. Interviewed and collaborated with various participating Institutes and Centers (ICOs) to document operational requirements and identify pain points. Conducted a comparative analysis of alternative solutions, assessing them against the current capabilities, interoperability, and cost-benefit factors.

Department of Health and Human Services (HHS) - CDM Program Gap-Filled

  • Task 2: Federal Information Security Modernization Act (FISMA) Boundary Association. Align identified assets and their attributes as part of the Master Device Record (MDR) with the agency's appropriate FISMA system boundary to ensure that assets are aligned with authorized systems and effectively communicate risks to system owners.

Defense Information Systems Agency (DISA) - SASE Client Integration / DoD IPv6 Modernization

  • Researched and tested client provisioning and conditional access for DISA's SASE edge deployment using Versa Networks. Evaluated zero-trust capabilities, including device posture verification, geo-based restrictions, and session timeout configurations, to ensure compliance with DoD STIG requirements. Developed PowerShell scripts to automate and validate provisioning processes.
  • Researched and mitigated critical risks in the DoD's IPv6 modernization, focusing on Flow Label vulnerabilities for secure IPv6 implementation.

Department of Veterans Affairs (VA) - FISMA Containerization

  • Performed assets discovery, analysis, and recommending automated solutions for real-time risk visibility while ensuring compliance with federal mandates. Aligned over 2 million assets, and exceeded the 85% metric.

Department of the Treasury - CDM Program Maturation:

  • RFS-DEFEND_005: Focuses on Network Access Control (NAC), which includes the discovery, design, and deployment of basic NAC.
  • RFS-DEFEND_006: Focuses on "What is on the network" Asset Management capability domain that covers HWAM/SWAM, CSM, VUL, and EMM.
  • RFS-DEFEND_007: Addresses “Who is on the Network” with IdAM capabilities to manage users and accounts, which comprises four components of TRUST, BEHAVE, CRED, and PRIV.

Information Security Engineer

County of Loudoun DIT
Leesburg, VA
10.2016 - 01.2019

Protected critical county infrastructure and sensitive data as Loudoun County's Information Security Engineer by implementing comprehensive cybersecurity capabilities across asset management, vulnerability assessment, network access control (NAC), continuous monitoring, incident mitigation, and firewall management domains.

  • Established and maintained a complete asset inventory with risk-based categorization, enabling prioritized vulnerability scanning, and patch management across all networked systems.
  • Designed and enforced NAC policies to segment and secure county networks, while managing next-generation firewall configurations to block emerging threats.
  • Developed a continuous monitoring program using SIEM analytics and log correlation to detect real-time anomalies. Led rapid incident response operations, from the initial event through root cause analysis, and mitigation.

Information Technology Specialist

Chesterfield County IST
Chesterfield, VA
09.2014 - 10.2016

Supported Chesterfield County's IT operations and security infrastructure by delivering comprehensive asset management solutions. Addressed hardware/software issues and network connectivity challenges while implementing enterprise-wide system upgrades that improved operational efficiency.

  • Contributed significantly to cybersecurity enhancements through disciplined patch management cycles, enterprise endpoint protection deployment, and system hardening that reduced vulnerabilities.
  • Played a vital role in the successful county-wide Windows 10 migration by performing standardized system imaging, assisting with access control implementation, and validating post-deployment security configurations.
  • Worked collaboratively with IT teams to maintain 99.9% system availability, while establishing protective measures that safeguarded sensitive government data and complied with security policies.

Education

Master of Science - Cybersecurity and Information Assurance

Western Governors University, Salt Lake City, UT
01.2017

Bachelor of Science - Information Security

Western Governors University, Salt Lake City, UT
01.2016

Skills

Security Domains: Asset Management (AM) Configuration Security Management (CSM) Network Access Control (NAC) Vulnerability Management (VUL) Identity & Access Management (IdAM) FISMA Containerization

Frameworks: Continuous Diagnostics & Mitigation (CDM) Zero Trust Artchitecutre (ZTA) NIST DISA STIG

Technical Tools: ForeScout BigFix Tenable Qualys LogRhythm Splunk Palo Alto Check Point RSA 2FA SailPoint Cisco ISE McAfee Security Suite SonicWall VPN Versa SASE Axonius

Certification

  • Artificial Intelligence Enablement
  • ICAgile Certified
  • Computer Hacking Forensic Investigator (CHFI)
  • Certified Ethical Hacker (CEH)

Military Service

  • US Navy, Active Duty, 06/01/92, 06/01/96
  • US Navy, Active Reserve, 06/01/96, 12/01/01

Timeline

Cybersecurity Solutions Architect - Booz Allen Hamilton
01.2019 - Current
Information Security Engineer - County of Loudoun DIT
10.2016 - 01.2019
Information Technology Specialist - Chesterfield County IST
09.2014 - 10.2016
Western Governors University - Master of Science, Cybersecurity and Information Assurance
Western Governors University - Bachelor of Science, Information Security
Calvin Pan