Accomplished Digital Forensic Examiner well-educated in conducting digital investigations, data recovery and electronic discovery. Well-rounded and conscientious professional with expertise in writing concise forensic examination reports and case notes and utilizing technical analysis to maintain organization's capabilities. Recognized as expert witness in area of forensic analysis and digital evidence collections in multiple federal and state jurisdictions.
Overview
25
25
years of professional experience
4
4
years of post-secondary education
6
6
Certificates
Work History
Sr. Technical Exploitation Officer
Defense Intelligence Agency, DIA
07.2018 - Current
Managed and lead multiple digital forensic teams through training and deployments to North America, Southeast Asia, Southwest Asia, and Europe; These teams included expert level digital forensic examiners that cover full spectrum of forensic capabilities. Additionally, expertly led five overseas forensic detachments that responded throughout Middle East, Europe, and INDOPACOM. Major roles included Technical Exploitation Chief in Iraq and Afghanistan, Readiness and Training Leading Chief, and Senior Technical Officer.
Served as Senior Digital Forensic Examiner for Technical Exploitation Division at National Media Exploitation Center. Oversaw operations and training for digital forensics, data recovery, software reverse engineering, software development, multimedia forensics, and lab maintenance & training. Served as senior technical officer conducting full cycle national digital forensic & technical exploitation foreign intelligence collection activities in response to national level intelligence requirements.
Performed full cycle digital forensic activities on 4000 devices which led to identification and capture of100 terrorist members worldwide.
Fostered strategic partnerships with NATO allies, intelligence community stakeholders, federal law enforcement (FBI, DHS, DC3, CIA) and technology providers to enhance NMEC's digital forensic and technical exploitation capabilities and expand their worldwide presence.
Maintained and tracked $11 million worth of government equipment as hand receipt account holder. Used DoD software and hardware acquisition process for procuring new forensic lab equipment from small software items to large scale x-ray systems.
Developed division level forensic standard operating procedures based off policies and procedures that govern computer forensic operations in intelligence community and federal law enforcement. Adjusted business requirements based off changing digital forensic techniques and operational requirements.
Utilized advanced technical tools for effective data collection, analysis, and visualization of complex information sets.
Improved internal communication channels by developing standard operating procedures for efficient information flow among team members.
Kept abreast of technological advancements in field of technical exploitation, incorporating innovative approaches into daily workflows as appropriate.
Engaged with international counterparts to share intelligence findings and coordinate joint efforts against common adversaries.
Performed malware analysis on suspicious files, identifying threats and assisting in incident response efforts.
Evaluated new software tools for integration into forensic analysis workflow, enhancing overall investigative capabilities.
Participated in multi-disciplinary teams for complex cases, collaborating with other experts to provide comprehensive investigative support.
Mentored new hires on proper digital forensic methodologies and procedures, strengthening team cohesion and effectiveness.
Enhanced digital forensic investigation efficiency by implementing advanced analytical tools and techniques.
Managed complex cases involving multiple devices and terabytes of data, delivering thorough analyses under tight deadlines.
Provided technical support to clients during sensitive investigations, maintaining clear communication and fostering positive relationships.
Maintained chain-of-custody documentation for all collected evidence, ensuring admissibility in court proceedings.
Delivered high-quality training programs, enhancing employee skill sets and contributing to professional development efforts.
Collected, preserved and analyzed evidence found at crime scenes
Improved overall department efficiency by streamlining processes and implementing new policies
Sr. Digital Forensic Examiner
Foxhole Technology
06.2017 - 07.2018
Led digital forensics initiative while performing 50 digital forensic investigations reporting to CIO, Secretary of Education, and Office of Inspector General.
Investigations stemmed from misuse of government equipment, improper release of government proprietary information, intrusions, and malware analysis.
Performed malware analysis on suspicious files, identifying threats and assisting in incident response efforts.
Assisted legal teams with e-discovery requests, ensuring timely delivery of relevant electronic documents for litigation purposes.
Assisted in designing and implementing secure evidence storage system, preserving integrity of digital artifacts for future analysis.
Recovered lost or deleted data from various digital devices, enabling clients to retrieve valuable information and mitigate potential losses.
Managed complex cases involving multiple devices and terabytes of data, delivering thorough analyses under tight deadlines.
Enhanced digital forensic investigation efficiency by implementing advanced analytical tools and techniques.
Conducted comprehensive digital forensics investigations, leading to accurate identification of suspects and increased conviction rates.
Implemented cybersecurity best practices within organization, reducing vulnerability to external threats and data breaches.
Sr. Technical Exploitation Officer
ManTech
10.2015 - 06.2017
Performed malware analysis on 50 suspicious files, identifying threats and assisting in incident response efforts.
Evaluated new software tools for integration into forensic analysis workflow, enhancing overall investigative capabilities.
Participated in multi-disciplinary teams for 100 complex cases, collaborating with other experts to provide comprehensive investigative support.
Mentored new hires on proper digital forensic methodologies and procedures, strengthening team cohesion and effectiveness.
Reviewed various formats of cell phone data to assist with cell site mapping and perform call detail record analyses.
Communicated with law enforcement agencies, corporate entities and compliance officers to build institutional relationships.
Built and enhanced complex cases and investigations by assisting with large-scale data collection, organization and analysis.
Conducted comprehensive digital forensics investigations, leading to accurate identification of suspects and increased conviction rates.
Spearheaded successful projects from conception through completion, showcasing strong project management abilities
Sr. Digital Forensic Examiner
Bowhead
11.2014 - 10.2015
Performed full scope computer & network forensic investigations which led to arrest of 2 NSWCDD employees and removal of 15 NSWCDD federal employees and contractors. Other investigations included violations of law, intrusions, and human resource requests.
Presented regular updates to executive management on organization's cybersecurity posture and incident response activities, ensuring alignment with overall business objectives.
Served as subject matter expert in incident response, providing guidance and support to other departments seeking assistance in managing security incidents.
Mentored new hires on proper digital forensic methodologies and procedures, strengthening team cohesion and effectiveness.
Stayed current on industry trends through continued education opportunities such as conferences and workshops to bring innovative solutions to workplace.
Evaluated new software tools for integration into forensic analysis workflow, enhancing overall investigative capabilities.
Performed malware analysis on suspicious files, identifying threats and assisting in incident response efforts.
Streamlined processes for evidence collection, reducing case backlog and increasing successful case resolution.
Maintained chain-of-custody documentation for all collected evidence, ensuring admissibility in court proceedings.
Prepared well written reports and briefs where facts were presented in detail to accurately convey information to senior leadership.
Developed strong relationships with internal and external stakeholders, fostering open communication and collaboration
Digital Forensic Examiner
National Aeronautics And Space Administration, NASA
06.2013 - 11.2014
Conducted digital forensic support to criminal investigations relating to NASA employees, NASA contractors, agency property, and systems accessing and hosting NASA data. Investigated Allegations in which NASA was potential victim of fraud, waste, or abuse by employees, grantees, and contractors.
Performed specialized computer forensic investigative tasks such as installing network taps, conducting covert forensic acquisitions, and completed warrants and preservation orders.
Used variety of currently available computer forensic software suites to obtain forensically sound and reproducible results while conducting at least 10 forensic examinations.
Performed malware analysis on suspicious files, identifying threats and assisting in incident response efforts.
Evaluated new software tools for integration into forensic analysis workflow, enhancing overall investigative capabilities.
Participated in multi-disciplinary teams for complex cases, collaborating with other experts to provide comprehensive investigative support.
Provided expert testimony in court proceedings, resulting in successful prosecution of cyber criminals.
Stayed current on industry trends through continued education opportunities such as conferences and workshops to bring innovative solutions to workplace.
Assisted legal teams with e-discovery requests, ensuring timely delivery of relevant electronic documents for litigation purposes.
Collaborated with law enforcement agencies to provide critical digital evidence, expediting criminal investigations.
Assisted in designing and implementing secure evidence storage system, preserving integrity of digital artifacts for future analysis.
Maintained chain-of-custody documentation for all collected evidence, ensuring admissibility in court proceedings.
Developed detailed reports outlining findings from forensic examinations, supporting legal teams in building strong cases against offenders.
Conducted comprehensive digital forensics investigations, leading to accurate identification of suspects and increased conviction rates.
Leveraged technical expertise to prepare investigative reports for prosecutorial and management officials.
Testified in grand jury proceedings, hearings and trials by describing analytical processes in laymen's terms and responding to cross-examination.
Combat Engineer
United States Marine Corps, USMC
01.1999 - 05.2013
Conducted engineer reconnaissance; emplaced obstacle systems; conducted breaching operations, to include reducing explosive hazards; conducted mine/countermine operations; employed demolitions and military explosives; conducted urban breaching; conducted route clearance; provided assault bridging, tactical bridging and non-standard bridging/repair; constructed and maintained combat roads and trails; constructed expedient roads and airfield/ landing zones; designed and constructed survivability positions; performed expedient vertical and horizontal construction; designed, constructed and maintained base camps/forward operating bases and combat outposts; and fought as provisional infantry.
Trained and deployed with multiple teams to Iraq and Afghanistan 4 times to engage in combat operations against Al-Qaeda, Taliban, ISIS-K, and other terrorist organizations. Teams were awarded by General grade officers on multiple occasions.
Led team of combat engineers during initial stages of Iraq Campaign to breach Iraqi border initiating ground assault against Iraqi forces. Breach point was used by approximately 80,000 combat and support US and UK ground forces to gain entry into Iraq.
Led and conducted hundreds of combat patrols and mission throughout Al-Anbar Province, Iraq and Helmand Province, Afghanistan to engage enemy forces and destroy IED and landmine emplacements.
Led teams of combat injured Marines through recovery and rehabilitation at Walter Reed National Military Medical Center.
Strengthened unit readiness by consistently maintaining high level of physical fitness and tactical expertise as required for combat engineer duties.
Streamlined communication between units by installing and maintaining wire obstacles, facilitating coordination during missions.
Enhanced survivability of structures under attack through implementation of advanced force protection measures such as HESCO barriers and berm construction.
Safeguarded personnel against IED threats by conducting route clearance operations, enhancing overall troop safety during patrols.
Boosted operational efficiency through timely demolition of enemy structures using explosives, enabling successful completion of objectives.
Maximized effectiveness of defensive positions by expertly employing mine warfare techniques to protect critical assets from enemy forces.
Maintained 100% accountability of assigned equipment worth more than $30,000,000.
Trained in use of tear gas, passive ordnance, and explosives.
Trained in small arms, anti-armor and indirect fire weapons.
Maintained required level of proficiency in use of firearms.
Increased unit proficiency by leading rigorous training exercises in demolitions, mine warfare, and obstacle construction
Education
Bachelor of Science - Computer And Information Systems Security
American Military University
Charles Town, WV
06.2020 - Current
Skills
Incident Response
Software
Magent Axiom
X-Ways
Cellebrite
XRY
FTK
Logicube
Oxygen
Paladin
Encase
Timeline
CompTIA Security+
03-2024
CompTIA Network+
03-2024
CompTIA A+
03-2024
Cellebrite Certified Mobile Examiner
03-2024
Cellebrite Certified Recovery Specialist
03-2024
Bachelor of Science - Computer And Information Systems Security
Perform digital forensic, technical exploitation, and incident response training under the guidance and supervision of the Senior Technical Exploitation Officer for the National Media Exploitation Center, Technical Exploitation Division. Training subject matter includes:
Digital forensic evidence crime scene processing and inventory
Forensic acquisitions using Cellebrite, hardware & software write blockers, boot disks, and various forensic imaging tools commonly used in DFIR
Case management and folder structures during forensic examinations
Forensic analysis techniques using Magnet Axiom, X-Ways, Cellebrite PA, XRY
Malware identification and analysis
Soldering and device disassembly & repair of screens and USB
Decryption identification techniques
Advanced data recovery techniques to include before first unlock, flasher boxes, and chip-off
Forensic reporting formats for different audiences. Law enforcement, incident response, and intelligence.
Airborne Mission Technician at Defense Intelligence Agency, DIA; U.S. Air ForceAirborne Mission Technician at Defense Intelligence Agency, DIA; U.S. Air Force