Accomplished Security Control Assessor (SCA) and Project Manager with over 10+ years of progressive experience at renowned technology firms within US Government Contracting, providing crucial support to the Intelligence Community. Specialized in conducting Security Control Assessments, ensuring the robustness and compliance of IT systems. Focused on managing project lifecycles and optimizing operational efficiency, I bring a proven history in adherence to solution design and Information Assurance (IA) standards. Given my extensive background and expertise in Security Control Assessment (SCA), project management, and team leadership, my next career step is geared toward roles that leverage my technical acumen, strategic planning skills, and leadership experience. I seek opportunities to drive large-scale projects and innovations in Security Control Assessment and systems management within roles that challenge and expand my capabilities in a dynamic, forward-thinking environment.
Lead enterprise-wide vulnerability scanning, analysis, and reporting using ACAS (Tenable.sc) for traditional infrastructure and AWS Inspector for cloud-hosted assets.
• Interpret and apply DISA STIGs to establish secure configuration baselines, develop remediation plans, and manage POA&M lifecycle activities.
• Coordinate with system owners, application teams, and ISSOs to drive timely remediation of findings and risk reduction.
• Automate vulnerability scanning and reporting pipelines to increase coverage and reduce cycle time.
• Create and maintain vulnerability dashboards, compliance reports, and audit-ready documentation for leadership and auditors.
• Support RMF continuous monitoring and ensure timely ingestion and tracking of findings in SNOW
• Mentor junior analysts and contribute to SOP development and policy refinement
Security control assessor Insight Global, McLean, VA
• Supported incident response efforts by analyzing security breaches and recommending appropriate corrective actions.
• Maintained up-to-date knowledge of emerging cyber threats, ensuring relevant expertise in assessing security risks.
• Recommended improvements in security policies and procedures, leading to enhanced protection against potential threats.
• Developed detailed reports on security control assessment findings for stakeholders to facilitate informed decision making.
• Streamlined the security control assessment process by creating standardized templates and procedures.
• Evaluated and improved security controls by conducting thorough risk assessments.
• Performed gap analyses on existing security controls, identifying areas requiring improvement or additional measures.
• Reduced cybersecurity vulnerabilities through the development of tailored mitigation strategies.
• Conduct comprehensive security control assessments for diverse information systems, ensuring alignment with NIST, FISMA, and other relevant frameworks
• Applied a holistic approach when assessing systems, considering both technical aspects as well as human factors influencing overall risk posture.
• Develop and implement assessment plans, methodologies, and risk analysis strategies to evaluate controls' effectiveness
• Generate detailed Security Assessment Reports (SARs) and findings reports, articulating assessment results and providing actionable recommendations
• Collaborate with system owners, administrators, and stakeholders to gather necessary assessment information and address security concerns
• Establish continuous monitoring procedures, track system environment changes, and provide ongoing risk analysis
• Assisted in security control assessments, vulnerability assessments, and risk management activities
• Conducted security awareness training sessions for employees, emphasizing best practices and compliance with security policies
• Supported audit activities by providing documentation and evidence of security control assessments and addressing audit findings.