Highly skilled cybersecurity risk governance with comprehensive knowledge of risk assessments and management frameworks, compliance standards, and security technologies. Proficient in conducting security assessments, vulnerability analyses, and provide professional security recommendations to stakeholders. Strong leadership abilities demonstrated through successful management of cross-functional teams and projects.
Overview
30
30
years of professional experience
Work History
SENIOR CYBERSECURITY CONSULTANT/FedRAMP/FISMA
Coalfire Federal
01.2023 - Current
Led and managed large portion of end-to-end process of FedRAMP compliance, including initiating, planning, executing, monitoring, and closing FedRAMP assessments for cloud service offerings
Seeking authorization, ensuring compliance with FedRAMP and NIST standards
Serving as Senior Consultant for FedRAMP/FISMA Service team, led teams of cybersecurity professionals in conducting comprehensive security assessments for clients across various organizations to include Solventum, formerly 3M, and Google
Provided assessor support to several additional FedRAMP assessments that led to successful annual and initial assessments
Prepared assessment reports documenting findings, recommendations, and remediation plans
Provided guidance and support to CSPs throughout the authorization process, addressing questions and concerns, sometimes traveling to client site to perform assessment requirements
Participated in continuous improvement initiative to enhance assessment methodologies and tools, which include developing guidance for promoting consistency and quality in documented assessment deliverables
Provided guidance and training to internal team on FedRAMP requirements, best practices, and compliance strategies
Served as primary point of contact for FedRAMP-related inquiries from cloud service providers
Stayed abreast of latest cybersecurity threats and trends to continually improve assessment methodologies and techniques.
Built relationships and fostered effective communication with legal personnel to conduct practical investigations
Monitored confidential company data and mitigated hacking through network systems updates
Managed anonymous online and phone-call tips, implementing uncovered information into investigation processes to solve cases
Performed risk analyses to identify appropriate security countermeasures
Developed plans to safeguard computer files against modification, destruction, or disclosure
Recommend improvements in security systems and procedures
Encrypted data and erected firewalls to protect confidential information
Conducted security audits to identify vulnerabilities
Self-motivated, with a strong sense of personal responsibility
Demonstrated strong organizational and time management skills while managing multiple projects
Demonstrated leadership skills in managing projects from concept to completion
Adaptable and proficient in learning new concepts quickly and efficiently
Gained extensive knowledge in data entry, analysis and reporting
Organized and detail-oriented with a strong work ethic
Worked effectively in fast-paced environments
Passionate about learning and committed to continual improvement
Participated in team projects, demonstrating an ability to work collaboratively and effectively
Identified issues, analyzed information, and provided solutions to problems
Provided professional services and support in a dynamic work environment
Identified issues, analyzed information, and provided solutions to problems
SENIOR CYBERSECURITY CONSULTANT/FedRAMP/FISMA
A-LIGN
02.2021 - 01.2022
Provided oversight of engagements through the management of standard project execution, client service activities, and staff consultants
In addition to developing junior level staff, you will have the opportunity to provide input on methodology development, technical assessment strategy, and engagement planning
Completed FISMA/FedRAMP/CMS/CSF and CMMC readiness risk assessments and provided consultations to clients for readiness and compliance
Provided support as needed to complete Security Authorization Packages and Security Assessments
Collaborated with multiple internal teams, to include FISMA, FedRAMP, PCI, HITRUST and ISO teams to completed assigned client engagements
Monitored the progress of engagements and key project activity dates
Reviewed and analyzed Security Authorization Packages for completeness and compliance with FedRAMP requirements and other authoritative IT security guidance
Provided Plan of Actions and Milestones (POA&M) support helping clients implement remediation activities.
SENIOR CLOUD SECURITY ANALYST/INFORMATION SYSTEM SECURITY OFFICER/MANAGER/NAVAIR
Booz Allen Hamilton
12.2019 - 01.2021
Supported cybersecurity missions by preparing client systems for assessment and authorization
Leveraged subject matter expertise in various cybersecurity areas including the risk management framework and performing security assessment and compliance activities using assessment tools, procedures, and security technical implementation guides
Conducted testing and analysis to identify vulnerabilities and potential threat vectors into systems and networks, develop exploits, and engineer attack methodologies
Completed multiple system authorization by identifying classification and controls and establishing security policies for security implementation and company governance
Evaluated cyber compliance of a system against Risk Management Framework and DoD Cybersecurity policies
Provided information assurance, cyber engineering, or operational cyber support, including supporting information operations, cyber operations, system administration, and systems security.
CORPORATE PROGRAM MANAGER/COMPLIANCE SUBJECT MATTER EXPERT/SECURITY CONTROL VALIDATOR-ASSESSOR
Netizen Corporation
11.2016 - 12.2019
Worked directly with the CEO to develop and execute new growth directives along the lines of cybersecurity solutions in accordance with the company's mission
Managed contracts and clients that supported Department of Defense information systems, including personnel sourcing, contract reporting, and feedback to the corporate partners and teams
Provided professional development and mentorship for staff of 20 cybersecurity engineers to include government required cybersecurity training and company level training to meet contractual and career progression requirements
Served as the Senior Team Lead for Risk Management Framework Assessments as necessary to support Army Corps of Engineers Security Control Assessor-Validator team on CONUS and O-CONUS engagements (United States Army Corps of Engineers (USACE) Engineering and Research Development Center (ERDC)).
TACTICAL COMMUNICATIONS PLANNING AND ENGINEERING OFFICER/SYSTEMS PLANNING AND ENGINEERING
United States Marine Corps
09.1994 - 05.2016
Effectively supported over 150 military exercises and operations supporting 6 different commands and 10 different coalitions and allied partners in 15 different geographically diverse locations
With limited resources, I was able to increase network throughput by 50%, providing a more robust solution to support over 48,000 users in a forward deployed architecture
Supervised the installation of secure wireless towers, and multiple subsystems spanning some 200 square miles in Afghanistan, producing widespread connectivity and reliability to dislocated sites
A training evolution required a coordinated network to support 45 systems/network administrators, telecommunications managers, and RF engineers
Leading a small team, I implemented a secure Campus Area Network (CAN), creating highly flexible solutions meeting requirement for an effective training evolution
Through direct coordination with Combatant Commands (COCOM), joint and federal agencies, provided direct oversight of Marine Corps tactical networks both CONUS and O-CONUS
Provided input on the career progression, professional development and force capacity requirements for personnel supporting the transmission, network and cybersecurity occupational skillsets for personnel supporting Marine Corps communications.
Education
Master of Science - Information Technology, Project Management
Kaplan University
Davenport, Iowa
02.2014
Bachelor of Science - Information Technology
Kaplan University
Davenport, Iowa
10.2012
Skills
Vulnerability Assessment
Business Continuity
Incident Response
Configuration Management
Compliance Management
Privacy regulations
Network Security
Teamwork and Collaboration
Written Communication
Risk Assessment
Attention to Detail
Effective Communication
Information Governance
Network protocols
Software and Technical
MS Suite
EMASS
Tenable
Routing and Switching
Amazon Web Service
Certifications
Certified Information Systems Security Professional, #538760, 2025
Certified Chief Information Security Officer, #ECC6583971420, 2025