Dynamic cybersecurity leader with extensive experience in federal IT management and risk mitigation. Proven ability to shape compliance strategies, enhance security postures, and lead cross-functional teams in executing effective cybersecurity programs that align with federal regulations and organizational goals.
Overview
1
1
Certification
20
20
years of professional experience
Work History
Information Systems Security Manager / SME USPTO Contract
ASRC Federal
12.2025 - Current
Acts as the Information Systems Security Manager (ISSM) and senior cybersecurity advisor for the US Patent and Trademark Office (USPTO), driving RMF implementation, ongoing monitoring, and expedited Authorization to Operate (ATO) efforts across product lines.
Serves as the primary liaison to the Chief Information Security Officer (CISO) and Authorizing Officials (AOs), providing strategic guidance on system authorization decisions, risk posture, and compliance. Establishes, documents, and oversees product-line cybersecurity program implementation, ensuring compliance with FISMA, FEDRAMP, agency policies, and federal mandates. Establishes, documents, and oversees product-line cybersecurity program implementation, ensuring compliance with FISMA, FEDRAMP, agency policies, and federal mandates.
Conducts independent security assessments and compliance reviews against NIST SP 800-53 controls and RMF requirements, identifying gaps and driving remediation efforts to enhance security posture.
Performs final review and approval of authorization artifacts, including System Security and Privacy Plans (SSPPs), risk acceptance packages, and ATO documentation within CSAM, and ensured completeness, accuracy, and audit readiness.
Oversees continuous monitoring activities, including POA&M management, vulnerability remediation tracking, and compliance reporting.
Facilitates cloud security initiatives by ensuring compliance with industry standards, and FedRAMP-aligned initiatives, with emphasis on AWS environments.
Ensures compliance with DHS Binding Operational Directives (BODs), privacy regulations, and federal cybersecurity policies.
Collaborates with system owners, ISSOs, and engineering teams to integrate security into system lifecycle processes.
Drives process improvements and standardized RMF artifacts across product teams, enhancing operational consistency and compliance.
Branch Chief, Senior Information Security Technical Authority
U.S. Department of Agriculture
06.2024 - 10.2025
Directed FISMA, RMF, FEDRAMP, and SOC audit compliance as the senior information security authority for mission-critical federal financial systems distributing over $5B annually in SNAP and WIC benefits, maintaining full adherence to NIST SP 800-53, OMB A-130, and federal security requirements that protect sensitive data and sustain uninterrupted benefit delivery.
Expertly managed the Assessment and Authorization (A&A) and Information Security Continuous Monitoring (ISCM) processes to ensure systems obtain and maintain Authorities to Operate (ATOs).
Lead a team of IT security professionals in planning, assigning, and prioritizing tasks, ensuring timely, high-quality deliverables while adjusting short-term priorities to meet organizational objectives.
Identified and protected High Value Assets (HVAs) within federal financial systems, coordinating with OMB and CISA to align with national security and FISMA requirements.
Developed and implemented comprehensive policies, frameworks, and operational guidelines to ensure compliance with FISMA, OMB Circular A-130, and other federal IT requirements.
Initiated enhancements to USDA overall security posture, proactively addressing emerging threats and vulnerabilities.
Provided advanced technical expertise to safeguard IT systems, networks, and associated infrastructure.
Coordinated with stakeholders to manage system vulnerabilities and develop contingency plans.
Director, Cybersecurity / Enterprise ISSM
U.S. Naval Education and Training Command
Pensacola, Florida
04.2019 - 06.2024
Supported echelon II information systems security management for geographically dispersed cybersecurity team serving largest shore command in U.S. Navy, protecting 40,000+ network hosts and 20,000+ users across NETC classified NNPI and unclassified networks and systems connected to DoDIN throughout United States, Europe, Asia, and Pacific Islands.
Provided direction and mentorship to 56 geographically dispersed ISSMs across full cybersecurity spectrum while aligning resources and funding to mission priorities for enterprise cybersecurity execution.
Built echelon II guidance and policy to maintain compliance with federal statutes, DoD, DOE, DON policies, and NIST guidelines, reinforcing cybersecurity framework across organization.
Supported FISMA compliance audits and inspections for subordinate commands.
Managed NETC Vulnerability Remediation Asset Manager portfolio to maintain situational awareness of cybersecurity posture across NETC domain and support timely vulnerability remediation.
Delivered outstanding results by leading NETC through 2 Command Cyber Readiness Inspections administered by USCYBERCOM, producing NETC's highest inspection score on record.
Directed implementation and oversight of NETC insider threat program, supporting compliance with DoD regulations, strengthening security awareness, and improving risk mitigation efforts.
Responded to cybersecurity incidents and investigated electronic spillages involving classified NNPI, personal health information, and personally identifiable information.
Identified and recruited high-performing talent to fill cybersecurity vacancies across NETC domain in highly competitive market.
Program Manager, Risk Management Framework / ISSM
U.S. Naval Education and Training Command / U.S. Navy
11.2010 - 04.2019
Provided Risk Management Framework (RMF) program management expertise and leadership for the assessment, authorization, and continuous monitoring of the Naval Education and Training Command (NETC) enclave, sites and systems throughout the United States, Europe, Asia and the Pacific Islands.
Developed and expertly managed the NETC RMF and Continuous Monitoring programs, resulting in NETC becoming the first Navy echelon II command to fully transition from the DoD Information Certification and Accreditation Process (DIACAP) to RMF and the successful transition and authorization of all networks and systems in the NETC portfolio. This program has been recognized by the Office of the Navy Security Control Assessor (SCA) as the Gold Standard for the Assessment and Authorization of Navy systems and networks through repeatable processes to conduct risk assessments and continuous monitoring throughout the lifecycle of the systems.
Directed the Echelon II Package Submitting Office (PSO) and EMASS administration, maintained RMF authorization packages, managed user accounts and role assignments, validated control implementation evidence, and created accurate, audit-ready documentation throughout the system lifecycle.
Conducted reviews of emerging technology infusion, proposed system interfaces and cloud migration initiatives to ensure the confidentiality, integrity and availability of Classified, Unclassified, and Naval Nuclear Power (NNPI) information throughout the NETC enterprise.
As Senior Navy Qualified Validator (NQV), lead and mentored junior NQVs conducting independent RMF security-control assessments; ensures assessment quality, evidence traceability, vulnerability and residual-risk analysis, and accurate SAP, SAR, POA&M, and eMASS documentation supporting SCA and Authorizing Official risk decisions.
- Reviewed and interpreted new IT-related federal legislation, DoD and Navy policies, and briefed senior leadership on applicability and compliance status within the NETC domain.
Conducted compliance inspections for subordinate organizations in the NETC domain.
Established cyber incident and classified electronic spillage management policies and guidance for timely identification, response, and recovery from cyber security incidents and classified spillages.
Managed the investigation, reporting and remediation of over 150 cybersecurity incidents annually throughout the NETC Domain.
Lead investigations and coordinated the timely response and PII spillages to ensure that spillages are properly contained preventing further compromise.
Principal Security Compliance Leader
Computer Sciences Corporation
11.2007 - 11.2010
Project Manager, Public Key Infrastructure (PKI)
Science Applications International Corporation
08.2006 - 03.2007
Education
Bachelor of Science - Information Systems Management
University of Maryland
Adelphi, MD
05-2004
Skills
Risk management framework
Security compliance
Continuous monitoring
Incident response
Vulnerability assessment
Cloud security
Cybersecurity strategy
Certification
Certified Information Systems Security Professional (CISSP), ISC2 323167 Issued 2009-10, Governance, Risk and Compliance Certification (CGRC), ISC2 323167 Issued 2011-11
Timeline
Information Systems Security Manager / SME USPTO Contract
ASRC Federal
12.2025 - Current
Branch Chief, Senior Information Security Technical Authority
U.S. Department of Agriculture
06.2024 - 10.2025
Director, Cybersecurity / Enterprise ISSM
U.S. Naval Education and Training Command
04.2019 - 06.2024
Program Manager, Risk Management Framework / ISSM
U.S. Naval Education and Training Command / U.S. Navy
11.2010 - 04.2019
Principal Security Compliance Leader
Computer Sciences Corporation
11.2007 - 11.2010
Project Manager, Public Key Infrastructure (PKI)
Science Applications International Corporation
08.2006 - 03.2007
Bachelor of Science - Information Systems Management
Information Systems Security Manager at Logistic Services International, IncorporatedInformation Systems Security Manager at Logistic Services International, Incorporated
Information Systems Analyst /Information Security Analyst at Ministry of Interior (MOI)Information Systems Analyst /Information Security Analyst at Ministry of Interior (MOI)