

Results-driven Information Security Specialist with a strong focus on aligning security policy, governance, compliance, and plans with standard operating procedures and business objectives. Proven expertise in identifying business risks and compliance issues, and developing proactive data security solutions. Skilled in robust data security and compliance practices, combined with versatile management and administrative abilities gained through work experience and professional development training. With 5+ years of experience, excels in safeguarding sensitive information and mitigating potential threats to organizational security.
Department of Veterans Affairs, Contract
Core Responsibilities and Accomplishments
● RMF Lifecycle Execution: Led and supported full RMF lifecycle activities, including system categorization, control selection, implementation, assessment, authorization, and continuous monitoring for multiple controlled unclassified federal systems, ensuring NIST RMF compliance, which significantly enhanced overall security and reduced risk exposure.
● Security Authorization Packages: Developed and maintained comprehensive security documentation, including Standard Operating Procedures (SOP), System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and Risk Assessments in support of Authority to Operate (ATO) packages.
● Control Implementation and Assessment: Conducted in-depth reviews of security controls in accordance with NIST SP 800-53, ensuring effective implementation and alignment with organizational risk tolerance and mission requirements.
● Stakeholder Engagement: Collaborated with Information System Owners (ISOs), Information System Security Officers (ISSOs), and Authorizing Officials (AOs) to ensure timely completion of assessment and authorization activities. Aligned security initiatives with business goals by collaborating closely with executive leadership and other key stakeholders.
● Vulnerability and Risk Management: Utilized tools such as ICAMP, Nessus, and CSAM to perform vulnerability scans, identify and interpret results, and advise on mitigation strategies to reduce overall system risk.
● Compliance and Policy Guidance: Provided ongoing advisory services to ensure compliance with FISMA, DoD RMF, FISCAM, and agency-specific policies and procedures.
● Continuous Monitoring: Supported ongoing monitoring efforts through periodic control assessments, incident response coordination, and system status updates to maintain system authorization and security posture.
Key Achievements:
● Improved documentation consistency and reduced audit preparation time and increased audit readiness.
● Strengthened compliance posture through proactive threat assessments.
● Assist in the update and revision of information security, operations security procedures, and any other policy manuals and documents.
United States Patent and Trademark Office, Contract
Core Responsibilities and Accomplishments
RMF Specialist
United States Patent and Trademark Office, Contract
Core Responsibilities and Accomplishments
United States Patent and Trademark Office, Contract
Core Responsibilities and Accomplishments
Key Achievements:
● Recognized for leadership and performance excellence through multiple awards, implemented cross-training and staff realignment strategies that ensured consistent service delivery.
● Throughout my time with the company, I progressed through increasingly responsible roles, starting as a file clerk and eventually becoming department operations support supervisor. I built a strong administrative foundation, advanced to senior team lead mentoring colleagues, and later served as backup supervisor to maintain operations during leadership absences. As assistant operations manager, I contributed to strategic planning and process improvements. In my final role as department supervisor, I led performance initiatives, aligned goals with company objectives, and ensured smooth operations through the end of our contract.
ISACA VA Chapter is a non-profit organization dedicated to the continued development and enhancement of the information systems audit and control profession by providing benefits to its member and the professional community-at-large.