Summary
Overview
Work History
Education
Skills
Technical Certifications
Organizations
Timeline
Generic

Nigel Roberts

Bowie,MD

Summary

Dynamic cybersecurity leader and Founder & Managing Director of NexSecure, with over a decade of comprehensive experience in third-party risk management, operational security, and strategic compliance management. Proven track record in driving business growth, leading high-impact security projects, and developing innovative security solutions. Skilled in fostering strong client relationships, leading cross-functional teams, and steering organizations toward achieving unparalleled information security resilience. Seeking to leverage deep industry expertise and visionary leadership in a senior executive role.

Overview

9
9
years of professional experience

Work History

Founder & Managing Director

NexSecure
01.2024 - Current
  • Architect the strategic direction and vision of NexSecure, aligning company objectives with the evolving cybersecurity landscape to drive innovation and business growth
  • Leading business development efforts, forging strategic partnerships and expanding the company's market presence through effective marketing and client engagement strategies
  • Oversees the daily operations of the company, ensuring the delivery of high-quality cybersecurity services while maintaining operational efficiency and adapting to market changes
  • Building and leading a team of cybersecurity experts, fostering a culture of excellence, innovation, and continuous professional development
  • Provides strategic cybersecurity consulting to clients, including risk management strategies, compliance with cybersecurity standards, and development of customized security frameworks
  • Engages directly with clients to assess their cybersecurity needs, delivering expert consultations, assessments, and actionable recommendations to enhance their security posture.

Information Security Manager

Patient-Centered Outcomes Research Institute
12.2020 - 10.2023
  • Transformed the cybersecurity awareness training from a basic program with less than 40% engagement to a comprehensive curriculum covering critical cybersecurity pillars
  • Achieved a remarkable 94% completion rate within two weeks, progressing to 100% by 30 days, thereby significantly bolstering the organization’s defense against cyber threats
  • Spearheaded the development and implementation of a robust information security program, addressing critical deficiencies identified in previous assessments
  • This initiative dramatically reduced the attack surface, cutting down attacks from 100,000 to 500-1,000 daily by rectifying outdated protocols in O365
  • Identified and remediated an internal security breach involving privileged account misuse, enhancing overall system integrity
  • Advocated for and applied CIS system hardening guides across platforms, significantly strengthening the organization's security posture
  • Initiated DRP/BCP planning, aligning IT strategies with business continuity objectives
  • Led prioritization and remediation efforts based on security assessment findings, showcasing a proactive approach to risk management
  • Managed a $10 million information security budget, directly contributing to strategic security investments and operations
  • Established and executed a third-party vendor assessment program, ensuring stringent security compliance through DSAP agreements, enhancing data protection and vendor relations and third-party vendor assessments
  • Led comprehensive security incident investigations from inception to resolution, including direct reporting to C-suite executives
  • Implemented a revamped onboarding and offboarding process for secure device management and user training, ensuring all new hires received essential cybersecurity awareness training
  • Authored and instituted key policies including Vulnerability Management, Data Classification, and Cybersecurity Awareness Training
  • Introduced an annual user awareness training program, achieving 100% compliance across the organization, and mandated risk assessments for all new vendors
  • Secured the Zendesk platform against malicious attacks and managed the organization's $5 million cybersecurity insurance plan, demonstrating strategic foresight in technology and financial risk mitigation.

Information Systems Security Officer

ICF
11.2019 - 12.2020
  • Implemented security procedures and practices in alignment with Customer goals and current DoD regulations, enhancing the organization's security posture and compliance
  • Established a software assessment process as a means to identify what risks would be introduced to their environment should a new software be introduced
  • Managed their user awareness training compliance program
  • Evaluated new technologies and provided technical recommendations, supporting the organization's mission-critical research needs and IT service expansion
  • Developed Software Asset Management requirements for a new tool to streamline the process of requesting, approving, installing and updating software
  • Managed the Approved Software and Hardware list and completed periodic assessments of approved software
  • Managed the Information Systems Security Analysts team, ensuring timely resolution of user requests and adherence to Army and DoD policy
  • Ensured that all Information Systems within the area of responsibility were certified, accredited, and maintained in accordance with established policies and procedures.

IT Security Officer

United States District Court – District of Maryland
01.2015 - 11.2019
  • Reviewed and evaluated the courts’ technology security programs using NIST 800-53, establishing repeatable security processes across the district’s information technology services
  • Proactively identified, tracked, and mitigated security risks, implementing measures to enhance the court's security posture and resilience to cyber threats
  • Managed information security projects, ensuring milestones were completed promptly and in accordance with federal and judiciary security regulations
  • Established and promoted security best practices, training court staff in security awareness and contributing to the development of a security-conscious culture.

Education

Bachelor of Science in Cybersecurity and Information Assurance -

Western Governor’s University
01.2023

Skills

  • In-depth knowledge of NIST, SOC 2, policy development, standards, and training
  • Expertise in cloud security, cloud architecture, and governance risk and compliance
  • Proficient in strategic planning, threat management/remediation, and cybersecurity incident response
  • Strong background in Amazon Web Services, change management, audit and accountability
  • Familiarity with FISMA, ISO 27001, and configuration management and risk assessment control families in NIST SP800-53 Rev 4 and Center for Information Security CIS Critical Security Controls
  • Comprehensive understanding of DoD 8500 series, NIST SP 800 series, DoD regulations, and instructions, including Cloud Computing SRG v1r3, DoDI 851001, AR 25-2, Risk Management Framework (RMF), and DoD Information Assurance Certification and Accreditation Process (DIACAP)

Technical Certifications

  • CompTIA Secure Infrastructure Specialist (CSIS)
  • CompTIA IT Operations Specialist (CIOS)
  • CompTIA Project+
  • CompTIA Network+ CE
  • CompTIA A+ CE
  • CompTIA Security+ CE
  • ITIL v3 Foundation
  • ISC2 Certified Cloud Security Professional (CCSP)
  • CompTIA Cybersecurity Analyst (CySA+)
  • Certified Information Systems Security Professional (CISSP)

Organizations

  • The National Society of Leadership and Success
  • NIST Privacy Workforce

Timeline

Founder & Managing Director

NexSecure
01.2024 - Current

Information Security Manager

Patient-Centered Outcomes Research Institute
12.2020 - 10.2023

Information Systems Security Officer

ICF
11.2019 - 12.2020

IT Security Officer

United States District Court – District of Maryland
01.2015 - 11.2019

Bachelor of Science in Cybersecurity and Information Assurance -

Western Governor’s University
Nigel Roberts