
Solution-oriented, results-focused cyber security professional with solid, business/mission awareness of security engineering realities central to information protection governance. Experience supporting simple and complex Governance Risk & Compliance (GRC) efforts, validating baseline test results from selected NIST800-53x controls, documenting residual risk for AO Acceptance or further mitigation. Strong analysis, troubleshooting, collaborative problem-solving remediation / mitigation skills with a proven track record of success. Achievements include sustainment of baseline compliance controls, resolution of substandard assessments, documentation development / repair, recovery from failed or adverse audits, and validation coordination between approved baseline assessments and applicable configuration item (CI) End of Life considerations. Expertise includes the ability to squeeze detailed findings from assessment tools to substantiate baseline control compliance and identify / solve compliance issues. Extreme examples include Supply Chain Management (SCM) resolution and adverse Inspector General & authoritative agency audit remediation such as Treasury Federal Taxpayer Info (FTI); HHS/CMS HIPAA; FDA medical devices electronic health record protection compliance; and protection of classified and sensitive data. Skillset includes detailed analysis skills to prove or disprove and issue down to the configuration item CWE/CVE by analyzing scan dumps in pivot tables and sorting by PID, CWE/CVE, criticality of raw risk, residual risk, DISA/NSA CTO TaskOrd, etc.
Further experience in supporting complex avionic, electronic warfare, COMSEC communications & Telecommunications TSEC Encryption system maintenance, ground, UAV/UAS, Autonomous Vehicle, Ground Station, Space Hardware, Platform IT (PIT), and other hybrid systems on top of traditional endpoint, mobile, enterprise, & Cloud.
· Commonwealth of Virginia Pinnacle/Unisys Team Customer Facing Information Security Officer (ISO) managing cyber security compliance, developing SSP and Federal Audit remediation plans, resolving server as well as other asset / network security issues and resolving the confusion generated between audit processes using multiple (differing) standards to manage risk to an acceptable level. This involved analyzing Tenable NESSUS Security Center raw findings and informing the appropriate stakeholders if compliance deviations or vulnerabilities were associated with the hosting asset operating system, the hosted application, or architectural compliance for defense-in-depth security of protected data. These tasks included SEIM tracking via RSA Archer GRC toolset.
· Commonwealth of Virginia ADITI-SAIC Governance Requirements Compliance Lead (ISO) for Virginia IT Agency (VITA Assist) Governance Risk and Compliance (GRC) Transition Assistance / reinvention, supporting 84 State Agencies as well as VITA CSRM within the Commonwealth of Virginia while assisting several agencies in resolution of overdue Federal FTI and PHI Audits. This included regular and privileged account processing; Tenable/Nessus account management and scanning; Vendor Service account transition; and documentation of system compliance status. As GRC Team lead, supported COV Agencies under Virginia IT Agency Transition Assistance Program including COV Department of Taxation, VDOT, DSS, VDH, VEC, DMV, VITA Core Services. Other Cyber Security tasks included scanning, CVE/CWE reporting, SIEM/Incident documentation, and NIST RMF/SEC501 compliance. VITA ISO training completed. Member of CAB (Change Advisory Board).
· GRC Routine ISO tasks included account lookups in ARS, approval of creation and modification of role based access (RBA) within the COV Virginia.Gov domain(s); Assisting customers with account issues prior to submission to the VCCC or after rejection by the VCCC; Reviewing accounts and requests for Role-Based and Least Privilege access insuring adherence to agency security requirements; troubleshooting account issues with Active Directory and other account workflows; Process exception requests, wavers, firewall rule changes, etc. Maintain agency security operations documentation; assist with agency security operations including Topology, Configuration, and Vulnerability compliance scanning while populating risk mitigation documentation and POA&Ms as required.
· Details of special deliverables and project accomplishments as GRC Lead include:
o Refresh of Nessus Scanner and other tools / processes after many years of being forced into the canned reports from ePO (e Policy Orchestrator) and Tenable Security Center.
o Developed targeted environment Tenable NESSUS scans for Virginia Department of Elections in support of the Mid Term Elections; as well as Virginia Department of Taxation & Virginia Department of Social Services to resolve overdue IRS Federal Audit findings - identifying broken McAfee signature databases, certificate problems, configuration problems, patch non-compliance, and unauthorized software. This included in-depth pivot table analysis of raw SC data dumps..
· Discovered and analyzed urgent findings in support of State Agency workstations and servers (Previously un-ticketed, yet critical, high and moderate risk issues) in time to remediate/mitigate risk for Department of Elections, and Department of Taxation & VDSS prior to urgent event windows.
Education-Training: COV VITA-ISO, RSA ARCHER GRC, VSM, ServiceNow/Keystone Edge, MCP, MCSE, CompTIA Security+ CE; ISC2 CISSP; F5 Networks LTM/GTM SE, Cisco CCNET/CCNA, DoD ACAS, Telos (XACTA-DHS IACS), NESSUS PVS, N-Circle 360; Certified Ethical Hacker Core; Microsoft MCITP Refresh of MCP and MCSE. CISA Cert Scheduled.
Extensive commercial, federal/military technical training – transcripts available.
University Undergraduate Level: 4 Years of Information Technology, Electrical Engineering Technology / Eng. Mgt.
Graduate Level: NSA Core Certs NSA 4011-4016a/CNSS1253/ Grad Certificates supporting a Masters in Cybersecurity.
DOD 8570 Information Assurance Workforce Registered IAT and IAM Registered, DoDD 8140 Cyber Workforce Mgt..
o CISSP: ISC2 Certified Information Systems Security Professional Certificate 410346 in work - renews 7/2024
o SECURITY + CE: CompTIA: Certificate: COMP001020390368 renews 5/2024
o CISA/CRISC Class and testing planned Oct-Nov 2021
o DoD, Army CIO, and Navy RMF Validator training for EMASS. DHA MEDCOM RMF training.
o PM eMASS OSD/WHS DoD eMASS Program Train the Trainer Pilot (BAH/PM eMASS)
o PM eMASS Army CA Rep eMASS Training (BAH/PM eMASS)
o USMC C4IA Telos XACTA MCCAST Training
o *Fully Qualified Navy Validator: FQNV #I1296; Next Gen Navy QNV/NQV Training completed
o SPAWAR-NQV-101 Navy Qualified Validator Course - Introduction for Navy Validators
o SPAWAR-NQV-102 Navy Qualified Validator Course - Risk Management Framework
o SPAWAR-NQV-103 Navy Qualified Validator Course - Security Controls
o SPAWAR-NQV-104 Navy Qualified Validator Course - A&A Tools
o SPAWAR-NQV-201 Navy Qualified Validator Course – BAH Resident Tng w/eMASS
o DOJ/FEMA WMD Counterterrorism; DEARNG CST Chem Bio; USArmy 74D CBRNE training.
o US Navy/Marine Corps Aerospace Electronics, Avionics, Aviation Elect, Electronic Warfare & COMSEC training.