Summary
Overview
Work History
Education
Skills
Certification
Work Availability
Timeline
Rick DeGraffenreid

Rick DeGraffenreid

Quantico,VA

Summary

Solution-oriented, results-focused cyber security professional with solid, business/mission awareness of security engineering realities central to information protection governance. Experience supporting simple and complex Governance Risk & Compliance (GRC) efforts, validating baseline test results from selected NIST800-53x controls, documenting residual risk for AO Acceptance or further mitigation. Strong analysis, troubleshooting, collaborative problem-solving remediation / mitigation skills with a proven track record of success. Achievements include sustainment of baseline compliance controls, resolution of substandard assessments, documentation development / repair, recovery from failed or adverse audits, and validation coordination between approved baseline assessments and applicable configuration item (CI) End of Life considerations. Expertise includes the ability to squeeze detailed findings from assessment tools to substantiate baseline control compliance and identify / solve compliance issues. Extreme examples include Supply Chain Management (SCM) resolution and adverse Inspector General & authoritative agency audit remediation such as Treasury Federal Taxpayer Info (FTI); HHS/CMS HIPAA; FDA medical devices electronic health record protection compliance; and protection of classified and sensitive data. Skillset includes detailed analysis skills to prove or disprove and issue down to the configuration item CWE/CVE by analyzing scan dumps in pivot tables and sorting by PID, CWE/CVE, criticality of raw risk, residual risk, DISA/NSA CTO TaskOrd, etc.

Further experience in supporting complex avionic, electronic warfare, COMSEC communications & Telecommunications TSEC Encryption system maintenance, ground, UAV/UAS, Autonomous Vehicle, Ground Station, Space Hardware, Platform IT (PIT), and other hybrid systems on top of traditional endpoint, mobile, enterprise, & Cloud.

Overview

43
43
years of professional experience
1
1
Certification

Work History

US Army Retired Reserve (District/Maryland/Virgini

US Army Reserve
Washington , DC
12.2010 - 08.2021
  • Maintained confidentiality when addressing sensitive information with tact and diplomacy.
  • Communicated clearly and listened attentively throughout interview process to facilitate exchange of information.
  • Remained composed and poised even in most demanding of situations and physically stressful environments.
  • Worked closely with team members to deliver project requirements, develop solutions and meet deadlines.
  • Prioritized and organized tasks to efficiently accomplish service goals.
  • Juggled multiple projects and tasks to ensure high quality and timely delivery.
  • Demonstrated self-reliance by meeting and exceeding workflow needs.
  • Demonstrated leadership by making improvements to work processes and helping to train others.
  • Provided excellent service and attention to customers when face-to-face or through phone conversations.
  • Improved operations by working with team members and customers to find workable solutions.
  • Motivated and encouraged team members to communicate more openly and constructively with each other.

GRC Lead

State Of Virginia VITA-TAP-MSI
Richmond, VA
08.2018 - 07.2019
  • Monitored team progress and enforced deadlines.
  • Delegated daily tasks to team members to optimize group productivity.
  • Fostered positive employee relationships through communication, training and development coaching.
  • Counted inventory, resolved discrepancies and completed paperwork to keep system accurate and current.
  • Integrated process improvements to increase overall workflow.
  • Organized and prioritized incoming work orders and optimized team workflows and resources to handle dynamic demands.
  • Documented production levels, materials used and special incidents to keep management informed of daily activities.
  • Developed and monitored weekly staff schedules.
  • Developed and implemented policies, procedures and process improvement initiatives to improve retention rates and increase customer satisfaction.
  • Kept work flowing smoothly in and out of department by working closely with shipping, warehouse and other personnel to coordinate movements.

· Commonwealth of Virginia Pinnacle/Unisys Team Customer Facing Information Security Officer (ISO) managing cyber security compliance, developing SSP and Federal Audit remediation plans, resolving server as well as other asset / network security issues and resolving the confusion generated between audit processes using multiple (differing) standards to manage risk to an acceptable level. This involved analyzing Tenable NESSUS Security Center raw findings and informing the appropriate stakeholders if compliance deviations or vulnerabilities were associated with the hosting asset operating system, the hosted application, or architectural compliance for defense-in-depth security of protected data. These tasks included SEIM tracking via RSA Archer GRC toolset.

· Commonwealth of Virginia ADITI-SAIC Governance Requirements Compliance Lead (ISO) for Virginia IT Agency (VITA Assist) Governance Risk and Compliance (GRC) Transition Assistance / reinvention, supporting 84 State Agencies as well as VITA CSRM within the Commonwealth of Virginia while assisting several agencies in resolution of overdue Federal FTI and PHI Audits. This included regular and privileged account processing; Tenable/Nessus account management and scanning; Vendor Service account transition; and documentation of system compliance status. As GRC Team lead, supported COV Agencies under Virginia IT Agency Transition Assistance Program including COV Department of Taxation, VDOT, DSS, VDH, VEC, DMV, VITA Core Services. Other Cyber Security tasks included scanning, CVE/CWE reporting, SIEM/Incident documentation, and NIST RMF/SEC501 compliance. VITA ISO training completed. Member of CAB (Change Advisory Board).

· GRC Routine ISO tasks included account lookups in ARS, approval of creation and modification of role based access (RBA) within the COV Virginia.Gov domain(s); Assisting customers with account issues prior to submission to the VCCC or after rejection by the VCCC; Reviewing accounts and requests for Role-Based and Least Privilege access insuring adherence to agency security requirements; troubleshooting account issues with Active Directory and other account workflows; Process exception requests, wavers, firewall rule changes, etc. Maintain agency security operations documentation; assist with agency security operations including Topology, Configuration, and Vulnerability compliance scanning while populating risk mitigation documentation and POA&Ms as required.

· Details of special deliverables and project accomplishments as GRC Lead include:

o Refresh of Nessus Scanner and other tools / processes after many years of being forced into the canned reports from ePO (e Policy Orchestrator) and Tenable Security Center.

o Developed targeted environment Tenable NESSUS scans for Virginia Department of Elections in support of the Mid Term Elections; as well as Virginia Department of Taxation & Virginia Department of Social Services to resolve overdue IRS Federal Audit findings - identifying broken McAfee signature databases, certificate problems, configuration problems, patch non-compliance, and unauthorized software. This included in-depth pivot table analysis of raw SC data dumps..

· Discovered and analyzed urgent findings in support of State Agency workstations and servers (Previously un-ticketed, yet critical, high and moderate risk issues) in time to remediate/mitigate risk for Department of Elections, and Department of Taxation & VDSS prior to urgent event windows.

Federal & State Contractor

Federal & State Contracting
DMV, Va, Md, Dc
01.2000 - 07.2018
  • Protected secure data files and regulated access.
  • Made recommendations to improve security procedures and systems.
  • Analyzed system risk to identify and implement appropriate security countermeasures.
  • Audited networks and security systems to identify vulnerabilities.
  • Analyzed security procedure violations and developed plans to prevent recurrence.
  • Designed, implemented and maintained security systems and controls.
  • Updated virus protection systems based on computer virus reports.
  • Designed and implemented plans to secure computer files against breach, destruction or accidental modification.
  • Built firewalls and encrypted data to secure confidential information.
  • Conducted record searches and coordinated with other units on procedural problems involving complex cases.
  • Managed [Software] information system accounts, facilitating transfer of data to users.
  • Researched and designed advanced computer forensic tools.
  • Worked closely with team members to deliver project requirements, develop solutions and meet deadlines.
  • Prioritized and organized tasks to efficiently accomplish service goals.
  • Juggled multiple projects and tasks to ensure high quality and timely delivery.
  • Demonstrated self-reliance by meeting and exceeding workflow needs.
  • Demonstrated leadership by making improvements to work processes and helping to train others.
  • Provided excellent service and attention to customers when face-to-face or through phone conversations.
  • Improved operations by working with team members and customers to find workable solutions.

Army National Guard Technical Supervisor

Army
DMV
06.1986 - 12.2010
  • Evaluated and reviewed staff performance.
  • Ordered supplies and managed inventory.
  • Determined proper allocation of resources to maximize work coverage and team effectiveness.
  • Resolved customer issues and provided creative solutions.
  • Devised strategies for optimizing work procedures, technical training and standard processes.
  • Generated reports outlining latest updates, results and proposed solutions.
  • Conducted inventory counting [Number] times per year.
  • Managed group of [Type] professionals accomplishing [Name], [Name] and [Name] objectives.
  • Managed administrative office functions, including [Duty], [Duty] and [Duty].
  • Troubleshot and resolved problems with programs and systems.
  • Troubleshot malfunctions with systems and programs to pinpoint root cause of issues and restore.
  • Executed and implemented solutions on time and within budget constraints.
  • Trained end-users in best practices to minimize errors and protect key data.
  • Offered technical helpdesk support to customers on printers, PCs and laptops and mobile devices.

Electronics Warfare Instructor and DECM Tehnician

USMC
2nd MAW & Flight, Multiple
01.1979 - 12.1986
  • Assessed effectiveness of training program to identify and resolve deficiencies or issues.
  • Utilized standard electrical components in analog and digital circuits.
  • Observed safe work practices and conducted safety inspections to reduce workplace accidents.
  • Enforced safety mandates and OSHA restrictions with good leadership skills.
  • Encouraged student critical thinking and discussion using variety of teaching techniques.
  • Optimized project completion time by troubleshooting after-hour emergencies for immediate repair.
  • Evaluated students' performance and issued progress reports.
  • Applied variety of instructional resources to meet needs of students with varying backgrounds and learning styles.
  • Created appropriate learning environments for students.
  • Planned and conducted activities for balanced program of instruction, demonstration and work time, providing students with opportunities to observe, question and investigate.
  • Conducted on-the-job training classes and demonstrated principles, techniques, procedures and methods of diverse subjects.
  • Crafted lesson plans to meet diverse learning modalities and ensure inclusive learning environment.
  • Selected curriculum and instructional aids to increase students' understanding of core concepts.
  • Supervised advanced student work, including both independent and group projects.
  • Collaborated with other educators to address deficiencies in program offerings.
  • Maintained student records detailing progress, attendance and program requirements.
  • Gave constructive feedback to students to improve learning and progress against course objectives.

Education

Master of Science - Graduate Certificates NSA 4011-4016a

Security University, Herndon, VA
08.2015
  • Completed coursework in [Subject], [Subject] and [Subject]
  • Major in [Subject]

Bachelor of Science - Electrical Engineering Technology/Computer Network

ARNGI - DANTES, NAS Pensacola
09.2001

Skills

  • Tenable Nessus
  • Protecting networks
  • Encryption
  • Preparing summaries
  • Problem resolution
  • Customer service
  • Intrusion defense
  • Business process lifecycle
  • Business initiatives proficiency
  • Adobe Illustrator
  • Microscope use
  • Hazardous chemicals
  • Customer and personnel training
  • Personalized customer service
  • Power tool use

Certification

Education-Training: COV VITA-ISO, RSA ARCHER GRC, VSM, ServiceNow/Keystone Edge, MCP, MCSE, CompTIA Security+ CE; ISC2 CISSP; F5 Networks LTM/GTM SE, Cisco CCNET/CCNA, DoD ACAS, Telos (XACTA-DHS IACS), NESSUS PVS, N-Circle 360; Certified Ethical Hacker Core; Microsoft MCITP Refresh of MCP and MCSE. CISA Cert Scheduled.

Extensive commercial, federal/military technical training – transcripts available.

University Undergraduate Level: 4 Years of Information Technology, Electrical Engineering Technology / Eng. Mgt.

Graduate Level: NSA Core Certs NSA 4011-4016a/CNSS1253/ Grad Certificates supporting a Masters in Cybersecurity.

DOD 8570 Information Assurance Workforce Registered IAT and IAM Registered, DoDD 8140 Cyber Workforce Mgt..

o CISSP: ISC2 Certified Information Systems Security Professional Certificate 410346 in work - renews 7/2024

o SECURITY + CE: CompTIA: Certificate: COMP001020390368 renews 5/2024

o CISA/CRISC Class and testing planned Oct-Nov 2021

o DoD, Army CIO, and Navy RMF Validator training for EMASS. DHA MEDCOM RMF training.

o PM eMASS OSD/WHS DoD eMASS Program Train the Trainer Pilot (BAH/PM eMASS)

o PM eMASS Army CA Rep eMASS Training (BAH/PM eMASS)

o USMC C4IA Telos XACTA MCCAST Training

o *Fully Qualified Navy Validator: FQNV #I1296; Next Gen Navy QNV/NQV Training completed

o SPAWAR-NQV-101 Navy Qualified Validator Course - Introduction for Navy Validators

o SPAWAR-NQV-102 Navy Qualified Validator Course - Risk Management Framework

o SPAWAR-NQV-103 Navy Qualified Validator Course - Security Controls

o SPAWAR-NQV-104 Navy Qualified Validator Course - A&A Tools

o SPAWAR-NQV-201 Navy Qualified Validator Course – BAH Resident Tng w/eMASS

o DOJ/FEMA WMD Counterterrorism; DEARNG CST Chem Bio; USArmy 74D CBRNE training.

o US Navy/Marine Corps Aerospace Electronics, Avionics, Aviation Elect, Electronic Warfare & COMSEC training.

Work Availability

monday
tuesday
wednesday
thursday
friday
saturday
sunday
morning
afternoon
evening
swipe to browse

Timeline

GRC Lead - State Of Virginia VITA-TAP-MSI
08.2018 - 07.2019
US Army Retired Reserve (District/Maryland/Virgini - US Army Reserve
12.2010 - 08.2021
Federal & State Contractor - Federal & State Contracting
01.2000 - 07.2018
Army National Guard Technical Supervisor - Army
06.1986 - 12.2010
Electronics Warfare Instructor and DECM Tehnician - USMC
01.1979 - 12.1986
Security University - Master of Science, Graduate Certificates NSA 4011-4016a
ARNGI - DANTES - Bachelor of Science, Electrical Engineering Technology/Computer Network
Rick DeGraffenreid