Summary
Overview
Work History
Education
Skills
Timeline
SKILLS
References
Generic

Robert Lima

Germantown,MD

Summary

A highly motivated, versatile, and team-oriented Cybersecurity RMF SME with 10+ years of experience. I’m seeking a challenging position with an organization that allows me to broaden my skills within my discipline, as well as contributing my creativity and hard work towards the success of an organization.

Overview

9
9
years of professional experience

Work History

Family Caregiver (Temporarily)

Full Time
05.2025 - 11.2025
  • Provided full-time care for an elderly parent, managed & coordinated medical appointments, and overseeing daily living needs. Family caregiving often involves:
  • Organization & Scheduling – Coordinated healthcare appointments and communicated effectively with medical professionals for optimal care.
  • Communication – family liaison with doctors and medical staff, insurance, and close family members.
  • Problem-Solving – Handling emergencies and adapting to changing needs.
  • Budget Management – Managing household & medical expenses.
  • Developed strong organizational, problem-solving, and advocacy skills.
  • Provided compassionate care and emotional support and enhancing quality of life.
  • Managed daily living activities including meal preparation and medication administration.

Assessment and Authorization (A&A) SME

NexGen Data Systems
07.2023 - 04.2025


The Cloud Capability Integration Technical Initiative (CITI) project aims to provide cloud native services that increase our Mission Owner’s ability to deliver secure applications/services at a high velocity. Expert in NIST SP 800-53(r5) & NIST SP 800-37(r2).

  • Manage Plans of Actions and Milestones (POA&Ms) resulting from system vulnerabilities from ACAS, Nessus scans, Prisma Cloud Compute (PCC) for containerized workloads to include DISA STIG checks.
  • Review and recommend updates to package artifacts such as policies and procedures to address non-compliance controls, security gaps and deficiencies.
  • Identify vulnerabilities related to outdated patches and notify DC2H2 Service areas on user patching can be coordinated and addressed in a timely manner to maintain compliance with DoD IAVM standards.
  • Customer Service - assess RMF IT stakeholder business requirements and provide industry best practice recommendations and assist where needed. Establish strong partnerships with multiple internal business units and IT programs.
  • Responsible for translating business requirements to system owners, relationship management and executive communication.
  • Problem Solving - proactively identify weaknesses or risks, determine accuracy and relevance of information, with a team player mentality and approach through a comprehensive information gathering and relaying to the product team and ISSM through exceptional interpersonal communication skills.
  • Passionate, motivated, and meticulous attention to detail, solution deadline focus with experience in constantly updating and writing and editing documents (SSP, POA&M, etc.), as well as compiling the necessary documents for A&A recertification of the assigned systems, use sound judgment to generate and evaluate alternatives and make recommendations.
  • Proven ability to learn quickly and adapt to new situations.
  • Led cross-functional teams to develop and implement data management strategies.
  • Managed time efficiently in order to complete all tasks within deadlines.

Information Systems Security Officer (ISSO)

SeKON Enterprise Inc.
02.2017 - 06.2023

The mission lifecycle of DHMS is to competitively acquire, test, deliver, and successfully transition to a state-of-the-market electronic health record (EHR) system. Develops a deployment and sustainment strategy to optimize the delivery of a modernized EHR with minimal disruption to the military health care community.

  • Gap analysis expert - identified workstreams with SME vacancies & assisted with business development strategies. Company growth - Added resources to new and existing project portfolios resulted in $15 million revenue increase.
  • Self-motivated, with a strong sense of personal responsibility.
  • Worked effectively in fast-paced environments.
  • Skilled at working independently and collaboratively in a team environment.
  • Utilized vulnerability & compliance scanning tools (ACAS, SCAP, DISA STIG Viewer); evaluated results, and collaborated with Product Team(s) for determining remediation steps.
  • Writing POAMs, including detailed justifications for program-required non-compliant item(s) or security weaknesses.
  • Experienced with the Federal Information Security Management Act (FISMA) and FedRAMP AWS Moderate/High environments (PaaS/IaaS).
  • Ability to work multiple projects concurrently within deadlines while ensuring that complex information is conveyed in a clear, accurate, and concise manner under normal or in rare crisis situations.
  • Ensured A&A support documentation packages for systems(s) are developed, maintained, and updated as required in the eMASS system of record.
  • Coordinated security procedures with the ISSM and initiate investigative procedures for security related events, and institute protective or corrective measures upon discovery of an IA incident or vulnerability.
  • Conducted Risk Assessments, Continuous Monitoring activities & Annual Tabletop exercises.
  • Developed and implemented security policies to safeguard sensitive information across organizational systems.
  • Conducted physical site assessments to identify vulnerabilities within IT infrastructure and recommended appropriate mitigation strategies.

Education

Master of Science - Cybersecurity Technology

University of Maryland University College
Adelphi, MD
05.2015

Bachelor of Arts - Technology Management

Saint Leo University
Norfolk, VA
03.2012

Associate of Arts - Liberal Arts

Saint Leo University
Norfolk, VA
05.2010

Skills

  • ISC2 - Certified Authorization Professional (CAP), (2017, re-certified in 2020)
  • ISC2 - Certified in Governance, Risk, and Compliance (2023 to present)
  • CompTIA Security certification (2009 Edition)
  • Pursuing CompTIA Advanced Security Practitioner (CASP) certification (Spring 2026)
  • Active DoD secret clearance (3/2015 to present) - Contractor
  • DoD Top Secret/SCI clearance (2008 to 2013) - U S Navy
  • DoD Secret clearance (2001 to 2007) - U S Navy

Timeline

Family Caregiver (Temporarily)

Full Time
05.2025 - 11.2025

Assessment and Authorization (A&A) SME

NexGen Data Systems
07.2023 - 04.2025

Information Systems Security Officer (ISSO)

SeKON Enterprise Inc.
02.2017 - 06.2023

Master of Science - Cybersecurity Technology

University of Maryland University College

Bachelor of Arts - Technology Management

Saint Leo University

Associate of Arts - Liberal Arts

Saint Leo University

SKILLS

  • Specialized Software/Applications:
  • ACAS, Nessus, SCAP, DISA STIG Viewer, WebInspect, HIAT/PCAT Tool, Prisma Cloud Compute & Trivy container scanners/containerized workloads
  • eMASS, DADMS, JIRA, SNOW, CACAMS, IBM Jazz Tool
  • Cybersecurity Maturity Model Certification (CMMC), NIST SP 800-171
  • RMF Gap Analysis, Navy Validator/Assessor NIST SP 800-37(r2), NIST SP 800-53(r5)
  • FISMA, FedRAMP Moderate/High (IL4, IL5), AWS GovCloud, PaaS, IaaS
  • Wireshark, Juniper products, DameWare, Mini Remote-Control, eRetina
  • Privileged / Non Privileged User Activity Log Reviews

References

  • Cal Hardy, Senior Cybersecurity SME, (757) 477-9598
  • Michelle Rowe, ISSM/ISSO, (240) 923-4520
  • Chris, Tillison, Senior Security Engineer, (520) 961-4041
  • Randy Day, Project Manager, (337) 375-3242
  • Yvette Simon, ISSM, (571) 236-9014