Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic

Simon Gomes

Laurel,MD

Summary

Results-driven Compliance Analyst with seven years in IT security infrastructure and risk assessment, specializing in FedRAMP Moderate and CMMC compliance. Skilled in ATO acceleration and cloud security, leveraging Agile methodologies and DevSecOps to enhance security frameworks. Committed to driving digital transformation and cloud migration through innovative security solutions.

Overview

4
4
Certifications
7
7
years of professional experience

Work History

Information Systems Security Officer

Booz Allen Hamilton Inc
Washington, DC
10.2025 - Current
  • Developed and implemented organization-wide information security policies, procedures, and standards.
  • Implemented security controls to mitigate risks and enhance system integrity.
  • Designed, implemented, and maintained security systems and controls.
  • Developed security policies that protected sensitive information and systems from identified threats.
  • Collaborated with cross-functional teams to ensure compliance with industry regulations and standards, strengthening security posture.
  • Monitored network traffic for unusual activity and potential security threats.
  • Evaluated security tools and technologies for effective threat detection and response.
  • Evaluated network architecture designs to identify potential vulnerabilities.
  • Recommended corrective actions to mitigate identified risks and vulnerabilities.

Information Security Analyst

Booz Allen Hamilton Inc.
Washington, D.C.
11.2021 - 09.2025
  • Analyzed data to produce comprehensive reports assessing system readiness for ATO, ensuring alignment with NIST 800-53 FISMA Moderate Standards.
  • Worked with system owners and network teams to gather data for ATO packages, ensuring compliance with eMASS and various NIST publications standards.
  • Utilized NIST 800-53 knowledge to create and refine A&A documentation, enhancing risk management through collaboration with system teams.
  • Analyzed existing systems to identify improvement areas, contributing to enhanced security posture.
  • Evaluated system performance, identifying optimization areas to support compliance and operational efficiency.
  • Prepared comprehensive reports on analysis findings and recommendations, facilitating informed decision-making for remediation efforts.
  • Supported project management efforts by tracking timelines and deliverables effectively.

SENIOR CONSULTANT/SECURITY ENGINEER

Booz Allen Hamilton
Washington, D.C.
10.2021 - 11.2021
  • ' Provided security consultation for digital transformation architecture, guiding implementation and applying Information Assurance (IA) best practices.
  • ' Collaborated with cross-functional teams to integrate security measures into digital transformation projects, ensuring compliance and safety.
  • ' Developed front-end web interface for climate data analytics, improving data oversight for the Department of Information Resources.

CYBER GRC ANALYST

Science Applications International Corp (SAIC)
Reston, VA
01.2020 - 09.2021
  • Conducted security assessments and consultations for program task orders, improving Cloud Migration compliance and facilitating ATO solutions.
  • Supported task orders in defining and implementing agile Risk Management Framework processes and methodologies, serving as the key technical interface to the customer for determining technical solutions.
  • Established secure Azure virtual servers and components in accordance with security architecture and standards for FedRAMP Moderate Compliance.

APPLICATIONS & ARCHITECTURE DEVELOPER

Unisys Federal
Reston, VA
05.2019 - 01.2020
  • ' Analyzed and implemented cutting-edge compliance automation tools, streamlining ATO processes within DevSecOps environments.
  • ' Developed RMF automation solutions that enhanced compliance processes and expedited project timelines.
  • ' Streamlined RMF automation by identifying open-source solutions that improved project efficiency and compliance outcomes.
  • ' Conducted R&D for RMF automation projects, discovering open-source solutions that accelerated ATO processes.
  • ' Configured Federal open-sourced database servers and web servers for FEDRamp Compliance.
  • ' Ensured FEDRamp compliance through precise configuration of open-source servers, maintaining high standards of federal adherence.
  • ' Collaborated on AI and ML projects, facilitating integration of intelligent algorithms into client solutions.

Education

BS - INFORMATION TECHNOLOGY WITH A FOCUS IN INFORMATION SECURITY

George Mason University
Fairfax

Skills

  • Cybersecurity
  • Risk compliance assessment
  • Compliance Frameworks
  • Cloud Security Management
  • Infrastructure Security Strategies
  • Security strategy
  • Vulnerability assessment
  • Vulnerability evaluation
  • Compliance oversight
  • Governance assessment
  • ATO acceleration
  • Cloud readiness
  • Project coordination
  • Cross-functional collaboration
  • Problem solving
  • Network security
  • Policy formulation

Certification

CompTIA SEC+

Timeline

Information Systems Security Officer

Booz Allen Hamilton Inc
10.2025 - Current

Information Security Analyst

Booz Allen Hamilton Inc.
11.2021 - 09.2025

SENIOR CONSULTANT/SECURITY ENGINEER

Booz Allen Hamilton
10.2021 - 11.2021

CYBER GRC ANALYST

Science Applications International Corp (SAIC)
01.2020 - 09.2021

APPLICATIONS & ARCHITECTURE DEVELOPER

Unisys Federal
05.2019 - 01.2020

BS - INFORMATION TECHNOLOGY WITH A FOCUS IN INFORMATION SECURITY

George Mason University
Simon Gomes