About
Security and compliance professional with 14+ years of experience supporting federal government programs across DoD and DHS environments.
Demonstrated ability to analyze complex technical and operational data, produce clear analytical reports and briefing materials, and coordinate working groups and multi-stakeholder initiatives in support of government regulatory objectives.
Deep expertise in NIST RMF, ATO lifecycle management, risk assessment documentation, and policy development.
Proven track record of translating technical findings into actionable insights for government leadership.
Holds an active Top Secret clearance; Public Trust eligible.
What I'm looking for
SOC type roles, IOT hardening, Smart farming
Experience
Principal Cyber Systems Engineer
Northrop Grumman
Jun 2021 – Present
Led implementation and ongoing maintenance of regulatory compliance programs aligned with NIST SP 800 series and the DoD Risk Management Framework (RMF), ensuring federal systems met all applicable standards.
Served as a key analytical contributor within the Governance, Risk, and Compliance (GRC) function — researching emerging threats, assessing program risk posture, and producing research summaries for leadership review.
Conducted comprehensive security assessments and regulatory audits of federal information systems; authored written reports with prioritized, actionable recommendations that were adopted by program leadership.
Chaired weekly Change Configuration Board (CCB) meetings — developing agendas, coordinating participation across engineering, security, and compliance stakeholders, and producing post-meeting documentation and action item tracking.
Managed the full ATO accreditation lifecycle for federal information systems, coordinating with DoD regulatory bodies and authoring all required compliance documentation packages.
Collaborated with cross-functional teams to embed regulatory requirements into SDLC processes, ensuring compliance was addressed from project inception through deployment.
Developed and sustained a comprehensive library of security documentation — policies, procedures, and SOPs — supporting ongoing compliance, audit readiness, and knowledge transfer.
Provided expert analytical support during security incidents and regulatory reviews, preparing briefing materials and coordinating response activities with internal teams and external government stakeholders.
Executed recurring vulnerability assessments using industry-standard tools and produced technical summary reports supporting regulatory compliance obligations.
Microsoft 365YARAPowerShellNIST RMFRisk Assessment
Information Systems Technician (IT1, E-6)
United States Coast Guard
Feb 2012 – Present
Investigated and documented security events and communication anomalies across classified and unclassified federal systems, analyzing logs from routers, switches, satellite comms, and VoIP — findings informed operational and policy decisions.
Led a cross-functional network infrastructure migration project including fiber backbone installation and data center construction oversight, delivering the project on time and saving the Coast Guard an estimated $75,000 in outsourcing costs.
Established and managed communications systems for the National Command Center during Hurricane Harvey disaster relief — supporting response to 2,000+ emergency calls; recognized with a USCG Letter of Commendation for contributions.
Administered secure classified and unclassified communications systems in strict adherence to DoD and Coast Guard cybersecurity protocols, COMSEC standards, and federal identity and access management requirements.
Contributed to the development and execution of disaster recovery plans for telecommunications infrastructure, ensuring continuity of federal communications operations during emergencies.
Coordinated and executed migration of 800+ computers and 1,200+ software deployments during a Windows 10 enterprise rollout across multiple federal facilities, completed on schedule.
Resolved 900+ user-generated service tickets with documented root-cause analyses and long-term corrective actions tracked through BMC Remedy.
Trained and mentored incoming technicians on telecommunications systems, federal communication protocols, and preventive maintenance procedures.
COMSECBMC RemedyWindows 10
Education
University of Maryland Global Campus
Bachelor of Science · Computer Networking & Cybersecurity
Certifications
ISC2 Certified in Cybersecurity (CC)
ISC2
Dec 2023 – No expiry
CompTIA Security+
CompTIA
Oct 2021 – No expiry
Computer Networking (Undergraduate Certification)
University of Maryland Global Campus
Nov 2019 – No expiry
Skills
YARAPowerShellBMC RemedyCisco Secure EmailActive DirectoryMicrosoft 365TrellixNessusSplunk SIEMPolicy DevelopmentRisk AssessmentATO Lifecycle ManagementNIST RMF
Languages
English (Native or bilingual proficiency)