Senior Program Manager, C-SCRM Program at Department of State - Contracting Resources Group (CRG) - Washington, DC
(2025-10 - 2025-04)
Led enterprise‑wide C‑SCRM program activities in close partnership with the Department's C‑SCRM Director under the Office of the Enterprise Chief Information Security Officer (E‑CISO), ensuring alignment with mission priorities, federal mandates, and enterprise cybersecurity strategy.
- Established and managed program goals, performance metrics, and reporting mechanisms, directly supporting execution of the Department's C‑SCRM Strategic Plan and Roadmap.
- Ensured program compliance with federal directives, including NIST SP 800‑161 and Executive Order 14028, by driving adoption of standardized risk‑management and supply‑chain security practices across the enterprise.
- Presented executive‑level briefings, risk analyses, and strategic recommendations to senior leadership, enabling informed decision‑making and strengthening enterprise governance.
- Identified, assessed, prioritized, and mitigated C‑SCRM program risks, strengthening resilience against ICT and OT supply‑chain threats and improving enterprise risk posture.
- Oversaw FISMA audit readiness as the C‑SCRM Program Manager, coordinating cross‑functional teams to assess controls, validate security requirements, and remediate findings under NIST SP 800‑53 and SP 800‑161, resulting in improved audit outcomes and enhanced third‑party risk governance.
- Collaborated with internal bureaus, offices, posts, and external federal agencies to expand and mature the Department's C‑SCRM capabilities, strengthening interagency partnerships and shared risk‑management practices.
- Defined project scopes and objectives, developing stakeholder engagement plans that ensured technical feasibility, mission alignment, and cybersecurity integration.
- Communicated complex technical and risk concepts to diverse audiences, including executives, technical teams, and interagency partners, ensuring clarity and alignment.
- Maintained strong organizational discipline, ensuring quality control, attention to detail, and the ability to manage multiple concurrent priorities in a fast‑paced, high‑visibility environment.
Cyber Supply Chain Risk Manager | GS-14 - Office of Personnel Management - Washington, DC
(2024-05 - 2025-05)
Designed and executed OPM's enterprise C‑SCRM program, ensuring all acquisitions, procurements, and outsourcing efforts incorporated security requirements aligned with organizational and federal goals, reducing supply‑chain disruptions by 30%.
- Authored and institutionalized internal C‑SCRM policies aligned with federal directives, strengthening governance, accountability, and integration of security requirements into procurement, contracting, and operational planning.
- Secured OMB M‑22‑18 waiver approvals for SSD attestation extensions, reinforcing secure systems development and positioning OPM as a federal compliance leader.
- Implemented the Interos Resiliency Platform, integrating automated risk‑intelligence capabilities into system operations, vendor ecosystems, and continuous monitoring workflows.
- Orchestrated real‑time supplier‑threat monitoring and incident‑response architecture, enhancing operational security and reducing supplier‑related response times by 40%.
- Directed cross‑departmental third‑party risk reforms, identifying and integrating technical, financial, organizational, and administrative issues, resulting in a 25% improvement in audit performance.
- Guided cross‑functional cybersecurity teams in ensuring confidentiality, integrity, and availability across systems and programs, while embedding C‑SCRM controls into system integration, testing, operations, and maintenance.
- Conceptualized and integrated secure IT and supply‑chain risk controls into systems and network development efforts, ensuring alignment with enterprise risk‑management objectives.
- Performed enterprise security reviews, identifying gaps in supplier and system security architecture and driving recommendations incorporated into OPM's risk‑mitigation strategies.
- Led supervisory and managerial functions, including planning, assigning, reviewing, and approving work; coaching and facilitating team performance; resolving operational challenges; and executing performance ratings, awards, and corrective actions.
Information Systems Security Manager | GS-14 - Office of Personnel Management - Washington, DC
(2021-01 - 2024-05)
Led enterprise cloud-security, continuous monitoring, and risk-management functions supporting high-impact systems, FedRAMP-authorized platforms, and agency-wide cybersecurity operations. Provided strategic guidance to leadership, operational staff, and mission stakeholders to ensure a secure, resilient, and highly available IT infrastructure across the enterprise.
- Translated complex federal mandates and regulatory requirements into actionable, agency‑wide security policies, strengthening governance and improving compliance posture.
- Reviewed and assessed the impact of new system‑design policies, ensuring alignment with secure engineering practices and organizational risk‑management objectives.
- Served as the security lead for cloud‑native PaaS and SaaS platforms, embedding FedRAMP Moderate/High controls across the technology stack and ensuring secure system design.
- Directed successful FedRAMP Authorization to Operate (ATO) efforts for multiple cloud systems, aligning security architecture with NIST SP 800‑53 Rev. 5, OMB requirements, and agency‑specific mandates.
- Secured ATOs for multiple cloud systems by developing clear, actionable security policies and leading cross‑functional teams through assessment, remediation, and authorization activities.
- Conducted detailed impact analyses for system changes, ensuring alignment with FedRAMP, RMF, FISMA, and NIST requirements while guiding secure implementation strategies across cloud and on‑prem environments.
- Ensured secure implementation of new cloud technologies, maintaining continuous compliance with all federal security mandates and strengthening enterprise cloud‑security posture.
- Managed agency‑wide continuous monitoring operations using RSA Archer, Nessus, and Microsoft Defender, delivering real‑time threat insights, compliance tracking, and executive‑level reporting.
- Led enterprise vulnerability‑remediation initiatives, coordinating cross‑team responses to risks and ensuring alignment with federal benchmarks and agency risk‑tolerance thresholds.
- Minimized enterprise risk by delivering real‑time threat intelligence and enabling coordinated, strategic responses to emerging vulnerabilities across the organization.
- Strengthened operational resilience by integrating continuous monitoring outputs into risk‑management workflows and executive decision‑making processes.
- Collaborated with senior program managers, system owners, engineers, and mission stakeholders to ensure security requirements were integrated early and consistently throughout the system lifecycle.
- Communicated complex technical and risk concepts to diverse audiences, including executives, technical teams, and interagency partners, ensuring clarity, alignment, and informed decision‑making.
- Maintained strong organizational discipline, ensuring quality control, attention to detail, and the ability to manage multiple concurrent priorities in a fast‑paced, high‑visibility environment.
Cybersecurity and IT Systems Analyst - Multiple Federal Contractors
(2004 - 2021)
Multiple Cybersecurity and IT Systems Analyst Federal Contractor Roles
Information Systems Operator Analyst - US Army
(1997 - 2004)