Sr. Cybersecurity SME at C-Consulting LLC (2022-01 – Present)
- Supported Cybersecurity Assessment and Authorization process for Amphibious Warfare Systems platforms, ensuring comprehensive risk identification, assessment, and adherence to RMF guidelines.
- Managed and tracked RMF and ATO packages for PMS 377/317 systems across NAVSEA and NAVAIR, providing continuous monitoring and status updates.
- Reported ATO status for SIPR and NIPR systems, delivering clear insights to program management for informed decision-making.
- Reviewed and defined policies to enhance governance by identifying and mitigating risks, thereby maintaining data protection and regulatory compliance.
- Documented and communicated security findings with detailed risk analysis, ensuring effective control evaluation and continuous risk reduction.
- Conduct CMMC Level 2 certification assessment activities as a member of the assessment team under the direction of the Lead Assessor.
- Examine documentation and artifacts, interview personnel, and test security controls across the 110 NIST SP 800-171 Rev 2 requirements using NIST SP 800-171A methods.
- Document findings and recommend MET / NOT MET / NOT APPLICABLE determinations for assigned requirements, with supporting evidence.
- Support development of the assessment plan, scope validation, and pre‑assessment readiness reviews.
- Contribute to the assessment report and support POA&M closeout activities within the required timeframe.
- Maintain assessment evidence and working papers in accordance with C3PAO procedures and ISO/IEC 17020:2012.
- Adhere to the Cyber AB Code of Professional Conduct, conflict‑of‑interest, ethics, and impartiality requirements.
- Support clients during C3PAO Level 2 assessments: answer assessor questions, locate evidence, provide clarifications, and coordinate responses to findings.
- Conduct comprehensive gap assessments against all 320 objectives across 110 controls of NIST SP 800-171 Rev 2. Score each objective as Met, Not Met, or Partially Met.
- Proficient with new CMMC 2.0 requirements and knowledgeable about the Department of Defense's recently released final rule for the Cybersecurity Maturity Model Certification (CMMC) Program.
- Experience working with the Defense Industrial Base (DIB) and handling Controlled Unclassified Information (CUI).
- Prior experience developing Plans of Action and Milestones (POA&M) for cybersecurity compliance.
- Familiarity with the latest DFARS Clause 252.204-7021 requirements and the implications of the August 2024 CMMC 2.0 updates.
- Monitored cyber risks and vulnerabilities, overseeing the closure of POA&Ms while tracking progress to meet security standards.
- Supported RMF activities by reviewing cybersecurity requirements for LHA IPT systems, maintaining traceability of vulnerabilities and remedial actions in eMASS.
- Assessed system risks and conducted security control evaluations in line with NIST 800-53A standards, reinforcing robust risk mitigation strategies.
Sr. Security Controls Assessor at 22nd Century Technology (2020-01 – 2022-01)
- Supported the Rural Development Cybersecurity Compliance Program by executing IT Security Authorization, Continuous Monitoring, and FedRAMP Certification tasks with a focus on risk identification and mitigation.
- Performed risk assessments on planned and installed systems using the RMF, ensuring precise evaluation of vulnerabilities and alignment with NIST, USDA, and industry standards.
- Led the development and documentation of USDA Key Controls assessments, providing subject matter expertise to strengthen governance and regulatory compliance.
- Managed continuous monitoring processes, updating ATO package artifacts and POA&Ms to ensure effective control evaluation and risk reporting.
- Facilitated assessment kick-off meetings and developed detailed SAP per SP 800-53A, reinforcing control evaluation and technical risk management for new RD Information Systems.
- Prepared comprehensive Security Assessment Reports and maintained incident response plans, ensuring robust control governance and proactive risk mitigation.
Sr. Security Controls Assessor / Compliance Analyst at 22nd Century Technology - DOL (2019-08 – 2019-12)
- Prepare Authorization and Accreditation (A&A) package documents to enable the Authorizing officer to make risk-based decision to Authorization to Operate (ATO).
- Perform system security evaluations, audits related to the assessment and authorization process.
- Manage POAMs and provide oversight of system vulnerability assessment and monitor remediation efforts of findings and communicate progress to stakeholders.
- Provide advice on proposed change requests and work closely with auditors to identify key controls to be assessed.
- Support independent security control Assessments for all assigned systems. Run scans on systems and analyze vulnerabilities.
- Analyze vulnerability reports and produce summary guidance for System Owners and administrators.
Cybersecurity Analyst at Aurotech Consulting (2013-02 – 2019-08)
- Develop a security assessment plan (SAP) in preparation to security controls Assessment/Testing.
- Assessed information systems to make sure the controls are implemented correctly and performing their assigned functions using NIST 800-53 and Federal Information Processing Standards (FIPS199).
- Evaluate, analyze, and operate industry standard vulnerability assessment tools.
- Participating in incident response sharing efforts and contribute to education and awareness within the organization.
- Work with ISSO's to create and manage POA&Ms for identified system vulnerabilities and track findings to ensure that they are remediated and closed.
- Assessing Technical, Operational and Management controls following RMF NIST 800-37 rev 1 methodology and other NIST 800 publications. Maintain a working knowledge of local security policies and execute general controls as assigned.
- Experience reviewing/updating security artifacts including, but not limited to, SSP, SAR, POA&M, screenshots, Scan data. Conduct periodic and continuous reviews of the system to ensure compliance with the authorization package.