Director: Security, Cloud Services Resume
0/5 (Submit Your Rating)
SUMMARY:
- Program/Project Management: budget control, program and projects plans, resource allocation, personnel management, and communications;
- Expertise in Cloud, IT, and IT security; cyber security implementation and integration in data centers and Cloud, Enterprise Architecture - DODAF and FEAF:
- Cloud computing: procurement, architecture, security and engineering;
- Migration from Data Center to cloud environments; Transformation of Systems Applications and Processing (SAP);
- Cybersecurity. Compliance with FISMA: NIST—FEDRAMP, RMF;
- Expert in NIST and DoDI 8510.02- RMF, FedRAMP, Continuous Diagnostic and Monitoring (CDM) and Government Cybersecurity Architecture (.govCAR);
- Working knowledge of standards and guidelines applicable to security practices including ISO, ISO 20000 and 27000-series, IT Security/PCI DSS and security posture, HIPPA, SOX and PII and others;
- Documentation, Proposals and White Papers, Industry Forums.
PROFESSIONAL EXPERIENCE:
Confidential
Director: Security, Cloud Services
Responsibilities:
- Wrote deliverables submitted to the government:
- Government Cloud Business Process Reengineering. The document describes in significant details the process of reengineering required for migration of the UCSA application services to AWS Cloud Mil 0.2, including the process, its advantages/disadvantages, specific tasks, and allocation of resources with Basis of Estimate (BOE). It includes Fishbone Diagram describing the migration tasks at the high level, and detail WBS.
- Government Cloud Environment Service Design Plan. This document identifies the four stages of migration: Preproduction, Production, Authorization, and Operation.
- Led the migration process in Preproduction, Production and Authorization stages, including:
- Deployment of EC2s in the VPCs using the AWS CloudFormation and automation scripts
- FedRAMP based cybersecurity
- Review of the DISA Purchasing Orders for the AWS Cloud Mil 0.2 elements
Confidential
Responsibilities:
- Enterprise Architecture projects including assessment of cybersecurity architecture (using cybersecurity - EA mapping techniques, such as IDEF0)
- Cloud Services Architecture in the government space for the IaaS, PaaS, SaaS models; Cybersecurity Architecture and service delivery documentation
- AWS based cloud migration for the DHS application systems (e.g., E1E, TAXII), Security Audits and ATOs.
- Organized and leads weekly Cybersecurity Architecture Working Group (CAWG) that develops recommendation for migration to and operation of the DHS NCPS application systems in a cloud environment. From cybersecurity perspective, these recommendations are consistent with the concepts of CDM and .govCAR.
Rapid Web Deployment. Program Manager and Architect
Confidential
Responsibilities:
- Development of mission-related system and security architecture;
- Deployment of the WCoE servers’ instances in the AWS cloud, including firewalls, virtual private cloud (VPC) and secure access to the proxies, applications clusters and databases in the cloud
- Security Engineering and Integration, deployment of built-in security mechanisms imbedded in EC2 configurations, ELB scaling, EC2 replication and operation in multiple availability zones
- The cybersecurity (Information Assurance) process under RMF and FedRAMP, including adherence to FISMA requirements, Authorization to Operate (ATO) and continuous monitoring for the CoE’s Washington Headquarters System (WHS)
- AWS-DoD mandatory SOC operations including incident detection, response and reporting
- Implementation of Computer Network Defense Services (CNDS) in the cloud
- ITIL and CMMI change and configuration management.
DISA / PENTAGON.
Program Manager
Responsibilities:
- IBM Maximo and Tririga Modernization Program at Federal Facilities Division (FFD), Pentagon. Developed program and project plans, provided scheduled reports, and recommendations. Managed a team of multi-companies’ specialists
- Technical aspects included assessment of the Enterprise Architecture (DODAF), development effort and on-site analysis of currently deployed software suits, network configuration and topology, security settings and operations.
- Assistance with the GSA Cloud First Services (Schedule 70; Email as a Service (EaaS))
- Migration of NG Financial systems to the Microsoft Government SaaS Cloud. At the time (2013). Microsoft Azure was in the process of obtaining a Provisional Authorization (PA) for this Community Cloud
- Support to OCIO: security policies and procedures documentation, oversight of the Information assurance (IA) process under NIST RMF/FedRAMP, as well as FISMA Reports through the DHS Cyberscope Portal and support of external FISCAM and FISMA/FISCAM audit
- Program and Project Management: account management (quarterly EVM reports, budget reports), Project Plans, staff mentoring (assignments, for mandatory s and supervision)
- Implementation of the world-wide patent search system using the Amazon IaaS Cloud
- Development of security business and strategic plans
- Oversight of mandatory security
- Transition to Continuous Security Monitoring as recommended by NIST SP Rev.1 - RMF, with incremental Security Controls’ selections and annual security assessments
- SOC/incident reporting operations
- Extensive Security documentation for Information Assurance and FISMA reporting using automated tools such as CSAM, TAF, and RSA Archer
- Information assurance activities related to security risk assessment within a Homeland Security cyber security program: mitigation of security risks and development/ updates of security documentation and related configuration and change processes
- Development and Engineering of the OMB mandated Trusted Internet Connection (TIC), a secure Internet Portal, and IT consolidation at the DOJ Justice Management Division (JMD) and department-wide. The government-wide TIC programs were mandated to yield operations efficiency and enhance security of the Internet access. JMD was one of the first Government agencies to implement full scale TIC and Data Center Consolidation Department - wide. Currently, the TIC progress must be reported as a security feature in the annual FISMA reports
Confidential
Program Manager
Responsibilities:
- Migration of the World-Wide Patent Search system to AWS and NGFMS to Microsoft cloud
- Vulnerability and penetration testing with the results analysis and remediation/risk mitigation
- Authorization and risk management support
Confidential
Program Manager
Responsibilities:
- IT and cyber security operations of multifunctional IT master systems, Data Center SOC operations, incident reporting
- Vulnerability scanning, analysis, and remediation/risk mitigation
- Information Assurance
- Authorization support,
- Data center consolidation and
- Trusted Internet Connection (TIC) implementation
- Direct liaison to GSA and the vendor (Sprint) on service management, SLAs, ICSAs, and MOUs
- As the JCN PMO representative, worked with AT&T on decommissioning JCN prior to installation of AT&T’s MPLS-based JUTNET, creating four operations zones allowing gradual simultaneous deactivation and activation of the network services to DOJ with virtually no downtime.
- Contributed to the proposal of an initially $9 million TriCare IA contract, that subsequently grown to over $20 million annually.
- Participated in Security Assurance Services and Innovation (SASI) proposal for the Department of State Bureau of Diplomatic Security Chief Technology Officer. CACI was ed a $29 million prime task order under the SASI task blanket purchase agreement, which has a ceiling value of $710 million
- Provided EVM support for the Customs and Border Protection Security support project.
- Led corporate effort in company-wide implementation of the ITIL ITSM framework security, based on the ISO 27000/ISMS Standard Series. Contributed to the presentation of CACI-style ITIL framework at the corporate website aimed at attracting prospective clients with requirements to use the ITIL methodology
Confidential
Senior Principal Engineer
Responsibilities:
- Representative to the International Telecommunication Union (ITU) in Geneva. Introduced various INTELSAT products and services for world-wide standardization. In addition, led a marketing effort, developed press releases, conducted conferences within the ITU framework (e.g., working groups), and reported to the Board of Governors Technical Committee.
- Directed development and deployment of a private telecommunication broadband networks carrying high-speed data and voice over terrestrial and satellite links for variety of oversees companies, such as Lukoil Corporation. Contractual value $25.5 million.
- Led of Hughes satellite equipment under a purchasing agreement with $50 million ceiling.
- Provided project plans for point-of-sale transaction data network at Lukoil gas stations - estimated value of $4M a year
