Information Assurance Architect Resume
Reston, VA
SUMMARY:
Over 25 years in IT (defense, federal, commercial); cybersecurity compliance focus; published industry writer
SERVICE AREAS:
Cybersecurity: Program Development, Management, Strategic Support; Policy Development, Analysis;
Information Security: Engineering, Consulting, Testing, Incident Management, Monitoring, Data Forensics
Identity Management: CAC/PIV/ECA Integration; Key Generation and Management; CA and RA/LRA Interfaces
Software Assurance: ICT - SCRM Architecture, Static Code Analysis, Web Application Scans, Penetration Testing
Information Security Risk Management: Risk Analysis, Risk Decision Support, FedRAMP (CSP, 3PAO, Agency)
Sales Support: Business Development, Capture Management, Bid & Proposal, Strategy/Analysis, Partnerships
TECHNICAL SKILLS:
Systems: Microsoft Windows (Pro/Server/Datacenter); Red Hat Linux; Oracle Solaris; iOS, Android, FortiOS Intel/AMD/ARM based desktop, portable, server, rackmount, and mobile systems and components Cloud computing technology IaaS, PaaS, SaaS; Public, Private, Hybrid; Amazon AWS, Azure, O365
Equipment: Network switches, routers, firewalls, load balancers, wireless, cabling, DMZ, PKI, VPN, VoIP, HSM ID card technology smartcards, magstripes, contactless, card printers, fingerprint readers, imaging
Software: Microsoft HyperV, SQL Server, Terminal Services, System Center, SharePoint, VMware ESX HP ArcSight, Fortify SCA/360, EnCase Forensic, IBM Proventia, Xacta IA Manager, TAF, CSAM Retina, Nessus/ACAS, IBM AppScan, McAfee Foundstone, ePO, HBSS; VMS, CyberScope, eMASS
WORK EXPERIENCE:
Confidential, Reston, VA
Information Assurance Architect
Responsibilities:
- Evaluated Microsoft O365 and Azure FedRAMP packages on behalf of DLA and DISA for the Confidential Pathfinder project.
- Evaluated Information Assurance programs at enterprise, mission/business, and system levels for ‘as-is’ IA architecture.
- Designed and drafted DoDAF 2.0 based ‘to-be’ IA architecture and transition plans including unified project timeline.
- Provided consulting and strategic planning for agency and system level transition from DIACAP to Confidential RMF and ISC
- Authored proposal documents/content, industry briefings, strategic plans, LoE estimates, activity reporting.
- Evaluated RFP and pre-RFP opportunities. Recruited consultants and companies for strategic partnership initiatives.
Confidential, Fairfax, VA
Information Assurance SME
Responsibilities:
- Developed an Enterprise Security Framework (ESF) and Methodology (ESM) for executing Confidential based A&A projects.
Sr. Business Development
Confidential
Responsibilities:
- Served on multiple major proposal teams; managed multiple business development efforts; provided solicitation analysis.
- Architected and presented proposal solution for Confidential Continuous Diagnostics and Monitoring (CDM) and CMaaS.
- Managed, architected, and presented proposal solution for USPS Federal Cloud Credential Exchange (FCCX).
- Presented to senior management (EVPs, CxOs) on future IT/IA trends, recruited candidates for strategic hire initiatives.
- Information Assurance SME - Confidential Medical Support Agency (AFMSA/SG6S) Contract Duties
- Served as Agent of the CA ( Confidential ) for a portfolio of over 450 medical systems for the Surgeon General of the Confidential .
Confidential, Arlington, VA
Information Assurance Manager
Responsibilities:
- Served as eMASS POC and IA SME for over 250 Human Resource Management (HRM) systems Confidential wide.
- Served on Confidential and Confidential level Technical Advisory
- Authored Confidential and HRM level program strategy and policy for IA, Continuous Monitoring, and POA&M Management.
- Managed source code analysis, vulnerability management, and security testing & evaluation (ST&E) procedures.
Information Assurance Manager
Confidential
Responsibilities:
- Responsible for all IA and Security related LoE estimates, proposal, fulfillment, and activity reporting on all contracts.
- Authored proposal document packages, industry briefings, strategic plans, FedRAMP 3PAO application packages.
- Managed company network defense, vulnerability/risk management, PKI, employee entry/exit, IA training, IT policies.
Confidential, Herndon, VA
Lead Secure Systems Engineer
Responsibilities:
- Designed and implemented full service data forensics labs, policies and procedures using Confidential Enterprise.
- Engineered security event information management systems, PKI/PIV services, user session monitoring, remote access.
Lead Secure Systems Engineer
Confidential, Washington, DC
Responsibilities:
- Served as Information Systems Security Officer (ISSO) for multiple major/minor systems.
- Managed PKI/PIV interfaces.
- Established and led Vulnerability Management Group (VMG); Served on Change Advisory Board ( Confidential ).
- Developed SharePoint based security metrics and reporting center, policy and procedure framework.
