Principal Project Management Analyst Resume
Reston, VA
SUMMARY:
- Thirty years’ experience as a contractor at ODNI, DoD, DHS, DOE, and the FBI, and as a U.S. Government employee
PROFESSIONAL EXPERIENCE:
Principal Project Management Analyst
Confidential, Reston, VA
Responsibilities:- Support safeguarding and safeguarding terrorism and WMD information for the Classified Information Sharing and Safeguarding Office (CISSO) at Information Sharing Environment
- Track progress of Key Information Sharing and Safeguarding Indicators (KISSI) Metrics Program on IC networks
- Support Executive Secretariat at Senior Information Sharing and Safeguarding Steering Committee (SISSSC)
- Develop and integrate new metrics to track emerging national safeguarding priorities for National Security Council (NSC)
- Support initiatives to streamline duplicative data reporting policies and requirements among agencies
- Draft reports and briefings for Senior Executives, White House committees, and the Congress
Technical Lead/Project Manager
Confidential, Silver Spring, MD
Responsibilities:- Supervised team of six IA SMEs in preparing internal controls validation documents for a FISCAM audit
- Collaborated with DoDEA CIO to develop procedural and process guides for access control and authentication
- Developed and implemented a formal configuration management policy and associated protocols
- Developed and implemented a formal separation of duties policy and associated protocols as well as an escrow protocol and independent monitoring process
- Developed and implemented a formal systems categorization policy and associated protocols meeting 800 - 53 standards for all non-national security systems (NSS) and, separately, 1253 requirements for all NSS at DoDEA
Senior Security Engineer Department of Homeland Security
Confidential, Chantilly, VA
Responsibilities:- Provided specialized IA and system security engineering services to the National Cybersecurity Protection System (NCPS) at National Cybersecurity and Communications Integration Center (NCICC)
- Recommended appropriate countermeasures to nation-state and state-sponsored threat actor cyber capabilities
- Developed, maintained, and refined functional and non-functional requirements for the Security Requirements Traceability Matrices for the EINSTEIN, ECS and Einstein III programs
- Implemented Sandia’s Information Design Assurance Red Team (IDART) methodology and selected cybersecurity capabilities at TICAPS, MTIPS enclaves, and other ISP locations
- Tested enhanced tactics, techniques, and procedures (TTPs) for the protection of SCI
TEMPEST Engineer
Confidential, Arlington, VA
Responsibilities:- Led the F-35 Program Office’s TEMPEST accreditation programs
- Revised EMSEC testing methodologies to reflect updates to NSA and USAF policy and standards
- Created TEMPEST testing regime
- Supervised TEMPEST testing of JSF flight simulator
- Conducted Red/Black design review for type certification of aircraft system
Cybersecurity SME Department of Energy (DoE)
Confidential, Fairfax, VA
Responsibilities:- Developed DOE CIO’s response to Information Sharing Initiative
- Led NNSA/OCIO Joint Task Force’s response to PM-ISE 2014 Performance Assessment
- Led in-house review of the Deputy Secretary’s National Cybersecurity Initiative Memorandum.
- Led consolidated effort to identify all DOE national security systems, with special emphasis on classified NSSs and their authorized user and privileged user controls
- Supported DOE/OCIO/CISO/IM-30 in implementing DOE’s Information Sharing and Safeguarding Program (IS&SP)
- Provided guidance to DOE senior leadership in advance of and support monthly SISSSC meetings
- Supported NSS Architecture WG data call for PKI and FICAM
- Supported DOE efforts to establish and implement a Continuous Diagnostics and Mitigation (CDM) program
- Supported preparation of management response to OIG report regarding July 2013 PII spillage
- Prepared CISO’s and NNSA’s ICAM business case and funding line request
- Prepared DOE’s FY14 KISSI cybersecurity data call
- Prepared DOE’s response to the J15-established Cross-Agency Priority goals
- Supported Departmental implementation of OMB memorandum 14-03
- Supported Departmental review of draft NIST SPs
Information Systems Security Engineer
Confidential, Reston, VA
Responsibilities:- Created System Security Plan (SSP) for National Media Exploitation Center (NMEC)
- Developed NMEC’s Patch Management Program plan and standard operating procedures (SOP) documents
- Wrote NMEC’s Privileged User Account Implementation Guide
- Created CONOPS and SECONOPS for NMEC’s Remote Exploitation Solution (NRES)
- Reviewed Cyberspace Defense Reference Architecture for the Joint Information Environment (JIE)
Information Assurance
Confidential, McLean, VA
Responsibilities:- Determined, categorized, and allocated security controls for national security systems (NSS) against NIST (800-53), IC (CNSSI 1253 and ICD 503) and DoD (8500 series) standards
- Developed outreach strategy for the Unified NetOps Cyber Situational Awareness (UNSA) program
- Created CONOPS for the Joint Incident Management System (JIMS)
- Operations lead and outreach coordinator for Joint Incident Management System (JIMS)
- Created System Engineering Process Assessment for Global NetOps Information Sharing Environment (GNISE)
- Developed NetOps Data Standards Strategy and Sensor Data Dictionary for the GIG
- Determined, categorized, and allocated security controls for IC and DoD national security systems (NSS)
- Guide systems engineering teams regarding assessment and authorization (A&A) (formerly certification and accreditation (C&A)) requirements
- Developed and implemented security system enhancements and upgrades to support system architects
- Created and modified system documentation including SSAAs, SSPs, as-builts, and POA&Ms
- Developed and implemented enterprise-level security configuration policies
- Assessed system compliance based on new and revised IC cybersecurity policies
- Represented programs at CND Architecture Working Group (CAWG), Cyber Capabilities Working Group (CCWG), and Joint Information Environment Single Security Architecture (JIE SSA) Working Group TEMs
Senior Defense Research Analyst
Confidential, Herndon, VA
Responsibilities:- CND SME to Spectrum Communications Policy Directorate developing new network management policy
- Prepared staffing response package to HASC on Vulnerability Management
- Policy SME and primary technical authority to CND Architect for rewrite of DoD’s CND policy 8530 series
- Adversary emulation SME to NSA I74 and MILDEP Red Teams
- Coordinated package acceptance for CND Service Provider (CNDSP) GENSER and Special Enclave assessments
- Negotiated operating agreements for extensions of NIPRNet & SIPRNet authorities to connect (ATCs)
- Supported development of NSA’s CND Risk & Threat Matrix
- Created verification process for configuration management (CM) compliance in DoD’s new CM instruction
- Adjudicated and resolved DIBNet classified circuit connection renewal and CNDSP alignment processes
- Supported gap analysis of GIAP PMR and existing POM identified gaps in the GIAP CND IA Prioritization effort
- Coordinated CNDSP accreditation efforts for DIA GENSER and SE CNDSP C&A with Measures of Effectiveness (MOEs) and Evaluators’ Scoring Metrics (ESM)
- Coordinated with USCC/J33 in aligning non-DoD networks and information systems with CNDSPs
- Developed DoD C2 Information Sharing with Multi-National Mission Partners Roadmap
- IA architecture SME for DISA EWSE NetOps Technical Architecture, including Department-wide reference architectures such as JIEORA, ITIORA, and ADORA
- DIAP representative to Operations Gladiator Phoenix (OGP) and Gladiator Shield (OGS), Operation Buckshot Yankee (OBY), Terminal Fury, and Insider Threat (InT) Working Group
- Program Liaison Officer to IA/CND Enterprise-wide Solutions Steering Group (ESSG)
Principal Systems Specialist
Confidential, Falls Church, VA
Responsibilities:- As Lead IA Architect/engineer for TSAT Information Assurance (IA) Integrated Process Team (IPT) at AFSPACE/MCSW, developed TSAT’s information assurance network architecture
- With NSA counterparts, developed Space IA and SATCOM cybersecurity and information assurance policy
- Provided technical, managerial, and administrative direction for IA and CND problem definition, analysis, requirements development, and implementation for operationally responsive space-based Internet routers
- Developed ground-, launch-, space-, and terminal-based requirements definitions
- Developed IA and Quality of Protection (QoP) portions of the Net-Centric Implementation Documents (NCIDs)
- Supported Secure Networks Products Consortium (SNPC)
- As program liaison officer to NSA Space Special Program Office (SPO), negotiated TSAT IA robustness levels
Lead INFOSEC Engineer/Scientist
Confidential, McLean, VA
Responsibilities:- Created and implemented multi-level System Security Plan for the National Terrorism Screening Center, including a trust model for sharing SCI data among 17 different organizations
- Provided classification policy and procedural expertise in development of a Technical Enterprise-Wide Security Architecture for the FBI at DCID 6/3 PL-4 and PL-5 levels
- Supported the Inter-Agency Rapid COTS Technology Insertion and Information Assurance Working Group
- Supported policy direction for DoD’s IA Metrics program as member of IA Metrics Working Group and the Cross-Boundary Information Sharing (XBIS) Working Group
- Developed comprehensive guide to non-invasive forensics tools for dirty-word search techniques for downgrading after major SCI spillage at Treasury
Information Assurance Engineer/Scientist
Confidential, Anaheim, CA
Responsibilities:- Led IPT incorporating IA design principles into Confidential ’s Strategic Architecture Reference Model (SARM)
- Established corporate IA Center of Excellence to provide guidance and support for new IA initiatives
- Performed IA trade studies and analyses to support implementation of security architecture into SARM
- Supported development of the Network Centric Operations Industry Consortium (NCOIC)
- Led IA IPT for the JTRS proposal in providing technical solutions for both fixed and mobile ad hoc networks
- Developed and demonstrated robust, ubiquitous, HAIPE- and TRANSEC-compliant solutions
- As Information Assurance SME for Confidential ’s Network-Centric Operations IPT, researched and cataloged IA products suitable for re-use within Confidential
Information Systems Security Engineer
Confidential, Gaithersburg, MD
Responsibilities:- Developed IA metrics and controls for DLA’s Business Systems Modernization program based on 8500 series
- Wrote DDoS Attack Contingency Plan program for DISA
- Capture Manager, SPAWAR INFOSEC proposal
- Documented vulnerabilities and conducted risk assessments for civilian agencies
- Implemented multi-level security controls, procedures and countermeasures to protect information systems
- Developed programmatic-specific security policy and plans against existing DoD and IC IA doctrine
- Documented exploitations of technical vulnerabilities, conducted penetration tests and risk assessments, and performed security architecture analysis
- Taught security policy, certification, and accreditation
- Directed DITSCAP and NIACAP certification and accreditation programs for defense and civilian customers
- Technical Lead for Information Security to TSA STARS program, Radiant Trust, and Radiant Mercury
