Cyber & IT Professional
Securing Your Assets and the Data You Are Obligated to Protect
Securing Your Assets and the Data You Are Obligated to Protect
My most recent engagements have involved providing insight into client / customer supply chains and conducting third party risk assessments. This includes identifying gaps in the Software Development Lifecycle (SDLC), providing best practices for DevSecOps and the creation of Software Bill of Materials (SBOM)s
I am an accomplished, strategic IS and risk management leader, poised to develop, implement, and oversee all aspects of protecting information assets and technologies. I am adept at identifying gaps in security and implementing innovative, scalable solutions. I possess a proven ability to optimize operations by establishing best practices and implementing process improvements. My record is one of driving focused, high-performance teams to consistently produce high-quality project deliverables; prioritize resources on basis of risk, impact, and cost. I retain a demonstrated talent for translating and clarifying complex technical issues into impact statements easily understood by C-suite decision markers. I am recognized by organizational leaders and colleagues as analytical, decisive, persistent problem-solver with exceptional relationship-building and communication skills. I have earned a Masters of Science in IT.
Security Architect / Secure Architectures
Supply Chain Risk Management
Third Party Risk Assessments
Threat Detection, Identification and Remediation
Log Management (Splunk, LogRhythm, AlienVault)
DevOps / DevSecOps
SwA / Dynamic & Static Code Analysis
Agile Software Development
Cloud Computing and Security (AWS, Azure, Google)
Networking- Routers, Switches, Firewalls
Change Management and Process Improvement
Supplier / Contract Management
Prototyping / Pathfinders
Critical Infrastructure and Privacy Data Protection
Physical Security and Risk Management
Disaster Recovery, Business Continuity Planning
Mergers & Acquisitions Due Diligence
Security Awareness and Education
Group Policy Management and Deployment
Microsoft / Azure Active Directory
Cost management of information security projects
Aviation, Space and Energy Sector Security
Experienced in the following frameworks / standards:
CMMC
ISO 27000 series
NIST
COBIT
PCI DSS
SOX
NERC
ITIL
GDPR
CCPA
ITAR and EAR Export Control Compliance
Financial Reporting:
Tableau
Packaged Business Capabilities (PBCs)
Security Architecture;
TOGAF, DODAF, Firewalls, IDS/IPS, NAC, SIEM, Wireless
Sign up to hear from me.
I understand the value of an executive leader’s soft skills, specifically as it relates to fostering teamwork amongst internal and external business partners. I am experienced in building relationships with personnel working in the labs, on manufacturing and operations floors, as well as with senior government officials and those within the contractor community. I am a strong believer in “Management by walking around.”
Prior to joining The Aerospace Corporation, I was employed by Booz Allen Hamilton, consulting in many areas of systems engineering and process improvement, auditing critical capabilities across varying maturity dimensions such as processes, technology, and people, while incorporating advanced analytics to provide an evaluation of a client’s effectiveness.
I have also reported directly to the Chief Security Officer, The Boeing Company, managing compliance with government and corporate requirements, generating reports on the status of the overall health of the company’s security program, preparing risk analysis, and the implementation of plans that aimed for consistency across the enterprise and focused on the company’s vision, mission, and goals.
I believe that one of my strongest assets is my ability to build strong professional and personal relationships with stakeholders. I maintain relationships with senior executive leadership, in government and in industry.
Balancing strategic, tactical and technical requirements to provide executive leadership with solutions based on quantitative / qualitative analysis and sound risk management principles.
· Building high performing teams that achieve specific organizational goals. Utilizing tactical and strategic planning to manage resources.
· Proven success using a project management approach to cybersecurity for multimillion-dollar projects and global organizations that have been recognized for reduced costs and schedule durations.
· Performing complex assessments and making independent decisions based on risk management principles, while maintaining a focus on business enablement.
I can communicate technically and with a focused business acumen, and always come to the table with recommended solutions - finding a way.
My certifications as a Certified Information System Security Professional (CISSP), a Certified Chief Information Security Officer (C|CISO) and my Master of Science degree in Information Technology support my designation as an information technology and security professional. I am also a certified Project Management Professional (PMP) with both formal certification, training and many years of hands-on project management experience.