
IT Security Principal Leader at Jet Propulsion Laboratory
Phoenix, Arizona Area

IT Security Principal Leader at Jet Propulsion Laboratory
Phoenix, Arizona Area
Experience Highlights:
I serve as an IT Security Outreach and Awareness champion at the NASA Jet Propulsion Laboratory. My duties involve working closely with multidisciplinary teams on a wide variety of IT security objectives for Section 173. I am also the lead security engineer on the SFTP service for JPL and NASA as well as chief system and security architect on a wide variety of projects in support of Section 274 and served in the critical security evaluation of the Interplanetary Overlay Network (ION).
My projects include, but are not limited to, authoring security advisories, coding custom security software, performing security and system engineering, evaluating security solutions, implementing access control, and performing information security and risk management, vulnerability research and penetration testing.
As the security engineer for several projects, my work has provided both JPL and NASA with lasting confidentiality, integrity and high availability security solutions. In addition, my proficiency in technical writing with regard to policies, procedures, user manuals and tutorials have further provided JPL and NASA with the requisite information to operate and maintain the solutions I have delivered.
I am also a Certified Information Systems Security Professional (CISSP) and an active member in the Institute of Electrical and Electronics Engineers (IEEE) and the IEEE Computer Society.
Career Goals:
My goal is to continue in my current field of practice in addition to learning new technologies and applications. My focus will remain delivering top-notch solutions and securely implementing these technologies for my customers' development and production needs.
Specialization in host and network security, hardening and auditing; risk assessment and pentesting; firewall configuration; Checkpoint FW1 certified; intranet/extranet design, development & deployment; knowledgeable on International Traffic in Arms Regulations (ITAR) & Export Administration Regulations (EAR); technical and expository writing; extensive user & admin experience on a variety of operating systems ranging from Linux, Solaris (SPARC & x86), OpenBSD, MacOS, Windows 3.x thru Vista.
(Government Agency; Defense & Space industry)
February 2009 — Present (10 months)
Create, evaluate and document security solutions for a wide number of projects across the NASA and JPL IT infrastructure. Author of security policies, procedures, protective measures and auditing recommendations for several projects. As IT Security Principle Leader, I take the initiative to provide IT security outreach and awareness to all personnel across the enterprise.
(Computer & Network Security industry)
May 1995 — Present (14 years 7 months)
Assess, evaluate, recommend and implement software solutions and system improvements for small and medium businesses. Evaluate business IT performance, security and availability. Provide commercial off-the-shelf and custom IT solutions for businesses and individuals to meet their professional and personal computer and network needs.
(Government Agency; Defense & Space industry)
November 1995 — February 2009 (13 years 4 months)
Served as Security Engineer and System Architect on multiple projects ranging from the JPL Technical Report System (JPLTRS) (1995 to 2000); Security Engineer to JPL Knowledge Management (2000-2008); Lead Security Engineer for NASA public portal (2002-2004); Security Engineer to NASA Engineering Network (NEN) (2003-2008); System Architect and Security Engineer to InsideNASA Extranet (2006-2008); Chief Architect of NASA-wide Instant Messaging Service (2002-2006); and System Architect and Security Engineer for NASA-wide inter-center Emergency Operations Capability system (2006-2008).
In my 13 years as Security Engineer, I spearheaded many initiatives ranging from the NASA Jabber secure instant messaging pilot program to the NASA-wide Emergency Operations Center which I designed, developed and deployed. My work defined and delivered several core competencies for JPL/NASA. Under my care and guidance, these services became institutional standards for both NASA and JPL.
(Computer & Network Security industry)
April 2000 — August 2001 (1 year 5 months)
Authored security policies and procedures. Acquired, developed and deployed security solutions for various customers. Specialized in bastion host security, system auditing, black box penetration testing, firewall construction and configuration.
Contributing author to "Hack Proofing Your Web Applications" -- wrote chapter 5, "Hacking Techniques and Tools."
Bachelor of Science in Information Technology , Information Security Systems , 2008 — 2010 (expected)
Computer & Network Security, Programming, Professional Writing, Ethics, Commercial Illustration
Years ago I had a professor who advised me to never let school interfere with my education. This suggestion proved to be a guiding principle in the years that followed.
Though I am currently enrolled to complete my Bachelors of Science in Information Technology Security, I believe my personal passion in cultivating my talents and skills has made me uniquely qualified to succeed in the field of security engineering and system architecture.
security best practices, new technology, 802.11 standards, good coffee, technical writing, creative writing, woodworking, carpentry, painting, sculpting, drawing, fishing and minding my own business.
Institute of Electrical and Electronics Engineers (IEEE)
IEEE Computer Society
Recipient of NASA Engineering Network achievement award, June 2007.
Recipient of NASA Engineering Network achievement award, August 2006.
Recipient of NASA Group Achievement Award for work on the OneNASA Portal, May 2004.
Recipient of NASA Headquarters Civil Service/Contractor team award, November 2003.
Recipient of JPL award for work on JPL Technical Report Service, May 1999.