Information Security Architect
Washington D.C. Metro Area
Information Security Architect
Washington D.C. Metro Area
Security Architect with 14 years experience in the IT security and intelligence fields performing information assurance, systems design and engineering, web development, and security testing.
Information System Security Engineering Professional (ISSEP), 2005
Certified Information Systems Security Professional (CISSP) #50247, 2003
Department of Defense Advanced Linguistic Certification (Russian), 1992
System Security Engineering
Linux/Unix System Administration
Federal Security Regulations
Security Test and Evaluation
Certification and Accreditation
Open Source
Network security
Host-based security
NIST Information Assurance Framework
DoD Information Assurance Technology Framework
DITSCAP/DIACAP
DCID 6/3
(Computer & Network Security industry)
January 2008 — Present (1 year 11 months)
Working as a technical IT security generalist and manager.
(Non-Profit; 1-10 employees; Computer & Network Security industry)
March 2005 — Present (4 years 9 months)
•Teaches 2-day and 5-day seminars on the NIST Information Security Framework, Certification & Accreditation, and FISMA
•Commended by House of Representatives Government Reform Committee Chairman Tom Davis and NIST Computer Security Division Chief Joan Hash
•Has taught Information Assurance to IA contractors and members from every government agency
•Develops and updates training material to reflect the current state-of-the-art in Certification and Accreditation and government policies, standards, regulations, and compliance
(Public Company; 10,001 or more employees; Information Technology and Services industry)
July 2006 — January 2008 (1 year 7 months)
•CISO for FSDC with a scope of responsibility for 3 data centers, 5-story building, NOC, SOC, server management team, disaster recovery site, and various other support activities
•As needed, fulfills ISSO responsibilities for client systems
(Public Company; 10,001 or more employees; Computer & Network Security industry)
March 2005 — May 2006 (1 year 3 months)
•Works with engineering teams as System Security Engineer responsible for security aspects of projects including requirements definition, system and network design, documentation, configuration management, security testing, risk assessment, and risk management
ecurity requirements definition and determination of minimum security control baselines
•Develops Certification and Accreditation project plan with process flow and interactions with other security processes
•Advises Program Officials and Project Managers with agency-wide certification and accreditation strategy
•Assists System Owners and ISSOs in developing SDLC and C&A artifacts such as System Security Plans and Security Self-Assessment Questionnaires
(Government Agency; 10,001 or more employees; Military industry)
May 1999 — February 2006 (6 years 10 months)
•Mobilized in 2004/2005 for 12 months and deployed to Afghanistan for 7 months in support of Operation Enduring Freedom
•Mobilized and deployed for disaster relief during Hurricane Isabel (Virginia, 2003) and Biscuit Fire (Oregon, 2002)
(Public Company; 10,001 or more employees; Computer & Network Security industry)
November 2002 — March 2004 (1 year 5 months)
•Leader of a 4-person Certification and Accreditation team supporting the DITSCAP effort of the TRICare Management Activity
•Negotiates the area between contract and DITSCAP requirements with Military Healthcare System officials, Designated Approving Authority, Certification Authority, site Information Assurance Officers, site system administrators, project managers, and team members.
•Conducts security audits and design assurance testing for several large multi-campus networks spanning several states focusing on computer and network equipment, applications software, and security engineering principles.
(Privately Held; 1-10 employees; Information Technology and Services industry)
March 2000 — December 2001 (1 year 10 months)
•Designs and administers Corporate LAN/WAN; Linux web, database, and email servers; custom-built Linux firewalls; and Windows/Linux workstations
•Develops technical aspects of corporate web strategy
(Government Agency; 10,001 or more employees; Military industry)
August 1991 — May 1999 (7 years 10 months)
•Specialist in networking equipment, cryptographic key systems, and communications security
•Translates conversations in the Russian, Serbian, and Croatian languages using specialized computer systems
•Twice selected to compete at the Department of Defense Worldwide Language Olympics
Advanced DoD Certificate , Russian Language , 1991 — 1992
BS ,
Flyfishing, Linux, Information Security, Information Assurance, Russian, Public Policy, Security Economics
OWASP, Security Twits, ISM-Community