Qualifications

I have worked as an IT consultant since 1999, beginning my career installing Y2K patches for Hewlett-Packard. From technical support, I moved into software development before transitioning into cybersecurity in 2010. Since then, I have supported organizations ranging from small startups to some of the world’s largest companies, helping clients address challenges spanning PCI compliance, FedRAMP, privacy, export controls, incident response, and security operations.

My work has included developing cross-border privacy policies for telecommunications companies in the Middle East, helping Ukrainian drone manufacturers navigate ITAR requirements, and supporting forensic recovery and breach investigations. This breadth of hands-on experience allows me to quickly understand complex environments, identify practical solutions, and confidently take on projects where the stakes are high and the path forward is not always obvious.

An overview of my professional qualifications, certifications, and experience.

ISC² Certified Information Systems Security Professional (CISSP)

I have implemented NIST SP 800-53 and NIST SP 800-171 requirements for organizations ranging from small teams to environments supporting tens of thousands of users. My work spans security architecture, governance, risk management, compliance, incident response, vulnerability management, data protection, application security, and OT/ICS security.

I have extensive experience implementing and assessing FedRAMP and CMMC requirements and develop System Security Plans for both. I am comfortable with both the Secure Controls Framework and standard Enterprise Risk Management practices.

While most of my work is US-based, I have extensive experience with ISO 27001 and cross-border privacy and data requirements.

ISC² Certified Secure Software Lifecycle Professional (CSSLP)

My experience includes threat modeling, secure architecture reviews, SAST and DAST implementation, software supply-chain risk, CI/CD security gates, and developer-focused remediation practices.

While I have worked with both Snyk and SonarQube in the past, I currently rely on AI-based vulnerability analysis and have access to the latest cyber models. I have experience building harnesses and setting up working test environments but more importantly, I can translate the results into actionable remediation plans. For DAST I can work with Tenable or the various OS tools like Burp/VAS/ZAP.

I have written code (in order learned) in x86 Assembly, Pascal, C and C++, Visual Basic and Delphi, C#, Python, Go and (finally) Rust.

That’s right. No Java. My .NET hands-on experience ends at 4.

Microsoft Certified: Cybersecurity Architect Expert

In a greenfield environment, I can design and build a complete security and compliance program aligned with FedRAMP or CMMC requirements, from architecture and control implementation through documentation, evidence collection, and audit readiness.

In a brownfield environment, I can assess what is broken, identify the highest-risk gaps, and develop a practical remediation strategy to bring the organization back under control and move it toward compliance.

Microsoft Certified: Security Operations Analyst

Expert with both Sentinel and XDR with their separate versions of KQL. I have extensive hands-on experience deploying and optimizing Microsoft Defender for Endpoint across enterprise environments, including antivirus, endpoint detection and response, attack surface reduction, device security policies, threat hunting, and integration with Microsoft Defender XDR.

Microsoft Certified: Identity and Access Administrator

Experienced in designing and implementing identity and access controls for organizations of all sizes, including Conditional Access, role-based access, multifactor authentication, privileged access, and identity governance. I also build continuous monitoring and review processes to detect access risks, validate permissions, and maintain an effective security posture over time.

Microsoft Certified: Information Security Administrator Associate

Can handle the entire Purview stack including the auditing and monitoring required for CUI/FCI compliance.

Microsoft Certified: Cloud and AI Security Engineer Associate

Can configure and secure both the billion variations of Copilot and Azure AI Foundation. Capable of working with Microsoft’s version of the AI backend including Evals and what currently passes for guardrails.

Microsoft Certified: GitHub Advanced Security

What we do for CPEs…

Microsoft Certified: AI Transformation Leader

Unfortunately I have more experience with Copilot than I ever wanted and can also deploy and work with Copilot Studio.

Retired Microsoft Certs: Certified System Developer, Certified System Engineer

Cloud Security Alliance Certified: CSF

Can help you build a secure and compliant cloud environment as well as navigate the STAR registry process.

CMMC AB Certified: Advanced Practitioner

I paid $600