About

I am a principal system security engineer and cyber architect in Huntsville, Alabama. I built my career around being the person an organization pulls in when the cyber problem has to make sense at the top of the house and still get implemented on the program. Executives, product owners, engineers, assessors. If you want someone who does the work and can brief it at every one of those levels, you are in the right place. If you want a consultant who sells meetings and follow-ups, there is a large market elsewhere. I also work with counsel when the question is whether the required baseline was implemented and whether the record supports it.

I have been in cybersecurity and IT for over a decade. I started in computer science and cyber defense, then spent the next decade turning that into program work. In 2021 I moved into defense and national-security work as a contractor and spent the years since inside contracts, compliance, and the job of turning those requirements into something a program and an organization can actually run. I lead Risk Management Framework engineering from the first control set through implementation and assessment: NIST SP 800-53, CNSSI 1253 National Security Systems, FedRAMP and DoD cloud baselines, and CMMC built on 800-171 with selected 800-172 requirements when the level calls for them. I map controls and their Control Correlation Identifiers to the boundary. When a customer hands over a baseline and never writes the requirements, I write them. Across programs and organizations that work adds up to thousands of controls at the organization, the program, and the system. A lot of it sits on federal systems. A lot of it sits on non-federal systems that still hold federal information. That mix is why I can talk about cybersecurity risk management on both sides of that line.

I got there through product security on defense programs, including time leading a model-based engineering team that had to take enterprise rules and make them fit a product someone was going to ship. I also spent a year in public accounting on SOX, HIPAA, HITRUST, and GLBA reviews. I did not stay an auditor. I needed to see how an assessment actually works, what is supposed to be verified, and how thin a control narrative is when there is no evidence behind it. That year is still how I tell a real posture from theater.

In Maine I wrote cybersecurity policy at the state level and worked with municipal governments across the state to raise their programs toward CMMC 1.0.

Contracts and engineering kept landing on the same desk, so I enrolled in the Master of Studies in Law in National Security and Cybersecurity Law at George Washington University. The program is why I am better at seeing how the legal text and the technical work depend on each other. Coursework so far includes government contracts, cybersecurity law and technology, information privacy, consumer privacy and data protection, national security law, artificial intelligence law, and foreign access to U.S. technology.

Outside work I fly. I am a private pilot. I get out of the country at least once a year. The trip that stuck was the midnight sun over the Lofoten Islands and the water of the Norwegian Sea.

Qualifications

  • CISSP
  • B.S. Security and Cyber Defense and B.S. Computer Science, Thomas College, Waterville, Maine
  • M.S.L. candidate, National Security and Cybersecurity Law, George Washington University. In progress, projected 2027
  • Secret clearance

Courtroom, boardroom, or the negotiation table. If you want to work together, use Contact or find me on LinkedIn.

Contact Me