I've worked in Cybersecurity since 2008, performing numerous tasks in various roles throughout my career. I've done everything from vulnerability scanning to disaster recovery planning, including, but not limited to compliance tracking, compliance testing, vulnerability mitigation, system auditing and forensics, authoring RMF documentation, and working hand-in-hand with security controls assessors. I currently hold a CompTIA Security+ and ISC2 CISSP certifications as well as a Red Hat Server Security Specialist in Linux certification.
The vulnerability that gets caught in development is one that is never exploited in the wild. Integrating Cybersecurity into the software development process as early as possible can save a company from millions in lost revenue should one be exploited. I'm adept as integrating vulnerability scanners and static applications security tools into CI/CD pipelines and automating reporting and alerting.
I've worked with Linux since Red Hat 5. Not Red Hat Enterprise Linux 5, but Red Hat 5 (yes, 14 versions ago). I earned my Red Hat Certified Engineer (RHCE) certification in 2007, and have been actively administering Linux systems for over 20 years. This includes system hardening, service configuration (auditd, dhcpd, firewalld, fapolicyd, SELinux, exim, Sendmail, cups, Samba, etc.), and server software, such as Postgresql, MySQL / Mariadb, JBoss, Tomcat and Squid, and countless others.
During my employment with the US Army, I worked as one of two network engineers for the CECOM Software Engineering Center, at Fort Monmouth. When Fort Monmouth closed, I helped build the replacement datacenter at Aberdeen Proving Ground, MD.
I have extensive experience securely configuring Cisco Routers, Cisco Nexus and Catalyst series of switches, as well as layer 2/3 devices from Mellanox, Dell, and Unifi and Cisco Aeronet and Unifi wireless access points. In keeping with my security experience, I am also adept at configuring SonicWall and OPNsense firewalls.
As well as User Guides and Service Manuals, I have been authoring and maintaining a variety of documents in support of my projects, including, but not limited to software engineering documentation such as Software Requirements Specifications (SRS), Software Design Descriptions (SDD), Software Version Descriptions (SVD), etc. as well as technical bulletins. And I though my Software Engineering Masters Degree wasn't going to come in handy...
I've spent considerable time building, maintaining and deploying virtual machines as well as containerized applications with both Docker and Kubernetes. Including customized VMs and containers for software builds, for server applications (e.g., Postgresql / Timescaledb, Apache Tomcat, JBoss) as well as hardware management platforms (e.g., Unifi Controller) and vulnerability scanning.