Background
The record CMMC assessment work draws on.
Four roles, one thread: validating whether controls that exist on paper actually hold up in a facility, a network, or a program. Government-side inspection work first, then a decade of leading intelligence and security programs, then the certification.
Special Security Representative
07/2016 – 10/2017Washington Military Department — GS-0086-09
Managed personnel and physical security for a sensitive Defense Intelligence Agency facility. This is the direct antecedent to CMMC assessment work: verifying that physical, personnel, and information security controls were actually implemented, not just documented.
- Built the facility's threat registry and maintained ICD 705 compliance throughout.
- Served as the ICD 705 subject matter expert for physical and information security upgrades and new facility development.
- Developed a data organization structure to delegate tasks to six line security managers responsible for the security readiness of 10,000+ personnel.
Intelligence Directorate Branch Supervisor
12/2017 – 10/2021U.S. Cyber Command
Produced strategic APT threat analyses from the most comprehensive adversary intelligence available to any analyst — classified and unclassified collection, Five Eyes sharing, SIGINT-informed reporting on nation-state actors targeting U.S. and allied networks.
- Built threat hunt packages for Cyber National Mission Force Hunt Forward Operations, deployed across 28 countries — translating adversary infrastructure and tradecraft into hunt hypotheses that forward-deployed teams executed on arrival.
- Developed USCYBERCOM's first open-source intelligence program from scratch: processes, tooling, governance, data quality standards.
- Managed publication of 500+ technical intelligence products, consumed by the USCYBERCOM Commander, the NSA Director, and the President of the United States.
- Directed and mentored a team of six cyber intelligence analysts using MITRE ATT&CK, the Diamond Model, and the Cyber Kill Chain.
Intelligence & Cyber Programs Manager
03/2015 – 10/2022Washington Army National Guard
Built core CTI and information security programs from scratch — PIR frameworks, collection and dissemination workflows, partner-facing data management structures adopted across multiple organizations.
- Led and mentored up to 50 full- and part-time personnel across multiple teams.
- Partnered with the Defensive Cyber Operations team to build redundant defensive capabilities and establish policy and training pipelines.
- Reinstated and rebuilt the organization's security awareness and education program.
- Coordinated with state, federal, and national partners to align intelligence and security efforts.
Senior Security Engineer
03/2022 – PresentGoDaddy — de facto AI security subject matter expert
Advisor and architect, not implementer, on production AI systems. Threat models AI and agentic systems against the OWASP LLM Top 10 and MITRE ATLAS, defines security and privacy requirements for the production LLM gateway, and advises engineering teams on guardrail design before systems reach production.
- Authors the quarterly AI threat report the CISO uses in board-level reporting.
- Manages Anomali ThreatStream against roughly 10 million active indicators, engineering triage against a SIEM/EDR ingestion ceiling of about 1 million.
- Presented a three-option privacy and logging framework for the LLM gateway, balancing security visibility against user privacy.
Credentials & Education
Certifications, degrees, coursework
M.S., Cybersecurity and Leadership — University of Washington (GPA 3.85). SANS Cloud Security Graduate Certificate and SANS Cybersecurity Engineer Graduate Certificate, SANS Technology Institute.