CMMC Assessment Services / Seattle, WA
Before CMMC, there was ICD 705.
I spent a year and a half as a Special Security Representative, managing personnel and physical security for a sensitive Defense Intelligence Agency facility — SCIF operations, ICD 705 compliance, threat registries, control validation for a facility housing over ten thousand personnel. That work predates CMMC as a framework by nearly a decade. The habit of inspection came first; the certification came later.
That discipline carried through a decade of military intelligence program leadership at U.S. Cyber Command and the Washington Army National Guard, and into my current role as the de facto AI security subject matter expert at a Fortune 500 hosting company. I hold CISSP, CMMC CCP, and nine GIAC certifications. I'm looking for a subcontracted seat on a C3PAO assessment team, working under a Lead CCA, on the way to a CCA credential of my own.
Record
Oversight & inspection history
Credentials
Certifications & education
M.S., Cybersecurity and Leadership — University of Washington. CMMC CCP active; working toward CCA.
Also
Outside the day job, I run a self-hosted Kubernetes security lab — detection engineering, LLM guardrail architecture, a k3s cluster hardened from a deliberately broken baseline and documented end to end. It's public and it's real, but it's beside the point here: what's relevant to assessment work is the inspection record above, not the lab.