CMMC Assessment Services / Seattle, WA

Before CMMC, there was ICD 705.

I spent a year and a half as a Special Security Representative, managing personnel and physical security for a sensitive Defense Intelligence Agency facility — SCIF operations, ICD 705 compliance, threat registries, control validation for a facility housing over ten thousand personnel. That work predates CMMC as a framework by nearly a decade. The habit of inspection came first; the certification came later.

That discipline carried through a decade of military intelligence program leadership at U.S. Cyber Command and the Washington Army National Guard, and into my current role as the de facto AI security subject matter expert at a Fortune 500 hosting company. I hold CISSP, CMMC CCP, and nine GIAC certifications. I'm looking for a subcontracted seat on a C3PAO assessment team, working under a Lead CCA, on the way to a CCA credential of my own.

Record

Oversight & inspection history

Role & organization 2015 — Present
07/2016 – 10/2017
Special Security Representative
Washington Military Department — DIA-sensitive facility, ICD 705 SME
Facility Security
12/2017 – 10/2021
Intelligence Directorate Branch Supervisor
U.S. Cyber Command — hunt packages, OSINT program, 500+ published products
Program & Intel
03/2015 – 10/2022
Intelligence & Cyber Programs Manager
Washington Army National Guard — built CTI/InfoSec programs, led up to 50 personnel
Program Build
03/2022 – Present
Senior Security Engineer, AI Security SME
GoDaddy — AI/agentic threat modeling, quarterly board-level threat reporting
AI & Cloud Sec

Credentials

Certifications & education

CISSP
(ISC)²
CMMC CCP
Certified CMMC Professional
GMLE
GIAC Machine Learning Engineer
GSEC
GIAC Security Essentials
GCIH
GIAC Certified Incident Handler
GCIA
GIAC Certified Intrusion Analyst
GCTI
GIAC Cyber Threat Intelligence
GCSA
GIAC Cloud Security Automation
GPCS
GIAC Public Cloud Security
GCLD
GIAC Cloud Security Essentials

M.S., Cybersecurity and Leadership — University of Washington. CMMC CCP active; working toward CCA.

Also

Outside the day job, I run a self-hosted Kubernetes security lab — detection engineering, LLM guardrail architecture, a k3s cluster hardened from a deliberately broken baseline and documented end to end. It's public and it's real, but it's beside the point here: what's relevant to assessment work is the inspection record above, not the lab.

github.com/jhanna2/k8s-security-homelab →