🔹 Security Engineering & Infrastructure
•Drive STIG-based hardening and secure configuration baselines across Linux, web, and database
environments
•Lead migration of staging/production to DISA-managed RHEL servers, coordinating uptime and
compliance needs
•Build and secure core infrastructure, enforcing DISA STIG compliance for resilient deployments
•Authored technical documentation to support system sustainability and knowledge transfer
🔹 Development & Secure Engineering
•Developed and maintained legacy Java/JSP applications with PostgreSQL back end, streamlining
workflows to meet user needs
•Integrated Snyk into the codebase and led code reviews, embedding security visibility into the
development lifecycle
•Introduced Agile/Scrum practices, creating structure, cohesion, and accountability within the
engineering team
🔹 Risk Management and Compliance Expertise
•Lead technical/compliance efforts for Navy system ATO under NIST RMF (SP 800-37)
•Conduct STIG-based security assessments and translate findings into actionable POA&Ms with
verifiable artifacts
•Re-baselined and validated NIST SP 800-53 controls for accuracy and applicability
•Security liaison across Navy stakeholders, DISA, and engineering, driving risk-informed decision-
making
•Operationalize evolving standards (DISA, NIST, DoD, vendor advisories) into configuration, control, and
patch actions