I'm a Cloud Engineer at ManTech supporting DoD cloud infrastructure, with a background that spans cloud security engineering, infrastructure automation, and GRC. My current work focuses on AWS GovCloud environments using OpenTofu/Terraform, Python/boto3, and GitHub Actions CI/CD pipelines -- building and maintaining secure, compliant infrastructure at scale.
I bring a strong compliance foundation to everything I build. My background in RMF authorization, NIST 800-53, and FedRAMP shapes how I approach infrastructure as code -- security controls aren't an afterthought, they're baked into the pipeline from day one. I hold a CISSP alongside AWS and Azure certifications, and I'm currently pursuing AWS DevOps Engineer Professional.
Beyond my day job, I mentor aspiring security professionals through WiCyS, share technical content through my blog and community groups, and build open-source tools like this AWS Security Hardening Checklist. I believe in learning in public and giving back to the communities that helped me grow.
Designed and implemented a secure, STIG-hardened infrastructure in AWS, aligning with RMF controls. Automated baseline configuration checks and enforced compliance monitoring using native AWS services.
Built a compliance visibility dashboard showing the live status of key security controls mapped to RMF requirements. Data is automatically ingested from Config rules, Security Hub, and STIG checks.
Built a serverless pipeline to automate collection, formatting, and storage of control compliance evidence for NIST 800-53 controls. Replaced static manual evidence uploads with real-time data pulled from AWS Config.
Developed a reusable Terraform module library that codifies common NIST 800-53 and DISA STIG control requirements as IaC policies. Integrated enforcement through AWS Config and remediation via Lambda functions.
Created an automated POA&M tracking workflow that ingests AWS Config compliance findings and generates actionable POA&M entries. Non-compliance is logged and categorized by control family, severity, and resource.
Certified Information Systems Security Professional
GIAC Defensible Security Architecture
AWS Certified Solutions Architect – Associate
Cisco Certified Network Associate
CompTIA Security+
CompTIA Cybersecurity Analyst
Certified Ethical Hacker
Microsoft Certified: Azure Administrator Associate
Microsoft Certified: Azure Network Engineer Associate
eLearnSecurity Junior Penetration Tester
I'm always interested in connecting with fellow cybersecurity professionals, discussing new projects, or exploring opportunities in cloud security and GRC.