I build compliance programs and automation tools that drive FedRAMP authorizations for Cloud Service Providers. From SSP documentation to POA&M systemsβmy work has generated over $2M in annual revenue.
End-to-end ownership of FedRAMP Moderate and High authorization programs. SSP development, 3PAO coordination, agency sponsor engagement, and continuous monitoring.
System Security Plans, Rules of Behavior, Security Assessment Reports, and POA&M management. Translating NIST SP 800-53 Rev. 5 controls into actionable procedures.
Designing compliant architectures across AWS GovCloud, Azure Government, and Google Cloud. Infrastructure as Code with embedded security controls.
Building tools that automate artifact generation, POA&M tracking, and evidence collection. Reducing manual effort while improving audit readiness.
Partnering with Security, Engineering, Legal, Product, and SRE teams to embed compliance into operational processes without slowing delivery.
Coordinating 3PAO assessments, analyzing findings, driving remediation to closure, and preparing executive compliance reporting.
Built an end-to-end automation platform from scratch that streamlines FedRAMP artifact generation, security assessments, and client deliverables at scale.
Automated system running on AWS ECS that ingests scan results, generates action plans, tracks remediation, and syncs directly with government eMASS systems via API.
Led FedRAMP authorization efforts for Cloud Service Providers across Moderate and High impact levels, plus DoD IL4/IL5. Coordinated 3PAO assessments and drove findings to closure.
Reduced manual documentation effort by 60% through automated SSP generation, control mapping, and evidence collection workflows.
Franklin University
The Ohio State University
Amazon Bedrock Professional Certificate
Specialization Certificate
Multicloud Network Certification
Network Associate Certification