David J Davis
Senior Information Security Professional
Nice to meet you, here is a little something about me.
Dedicated and experienced Information Security professional with over 25 years of expertise in cybersecurity, risk management, and IT systems integration. Proven track record in managing complex security projects, ensuring compliance with industry standards, and implementing robust security frameworks. Adept at leading teams in fast-paced environments and driving initiatives to protect organizational assets and data integrity.
CORE COMPETENCIES
Leadership | Regulatory Compliance | Information Assurance | OWASP Top 10 | Information Security | Incident Investigation | Incident Management | Incident Response | Operational Risk Management | Risk Assessment | Root Cause Management | Security Compliance Audits | DevSecOps | Agile Methodology | Technical Architecture | Network Architecture | IT Service Management | Wireshark | Snort | Nessus | Metasploit | Nmap | AlienVault | Kali Linux | Pan-OS
Professional Experience
Sr. Principal Cybersecurity Systems Engineer
Northrop Grumman Company: 2021 – Present
-
Lead Program Protection and Security (PP&S) for the Missile Defense Agency (MDA) Development and Sustainment Contract (DSC).
-
Managed Agile processes for classified and unclassified networks, ensuring compliance with RMF, DFARS, CMMC, and SOW.
-
Oversaw Software Assurance (SA) for multiple software applications, managing CWE and CVE processes.
-
Chaired the Information Technology Change Control Board (IT-CCB) and performed Security Impact Analysis (SIA) for various applications
Principal Cybersecurity Systems Engineer
Northrop Grumman Company: 2020 – 2021
-
Conducted RMF NIST 800-53 audits for classified networks on the MDA DSC contract.
-
Led IT-CCB, ensuring security compliance for COTS, GOTS, and OSS applications.
-
Contributed to Program Protection sections of GMD Weapon System contracts, including CDRLs
Information Systems Security Officer (ISSO)/Systems Engineer/Consultant
Techni-Core Network Services: 2019 – 2019
-
Provided consulting expertise on RMF NIST 800-53 and 800-171 compliance, DFARS 252.204-7012, HIPAA, ITAR, and Exostar Cyber compliance.
-
Developed and submitted RMF packages to DSS, conducted DFARS/NIST compliance assessments, and supported client IT staff.
Information Technology Manager
Interfuze: 2018 - 2019
-
Managed migration from in-house infrastructure to Office 365 cloud-based environment, ensuring DFARS/NIST 800-171 compliance.
-
Implemented multi-factor authentication and managed outsourced desktop support and VoIP systems.
-
Created standardized IT environments and managed data moves to SharePoint 365.
Information Technology Manager
Sarai Investment Corporation (SIC): 2017 - 2017
-
Managed existing IT infrastructure, creating and executing project plans for ongoing and new projects.
-
Roles included Office 365 Account Admin, Exchange Admin, Network Manager, IT Help Desk Manager, IT Desktop Support Manager, VoIP Manager, Project Manager, Application Portfolio Manager, Network Operations Center Manager.
-
Successfully implemented a printing solution reducing costs from $15k to $4.5k annually.
-
Designed and installed the Network Operation Center monitoring room and created IT path forward roadmaps.
-
Implemented network security firewalls, Cisco routers, Net Gear Smart Switches, and Cisco wireless access points, including creating a Guest network.
-
Managed a 100 User VoIP PBX System across three remote locations, including configuration, deployment, and SIP Trunk management.
-
Managed Office 365 Business accounts for 100+ users, created SharePoint department, project, and team sites.
-
Developed a business case and project plan for implementing NIST 800-171 controls, conducted gap analysis, and standardized IT assets.
Information Assurance Engineer
Dynetics Technical Services, NASA Marshall IT Services: 2010 - 2016
-
Managed program risk for the MITS contract, implementing ISO 9001:2008 and conducting internal audits.
-
Led Lean Six Sigma Kaizen events for continuous process improvement.
-
Created and managed CMMI 1.3 policies and processes.
Certifications
​
-
CompTIA Security + CE
-
Code: F1CYTZXS3B111MSM
-
Verification: http://verify.CompTIA.org
-
-
ISO 9001:2008 Internal Auditor Refresher
-
NASA/MITS Contract
-
-
Six Sigma Certified Black Belt
-
NASA/MITS Contract
-
-
CMMi 1.3 Level 3 for Developers Certification
-
DTS/MITS Program
-
-
ISO 9001:2008 Internal Auditor
-
Lockheed Martin/ODIN Contract
-
-
ITIL v3 Foundations Certification
-
Lockheed Martin ODIN Contract
-
-
Six Sigma Certified Green Belt
-
Lockheed Martin/ODIN Contract
-
-
CMMi 1.2 Level 2 Certification
-
AZ Technology/UNITeS Program
-