Federal CDM automation at scale
Centers for Medicare & Medicaid Services
Built evidence and security-data pipelines for 100+ FISMA systems using AWS, Splunk, Python, Ruby, and repeatable IaC patterns. Expanded the workstream with Elastic Stack alignment, MITRE SAF-based assessment automation, and audit-ready POA&M reporting.
Focus areas: CDM, RMF/ATO, Splunk, Elastic, AWS, control validation
SOC modernization and digital forensics
Administrative Office of the U.S. Courts
Led SIEM deployment and migration work for the Security Operations Center, redesigned log collection to achieve full capture, and built C# forensic collection utilities to improve enterprise investigative response.
Focus areas: SOC engineering, incident response, C#, threat intelligence
Enterprise SIEM architecture and analytics
Microsoft / World Bank Group / federal programs
Architected large-scale ArcSight deployments, including a 200k+ EPS environment, and helped teams synchronize content, scale global telemetry, and modernize monitoring workflows across distributed environments.
Focus areas: ArcSight, analytics pipelines, global monitoring, content engineering
Emerging security concepts for next-phase monitoring
CMS / MITRE collaboration
Prepared proofs of concept and white papers for later CDM phases, including a custom SAF automation framework and post-quantum analysis proposed to CISA as a Phase 3 concept.
Focus areas: MITRE SAF, post-quantum analysis, control automation