Attack Surface Management · Vulnerability Management · Container Security · GRC / ATO
A security leader who turns technical risk into measurable, business-aligned outcomes.
📍 Houston, Texas · 🕔 UTC−05:00 · LinkedIn · Email
Security leader with 10+ years across attack surface and vulnerability management, container security, and governance, risk, and compliance. I currently lead container vulnerability management at EY across a 900+ cluster Kubernetes / AKS estate (160,000+ workloads), governing 600,000+ container images. I run two kinds of programs end to end — reducing the attack surface with data-driven, risk-based prioritization, and authorizing and governing systems against NIST 800-53, RMF, and FedRAMP — and I translate both into auditable outcomes and executive-ready reporting.
This profile is organized around those two programs. Each is presented as a project, with sanitized artifacts and working tooling as evidence.
Find everything we own, understand its exposure, drive the risk down. Unified asset discovery, vulnerability management, container security, and cloud posture into one risk-based program — cutting critical/high CVE exposure 48%, reducing MTTR from 18 → 7 days, and raising Kubernetes version-compliance to 85% across a 900+ cluster estate.
What the program covers
- Discovery & coverage — bringing shadow/unmonitored clusters and orphaned assets under continuous scanning; closing visibility gaps.
- Vulnerability management — risk-based prioritization (exploitability + business impact over raw CVSS) with Qualys VMDR, Tenable Nessus, and SLA-driven remediation.
- Container & Kubernetes security — Aqua Security across image, registry, CI/CD, and runtime; admission control and shift-left scanning.
- Cloud posture & attack paths — Wiz (CSPM / CIEM / CWPP) to prioritize confirmed, exploitable exposure over standalone findings.
- External attack surface — cyber-risk ratings and third-party exposure via BitSight, RiskRecon, and SecurityScorecard.
Evidence on GitHub
- 🐳 container-vuln-management — the program itself: Aqua handbook, SOP suite, and the KaaS-vs-Cluster-Owner ownership (RACI) model, plus a sanitized 240-cluster scan dataset.
- 📋 container-vuln-remediation-plan — the 15-section remediation plan mapped to NIST 800-53 / ISO 27001 / FedRAMP.
- 📊 container-vulnerability-risk-analytics — leadership risk reporting: severity, status, cloud/environment, and top-risk clusters at a glance.
- 📈 k8s-version-compliance-tracker — the version/EOL compliance reporting that gives leadership real-time posture visibility.
Turn security work into authorization and audit-ready evidence. Standardized SSP / SAR / POA&M, continuous monitoring, and control mapping to accelerate Authorization to Operate (ATO) timelines and strengthen audit readiness across NIST RMF, 800-53, and FedRAMP.
What the program covers
- ATO-as-a-Service — repeatable authorization support across enterprise, cloud, and federal contexts.
- Assessment & documentation — SSP development, Security Control Assessments (SCA), Security Assessment Reports (SAR).
- Continuous monitoring — ConMon strategy, POA&M tracking, and control-mapped evidence for sustained authorization.
Evidence on GitHub
- 🔗 grc-package — a sanitized ATO / GRC authorization package: SSP development, NIST 800-53 control implementation, continuous monitoring, and audit-readiness documentation.
| Domain | Tools & Frameworks |
|---|---|
| Attack Surface & Vulnerability Mgmt | Qualys VMDR · Tenable Nessus · Wiz · Aqua Security · BitSight · RiskRecon · SecurityScorecard |
| Container & Kubernetes Security | Kubernetes / AKS · admission control · runtime protection · CIS Benchmarks · shift-left CI/CD |
| Cloud Security (CNAPP) | CSPM · CWPP · CIEM · attack-path analysis · Azure · AWS |
| GRC & Compliance | NIST 800-53 · RMF · FedRAMP · ISO 27001 · SSP / SAR / POA&M · A&A · ConMon |
| Reporting & SIEM | Power BI executive reporting · Splunk · Microsoft Sentinel |
- EY — Cloud & Container Vulnerability Management Specialist (2019–present) · 900+ clusters, 160K+ workloads, 600K+ images; 48% CVE reduction; MTTR 18→7 days.
- Accenture Federal Services — Senior Compliance Analyst · A&A packages for 20+ federal systems; SCAs against NIST 800-53; Splunk-driven detection.
- NASA Johnson Space Center — Cybersecurity Analyst · RMF (800-37 / 800-53) across federal systems; contingency & DR planning.
| Certification | Issuer |
|---|---|
| Certified Information Security Manager (CISM) | ISACA |
| Certified Chief Information Security Officer (CCISO) | EC-Council |
| Certified Ethical Hacker (CEH) | EC-Council |
| Computer Hacking Forensic Investigator (CHFI) | EC-Council |
| CompTIA Security+ | CompTIA |
| Certified Data Privacy Solutions Engineer (CDPSE) | ISACA |
| Certified Cloud Security Professional (CCSP) | ISC² — In Progress, 2026 |
Open to roles and conversations in attack surface & vulnerability management, container security, and GRC / ATO.