OPEN TO WORK · REMOTE / HYBRID · JACKSONVILLE, FL

nick@jax:~$ whoami –verbose

GRC & Cybersecurity
Compliance Analyst_

Active TS/SCI. Six-plus years across federal NIST 800-53 / RMF programs and commercial SOC 2 / ISO 27001. Compliance work built on four years of 24/7 operational network defense, hardened by real audits.

6+years operational
1,000+incidents triaged
241systems / 24h zero-day
TS/SCIactive clearance

service_record

cat /var/log/career.log

DEC 2025 · PRESENT

AI Cybersecurity Specialist

Invisible Technologies · Contract · Remote

Red-teaming frontier LLM behavior: prompt injection defense, adversarial evaluation, and SOC/GRC scenario authoring that hardens model reasoning on incident response and control-mapping tasks.

JUN 2024 · JAN 2026

Senior Information Security Analyst

Lockheed Martin · Jacksonville, FL

Control assessments, eMASS accreditation packages, POA&M governance, and continuous monitoring on classified DoD programs. Python/PowerShell evidence automation. Splunk dashboards backing 100% audit log retention.

SEP · NOV 2023

Information Assurance Analyst

Five Stones Research Corporation · Contract

ATO sustainment across ~200 servers and ~2,000 workstations: McAfee HBSS, STIG baselines, IAVM compliance, image certification.

APR 2019 · JAN 2023

NOC Administrator & Systems Administrator

U.S. Air Force · Ramstein AB, Germany

24/7 watch-floor defense for 3,000+ personnel across three Combatant Commands. 1,000+ Tier 1/2 incidents. Zero-day mitigation across 241 systems at 11 sites inside 24 hours, with zero rework on the follow-up audit. RHEL/Windows fleets at 99.9% uptime.

operator_loadout

ls /usr/bin/skills –sort=priority

grc/ · compliance & risk

Full control lifecycle: gap analysis → remediation → narrative authoring → evidence → POA&M closure.

NIST 800-53800-171RMFSOC 2ISO 27001CMMC 2.0FedRAMPeMASSDrata

soc/ · detection & response

Four years of shift-based ops. I know which control failed behind an alert, and what the reporting obligation is.

SplunkSIEM tuningMITRE ATT&CKEDR / HBSSACAS / NessusIR

auto/ · compliance automation

Scripts that pull configuration evidence from cloud and endpoint sources and normalize it into audit-ready artifacts.

PythonPowerShellBashREST APIs

ai/ · emerging surface

Active red-team practice against frontier models, the fastest-moving attack surface in the field.

LLM red-teamingprompt injectionadversarial evalAI governance

credentials

certs –list –verified

nick@jax: ~/credentials
$ certs –list
[✓] GIAC GSEC · Security Essentials
[✓] GIAC GFACT · Foundational Cybersecurity Technologies
[✓] CompTIA Security+ CE # DoD 8570 IAT Level II
[✓] CompTIA Network+ · CompTIA A+ · ITIL 4 Foundation
[…] CISSP · in progress
$ education –status
[▸] B.S. Cybersecurity & Information Assurance · WGU (Dec 2026)
# completed alongside full-time work

human_readme

cat ~/human.txt

human.txt · plain text, no markup, no ghostwriter
$ cat human.txt
Jacksonville based. Ocean powered. I taught open-water sailing
before I ever touched a SIEM, and I still do my best thinking
within sight of salt water.

coffee: black, early, non-negotiable
off_hours: homelab tinkering · CyberWarfare Labs challenges ·
finishing a WGU degree at night # graduation close enough to taste
personality: GRC aficionado # yes, that is a real personality type

contact

open –channel

Hiring for GRC, compliance, ISSO, or security analyst roles? I’m interviewing now: remote, or hybrid/onsite in Jacksonville. 15-minute intro calls welcome.

Scroll to Top