nick@jax:~$ tree /skills –depth=2

Skill Tree_

Six years of allocated points. Main spec: GRC. Off-spec: operations. The build is deliberate.

main_spec · grc & compliance

skills/grc/ [████████░░ mastery track]

federal_frameworks.pkg

Daily-driver frameworks from four years of DoD programs. Assessed, not just studied.

NIST 800-53 Rev 5NIST 800-171800-37 / RMFCMMC 2.0FedRAMPSTIG

commercial_frameworks.pkg

Commercial attestation work: SOC 2 program operations end to end, ISO alignment, trust reviews.

SOC 2 / TSCISO 27001:2022NIST CSF

control_lifecycle.bin

The full loop, repeatedly shipped: gap analysis → remediation planning → narratives → evidence → POA&M closure.

eMASSPOA&M governanceATO sustainmentcontrol inheritanceConMon

grc_automation.sh

The multiplier skill: evidence collection as code instead of screenshots-in-folders.

PythonPowerShellBashREST APIsDrata admin

off_spec · operations

skills/ops/ [███████░░░ battle-tested]

detection_response.d

Four years on a 24/7 watch floor. 1,000+ incidents from first alert to closed ticket.

SplunkSIEM tuningMITRE ATT&CKtriage & escalationMcAfee HBSS / EDRACAS / Nessus

infrastructure.d

The systems the controls protect: administered at 99.9% uptime on classified networks.

RHEL 6/7Windows ServerActive DirectoryAzureVMware

new_branch · ai_security

skills/ai/ [█████░░░░░ actively leveling]

llm_redteam.rs

Current daily work at Invisible Technologies: breaking frontier models to make them safer.

prompt injectionadversarial evaljailbreak taxonomytool-use abuse

ai_governance.rs

Where the tree grows next: mapping AI risk into the control frameworks enterprises already run.

AI risk assessmentNIST AI RMFmodel eval rubrics

respec_queue

queue –upcoming

talent_queue
$ queue –list
[▸] B.S. Cybersecurity & IA · WGU # Dec 2026, on schedule
[▸] CISSP # in progress, see /cissp-battle-plan/
[▸] CyberWarfare Labs · SOC challenges # SO-NET-01 complete
[▸] helm_time # restored whenever the Atlantic cooperates
Scroll to Top