John Printz
H - ** Leigh St.
Framingham, MA **701
*******@*****.***
W - 77 A Street
Needham, MA 02494
****.******@*****.***
Qualifications
. Over twenty-two (22) years experience
. Considerable project management experience
o MBA from the University of Iowa
o Integrated Product Team (IPT) leadership
o Cost Account Management and Earned Value Measurement System (EVMS)
experience
o Experienced MS Project user
. Extensive Security Engineering experience
o Hands-on experience with Public Key Infrastructure (PKI) and Key
Management Infrastructure (KMI)
. Certificate/Key distrubution
. Service Oriented Architecture (SOA)
o Hands-On network security experience
. Secure Socket Layer (SSL) and Transport Layer Security (TLS)
utilizing both self-signed and Certificate Authority (CA)
provided certificates
. Firewall and content filter policy development (requirement
allocation and implementation)
o Operating Systems - Microsoft Server 2000 and 2003 and Red Hat
Enterprise Linux Version 5
o National Institute of Standards and Technology (NIST) guideline and
checklist recommendation and implementation
o Role-Based Access Control (RoBAC) and Rule-Based Access Control
(RuBAC) implementations
o Secure Socket Layer (SSL) / Transport Layer Security (TLS) user
authentication into a Service Oriented Architecture (SOA) network
o Password storage (e.g.; one-way encryption)
o Database replication utilizing SSL/TLS
o Audit log replication utilizing SSL/TLS
. Over ten (10) years experience with secure system (network) design,
development, and Certification & Accreditation (C&A)
o DITSCAP (DoD 8500.1) - System Security Accreditation Agreement
(SSAA) generation including the following appendices: Trusted
Facility Manual (TFM) and Security Features Users Guide (SFUG)
o DIACAP (DoD 8500.2) -Trusted Facility Manual (TFM) and Security
Features Users Guide (SFUG) generation
o NISCAP (DCID 6/3) - System Security Plan (SSP) generation including
the following appendices: Security Concept of Operations
(SeCONOPS), Trusted Facility Manual (TFM) and Security Features
Users Guide (SFUG)
o Common Criteria Evaluation Assurance Level (EAL) 4 certification,
including generating Protection Profiles and Security Targets
o National Security Agency (NSA) Type-1 Certification, including
generating the following documents: Theory of Design and Operation
(TDO), Theory of Compliance (TOC), Fail Safe Design and Analysis
(FSDA) Steps 6 through 9, Key Management Plan (KMP) Parts 1 through
3, Covert Channel Analysis (CCA), and Security Verification Test
(SVT) Plan, Procedures, and Report
o Test Plan and Procedure generation for DITSCAP and NISCAP
Certification and Accreditations
o Implementation of STIGs, SNACs, and NIST guidelines for hardening
COTS networking components and software
o Security Requirement derivation and allocation (Tailored Unified
Information Security Criteria (TUIC), Common Criteria Security
Target requirements, DITSCAP/DIACAP/NISCAP requirements)
o Participation in Security Readiness Reviews (SRRs) for multiple
programs
. CISSP examination taken 25 April 2011
. Extensive interpersonal verbal & written communication skills
o Customer-deliverable document generation - primarily for US
Department of Defense (DoD) and UK Ministry of Defense (MoD)
o Numerous executive-level presentations
o Over 20 years experience with MS Office suite (Word, Excel,
PowerPoint, and Visio)
. Extensive experience with Information Technology regulations and laws
o Privacy Act of 1974
o Sarbanes-Oxley Act of 2002
o National Institute of Standards and Technology (NIST) guidelines
and checklists
o Information Technology Security Criteria (ITSEC) requirements and
evaluation
Education
. Master of Business Administration, University of Iowa, Iowa City, IA,
degree awarded May 2005
. Master of Science in Electrical Engineering, Polytechnic University of
New York, Brooklyn, NY, degree awarded June 1995
. Bachelor of Science in Electrical Engineering, University of Maryland,
College Park, MD, degree awarded December 1988
Experience
. General Dynamics C4S IAD, Needham, MA, October 2008 to present. Systems
security engineer assigned to DoD programs. Duties include allocation of
security-related requirements, generation of certification documentation.
. Rockwell Collins, Cedar Rapids, IA, May 2001 to October 2008. Systems
and systems security engineer assigned to multiple programs. Duties
included allocation of security-related requirements, generation of
certification documentation, generation of system and security
verification plans, procedures, and reports, cost account management,
Integrated Product Team (IPT) leadership
. 3Com, Rolling Meadows, IL, September 2000 to March 2001. Software test
engineer assigned to multiple programs. Duties included generation of
software and system verification and integration plans, procedures, and
reports.
. Northrop Grumman, Rolling Meadows, IL, May 1996 to September 2000.
Systems engineer assigned to multiple programs. Duties included system
integration plan, procedure, and report generation, flight test plan,
procedure, and report generation, system integration laboratory design,
cost account management
. US Army ARDEC (Civilian Employee), Picatinny Arsenal, NJ, January 1989 to
May 1996. Electronics engineer (GS-0855-12) assigned to multiple
programs. Duties included verification plan, procedure, and report
generation, field engineering support, production and deployment support,
cost account management
References
Available upon request