Active TS
Ricky Lee Jones
SUMMARY
Information security compliance professional with two decades of experience with security operations & compliance frameworks.
Expert with highly regulated environments including FISMA and FedRamp
Risk Assessments, Security Operations, Incident Response, Policy, Procedures, Control Implementation, System Security Plans
Incident Response Tabletop Exercises for all stakeholders
NIST SP 800-53, 800-53A, 800-37, 800-30, 800-171, 800-218
Technical security control implementation, Vulnerability Management, Incident Response, Access Control, Identity Management
EDUCATION
Bachelor of Science Computer Information Systems
SKILLS
Information Security Risk Assessment and Control implementation per NIST 800-53, 800-171, FedRAMP, System Documentation, Security Awareness Training, Tabletop Exercises.
EXPERIENCE
The Boeing Company 2001 – 2023 Kent WA
Chief Architect (Boeing Global Satcom Services):
Led the cybersecurity maturity assessment of asset management and access control projects using the CMMI model.
Developed processes that improved maturity by 95% in first-year post-assessment.
Resolved 100% of Red Team assessment findings by partnering with operations teams and stakeholders to drive process improvement.
Coordinated unknown asset identification with cybersecurity teams and infrastructure owners.
Presented assessment reports to senior leadership with 100% result acceptance and support to resolve findings.
Mentored and empowered junior engineers to reach stretch goals.
Partnered with engineering and product management teams to deliver company-wide SSL certificate notification system to track expiring certificates, eliminating expiration-based outages.
Designed processes to identify and remediate risky, externally exposed systems in collaboration with cybersecurity and infrastructure teams.
Developed zero-trust architecture to update and modernize legacy interfaces using Rest and Spring Boot. Guided team through application agile development process JIRA and bitbucket version control. Ensured software was documented and loaded to Teamcenter.
AT&T Wireless 2000-2001
Security Consultant:
Responsible for the implementation, management, and support of the enterprise perimeter security controls, including enterprise firewalls and intrusion detection/prevention systems.
Ensured system security needs were established and maintained for operations systems. As a Certified Information Systems Professional (CISSP) I was tasked with certification and accreditation of systems, continuity planning and provided analytical support for security policy.
US Army Space Command 1988-2000
Satellite Manager
Planned satellite networks, liaised with communications units and calculated link budgets for tactical and strategic customers as a part of a multi-service organization including all of USSTRATCOM’s service components commands (Army, Navy, Air Force) and the Defense Information Systems Agency.
Regional Space Support Center – Responsible for development of frequency management software that allowed managers to deconflict spectrum in real time. Recognized by Army Space Commander for dedication and commitment to excellence that greatly enhanced commands ability to provide satellite planning services.
Requested by name to support Bright Star military exercises providing communications for nearly 60,000 troops. Deployed to Egypt to support real-time planning in support series of combined and joint training exercises led by American and Egyptian forces.
Selected to deploy to Europe to support Operation Allied Force. Was entrusted with frequency allocation and link analysis for forces deploying to a wartime environment. Recognized by DISA Headquarters Commander for contributing to the command quick reaction efforts.
Awards
Nationally recognized as a Modern-Day Technology Leader award at the 2021 BEAY Engineer conference.
Two-time winner of Boeing’s prestigious Atlas Award, which recognizes outstanding team achievement and acknowledge employees who develop innovative solutions to problems.