Allen W. Gresick, Sr. - CISSP
Colorado Springs, Colorado 80915
**********@*****.***
SUMMARY
An accomplished, cleared Information
Assurance (IA) Engineer with 35+ years of IA
Engineering experience within various
Intelligence Community (IC) agencies.
Specialties include Approval & Authorization
(A&A), vulnerability and risk management,
SDLC, and information security policy drafting,
review, and interpretation. Knowledge and
experience in USG regulations, such as ICD
503, HIPAA, PCI-DSS, NISPOM, FISMA,
FEDRAMP, SOX, NIST Special Pubs, and
STIGs. Working knowledge of vulnerability
scanning tools, such as BeyondTrust Retina,
Tenable NESSUS and WASSP.
Allen has a reputation for excellent customer service, attention to detail, and doing whatever is necessary to get the task accomplished on time and on budget.
SECURITY CLEARANCES
Active TOP SECRET SECURITY CLEARANCE WITH SCI ACCESSES with a background investigation (SSBI closed 3/5/2013) and CI polygraph (Oct 2015). SCI adjudicated by NGA - 5/28/2013. Currently on Continuous Evaluation
(CE).
PROFESSIONAL EXPERIENCE
Aug 2022 – Present Adjunct Professor-Cyber Security Colorado Technical University, Colorado Springs, CO
Serves as a part-time Adjunct Instructor for various online cyber security courses for the CTU College of Engineering to include:
• CSS150 – Introduction to Computer Security
• CSS200 – Introduction to Network Security
• CSS280 – Ethical Hacking
• CSS330 – Business Continuity & Disaster
Recovery
• CSS410 – Secure Cloud Computing
Mar 2024 – Present Senior, Information Security Systems Engineer Galapagos, Colorado Springs, CO Plays a pivotal role in safeguarding classified networks and supporting the IT office and the US Space Force (USSF). Responsible for delivering direct, day-to-day support within classified areas, to ensure the integrity and security of classified networks while executing cybersecurity duties aligned with classified network objectives. By providing expert recommendations and solutions, the ISSE contributes to the implementation of robust cybersecurity programs and projects, enhancing the USSF’s cybersecurity posture.
• Recognized as an industry leader, renowned for possessing robust analytical skills that drive strategic decision-making and problem-solving.
• Exhibits outstanding organizational and presentation skills, ensuring clarity and effectiveness in convey- ing complex information to diverse audiences.
• Thrives in autonomous work environments, adept at operating with minimal supervision while seamlessly collaborating with team members and senior leadership.
• Demonstrates strong critical thinking abilities, proactively identifying and addressing challenges to prevent issues from escalating.
• Takes a proactive approach to problem-solving, anticipating potential issues and implementing preemp- tive measures to mitigate risks.
Cybersecurity Compliance and Engineering experience
Supervisory skills and experience
Intelligence Community experience
ICD 503, HIPAA, PCI-DSS, FISMA, SOX, NIST Pubs, STIGs
Top Secret/SCI clearance w/ CI polygraph
BS-EET degree; MS degrees in IT Management & IA
Nessus & Retina vulnerability scanning tools
RMF A&A experience
Xacta, eMass & RiskVision experience and knowledge
Excellent customer service skills
Taught Cyber Security courses at ISU and CTU
Allen Gresick – 571-***-**** Page 2
• Excels in written and oral communication, showcasing exceptional leadership capabilities and fostering a culture of collaboration and teamwork.
• Adhering to DAF, DoD, and IC standards, and processes outlined by the government, provides timely program reviews, schedules, and action item updates to meet established deadlines.
• Ensures confidentiality, availability, and integrity in the development and delivery of capabilities in align- ment with USSF priorities.
• Provides crucial cyber support to bolster security posture, designs and implements security features to combat unauthorized access and emerging threats in support of classified network objectives.
• Offers recommendations and solutions to the government for the implementation of cybersecurity pro- grams and projects.
• Conducts thorough and timely research on policies and processes, applies IT security control require- ments to uphold the confidentiality, integrity, and availability of system data and resources. Nov 2023 – Feb 2024 Lead, Information Security Systems Engineer Rothe Development, Colorado Springs, CO
Provided innovative and practical cyber security solutions and support to Missile Defense Agency
(MDA) in Colorado Springs, Colorado.
• Implemented the Risk Management Framework (RMF) process on government systems and recom- mended solutions for problematic issues.
• Developed and implemented information security procedures, system security plans, and POA&Ms for the operation of networked and standalone classified computer systems, as well as coordinating government agency approvals/accreditation.
Nov 2021 – Oct 2023 Lead, Information Security Systems Engineer L3Harris, Colorado Springs, CO Provided innovative and practical cyber security solutions and support to various USSF space and land-based satellite communications/radar programs in Colorado Springs, Colorado.
• Implemented the Risk Management Framework (RMF) process on government systems and recom- mended solutions for problematic issues.
• Developed and implemented information security procedures, system security plans, and POA&Ms for the operation of networked and standalone classified computer systems, as well as coordinating government agency approvals/accreditation.
• Provided security engineering guidance and expertise, such as design, development, integration, and analysis, to various DevSecOps programs, which support the USSF ground and space-based radar and communication systems.
• Utilized Unified Kill Chain and Threat Modeling to determine the threats and risks posed on various classi- fied systems.
• Consulted on several USSF classified and CUI computing systems.
• Performed information system hardening configuration and remediation.
• Identified and monitored system vulnerabilities and implemented security remediation where necessary.
• Designed, developed, and implemented leading-edge analytical and technical methodologies, tools, and policies/standards to ensure a cyber-secure environment for customer organizations. June 2020 – Nov 2021 Principle Cyber Security Liaison Officer Parsons Corporation, Colorado Springs, CO Provided innovative and practical Cyber security solutions and supported the USSF Space and Missile Systems Center’s (SMC) Cyber security and space projects in Colorado Springs, Colorado.
• Implemented the Risk Management Framework (RMF) process on government systems and recom- mended solutions for problematic security issues.
• Developed and implemented information security procedures, system security plans, and POA&Ms for the operation of networked and standalone classified computer systems, as well as coordinating government agency approvals/accreditation.
• Conducted periodic system self-inspections/testing, weekly system audits, media reviews and investiga- tions of computer security incidents.
• Consulted on the design, development, integration, and analysis of classified and CUI computing sys- tems.
• Performed information system hardening configurations and remediation. Allen Gresick – 571-***-**** Page 3
• Identified and monitored system security vulnerabilities, and security protection.
• Designed, developed, and implemented leading-edge analytical and technical methodologies, tools, and policies/standards to ensure a cyber-secure environment for customer organizations. Aug 2017 – Jun 2021 Adjunct Professor-Cyber Security Idaho State University, Pocatello, ID
• Taught Cyber security classes for the College of Technology, Cyber-Physical Security Program, such as: o Risk Assessment
o Introduction to Cyber Security
o Introduction to IT
o Preparation course for the SSCP Certification
o Encryption and Secure Communications
• Taught Cyber security continuing education classes for the ISU Continuous Education Center Aug 2018 – June 2020 Sr. Information System Security Engineer Buchanan & Edwards, Pocatello, ID Provided Information System Security Engineer (ISSE) services to the Federal Bureau of Investigation
(FBI) in Pocatello, Idaho.
• Served as Senior ISSE supporting the Pocatello FBI Information System Security Manager (ISSM) in her effort to ensure secure information systems are utilized throughout the FBI.
• Utilized RiskVision software to monitor and maintain the progress of FBI systems undergoing the NIST Risk Management Framework (RMF) process.
• Provided security engineering support to FBI’s Security Division (SecD) during information system devel- opment, integration, and operation to include the FBI’s Data Center Transition Initiative (DCTI), which consolidated enterprise data centers from six to two.
• Served as Security Engineering Subject Matter Expert (SME) for new and legacy FBI information systems undergoing the NIST RMF process.
Provided Information System Security Engineer (ISSE) services to the Federal Bureau of Investigation
(FBI) in Pocatello, Idaho.
• Served as Senior ISSE supporting the Pocatello FBI Information System Security Manager (ISSM) in her effort to ensure secure information systems are utilized throughout the FBI.
• Utilized RiskVision software to monitor and maintain the progress of FBI systems undergoing the NIST Risk Management Framework (RMF) process.
• Provided security engineering support to FBI’s Security Division (SecD) during information system devel- opment, integration, and operation to include the FBI’s Data Center Transition Initiative (DCTI), which consolidated enterprise data centers from six to two.
• Served as Security Engineering Subject Matter Expert (SME) for new and legacy FBI information systems undergoing the NIST RMF process.
Oct 2015 – Sep 2016 Lead, Security Control Assessor General Dynamics IT, Reston, VA Provided Security Control Assessor (SCA) and Team Management services to the Defense Intelligence Agency (DIA) in Reston, Virginia.
• Served as General Dynamics IT (GDIT) Team Lead/Manager which included management responsibili- ties, such as timecard approvals, performance appraisals, task assignments, conflict resolution, new hire interviews, etc. of a team comprised of 20+ SCAs located globally with the majority located in the National Capitol Region (NCR).
• Served as SCA SME for the design and implementation of Xacta for DIA CIO’s RMF 2.0 initiative.
• Served as SCA providing assessor services to offices within DIA resulting in classified systems success- fully navigating the RMF process and obtaining Approval and Authorization.
• Encouraged informed risk-taking and acted as a catalyst for innovation; generated practical, sustainable and creative options to solve problems and created business opportunities, while maximizing existing re- sources.
Sep 2016 – Aug 2018 Sr. Information System Security Engineer ALTA IT Systems, Pocatello, ID Allen Gresick – 571-***-**** Page 4
• Used subject matter/functional expertise, influence and process skills to help internal customers and stakeholders identify and meet their high priority needs and requirements while considering cultural, polit- ical and security implications.
• Prepared security authorization Body of Evidence (BOE) packages pursuant to the RMF process to in- clude System Security Plans (SSPs), Risk Assessments, Plan of Action and Milestones (POA&Ms), As- sessor Memos, Draft Approval to Operate (ATO)/Interim Approval to Test (IATT) packages, Security As- sessment Reports (SARs), Security Control Traceability Matrices (SCTMs), System Inventories, and Se- curity Test Procedures (STPs).
• Reviewed BOE packages for consistency, accuracy and format while ensuring that the packages reflect- ed the overall security posture of the classified system under test.
• Served as an IA SME representing the CIO’s office in various working groups and teams resulting in en- hanced security across the systems employed by DIA.
• Utilized various tools and testing techniques to accomplish the security assessment of classified systems, such as Nessus, Retina and DISA Security Technical Implementation Guides (STIGs). Nov 2014 – Oct 2015 Sr. Information Assurance Engineer Engility Corp., Chantilly, VA Sep 2013 – Nov 2014 Sr. Information Assurance Engineer Parsons Corp., Centreville, VA Note: These duties apply to both Engility and Parsons employment due to the contract transfer from Parsons to Engility.
Provided IA engineering services to the National Reconnaissance Office (NRO) in Chantilly, Virginia.
• Accessed/coordinated/validated IA requirements with Program Managers, Security and Certifica- tion/Accreditation personnel within the RMF process.
• Encouraged informed risk-taking and acted as a catalyst for innovation; generated practical, sustainable and creative options to solve problems and created business opportunities, while maximizing existing re- sources.
• Created a Security CONOPs template form for industry partners (IPs) that use their corporate networks to store, process and transmit USG Controlled Unclassified Information (CUI), which resulted in a consistent format for risk evaluation comparisons.
• Implemented a standardized approach to assessing IA risk by creating an automated tool to analyze a completed Security CONOPs template for potential security risks associated with IPs’ corporate networks processing USG CUI which resulted in a consistent risk evaluation across all networks evaluated.
• Ensured IA requirements are addressed and integrated at the appropriate system development lifecycle
(SDLC) resulting in budget savings and increased security.
• Provided sound advice and guidance to the customer regarding the creation or alteration of organizational IA policies and implementation of security controls and appliances which lead to consistent policy inter- pretation and security control implementation.
• Represented customer's IA interests as an IA SME in various meetings and working groups.
• Performed IA-related research as required.
• Supported ICD 503 A&A activities within the RMF process while minimizing costs without compromising security requirements.
Aug 2010 – Jun 2013 Sr. Information Assurance Engineer DigitalGlobe, Herndon, VA Provided IA engineering services to the National Geospatial-Intelligence Agency (NGA) Enhanced View contract.
• Oversaw the Certification and Accreditation (C&A) process of the Enhanced View program resulting in complete classified system accreditation.
• Oversaw and contributed to the development of secure DigitalGlobe and Enhanced View network architectures and implementations, resulting in accredited, classified systems. Sep 2009 – Aug 2010 Sr. Information Assurance Engineer TASC Inc., Chantilly, VA Assigned to the NGA, NSG SI.
Nov 2005 –Sep 2009 Lead, INFOSEC Engineer MITRE Corporation, McLean, VA Assigned to the DoD, Intelligence Systems Support Office (ISSO) and to the Director of National Intelligence
(DNI).
Allen Gresick – 571-***-**** Page 5
Nov 2002 – Nov 2005 Sr. INFOSEC Engineer Advanced Concepts, Inc., Columbia, MD Assigned to the Central Intelligence Agency (CIA) providing engineering and Certification and Accreditation expertise to various programs and projects.
Nov 1996 – Nov 2002 IT Security Engineer/Deputy PM Computer Sciences Corp, Falls Church, VA IT Security Engineer/Lead of a CSC computer security team assigned to NGA, Certification and Accreditation Division (SISA) overseeing the C&A of NGA classified information systems. Apr 1996 – Nov 1996 IT Security Engineer Macfadden & Associates, Inc., Silver Spring, MD Technical member of an MAI computer security team assigned to the Department of State's (DoS), Bureau of Diplomatic Security, Information Security Technology (IST) Lab. Jul 1985 – Apr 1996 Security Officer Central Intelligence Agency (CIA), Washington, DC Assigned to the Office of Security (OS) and served as Personnel Security Officer, Technical Security Officer, Physical Security Officer, and Information Security Officer.
EDUCATION/PROFESSIONAL CERTIFICATIONS
CISSP – Awarded January 2012 – Registration #415163 MS - Information Assurance - Capitol Technology University (CTU) (formerly Capitol College), Laurel, MD - 2009
MS - Information & Telecommunications Systems Management - CTU, Laurel, MD - 2003 BS - Electronics Engineering Technology - CTU, Laurel, MD - 1991 AAS - Electronics Technology - Northern Virginia Community College, Annandale, VA - 1986 ADDITIONAL INFORMATION/WORK PRODUCT EXAMPLES
Further work details can be found in a Resume Addendum. Click here for more details. Additional documents, such as Certificates of Appreciation and sample work products can be found here.