Dr. Phillip Edward Sprague, CISA, CISSP, CRISC, CAPM
Laguna Niguel, CA 92677
714-***-**** *************@*****.***
SUMMARY:
I have 2.5 years’ experience as an Information Systems Security Officer (ISSO) for DoD clients. In addition, I have
32 years of IT Audit experience which includes 8.5 years as an internal auditor and 10 years’ contractor experience with IT General Controls (ITGC) for Sarbanes-Oxley (US-sox and J-sox), HIPAA, and DoD compliance. The internal audit experience includes audits of Oracle, PeopleSoft, and SAP modules, Hyperion, project audits, SSAE16 SOC 1 audits, Agreed Upon Procedures (AUP) self-assessment, ISO 27001 (formerly BS 7799) Strataware medical billing software and Salesforce. I have experience with vendor risk assessments and Identity Management. I have a security certification, an IT Audit certification, an IT Risk certification, graduate level statistics classes, and Six Sigma certification.
I have diligently delivered contractual obligations to all clients listed below, to include security, compliance, audit, risk, and best practices. I have a Top-Secret clearance.
EXPERIENCE
Employer: BAE Systems, Salt Lake City, UTAH. Cyber Analyst Sr./ISSO (in DoD Terminology)
US Air Force (Contract) September 2023 - February 2025
Member of Cyber Innovation & Engineering Team
Tested security controls in a secured Air Force lab setting, AP
Prepared documentation for control testing
Worked in a Team Environment with ISSE’s and ISSMs
Work tasks managed through Jira
Nessus Scans
Splunk Reports
ePo Trellix scans
Employer: December Group, Arlington, VA. IT Auditor, November 2020 – KPMG/US Marine Corps (Contract); US Army Analyst (Contract) – August 2023.
Worked on IT aspects of US Marine Corps Financial Audit
Reported audit status to KPMG
Tracked meetings and recorded minutes for distribution
As part of AS Army TRADOC team, worked on implementation of new recruiting system, specifically controls over access to personal and health information
Employer: 22nd Century Technologies, Somerset, NJ. Information Systems Security Officer (Contract) July 2019 – June 2020. Client: Patuxent River NAS, MD; Project: PMA-271. 40 hours/week.
Worked on security packages for HRE systems SASS, BlockI, IPBE, and Sil-STIM.
Created Training guides for new employees
Investigated the state of artifacts in eMASS and reported on the necessity for improved quality
Wrote weekly and monthly Project Reports
NIST 800-53 Framework
Developed Agile approach for team
Wrote VRAM procedure for team
Top Secret clearance obtained for above work
Employer: Rabo Bank, Santa Maria, CA. Senior Security Analyst (Contract) June 2018 – March 2019. 40 hours/week.
Vendor Risk Analysis
Security Auditing
Access Management/Identity Management Procedure
Security Policy Creation and Updates
Employer: Obxtek, Tyson’s Corner, VA. (Contract) Aug 2017 – April 2018.
Client: DoD - United States Marine Corps, Albany, GA. IT Audit Team Lead. 40 hours/week.
Reviewed prior audit findings
Performed Audit Readiness tasks for PWC external audit
Reviewed FIAR framework
Audit readiness work based on FISCAM and NIST models
Investigation of access controls, segregation of duties, and micro-applications
Secret Clearance obtained for above work.
Employer: Insight Global Jan 2017- May 2017
Client: UCSD Medical Center, (Contract) La Jolla, CA. Team Lead Risk Assessment. 40 hours/week.
Reviewed electronic and hard copy files for PII/PHI
Assessed risk of exposure
Scanned endpoints
Wrote executive reports to management
Employer: Stratacare Medical Billing Review (Conduent Business Unit), Irvine, CA. March 2014 – January 2017
Security Auditor (FTE). 40 hours/week.
Interfaced with KPMG for SSAE16 Soc 1 audits
Provided audit support for company - an SaaS provider
AUP (Agreed Upon Procedures) performed - internal security self-assessment
Audited vendor contracts and vendor SSAE16 Soc 1 reports
Assessed risk of vendor engagements and their annual SSAE16 SOC1 reports.
Authorization To Operate (ATO)
Performed SOC II Audits
Performed Quarterly Health Check Audits
Performed Quarterly internal audits
Supported external audit firm
Used SharePoint to store audit documents, Policies & Procedures, etc.
Retrieved records from Service Now – migration data and authentication & authorization records.
Wrote Policy & Procedures
Employer: VACO Oct 2013-Feb 2014
Client: OA, (Contract) Calabasas, CA, IT Audit Consultant. 40 hours/week.
Sarbanes-Oxley (SOX) Compliance audit
Logical Controls, Change Management testing, physical controls
Financial control testing – Fixed Assets, Bank Reconciliations
EDUCATION:
D.Sc, Colorado Technical University (Computer Science – emphasis on Information Assurance)
M.Sc, Cyber Security, Florida Technical University
MBA, IT and Finance, West Coast University, Los Angeles, CA
BA, Business Administration, Accounting and IT, California State University, Fullerton, CA
SAP and Oracle modules, ITIL, COBIT, NERC, ISO, SCADA
Dissertation available upon request.
CERTIFICATIONS
Certified Information Systems Auditor (CISA) #9819205 (ACTIVE)
Certified Information Systems Security Professional (CISSP) #29642 (ACTIVE)
CRISC #1316809 (ACTIVE-IT Risk Assessment)
Lean Six Sigma Green Belt (ACTIVE)
CHA (HIPAA) # h10101-000497 (ACTIVE)
COBIT (ACTIVE)
IS09001:2208 #14978 (ACTIVE)
SCADA Security Architect (ACTIVE)
SAC Critical Infrastructures Protection (NERC-CIP) #260270 (ACTIVE)
CAPM (Project Management – PM Institute)
RECENT/ONGOING EDUCATION
JIRA Training
Network Monitoring
eMASS
RMF
Nessus
Navy Qualified Validator (NQV)
Linux (FEDvte)
Windows Scripting (FEDvte)
Windows Security (FEDvte)
Lean Innovation (Villanova U)
Agile Development (Villanova U)
Python
CYSA certification
ISACA AI
CMMC
LANGUAGES
Studied: R, Visual Basic, C#, Sql-server, Python