JANET L. MCFAUL
Maryland, US +1-540-***-**** *********@*****.*** https://www.linkedin.com/in/janet-mcfaul-a5667179/
Cybersecurity Systems Security Engineer (ISSE) ISSM Cloud Security RMF FedRAMP
United States Air Force Veteran –Enlisted Officer Major (O4)
Stateside or Remote
CISA CISM AWS Cloud Practitioner
EXECUTIVE SUMMARY
Cybersecurity and Systems Security Engineer with over 15+ years supporting Department of Defense, Intelligence Community, and Federal Civilian agencies in securing missioncritical onpremises and cloud environments up to Top Secret/SAP classification levels. CI Poly.
Recognized NIST Risk Management Framework (RMF) and FedRAMP governance authority with demonstrated success leading Authorization to Operate (ATO) initiatives, Zero Trust implementations (NIST SP 800207), and enterprise vulnerability management programs across largescale acquisition and cloud modernization efforts.
Proven record of reducing system vulnerabilities by over 20%, remediating compliance backlog across 1,500+ IT artifacts, and enabling CCRI/CORA certification readiness through documentation overhaul, policy updates, and auditdriven remediation strategies.
Experienced across AWS GovCloud, Kubernetes/OpenShift platforms, CI/CD pipelines, ACAS/Nessus scanning, and Microsoft Defender migration initiatives in support of DoD Zero Trust architecture mandates.
Seeking to leverage RMF, SOC 2, FedRAMP, and enterprise risk assessment expertise in an ISSE, ISSM, or Cybersecurity Analyst role supporting secure mission delivery.
CORE COMPETENCIES
NIST 80037 RMF Implementation
NIST 80053 Rev 5 Security Controls
FedRAMP High / IL5IL6 Systems
Zero Trust Architecture (NIST 800207)
DISA STIG Hardening
SOC 1 / SOC 2 Readiness
Enterprise Vulnerability Management
ATO Accreditation Lifecycle
ACAS / Nessus / AWS Inspector Vulnerability Scans
Fortify and Xray Static Scans
eMASS / XACTA Archives
Kubernetes / OpenShift
Supply Chain Risk Management (SCRM)
Cloud Security (AWS GovCloud)
HBSS to Microsoft Defender Migration
POA&M / SSP / STP / SAR
PCIDSS / ISO 27001 Alignment
PKI Implementation
COOP / DR / IR Planning
Project planning and AGILE processing.
PROFESSIONAL EXPERIENCE
Systek Corporation
Cybersecurity Systems Engineer- US Army
May 2026 – Present Onsite Hanover, MD
Assist the CISO in meeting their duties and responsibilities. Implement and enforce all DoD Information Systems and Platform IT system cybersecurity policies and procedures, as defined by cybersecurity-related documentation.
Ensure that all users have the requisite security clearances and access authorization and are aware of their cybersecurity responsibilities for DoD IS and PIT systems under their purview before being granted access to those systems.
In coordination with the CISO, initiate protective or corrective measures when a cybersecurity incident or vulnerability is discovered and ensure that a process is in place for authorized users to report all cybersecurity-related events and potential threats and vulnerabilities to the ISSO.
Ensure that all DoD IS cybersecurity-related documentation is current and accessible to properly authorized individuals.
Review reports from static code analysis, Pen Testing, and Scanning Results for vulnerabilities and compliance.
Review network, data flow, org charts and other security artifacts for potential vulnerabilities related to processes or personnel.
Thorough knowledge of NIST 800 series Special Publications, Federal Information Processing Standards (FIPS) and other relevant federal and DoD cybersecurity regulations.
Create and maintain security configuration baselines for Windows and Linux platforms, networking equipment, cloud technologies and custom hardware and software applications.
Update security archives on CUI and multiple high security level and departmental systems.
Ensure proper security protocols when accessing and retrieving classified materials.
ManTech Corporation
Cybersecurity Systems Engineer – US Navy
Nov 2025 – April 2026 Remote & Hybrid
Support FedRAMP IL5/IL6 cybersecurity authorization activities for U.S. Navy enterprise systems.
Apply NIST 80037 RMF processes and NIST 80053 security controls to balance system risk with cost, schedule, and performance.
Perform ACAS and AWS Inspector vulnerability assessments utilizing Nessus and STIGRevolution toolsets.
Develop architecture diagrams, privacy impact assessments, and security integration plans.
Provide recurring cybersecurity risk posture briefings to senior leadership supporting program compliance.
KBR Corporation
Cybersecurity Systems Engineer
Mar 2025 – Oct 2025 Eglin AFB
Led cybersecurity engineering efforts supporting the Hypersonic Attack Cruise Missile acquisition program.
Implemented AntiTamper (AT) and Defense Exportability Features (DEF) security requirements.
Developed Supply Chain Risk Management (SCRM) strategies to mitigate hardware/software vulnerabilities.
Produced program security documentation including SEP, SRD, SOW, and Program Protection Plans (PPP).
Ensured compliance with FedRAMP and PCIDSS control baselines within SSEdriven security initiatives.
Position reclassified by Government.
US Army Corps of Engineers
Senior Cybersecurity & Systems Engineer
Jun 2024 – Jan 2025 Remote
Led enterprise cyber compliance efforts for JFHQDODIN CCRI/CORA inspection readiness.
Eliminated eMASS compliance backlog by reviewing 1,500+ archived security artifacts.
Conducted 40 stakeholder interviews resulting in CIOlevel report identifying 35+ process improvement initiatives.
Assessed 50+ COOP, Disaster Recovery, and Incident Response plans.
Delivered enterprise impact analysis supporting migration from Trellix HBSS to Microsoft Defender in hybrid cloud environments.
Advanced organizational Zero Trust compliance to 90% in alignment with NIST 800207 standards.
Chenega Corporation
Senior Cybersecurity Cloud Engineer
Nov 2021 – Apr 2024 On-Site Springfield, Virginia
Supported $100M+ IC cloud modernization program as cybersecurity SME.
Implemented AWS GovCloud solutions aligned with ISO 27001, SOC 2, PCIDSS, and NIST 80053 control frameworks.
Served as DIA Kubernetes/OpenShift security SME AWS Cloud environments. Zero Trust Mesh network.
Performed vulnerability assessments using Prisma Cloud and JFrog across CI/CD pipelines.
Developed enterprise security policies and conducted cloud risk assessments.
Peraton Corporation
Cybersecurity Project Manager
Nov 2019 – Nov 2021 On-Site Springfield, Virginia
Reduced enterprise security breaches by 20% through CIS benchmark implementation and ACAS remediation.
Led RMF implementation enabling Authorization to Operate (ATO) for cloudbased defense program.
Managed PKI provisioning and log archival for enterprise audit compliance.
Authored ISCP and CONOPS supporting incident response lifecycle.
Deloitte
Senior Security Control Assessor
Sep 2018 – Nov 2019 On-Site Springfield, Virginia
Led security assessments across hundreds of federal IT systems.
Served as RMF, COBIT5, and NIST 80053 SME.
Developed POA&M, SAR, RAR, SSP, and Continuous Monitoring CONOPS artifacts.
Provided executivelevel cybersecurity compliance briefings.
CERTIFICATIONS
AWS Cloud Practitioner (2022–Present)
Certified Information Systems Auditor (CISA) (2018–Present)
Certified Information Security Manager (CISM) (2019–Present)
CMMI Level 3
EDUCATION
M.S. Cybersecurity Technology – University of Maryland Global Campus, College Park, MD.
M.S. Information Systems Management – Golden Gate University, San Francisco, CA.
B.A. Economics – California State University, Fresno, CA.
MILITARY SERVICE
United States Air Force – Enlisted/ Officer Major (O4)
22 Years Active Duty / Reserve
Systems Technician Senior Systems Engineer DISA HQ Watch Officer Network Systems Engineer UNIX/Linux Systems Engineer