Mary Koroma
National Capitol Region (NCR) 571-***-**** *************@*****.***
Cybersecurity Consultant with experience supporting GRC, RMF, FedRAMP, DISA PA, and ICAM initiatives across federal, DoD, fintech, and enterprise environments. Skilled in NIST CSF, NIST SP 800-53, control mapping, audit readiness, IAM policy administration, MFA, RBAC, and Zero Trust-aligned identity modernization.
• Active Clearance: Public Trust, Willing to Obtain Secret/Top Secret/SCI
• DoD Workforce Compliance 8140/8570 - IAT Level II: CompTIA Security+ IAM / ICAM: Experience with identity lifecycle
management, MFA, RBAC, SSO, federation, access
governance, and Zero Trust-aligned identity
modernization using SailPoint, CyberArk,
BeyondTrust, Okta, Keycloak, Oracle IAM,
Microsoft Entra ID, PingFederate, Radiant Logic,
Keyfactor, and AppViewX.
• Governance Risk & Compliance (GRC):
Experience supporting cybersecurity governance,
risk, and compliance initiatives across RMF, NIST
CSF, NIST SP 800-53, FedRAMP, DISA PA, SOX,
PCI DSS, SOC 2, and ISO 27001, including control
mapping, gap assessments, evidence collection &
Continuous Monitoring (ConMon).
•
Project Management: Experience coordinating
technical initiatives, tracking project milestones, documenting requirements, supporting stakeholder
meetings, managing deliverables, and aligning teams to client objectives.
• ITSM / Service Delivery: Experience using
ServiceNow and Jira for incident management,
service requests, change management, SLA tracking, KPI reporting, ticket documentation, and operational support.
•
Microsoft 365 / Productivity: Experience
supporting Microsoft 365 tenants, SharePoint,
OneDrive, Teams, Outlook, user adoption,
collaboration workflows, migration support, and
secure productivity enablement.
• Endpoint & Systems Administration: Experience
with SCCM/MECM, WSUS, Windows Deployment
Toolkit, Intune, Windows Server 2012 R2, on-prem
Active Directory, endpoint patching, imaging, and
configuration management.
•
Security Monitoring / SIEM: Experience using
Microsoft Sentinel and Elasticsearch to support log review, identity monitoring, event analysis,
authentication visibility, and access-related
investigations.
• Technical Documentation: Experience developing
SOPs, process documentation, compliance artifacts, user guides, training materials, control narratives, meeting notes, and executive-ready status updates.
•
ICAM Consultant, 09/2024 - 04/2025
Olympus Solutions, US Department of Treasury (BEP) – Washington, DC Supported ICAM consulting initiatives for federal Department of Treasury customers, administering identity and access capabilities across Microsoft 365 tenants, Microsoft Entra ID, Keycloak, SailPoint, CyberArk, BeyondTrust, Okta, Oracle IAM, PingFederate, Radiant Logic, Keyfactor, and AppViewX.
•
Professional Summary
Skills
Work History
Administered MFA enrollment, IAM policies, RBAC models, and access control workflows to strengthen least-privilege access, improve identity governance, and support secure authentication across federal cloud environments.
•
Supported RBAC design and access control activities by helping define user roles, permissions, entitlement structures, and access workflows to improve least-privilege enforcement and identity governance.
•
Supported Zero Trust mandates and identity modernization efforts by helping align ICAM capabilities with federal security objectives, BYOD strategy, conditional access, device trust, and secure access requirements.
•
Collaborated with identity engineers, security architects, and client stakeholders to support IAM, PAM, IGA, PKI, federation, SSO, certificate lifecycle management, and Microsoft 365 security initiatives across enterprise and government environments.
•
Leveraged Elasticsearch and Microsoft Sentinel SIEM capabilities to support identity monitoring, security event analysis, access-related investigations, and visibility into authentication and user activity across federal customer environments.
•
Cybersecurity Consultant, 07/2023 - 02/2024
Diligent – Washington, DC
Supported FedRAMP and DISA Provisional Authorization efforts for federal, DoD, and commercial clients by assisting with control implementation, compliance documentation, evidence collection, and audit readiness activities.
•
Consulted with fintech organizations, Fortune 500 companies, government agencies, and DoD customers, including Department of Agriculture and DoD environments, to support cybersecurity governance, risk, and compliance initiatives across regulated systems.
•
Leveraged Diligent HighBond / Diligent One Platform to manage GRC workflows, track control performance, document risks, collect evidence, and support compliance activities across NIST CSF, RMF, SOX, PCI DSS, SOC 2, and ISO 27001 frameworks.
•
Mapped NIST SP 800-53 controls and ISO 27001 Annex A controls to applicable frameworks, helping clients identify control overlap, streamline compliance activities, reduce duplication, and improve audit readiness.
•
Collaborated with Sales Engineers, Account Executives, client stakeholders, and technical teams to support product demos, translate compliance requirements into Diligent One Platform capabilities, and align GRC solutions with client risk and regulatory needs.
•
Supported RMF lifecycle and Zero Trust initiatives, including control selection, implementation tracking, gap analysis, risk documentation, POA&M support, and continuous monitoring aligned with DoD Zero Trust Strategy, OMB M-22-09, and federal cybersecurity requirements.
•
System Administrator, 01/2023 - 07/2023
Nuaxis Innovations, U.S Department of Labor (DOL) – Washington, DC Implemented and administered Microsoft Intune MDM/MAM policies to strengthen device security, application protection, compliance enforcement, and mobile endpoint governance across the enterprise.
•
Deployed, imaged, patched, and managed 2,000+ enterprise desktops using Microsoft Endpoint Configuration Manager / SCCM, Windows Deployment Toolkit, and WSUS, supporting secure endpoint operations and configuration compliance.
•
Managed ITSM workflows in ServiceNow, resolving incidents, service requests, and change tickets while consistently meeting SLAs, KPIs, and enterprise service quality standards.
•
Administered on-premises Active Directory in a Windows Server 2012 R2 environment and Microsoft Entra ID, provisioning 500+ user accounts annually while supporting IAM governance aligned with NIST 800-53
(AC) control requirements.
•
Resolved PIV badge, HID ActivID ActivClient, and PKI authentication issues while supporting secure authentication, privileged access workflows, M365 migration training, and user adoption for SharePoint and OneDrive.
•
Desktop Support Engineer, 08/2019 - 12/2022
Northern Virginia Mental Health Institute (NVMHI) – Falls Church, VA
• Implemented and managed EPIC electronic health record (EHR) system for patient information. Provided technical support to hospital staff for hardware, software, and network-related issues and managed the progress through Jira ticketing portal.
•
Assisted in technology projects, such as system upgrades, network enhancements such as VPNs, and software deployments using Microsoft System Center Configuration Manager (SCCM).
•
High School Diploma
C.D. Hylton High School - Woodbridge, VA
Education