MIRWAIS ‘WAIS’ KHAIRZAD
**** ****** ***** ****, *******, VA 22031
****************@*****.***
PROFESSIONAL SUMMARY:
Mr. Khairzad is a seasoned IT Security Engineer with over 20 years of experience supporting Federal and Government environments, specializing in cybersecurity, compliance, and risk management. He has extensive expertise in Red Team operations, penetration testing, security auditing, and Assessment & Authorization (A&A), with hands-on experience supporting CMMC Level 2 readiness aligned to NIST SP 800-171 and the Risk Management Framework (RMF) lifecycle in accordance with NIST SP 800-53 Rev 5 and NIST SP 800-37. With over 10 years of experience in policy development and compliance, he has led and supported the creation of SSPs, RTMs, POA&Ms, and audit-ready documentation, while conducting security control assessments, vulnerability testing, and continuous monitoring to ensure FISMA and NIST compliance and successful Authorization to Operate (ATO) outcomes. GDIT, DISA 04/2026 – Current
Cyber Security Engineer
• Design, develop, test, and evaluate information system security throughout the systems development life cycle.
• Provides ISSO services on government client system.
• Identify, analyze, and remediate system vulnerabilities; recommend improvements for future security enhancements
• Perform network security administration and support engineering tasks as directed by the Government
• Troubleshoot and resolve system outages and major network security issues in collaboration with other teams
• Evaluate and test new security technologies within enterprise lab environments
• Develop and validate system changes in test environments prior to production deployment
• Install and integrate new security hardware and software, ensuring compatibility with existing systems and networks
• Participate in Change Advisory Board (CAB) meetings to review and support secure implementation of system changes
• Utilizing core network security tools such as IDS/IPS, Firewalls, Web Content Filters, SIEM, DLP, etc.
• Actively working with end point security technologies such as HBSS, ACAS, Tanium.
• Experience developing customer or product requirements into total systems solutions that acknowledge technical, schedule, and cost constraints.
• Support ATO and working experience with policies, procedures, plans, RTM, SSP with eMASS.
• Provide security engineering support for COTS and GOTS product integration, managed services, and IT operations
• Scan using ACAS for compliance (STIGs) and vulnerabilities and ensure government client systems are safeguarded. CACI, DHS/USCG 06/2025 – 04/2026
Cyber Protection Team Analyst
• Actively review all data feeds, analytical systems, sensor platforms, and output from other tool products.
• Provide written or oral reports of findings to designated leadership for further investigation or for action.
• Participate in a variety of Information System Security (ISS) activities, including monitoring of systems status
• Escalating and reporting potential incidents; creating and updating incident cases and tickets
• Risk assessment analysis for High Assurance Gateway (HAG) access and Web Access Requests (WARs);
• Analyzing ISS reports; applying various antivirus, intrusion detection, DMA, and vulnerability assessment tools, techniques and procedures;
• Tuning the SIEM and IDS/IPS events to minimize false positives
• Maintain custom SIEM content
• Hardware and software evaluation and analysis
• Investigate and positively identify anomalous events that are detected by security devices or reported from external entities, USCG components, system administrators, and the user community, via security monitoring platform and tools, incoming phone calls, and emails.
• Provide informal investigation, review, and recommendation documentation, as necessary.
• Utilize client SIEM for enterprise monitoring and detection
• Create Security Event Notifications to document investigation findings
• Perform critical thinking and analysis to investigate cyber security alerts
• Analyze network traffic using enterprise tools (e.g. Full PCAP, Firewall, Proxy logs, IDS logs, etc)
• Collaborate with team members to analyze an alert or a threat MIRWAIS ‘WAIS’ KHAIRZAD
8920 Garden Stone Lane, Fairfax, VA 22031
****************@*****.***
2 P a g e
Secure Consulting Solutions, DHS/CISA 12/ 2022 – 03/ 2025 Red Team Tester
• Conducted onsite network penetration tests from an insider/outsider threat perspective.
• Utilized tools such as Nessus, Burp, Tenable SC, AppDetective, Bloodhound and Nmap.
• Performed tests against a wide range of areas, including web applications, appliances API/CLI’s and custom-built applications.
• Splunk – Created custom correlation searches and alerts for logs, missing patches, vulnerabilities, and outdated software
• Performed code review using Fortify
• Produced advisory reports to developers, engineers and high-level management regarding exploits, CVE vulnerabilities, and results from manual testing.
• Conducted security assessment using RMF in support of ATO.
• Continuous monitoring and vulnerability management.
• Provide technical scanning, analysis, and reporting in support of SCA support.
• Continuous monitoring and vulnerability management.
• Developed policies and procedures relate to information security. Axxum Technologies, US Courts 01/2020 – 12/2022
IT Security Engineer
• Analyze and evaluate information technology security risks and controls.
• Identify threats and vulnerabilities.
• Evaluate security administration and logical security controls over the following environments: UNIX, Windows, IOS, and VOIP.
• Database assessment (Oracle/SQL/DB2/MySQL/PostgreSQL).
• Web security assessment (Public/Private).
• Perform vulnerability testing with scanning tools such as Nessus, Tenable SC, AppDetective, Nmap, Burp, AppScan, FLUKE, and information technology security research.
• Perform general IT control review and analysis per NIST SP 800-53/ STIGs/ CIS Benchmark/ Best Practice.
• Continuous monitoring and vulnerability management.
• Provide technical scanning, analysis, and reporting in support of A&A.
• Assist Assessors with technical testing and recommendations. Axxum Technologies, TSA/DHS 03/2006 – 12/2019
IT Security Engineer
• Reported on and carry out Information Technology Vulnerability Assessments and Audits.
• Analyzed and evaluated information technology security risks and controls.
• Identified threats and vulnerabilities.
• Worked in SCIF environments and cleared contracts
• Evaluated security administration and logical security controls over the following environments: UNIX, Windows, Linux, and VOIP.
• Assessment of Database (Oracle/SQL/DB2/MySQL), and Web Security (Public/Private).
• Performed vulnerability analysis with scanning tools such as Nessus, AppDetective, Nmap, WebInsnpect, AppScan, FLUKE, EnCase, and information technology security research.
• Provided IT risk reduction recommendations.
• Assisted the forensic team with capturing images and analysis.
• Implemented risk management throughout information life cycle.
• Continuous monitoring and vulnerability management.
• Developed policies and procedures relate to information security.
• Performed general IT control reviews per NIST SP, DHS/TSA policy. MIRWAIS ‘WAIS’ KHAIRZAD
8920 Garden Stone Lane, Fairfax, VA 22031
****************@*****.***
3 P a g e
• Managed and performed security testing that follows national, federal, and organizational policy to ensure all TSA information systems (to include general support systems and major applications), both classified and unclassified.
• Complied with Department of Homeland Security (DHS) National Security Systems (NSS) Management Directives 4300B, and Department of Defense Information Technology policy and procedures regarding auditing of IT within TSA.
• Technical security testing of all TSA assets to included: web testing, database, OS, network devices, and software & hardware. ManTech, Dept. of State (DoS) 12/2003 – 03/2006
Sr. Security Analyst
• Conducted vulnerability scans and ST&E’s to determine potential weaknesses and vulnerabilities.
• Conducted vulnerability assessments for the Department of State.
• Worked with commercial computer product vendors in the design and evaluation of network and system assessment tools.
• Provided security engineering and integration services to customers.
• Conducted security training and provided security awareness.
• Performed vulnerability analysis with scanning tools such as Nessus, ISS, BTK, FLUKE, EnCase, and information technology security research.
• Evaluated policies, manuals, regulations, and other documents for relevance to information security management issues and ongoing efforts.
• Evaluated new network-monitoring tools designed for computer security.
• Identified potential network vulnerabilities and provided possible solutions for defense.
• Analyzed firewall, router, and application logs for security incidents and possible misconfiguration.
• Provided information system security training to other employees and performs oversight of all task-specific activities such as document preparation, writing, and methodologies.
• Performed Certification and Accreditation (C&A) assessments for FISMA/FISCAM, and NIST 800-53 requirements.
• Prepared security reports for delivery to the government client.
• Developed policies and procedures relate to information security. ManTech, Dept. of State (DoS) 03/2003 – 12/2003
Software Engineer
• Installed and configured networks, servers, and desktops on both the classified and unclassified side for U.S Embassy’s around the world.
• Installed and upgraded NT networks to Active Directory networks, including training of Embassy personnel in Active Directory usage and upkeep.
• Conducted quality assurance checks on Active Directory domain controllers, Exchange 2000 servers, and CableXpress and file and print servers.
• Created and worked with trusts between Active Directory domains and NT domains.
• Trained system administrators and Office managers to use and keep the systems. Imaged servers and desktops using Ghost imaging software and server.
• Set and built security templates based on DS security guidelines for servers and desktops.
• Worked with fiber optic cable, experience in running and termination of fiber cable.
• Worked with Cisco switches and routers in staging, setup, and configuration. ManTech, Dept. of State (DoS) 01/2001 – 03/2003
Sr. System/Hardware Engineer
• Installed and configured Network Intrusion Detection System (NIDS).
• Installed and configured Host Intrusion Detection System (HIDS).
• Configured routers and switches per policy requirements.
• Identified potential network vulnerabilities and provided possible solutions for defense. MIRWAIS ‘WAIS’ KHAIRZAD
8920 Garden Stone Lane, Fairfax, VA 22031
****************@*****.***
4 P a g e
• Worked with fiber optic cable, experience in running and termination of fiber cable.
• Worked with Cisco switches and routers in staging, setup, and configuration. EDUCATION:
Bachelor of Science (B.S.) Degree, Major in Computer Science, Strayer University 05/30/2003 CERTIFICATIONS:
• Security X (Formerly known as CASP+ CE) - Certified CompTIA Xpert Series (CAS-004)
• SECURITY+ CE – Certified CompTIA Security+ (SY0-601)
• PenTest+ - Certified CE – ComptTIA PenTest+ (PDTO-003)
• CNVP – Certified Network Assessment Professional (Comptia Stackable Cert)
• CWAPT – Certified Web Application Penetrating Tester
• FITSP – Certified Federal IT Security Professional Auditor (FITSI)
• CRISC – Certified in Risk and Information Systems Control Security Clearance:
• Active DoD TS SCI Continuous Evaluation (CE) clearance.
• Active TSA/DHS EoD clearance
Expertise:
• Operating System Scanners: Nessus Professional, Tenable Nessus Security Scanner, SuperScan, Titania Nipper Studio, Nmap/Zenmap, ACAS
• Web Applications scanners: Micro Focus (HP) WebInsnpect; IBM Security AppScan Enterprise, AppScan Standard Edition; Burp Suite Pro Scanner, GoBuster
• Database scanners: AppDetective Pro database audit tool, SQLmap
• Wireless scanners: Fluke OptiView Network Analyzer, NetStumbler wireless detector, Airsnort
• Code Review: Fortify
• Policy & Compliance: Risk Management Framework (RMF) lifecycle, A&A documentation packages in alignment with NIST SP 800-53 r5, NIST 800-171 R2, NIST SP 800-37 guidelines, System Security Plans (SSPs), Security Assessment Reports
(SARs), and Plan of Action & Milestones (POA&Ms), FISMA, FedRAMP, NIST Cybersecurity Framework (CSF),MITRE ATT&CK.
• Software: Splunk (SIEM), Wireshark, Netcat, Bloodhound, Sharphound
• Scripting Language: Python, PowerShell, Curl
• Virtualization: VMware, Docker, Container, Azure, AWS, ESXi, Virtual Machine Supported RMF lifecycle activities aligned with NIST SP 800-53 Rev 5 including Categorize, Select, Implement, Assess, Authorize, and Monitor phases.
• CMMC Level 1 & 2 Readiness: Built and maintained an evidence repository ensuring traceability between controls, implementation statements, and artifacts for assessment readiness, performed gap analysis against NIST SP 800-171 controls and implemented remediation across administrative, technical, and operational domains, led and supported CMMC Level 2 readiness activities aligned with NIST SP 800-171, including development of System Security Plans (SSP), Risk Traceability Matrix
(RTM), and Plan of Action & Milestones (POA&M).