David Alston CISSP
Hope Mills NC
********@*******.***
Professional Summary:
• Broad knowledge of SEIM & SOC Engineering in Global and Domestic Enterprises.
• Global and Domestic Infrastructure and Network Security Vulnerability Assessments
• SEIM and GRC Implementation and Management
• Artificial Intelligence Infrastructure & Fundamentals
• Design and implement enterprise-wide security architecture (network, cloud, endpoint, identity)
• Align security controls with frameworks like NIST, ISO 27001, SOC 2, or Zero Trust.
• Z/OS, RACF, JCL, SQL and DB2 Programming experience
• OWASP, NIST, FISMA, ISO Implementations for Regulatory Compliance
• PCI, PII, FISMA, NIST, CSV/CQV Controls
• Perform security architecture reviews for new systems and applications.
• IOT Cyber Program (Devices, Networks, Gateways, Cloud Applications)
• IAM, RBAC, MFA, GMP, GLP Implementations
• Policy & Compliance Management
• Third-Party Risk Management (TPRM)
• Design and configure advanced workflows, questionnaires, calculations, notifications, and record permissions.
• Define Archer application standards, best practices, and governance models.
• Collaborate with IT teams on integrations, data feeds, and automation initiatives
• Ensure alignment of Vanta & Archer solutions with regulatory frameworks
• Support internal and external audits by providing Vanta & Archer-based artifacts and reporting Professional Experience:
AT&T Cybersecurity Level Blue October 2013 – April 2026 Enterprise Security Architect
Description:
Responsible for the Implementation of MSSP Managed Security Services for AT&T Managed Customers Services. Supporting AT&T Cyber LOBS via Implementation, Operations, and New Technical Cyber initiatives. Customer Base Supported: Environmental Protection Agency, Department of Justice, Dow Chemical, Schell Oil, Tenet Health, 3M
Responsibilities:
• Cyber Security Architecture SME for MSSP Global and Domestic Managed Services
• Enterprise Vulnerability Management, Qualys, Nessus, Vanta, Archer
• IBM Mainframe JCL, Z/OS Operations Support
• Implement Zero Trust principles and micro-segmentation
• GRC support for internal and external customer base
• Nvidia Artificial Intelligence & Infrastructure target architectures
• Responsible for SEIM Integration Data Feeds, configuration, and administration.
• IOT Device Management for Government Special Projects
• JIRAA, Agile, Waterfall, PMI, TOGAF
• identifies security gaps, develops controls, determines functional and non-functional security requirements
• Responsible for deployment of SEIM ESM, Connectors, Loggers, and Databases for Security and Audit reporting
• Hands-on experience with Nessus, Qualys, Tenable, Sentinel Risk Mitigations
• Secure AWS/Azure environments (IAM, network segmentation, encryption)
• Security Management Standards & frameworks ISO 27002, NIST CSF, SOX, HIPPA, NIST, SOC2, PCI
• Harden servers, containers, Kubernetes clusters, and endpoint AT&T Solutions May 2012– October 2013
Enterprise Security Engineer
Description:
Responsible for Info Security Posture of Custom Managed Services via SIEM ArcSight, Splunk AT&T managed services. Ensure clients business requirements and security technical engagement tasks completed on schedule. Assessed the importance of potential security risks for clients’ networks and implement operational risk mitigation controls and planning.
Responsibilities:
• Global Network Designs implemented Utilizing GRC, AGILE with Enterprise Security Target Architecture
• HIPAA, HITRUST, PCI, PII, FISMA, CWE Code Reviews Pen Testing
• Zero Trust implementations and Testing
• Collaborate with Dev teams in designing and continuously improving the Secure Software Development Lifecycle (S- SDLC)
• Security Management Standards & frameworks ISO 27002, NIST CSF, SOC2, HIPPA, NIST, PII for custom services
• Deploy manage and implement security tools EDR, IDS/IPS, DLP into SEIMS Special Training (Courses):
• Artificial Intelligence
• NVIDA Artificial Intelligence Infrastructure
• ArcSight SEIM, Splunk
• Archer GRC, Vanta
• Fortinet, Cisco, Palo Alto
• AZURE, AWS
• Zero Trust Deployments
• Project Management
• TOGAF, PMI