Active TS/SCI  ·  Available 2027

Naval Academy Cyber graduate transitioning into security engineering.

TS/SCI-cleared Navy Lieutenant with direct operational DoD cybersecurity experience — STIG, ACAS, POA&M, RMF, and ATO — now building hands-on detection engineering capability ahead of a full-time civilian transition.

Focus areas Security Control Assessment · Configuration Governance · STIG/ACAS · RMF/ATO
Availability Full-time civilian cybersecurity roles beginning early 2027.
Proof of work Shipboard cyber program execution and GitHub-documented detection engineering lab.
Core strengths Technical decision-making · inspection readiness · accountable follow-through.
14-person IT leadership Directed a cybersecurity and enterprise-support team serving mission-critical users in operational environments.
Cyber Operations degree B.S. with Honors Program and Merit from the U.S. Naval Academy.
Shipboard cyber operations Executed STIG, ACAS, POA&M, RMF, and ATO sustainment work supporting mission-critical DoD systems.
Documented lab portfolio Engineered and validated a detection engineering lab with adversary emulation and telemetry-driven analysis.

About

My cybersecurity background combines operational DoD system security responsibility, formal cyber education, and documented detection engineering work.

Who I am

I am a TS/SCI-cleared U.S. Navy Lieutenant and Cyber Operations graduate with direct operational cybersecurity experience across mission-critical DoD systems.

What I’ve worked on

I’ve led STIG compliance, ACAS vulnerability remediation, POA&M management, ATO sustainment support, inspection readiness, and CANES enterprise infrastructure execution while also building hands-on detection engineering capability in a self-directed Active Directory lab.

How I approach the work

I prioritize technical rigor, configuration discipline, clear documentation, and calm execution under pressure. That approach has been central to both operational cyber responsibilities and high-reliability engineering watchstanding.

Experience

Across these roles, the common thread has been cybersecurity execution, technical leadership, and dependable performance in mission-critical operational environments.

Cyber Officer / Automated Data Processing Officer — USS Harpers Ferry (LSD-49) Oct 2021–Apr 2023

Command-designated cybersecurity representative responsible for enterprise cybersecurity readiness and remediation execution.

  • Oversaw STIG compliance across Windows and Linux workstations, Windows servers, virtualized systems, network devices, applications, and standalone systems; reviewed CAT I/II/III findings and manually validated controls through STIG checklists, Group Policy, registry settings, services, and implementation evidence.
  • Managed ACAS vulnerability remediation by prioritizing critical and high findings, reviewing affected hosts, CVEs, and recommended patches, directing corrective action, and verifying closure through scan and rescan results.
  • Created and maintained POA&Ms documenting severity, affected systems, remediation plans, completion dates, and status while driving stalled findings toward closure.
  • Managed STIG exceptions by documenting operational constraints and risk acceptance for Commanding Officer concurrence, coordinating exceptions with TYCOM N6, and tracking temporary deficiencies through POA&Ms.
  • Co-led quarterly Configuration Change Boards for the CO, XO, and CSO, briefing proposed cyber configuration changes, system impacts, constraints, and recommendations.
  • Reviewed ATO authorization artifacts and routed documentation to TYCOM N6; supported recurring authorization renewals and package maintenance.
  • Prepared for and facilitated Basic Phase Cyber Certification, continuing certification events, INSURV cyber assessments, COMSEC inspections, and a Fleet Cyber evaluation while directing corrective actions through closure.
  • Directed a 14-person IT team supporting cybersecurity readiness and enterprise services in operational environments; served as Top Secret Control Officer.
  • Supported CANES Version 3 infrastructure across NIPRNet and SIPRNet environments, Active Directory, network devices, firewalls, TACLANE, and SATCOM systems.
  • Recovered enterprise services following CANES backbone failures by restoring VMware snapshots, rebuilding virtual machines, coordinating external maintenance support, and validating restored functionality.
  • Developed a ship-wide bandwidth management strategy balancing mission requirements, command priorities, and constrained satellite communications capacity.
  • Supported a command cyber program that passed all inspections, performed above average during INSURV cyber assessment, received positive COMNAVSURFPAC N6 feedback, and became the first ship to pass a limited Fleet Cyber evaluation.
Assistant Reactor Electrical Assistant — USS Carl Vinson (CVN-70) 2026–Present

Support reactor electrical maintenance planning, engineering readiness, technical review, and department-level coordination for A4W nuclear propulsion electrical systems.

  • Review maintenance work packages, tag-outs, testing requirements, equipment status, and corrective actions before execution in a high-reliability environment.
  • Coordinate ship’s-force and contractor maintenance priorities during Planned Incremental Availability while tracking equipment readiness and emergent work.
  • Brief senior engineering leadership on system status, maintenance risk, troubleshooting progress, and corrective-action execution.
Reactor Electrical Division Officer — USS Carl Vinson (CVN-70) 2024–2026

Led a 20-person technical division responsible for nuclear propulsion electrical systems.

  • Managed fault isolation, redundancy, and casualty response in time-critical conditions.
  • Improved qualification rates and system reliability through structured training programs.
  • Led cross-functional execution where safety, precision, and accountability were non-negotiable.
  • Built team habits around technical rigor, procedural compliance, and calm troubleshooting.
A4W Propulsion Plant Watch Officer (PPWO Qualification) — USS Carl Vinson (CVN-70) Aug 2024–Present

Concurrent qualification held while serving in other Carl Vinson engineering roles, with delegated authority for safe propulsion plant operation.

  • Supervise engineering watch teams, direct reactor and propulsion plant evolutions, evaluate plant conditions, and coordinate casualty response.
  • Integrate operational requirements, maintenance status, procedural compliance, and engineering risk to make time-sensitive watchstanding decisions.
  • Served as one of eight ORSE-qualified Propulsion Plant Watch Officers during deployment in support of Operation Rough Rider.
Cyber Analyst Intern — General Electric Aviation Earlier experience

Supported threat identification and email analysis in a real-world enterprise setting.

  • Performed IOC research to support identification of malicious activity and emerging threats.
  • Reviewed emails for phishing, malware, or compromise and escalated confirmed issues.
  • Gained exposure to incident response, digital forensics, malware analysis, and secure development workflows in an enterprise environment.
Software Engineering Intern — Johns Hopkins University Applied Physics Laboratory (JHUAPL) Earlier experience

Supported software and technical research work for critical-infrastructure and national-security analysis.

  • Developed JavaScript functionality and integrated the Google Maps API for software supporting critical-infrastructure and national-security analysis.
  • Created Python automation to support technical research and data-processing workflows.
  • Produced technical documentation and collaborated in a mission-focused engineering research environment.

Projects

These projects come from documented lab work, with a focus on detection engineering, telemetry analysis, and adversary emulation.

Detection Engineering Lab

Built a VMware-based Active Directory lab with centralized Sysmon telemetry and Wazuh alerting. Authored and validated custom detections for controlled adversary behaviors including PowerShell abuse, scheduled-task persistence, and SMB lateral movement.

  • Instrumented Windows domain endpoints with Sysmon and forwarded telemetry into Wazuh.
  • Authored custom Wazuh rules mapped to MITRE ATT&CK techniques.
  • Validated detection logic against controlled adversary activity using Atomic Red Team and manual technique execution.
  • Documented detection logic, alert evidence, tuning notes, and investigation workflows.
  • Analyzed process trees, parent-child relationships, command lines, process identifiers, and Sysmon events to distinguish adversary behavior, telemetry, and detection logic.
  • Diagnosed DNS, VM networking, domain-join, service, and agent-enrollment failures to restore end-to-end detection-pipeline functionality.
Tools usedVMware, Active Directory, Sysmon, Wazuh, Atomic Red Team, Windows Event Logs
Skills demonstratedDetection engineering, telemetry pipeline design, MITRE ATT&CK mapping, rule tuning, adversary emulation
View this project in my GitHub portfolio

Project visuals

These visuals give a clearer view of the lab environment, telemetry flow, and the type of evidence behind the portfolio work.

Diagram of the enterprise cybersecurity home lab environment
Home lab architecture

A VMware-based enterprise-style lab with Active Directory, Windows endpoints, Wazuh, and Sysmon instrumentation.

Diagram of the detection engineering telemetry and alert pipeline
Detection pipeline

Sysmon telemetry flows into Wazuh and custom rules are validated against controlled adversary activity using Atomic Red Team.

Technical skills

Core capabilities across cyber systems engineering, DoD cyber processes, hardening, infrastructure, and detection tooling.

Cyber Systems Engineering

Security Baselines, Security Control Assessment, Security Architecture Support, Technical Analysis, Configuration Governance, Root Cause Analysis

DoD Cyber / RMF

NIST/RMF-Aligned Processes, ATO Sustainment, POA&M Management, Risk Acceptance Documentation, Inspection Readiness, Continuous Monitoring

Assessment / Hardening

ACAS, STIG Checklists, CAT I/II/III Findings, HBSS Oversight, Vulnerability Remediation, Remediation Validation

Systems / Infrastructure

Windows, Linux, Active Directory, VMware, Virtualized Systems, CANES, Network Devices, Applications, Standalone Systems

Security Tools / Code

Wazuh, Atomic Red Team, MITRE ATT&CK, Wireshark, Nmap, Burp Suite, Metasploit, Git, Python, C, C++, Java, JavaScript

Current direction

I’m targeting Cyber Systems Engineer and cyber defense roles where I can apply operational DoD cybersecurity experience alongside detection engineering and defensive telemetry analysis.

Proof of work

Public projects, technical writing, and supporting materials make it easier to see how I think and what I’ve built so far.

GitHub portfolio

GitHub-documented detection engineering, technical analysis, and defensive validation work.

View GitHub profile

Resume and credentials

A concise overview of my background, technical direction, and current qualifications.

Open resume PDF

Credentials, education, and availability

A straightforward overview of education, certifications, and where I’m headed next.

Education

United States Naval Academy

  • B.S., Cyber Operations — Honors Program
  • Graduated with Merit, 2021
  • NSA CAE-CO designated program

Credentials

  • Active TS/SCI
  • CompTIA Security+
  • CompTIA PenTest+ — In Progress
  • CompTIA CySA+ — In Progress

Looking ahead

Available for full-time civilian cybersecurity roles beginning early 2027.

Cyber Systems Engineer Cyber Defense Analyst Detection Engineer Security Engineer

Let’s connect.

I'm always glad to connect with people working in cybersecurity, particularly in security engineering, cyber defense, detection engineering, and adversary emulation.