
Douglas Smallwood Jr.
Chief Executive Officer / Primary IT Consultant
About
With over 20 years in information technology and extensive experience in cybersecurity, I currently serve as CEO and Primary IT Consultant. My expertise includes vulnerability management, Tenable Nessus, and XACTA, which I leverage to address system vulnerabilities and implement robust security measures. My mission is to ensure the integrity and security of critical systems through meticulous adherence to Risk Management Framework (RMF) standards. Holding certifications like CompTIA Security+ and Six Sigma Master Black Belt, I am dedicated to fostering a culture of cybersecurity excellence and compliance within organizations.
United States
College Park
Defense & Space
Streamlining Operations, Policies & Procedures, Vulnerability Management, Tenable Nessus, xacta, System Administration, Linux System Administration, Windows System Administration, Risk Management Framework (RMF), SIPRNET, ATO, IT Security Assessments, Enterprise Mission Assurance Support Service (eMASS), Risk Assessment, NIST 800-53, Recovery Plans, Vulnerability, Incident Response, Continuous Monitoring, Risk Management Framework
Experience

Chief Executive Officer / Primary IT Consultant
Strategic Thought Strategies
• Led a comprehensive 90-day cybersecurity and physical security assessment, evaluating network architecture, policies, and operational processes across the organization. • Conducted in-depth vulnerability assessments and penetration testing, identifying high-risk weaknesses and validating exploitability using industry-standard tools. • Performed detailed forensic analysis of prior security incidents, reconstructing timelines and uncovering root causes that informed remediation strategies. • Assessed IT leadership effectiveness, governance maturity, and incident response readiness, delivering actionable recommendations to strengthen organizational resilience.

Information Systems Security Manager (ISSM)
College Park, MD
Responsible for ensuring the security and maintenance of an information system in their assigned program throughout the Risk Management Framework (RMF) lifecycle, from planning through decommission, in accordance with Intelligence Community Directives (ICD) and Defense Intelligence Agency (DIA) policies. The ISSM manages and controls changes to the system or application, assesses the potential cybersecurity impact of those changes, provides technical expertise and continuous monitoring. • Thoroughly document misconfigurations, issues, and vulnerabilities from analyzed systems. • Properly uses XACTA to manage and store all relevant program information including documentation of risk assessments, security control implementations, POA&M tracking, and compliance status. • Monitor and track all POA&M items, ensuring that vulnerabilities identified in scans or audits are documented, mitigated, and closed appropriately. • Collaborate with ISSOs, SCAs, PMs, and other stakeholders by providing necessary guidance and clarifications. • Use automated tools to perform continuous monitoring activities to ensure compliance with security controls and timely reporting of incidents. • Oversee the development, implementation, and maintenance of security policies and procedures to ensure compliance with laws, regulations, and standards. • Lead risk management and compliance efforts (e.g., RMF process, security assessment and authorization). • Coordinate with various stakeholders to ensure alignment with security policies and ensure systems remain compliant. • Automate risk and compliance management using GRC tools like Xacta for streamlining tasks like ATO processes, audits, and compliance reporting. • Provide guidance on cybersecurity strategies and best practices across the organization.

Information Systems Security Specialist III
Stafford, Virginia, United States
• Provide technical guidance and complex systems integration functions for rapid technology integration of emerging COTS/GOTS hardware and software solutions, meeting DoD/NSA customer’s capability gaps and mission needs. • Spearheaded RMF implementation for Classified Systems, ensuring compliance with NIST standards and guidelines. • Analyzing SIGINT data for Classified Missions, configuring servers, exporting data for integration of management systems, and remediating vulnerabilities. • Led cross functional teams for design, development, integration, and system testing of computer hardware, operating systems, software, GPS, RF sensor and communication subsystems, including small unmanned aerial systems. • Manage project life cycle planning, assessment, schedule, resources, communication, coordination, and collaboration of projects for enterprise-wide implementation of services and capabilities. • Configuration of Tenable application using AI and machine learning for vulnerability scanning across networks & classified systems. Translating objectives into finite, measurable, and executable actions and tasks using Scrum Agile Methodology to produce a Vulnerability Priority Rating (VPR). • Completed installations of Virtual Machines/Troubleshooting data issues w/ storing and transmitting information to executive level officers. • Use and configuration of computer virtualization technology, containerization techniques, and software-defined networking (SDN). • Relational Database Management System (RDBMS) solutions design, configuration, and integration. • Windows and Linux client/server administration. • Document assessment findings, risk levels, and recommendations for improvement in detailed reports. • Perform vulnerability assessments, penetration testing, and security scans to identify weaknesses and potential threats.

Security Control Assessor Representative (SCAR)
San Antonio, Texas, United States
• Conducted rigorous security assessments, meticulously evaluating cybersecurity controls for compliance. • Authored comprehensive security assessment reports, complete with risk analysis and recommendations, in adherence to NIST SP 800-37. • Demonstrated unwavering commitment to NIST, Federal, DoD, DISA, and JSP policies, promoting a culture of cybersecurity excellence. • Instrumental in revising the Security Assessment Report (SAR) to identify and address cyber testing deficiencies, supporting informed fielding decisions. • Development of work breakdown structures, project schedules, resource plans, and risk management plans. • Perform vulnerability assessments, penetration testing, and evaluate security scans to identify weaknesses and potential threats. • Review and analyze security documentation, policies, and procedures to ensure compliance with relevant security standards and regulations. • Acted as a liaison between technical teams and security stakeholders to address security concerns and mitigate risks effectively.

Security Control Assessor - Validator (SCA-V)
San Antonio, Texas
• Led assessments of DoD Information Systems, ensuring strict compliance with RMF security controls, DoD Instructions 8500.01 and 8510.01, and NIST guidelines. • Orchestrated the development and maintenance of cybersecurity documentation, concept papers, and test plans, aligning with client policies and the Risk Management Framework. • Spearheaded Information Assurance support during system configuration, integrations, and the implementation of security mitigations and intrusion control mechanisms at Army Post. • Executed rigorous Security Technical Implementation Guide (STIG) processes, standardizing security protocols and fortifying network, server, computer, and logical designs. • Evaluated IT devices for Security Technical Implementation Guide (STIG) compliance using ACAS/Nessus, SCAP Compliance Checker, and meticulous manual checklist reviews. • Pioneered cybersecurity engineering research and analysis, providing recommendations for the implementation of advanced security mechanisms. • Assessed and validated McAfee HIPS policies and Firewall policies, ensuring robust intrusion detection and prevention. • Conducted technical assessments of security and surveillance equipment, enhancing overall situational awareness.

Cyber Security Analyst
San Antonio, Texas
• Orchestrated vulnerability scans for AWS IL2/IL4 environments within ACAS (Security Center). • Managed version control for sensitive documentation, including Information Technology (IT) artifacts, diagrams, and inventories, facilitating Authorization to Operate (ATO). • Oversaw the importation of vulnerability scans and the creation of Plans of Action and Milestones (POA&Ms) when applicable. • Maintained Ports, Protocols, and Services (PPS) worksheets, ensuring accurate registration. • Utilized Amazon Web Services (AWS) console for resource monitoring and management. • Established and managed a SharePoint platform for 500 personnel, promoting efficient collaboration and document management. • Maintained the Support Request database, efficiently managing all incoming requests and communication between contractors and customers via ServiceNow. • Assured the audit tracking, reliability, confidentiality, system integrity, and availability of IT software and systems. • Led Agile/Scrum development and management for all DevOps action items. • Developed templates for documentation standards in alignment with DoD regulations. • Deputy Program Manager in resource management, logistical planning, telecon management, and analysis of Performance Work Statements (PWS).

Cyber Security Analyst
San Antonio, Texas
• Provided crucial RMF support to Defense Health Agency, crafting and implementing security tests, evaluation scripts, and test plans. • Analyzed and interpreted technical procedures and regulatory requirements, ensuring comprehensive CM for four separate Information Systems (IS). • Produced reports, business correspondence, and procedure manuals, demonstrating proficiency in system design and administration. • Expertly planned hardware maintenance and upgrades, excelling in managing changes to network hardware, operating systems, and attached devices. • Collaborated with various analytic (ie. Artificial Intelligence) tools, managing diverse tasks related to networking and operating systems. • Advised top management on advanced cybersecurity techniques, particularly in the context of Certification and Accreditation processes for transitioning from DIACAP to RMF via eMASS.

Senior Technical Trainer/Instructional Designer
Middletown, Pennsylvania
• Lead ISD for training needs analysis, training course development and updates, and interactive multimedia training development. • CM lead for monitoring and tracking of training readiness for customers and project leaders. • Installed, managed & troubleshot Virtual Reality systems, and isolated malfunctions to specific software issues. • Drafted operation manuals and technical documentation for User Interface Applications • Training coordination and site setup, classroom and virtual training execution, formative and summative evaluations, functional area feedback, and lessons learned. • Oversaw the development of training packages, reviews, training-related documents, plans & reports, drafted technical papers, and maintained baselines. • Work closely with project teams, monitor the cost and schedule of projects, participate in project evaluations, respond to customer inquiries, and verify product technical quality. • Managed 4 Instructional Designers to design training to be conducted in classroom and field environments, in varying weather conditions, and at military installations.

Manager, Instructional Technology Unit
San Antonio, TX
• Led 12 person team for design, development, implementation & schedule of assigned technology based projects • Designed and developed programming strategies to support web and technical based training for 24K Tech Training and 31K Basic Military Training students • Engineered and developed teaching aids such as training handbooks, demonstration models, multimedia visual aids, computer tutorials, and reference works. • Formulated teaching outline and determined the proper instructional methods such as individual training, group instruction, lectures, interactive media instruction, meetings and workshops. • Provided quality oversight, evaluation, execution and documentation on all assigned flight tasks and multimedia projects • Spearheaded meetings with Subject Matter Experts (SMEs) and course development team • Displayed multiple flowcharts and created multiple storyboards from requirements documentation • Prepared course templates for development team and revised course curriculum • Developed progress checks, appraisals and end of course tests • Performed quality assurance and evaluation with integration testing • Evaluated course training standards and specialty training standards • Cost/Benefit Analysis for potential media selection and monitored training costs to ensure budget is not exceeded.

Information Assurance Manager/Cyber-security Liaison
San Antonio, TX
• Responsible for the security, integrity and compliance of Information Systems and data for approximately 3,000 people • Network administration - Created, edited and organized multiple security groups on the Air Force network, managed all authorized personnel and removed unauthorized personnel • Granted access control of network privileges and user profiles using IAO Express and Active Directory for secure network • Organized security groups on the network, managed authorized and unauthorized personnel and performed data sweeps to identify PII violations • Implemented policies and procedures for network and system security measures • Analyzed and removed all Operations and computer security vulnerabilities • Developed, refined, adjusted Standard Operating Procedures, Business Rules, and Quality Standards • Provided quality oversight, evaluation, execution and documentation on all assigned flight tasks and projects • Monitored and analyzed computer performance and audited software across 175 computer desktop platforms • Analyzed and removed all Operations and computer security vulnerabilities

Emergency Management Specialist
San Antonio, TX
• Wing Inspection Team Member responsible for base-wide inspections for over 16K personnel and facilities • Developed new plans & checklists annually for natural disaster or man-made as a result of chemical, biological, radiological or nuclear incident • Developed contingency and disaster preparedness plans to minimize casualties and damage from natural disasters, major accidents, wartime and other military operations • Trained Point of Contacts for response and recovery operations world wide • Managed the Unit Control Center for monthly readiness activities • Mandated accountability readiness exercises for 3K personnel across 5 separate units • Created and maintained accountability tracking databases as required • Coordinated actions to allow continuation or restoration of vital functions and operations • Established procedures for contamination control • Ensured NBC (nuclear, biological and chemical) protective clothing and devices are available • Conducted disaster preparedness and hazardous material emergency response training • Coordinated Active Shooter procedures for crisis/building management Keyword: FEMA

Deputy Project Manager, Aviation Resource Management System (ARMS)
Maxwell AFB, Gunter Annex AL
• Led 20 military and contractors to develop and sustain the Aviation Resource Management System; supporting 185 Wings flying operations and Air Forces $9.1B flying hour program • Managed & Controlled schedules, personnel and all life-cycle documentation for web application development projects • Tasked with Qualification, Test and Evaluation (QT&E) and Performance Testing • Regression tested Web application; validated functionality through 5K+ lines of scripts for $30M system • Created, ran and updated automated testing scripts for several levels of testing including functionality, performance, security, regression and QT&E • Developed and executed SQL and database queries to extract information • Interprets standards, specifications, and user needs as a system analyst; prioritizes deficiencies/change requests • Created automated tracking system for all discrepancies discovered in application testing • Developed matrix for outdated security patches; identified & resolved vulnerabilities • Validated capability enhancement requests & advised leadership on software release priorities to meet customer need • Responsible for software design, development, & maintenance of 186.8K lines of code for $30M Aviation Resource Management System program

Supervisor, Client Systems Lead/COMSEC Custodian
Ramstein Air Base, Germany
• Traveled extensively throughout the Europe providing network field engineering technical assistance and completing site inventories for 10 field sites • Configured rapid prototype, testing, and integration of new and upgraded equipment hardware solutions in order to evaluate all system enhancements • Identified weaknesses in fielded configurations while performing system requirement analysis and design modifications • Performed equipment installs, relocations, and maintenance of a wide array of fielded equipment including printers, scanners, external hard drives, monitors, audio equipment, VoIP phones, video teleconferencing equipment, modems, and cryptographic devices • Provided helpdesk support throughout United States and overseas solving 100% technical issues • Conducted inventory of all incoming communications security (COMSEC) equipment and docs. • Responsible for storing & destroying classified COMSEC material & equipment • Responsible for data administration using the local management system for identifying superseded material & distributing inventory reports • Responsible for information systems upgrades and new computer installation processing • Lead for all security incidents for network and computer mishaps

COMSEC Custodian Clerk
Yeongsan, South Gyeongsang, South Korea
• Conducted inventory of all incoming communications security (COMSEC) equipment and docs. • Responsible for storing & destroying classified COMSEC material & equipment. • Responsible for data administration using the local management system for identifying superseded material & distributing inventory reports. • Responsible for information systems upgrades and new computer installation processing • Lead for all security incidents for network and computer mishaps

Personnel Programs Database Administrator
Maxwell, Gunter, AL
• Responsible for database administration & installation for the unique Military Personnel database for 17 personnel in 2 directorates. • Leads the design, development, modification and execution on all personnel products requested by the Executive Director, the Commander or by other customers to facilitate the management of personnel resources. • Served as a liaison for the Maxwell AFB Personnel Systems Manager for the Personnel Concepts III (PC-III) systems for users at HQ 754 ELSG. • POC for computer installations and troubleshooting for the entire squadron and Command Support Staff. • Developed training materials on the Military Personnel (MilPers) program and interfaces associated. • Trained personnel Windows 3.1, Windows 95, Windows 2000 and all Microsoft products associated.

Computer Programmer/Web Course Developer
Wichita Falls, Texas, United States
• Supervised and performed as a computer analyst, coder, tester, and manager in the design, development, maintenance, testing, configuration management, and documentation of application software systems, client-server, and web-enabled software, and relational database systems critical to warfighting capabilities. • Determined, analyzed, and developed requirements for software systems through interpreting standards, specifications, and user needs as a system analyst obtaining and maintaining IT, system security, and programming certifications. • Determined, designed, and developed data requirements, database structure, process flow, systematic procedures, algorithms, and file structures to implement and maintain software systems using software engineering techniques. • Worked with systems using software methodologies such as distributed processing, systems networking, advanced information storage and retrieval, and management techniques. • Determined and recommended the most reasonable approach in designing new systems or modifying existing systems. Develops and maintains system specifications. • Conducted and participated in system reviews and technical interchanges. Select appropriate software development tools. • Developed standardized tools and interfaces, in accordance with Air Force Network Operations (AFNETOPS) guidance to transform raw data into actionable C2 information. • Developed and implemented policy to enable effective information discovery, indexing, storage, life-cycle management, retrieval, and sharing in a collaborative enterprise information environment.
Education

Cloud Computing
Learn core cloud computing skills like how to deploy cloud-based systems including AWS, Azure, and Google to increase the efficiency, storage, and processing power of an organization. You will also learn how to protect cloud environments and data from cyber threats.
Douglas Smallwood Jr.'s Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.





