
Miguel Antonio Rey
Information System Security Manager (ISSM) @ Raytheon
About
TRENDING TECHNOLOGY • AWS AI Practitioner Certified • MIT x PRO – Quantum Computing Program - o Quantum Computing Fundamentals: • Introduction to Quantum Computing • Quantum Algorithms for Cybersecurity, Chemistry, and Optimization o Quantum Computing Realities: • Practical Realities of Quantum Computation and Quantum Communication • Requirements for Large-Scale Universal Quantum Computation Accomplished and dynamic Lead Engineer, PMP Certified Project Manager / Business Analyst with 10+ years of progressive Information Technology experience utilizing various PM methodologies such as Traditional - Waterfall, Agile Software Development, including SCRUM, Feature Driven Development (FDD), DSDM (Dynamic Systems Development Method), Adaptive Software Development, eXtreme Project Management, and RUP (Rational Unified Process). Specialties: Knowledge of Rapid Application development methods to Systems Development Life Cycle (SDLC) including Spiral Development, Rapid Application Development (RAD), Joint Application Development (JAD), Requirements and Modeling, Conceptual Data Models, and Object – Oriented Analysis, UML,SQL, HTML, .jsp, CSS, UNIX/LINUX, JAVA 7 SE, JAVA EE BASED APPLICATIONS, ORACLE (11G,Discoverer, Hyperion), TOAD, ORACLE SQL DEVELOPER, SQL SERVER, PYTHON, JAVASCRIPT, jquery, PHP, WebServices, SOAP, XML, RestFul, WSDL, BPEL, Eclipse, Maven, Spring, Hibernate Cyber security - CEH, CSSLP - Nmap, Metasploit, Nessus, WebInspect, Maltego, AppDetective, Wireshark, Snort, Burp Suite Pro, Aircrack–ng) amongst others SCADA ICS Segmentation Crypto Services Database/Application Encryption, Tokenization
United States
Washington
Information Technology & Services
Quantum Computing, AWS AI Practitioner, Service Delivery, Customer Satisfaction, Presentations, Infrastructure Management, Key Performance Indicators, Deductive Reasoning, Active DoD Top Secret/SCI Clearance, PMP, Cybersecurity, Web Services, Software Development, SDLC, Agile Methodologies, Program Management, Identity & Access Management (IAM), Network Security, Oracle, SQL
Experience

Information System Security Manager (ISSM)
• Ensured alignment and implementation with Enterprise Risk Management (ERM) framework NIST RMF. • Developed and tested business continuity plans (BCPs) and disaster recovery plans (DRPs), reducing downtime during disruptions. • Conducted risk control self-assessments (RCSAs) to ensure compliance with internal policies and regulatory standards. • Conducted tabletop exercises and simulations to assess crisis response effectiveness, ensuring organizational preparedness. • Guide decision making and domain knowledge that may have a critical impact on overall project implementation. • Leverage endpoint protection tools (McAfee, CrowdStrike, CarbonBlack) to develop SOAR integration across environment. • Streamlined control testing processes, reducing compliance gaps and improving audit readiness. • Assisting the efforts of security staff to design, develop, engineer, and implement solutions to security requirements. • Reviewed vulnerability scanning & analysis (Tenable), Compliance deviation / Configuration Management (STIGS) • Reviewed & Approved Policy & Procedures while managing Contingency, Incident Response & Configurating Management Plans • Performing risk analyses which also includes risk assessment. • Utilize SIEM type tool (Splunk & Elk) to identify network anomalous behavior • Evaluating performance results and recommending major changes affecting short-term project growth and success. • Followed governance structures for risk oversight, creating regular reporting mechanisms for executive and board-level stakeholders • DHS CISA Incident Response certification

Information Systems Security Officer (ISSO)
@Department of Homeland Security (DHS) - Cybersecurity & Infrastructure Security Agency (CISA)
• Conducts risk analyses from vulnerability, compliance scans, pen testing results, or other audit activity. • Writes including but not limited to Plan of Action and Milestones, System Security Plans, Security Control Traceability Matrices, Configuration Management Plans, Contingency Plans and Test Results, Business Impact Analyses, and Security Impact Analyses. • Manage all aspects of an organization's information security system, including researching, testing, training and implementing programs designed to safeguard sensitive information from any possible breaches. • Oversees Incident Response Planning, Continuous Monitoring and vulnerability assessment on critical systems. • Performs trade studies for tools and participates in Agile Planning Events to provide technical input. • Perform vulnerability scanning & analysis (Tenable), Compliance deviation / Configuration Management (STIGS) • Leverage endpoint protection tools (McAfee, CrowdStrike, CarbonBlack) to develop SOAR integration across environment. • Utilize SIEM type tool (Splunk & Elk) to identify network anomalous behavior • Managed POAMs and key system artifacts, SSP, IR, etc. • Developed and tested business continuity plans (BCPs) and disaster recovery plans (DRPs), reducing downtime during disruptions. • Conducted tabletop exercises and simulations to assess crisis response effectiveness, ensuring organizational preparedness.

Chief Information Security Officer (CISO) - Acting
Dallas, Texas, United States
• Develop, implement, and monitor strategic, comprehensive, enterprise information security and IT risk management programs. • Define, build, and lead an Information Security organization in support of team mission and defined information security programs • Develop, maintain and publish up-to-date information security policies, standards and guidelines. • Lead all privacy and security governance efforts to ensure alignment with legal and regulatory requirements. • Led, managed and maintained security controls toward conformance with applicable standards including NIST, ISO, PCI, ISEA (SOC Type I & II) • Work directly with the functional business units to facilitate IT risk assessment and risk management processes, and work. • Facilitate a metrics and reporting framework to measure the efficiency and effectiveness of the program, facilitate appropriate resource allocation, increase the maturity of the security, while meeting the needs and expectations of applicable internal and external stakeholders • Provide regular reporting on the status of the information security program to senior management and business unit leaders. • Conduct security and privacy risk assessments to identify areas of unexpected risk to business and technology operations. • Establish and administer applicable processes for receiving, documenting, investigating, and responding to complaints and/or allegations of violations of privacy policies and procedures. • Create, communicate, and implement a risk-based process for vendor risk management, including the assessment and treatment for risks that may result from partners • Spearheaded the creation of a compliance risk register, improving visibility of potential privacy and regulatory risks. • Built key risk indicators (KRIs) and dashboards to monitor real-time risk exposures, improving decision-making efficiency. • Provide strategic risk guidance for IT projects, including the evaluation and recommendation of technical controls.

Information System Security Officer (ISSO) - FedRAMP
Sterling, Virginia, United States
• Provides daily information security guidance to federal and other programs, teams, enclaves, and systems. • Collaborated in Privacy related Compliance engagement with financial company (CCPA and State of Ohio regulations) • Provides daily program oversight and guidance for specific information security programs as assigned. • Provides daily program oversight for education and enforcing all applicable federal and state information security laws (FISMA, HIPAA, etc.), regulations (FedRAMP, DOD 8500.01, NYDFS CRR500, etc.), policies (OMB, DHS Directives, etc.), and standards (FIPS, NIST 800, CJIS, IRS, CMS ARS, etc.). • Maintain an operational security posture for regulated information systems or programs to ensure compliant information systems security policies, standards, and procedures are established and followed. • Assist the corporate and project management teams in understanding statutory and regulatory security aspects of the project and perform day-to-day security management of the project. • Perform regular vulnerability assessments and analysis to support federal assessment and authorization. • Provide IT configuration management guidance during the secure system design life cycle (SDLC) and change management guidance for all federal network, information system software, hardware, and firmware. • Review, approve, and manage changes to federal networks, systems, plus assess and document the security impact of those changes in a security impact assessment (SIA) document. • Enforce all annual statutory and regulatory security training and testing requirements. • Prepare and review compliant documentation to include but not limited to: Systems Security Plans (SSPs), Risk Assessment Reports, Assessment and Authorization (A&A) packages, System Requirements Traceability Matrices (SRTMs) and Readiness Assessment Reports; and • Support federal security authorization activities in compliance with FISMA, FedRAMP, CMS ARS, CMMC, etc.

Sr IT Security Architect @ Department of State
Moss Cape LLC
Rosslyn, VA
• Develop enterprise level plans to meet and validate FISMA compliance standards • Conduct research and coordination with subject matter experts as needed to resolve complex security issues • Responsible for the development of validation protocols for all aspects of IT compliance acting as the internal auditing function for FISMA compliance • Coordination with the technical writer to produce high quality, professional, and necessary documentation of the A&A process • Available to provide presentations and briefings as required • Work with system engineer to deploy tools required for vulnerability scanning and assessment, and to track progress as required • Assist in the development and maintenance of the security program that identifies architecture, requirements, objectives and policies, personnel and processes and procedures as they relate to NIST standards • Ensure appropriate analysis, periodic testing, evaluation, verification, accreditation, and review of information system installations is scheduled and conducted, including that development, review, endorsement, and maintenance of security compliance documentation is accomplished • Coordinate with organization to ensure that documentation is complete and includes the System Security Plan(s) (SSP) for all applications, networks, and stand-alone systems • Develop, coordinate, and conduct security and compliance training as required • Comprehensive technical and management reports on trends, issues, and potential problem areas in configuration management, architecture, and network security standards on existing or proposed interfaces with other computerized systems • Managing IT projects for system assessment and authorization (A&A) (NIST SP 800.53 & 800.37 RMF) • Documenting security compliance related correspondence required by governing authorities and documenting instructions, guidance, and procedures to specified audiences

Program Management Lead, Vice President - Institutional Clients Group (ICG) Information Security
Tampa, Florida, United States
• Continual identification of high-risk apps that require MFA protection; collaboration with the business, TISO and Development Manager in understanding MFA scope for the applications as well as appropriate MFA solution; driving the implementation of MFA controls; and ongoing monitoring of application risks in light of business, technology and threat landscape changes. • Evaluate the security threats that may affect Citi’s applications and ensure that the program evolves to incorporate processes and tools for Developers to provide tools and skills to alleviate those threats. • Facilitate departmental compliance with all Information Security policies, standards and regulations as part of the MFA and S-SDLC programs (Sarbanes Oxley, OCC, FFIEC, NIST, PCI, FRB, Cross-border Data Privacy, GLBA, etc.) • Drive execution of IS directives as mandated by Global IS Organization. Liaise with Business Information Security Officers (BISO) and application development community to assist in identifying and reducing IS risk within applications through driving the IS program compliance. • Act as a subject matter expert on all aspects of the MFA and S-SDLC programs. Proactively identify control deficiencies through assessments of in-scope applications against Information Security policies. • Facilitate the identification of Key Performance Indicators (KPIs) for MFA and S-SDLC programs and provide executive-level status updates on progress toward achieving those objectives. • Identify and record non-compliant issues (through self-testing, general analysis, control initiatives, etc.) as relates to MFA and S-SDLC programs. • Identify opportunities for process improvements and drive the execution across ICG and possibly at global level. • Responsible for understanding and implementing new initiatives driven by heightened regulatory guidance or internal policies.

Cyber Systems Test & Integration Engineer, Lead
McLean, VA
• Analyze, design, develop, and maintain test documentation for an integrated Cyber defense tool solution and conduct manual functional testing, regression testing, and systems integration testing. • Support user acceptance testing (UAT) and report issues and deficiencies found during the systems development and test life cycles. • Work with requirements, engineering, and development teams in conducting requirements analysis and mapping and developing the test methodology for verification of approved requirements. • Participate in testing, deploying, and administering the infrastructure hardware and software which are required to effectively manage the organization’s Cybersecurity operational services. • Works with enterprise Cyber defense tools, including Splunk, RSA Archer, BigFix, Tenable Security Center, CyberArk, and ForeScout, SailPoint (Identity and Access Management) • Capture through the configuration of Forensic Analysis function (packet capture), detect the attack generated at the same time evidence collection. • Knowledge of federal information security policies, standards, procedures, directives, frameworks, security authorizations, assessment, and risk management processes for enterprise systems DHS CDM • Create test documentation, including test plans, test procedures, use case scenarios, requirements traceability matrices (RTM), and test reports. • Support continuous improvement of the current test and quality assurance (QA) process. • Deployed SailPoint IIQ Connectors for various target systems along with Hands-on with aggregation, workflows, tasks, rules and roles. • CyberArk integration with SailPoint, ForeScout and Splunk. • Familiarity with CyberArk PVWA in V10 Interface as it relates to Vault and Encryption • Demonstrated Cisco ISE Network Admission Control (NAC) authenticate for wired, wireless, and VPN users and devices to the network. Performed MAB authentication.

Cyber Risk Data Protection / Encryption / DLP Manager
McLean, Virginia
• Advise clients in designing, deploying and managing technology and process solutions to reduce the potential of data compromise • Advise clients with developing technical requirements, evaluating vendor solutions, developing architecture & design, and testing of data protection and data security solutions • Advise clients in understanding the future state problems and challenges in cyber security and work collaboratively with them to enhance capabilities • Operate as a technical subject matter specialist on industry trends around cyber risk and data protection practices • Ability to translate business, risk and regulatory requirements into data protection solutions, and to effectively communicate those solutions to business leaders and executives. • Experience in designing and implementing technology and process solutions to reduce the potential risk of data compromise • Understanding of the entire ecosystem of data protection architecture and implementation: Encryption, tokenization, masking and redaction, Data Loss Prevention (DLP), Public Key Infrastructure (PKI) and Threat Intelligence • Insider Threat – User Entity Behavior Analytics (UEBA) • Ensured privacy solution to investigate all the traffic data necessary is available for forensic purposes. • Privacy – GDPR, CCPA, Data Governance • Site Reliability Engineering (AppDynamics, Dynatrace, Data Lake, Monitoring, Process Improvement) - ECS, Sysdig Prometheus • Conducted SRE Instrumentation Analysis and calibration with respect to existing tools • Conducted code review sessions to determine best entry point in code to place agents • Perform review of cloud architecture with existing business process to determine critical applications

Security Logging & Monitoring Lead
Dallas/Fort Worth Area
o Logging, Monitoring & Alerting - Developed dashboards and monitoring mechanisms to generate alerts utilizing ElkStack (LogStash, Elasticsearch, Kibana). Conducted extensive monitoring requirements related to performance, authentication, availability, and authorization. Identification of DDoS, Malware and Server/Client attacks. Risk Management Framework (SP – 800.37). Kafka, Storm, AQUA, Twistlock o Firewalls, Malware Analysis, Mitigation Strategies, DDoS Detection (various layers)

Security Assessments
Dallas/Fort Worth Area
o Security Assessment – Conducted review of all product workstreams based on a microservices (AWS, Azure) Kubernetes, NGINX, VNet Peering) architecture (APIs) to attest the appropriate level of security features. Conducted vulnerability assessment based on network, platform, data, application, identity management, mobile, and monitoring security.

Data Protection Lead
Greater New York City Area
o Crypto Services – examined cyber organization and identified cryptographic services needed to protect data (At-Rest, In-Transit, and In-Use). Provide tactical and strategic recommendation to sustain continued evolution of Quantum computing. o Cisco Catalyst 9000 architecture review as potential Post-Quantum solution

Technical Team Lead
Arlington, VA
• Ensures successful project completion by developing and planning projects/tasks, and adhering to scheduling, budgetary, quality control, risk management, and contractual obligations. • Builds internal and external networks that reflect diversity in thought, background, and experience. Promotes an inclusive, trusting team environment by sharing best practices, helping the team build consensus on decisions, and debriefing lessons learned. • Applies trends, developments, and innovations in the role/field/industry to client engagements and new or current service offerings. Shares knowledge and coaches to enhance the technical capability of the team or Functional Community and builds an external professional network • Demonstrates specialized expertise with a proven track record of developing and implementing technical solutions for complex client problems • Demonstrates, shares, and encourages others to develop an in-depth knowledge of technical or analytical methodologies and solutions and related disciplines; provides technical mentorship and is sought for their expertise • Risk Management Framework (SP – 800.37), Accreditation • Guide to Industrial Control Systems (ICS) Security (SP – 800.82), • Assessing Security and Privacy Controls in Federal Information Systems and Organizations (SP - 800.53) • National Checklist Program for IT Products – Guidelines for Checklist Users and Developers (SP – 800.70) • Network Analysis, Anomaly detection, IPS, IDS, Anomaly Response, OSI Model • Network Topology (Design), IDS, IPS, Data Modeling, Process Modeling • Organization Design and Security Plans (CSSM, CISSO, CISO, etc.) • Network Monitoring & Inventory Performance, Vulnerability Assessment • Materiel Course of Action Selection for Increment 1 (Network) & Increment 2 (Data – COTS, GOTS, Hybrid) • Architecture selection (DISA, milCloud, Gov AWS, AFNET, Enclaves, Stand Alone, etc.) • FIPS -Federal Information Processing Standards

Senior Program Analyst
SENTEL Corporation @Federal Aviation Administration (FAA)
Washington D.C. Metro Area
• Formulates/defines system scope and objectives for assigned projects. • Devises or modifies procedures to solve complex problems considering computer equipment capacity and limitations, operating time and form of desired results. • Prepares detailed specifications from which programs will be written. • Responsible for program design, coding, testing, debugging and documentation. Has full technical knowledge of all phases of applications systems analysis and programming. • Interface directly with FAA customers and has good understanding of the business or function for which application(s) is designed to include SMS/QMS, Hazard identification and tracking, Safety Risk Management, and Safety Assurance. • Instructs, directs, and checks the work of other systems analysis and programming personnel. • Responsible for quality assurance reviews to include Safety Management Tracking System project completion and user satisfaction. • Other duties that may be assigned to meet company and departmental goals and objectives

Analyst 1, Technologies Lead
Tempe, AZ
• Establish and maintain working relationships with internal business customer departments, internal IT support groups and vendors to achieve project goals using available resources • Developed and Maintained project artifacts while supervising an efficient communication plan to support timely deliverables. Responsible for completing compliance and supporting documentation required for business process. • Provide project coordination of medium projects and/or develop requirements documents, testing scripts, and act as a liaison with the business and other internal IT groups. • Delivered technology solutions for the business within established and approved schedule, scope and resources. • Worked closely with Database Administrators to successfully roll out deployment packages and new software releases. • Designed and Configure complex Reliability, Safety, and Quality Assurance applications. • Utilized SQL, PL SQL, HTML, Java script, Python, MS SQL08, Oracle, UNIX, manage, maintain and develop stored procedures. • Gathered requirements for .NET and complex SSIS packages. • Supported various Web Services which generate reports for multiple groups. Manage Apache Tomcat servers which support enterprise wide applications. Implement Java WAR files for the support of upgrades and deployments
Education
Miguel Antonio Rey's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.








