
TCHINDA M.
Cloud & AI Security Architect
About
Cloud & AI Security Architect with 10+ years of progressive experience — from SOC operations through enterprise cloud security architecture for federal agencies.Currently architecting Zero Trust identity frameworks across 300+ AWS accounts, leading RMF authorization for 8+ federal systems, driving DevSecOps adoption, and evaluating AI/ML workloads against NIST AI RMF and MITRE ATLAS.Also a published author (20 books, 2025), adjunct cybersecurity faculty at an NSA/DHS CAE-CD institution, Ph.D. candidate researching AI system security frameworks, and founder of K2CyberTek's AI Security Architect training program.Areas of expertise:→ Cloud security architecture — AWS, Azure, Zero Trust, IAM, Terraform, policy-as-code→ AI security governance — NIST AI RMF, MITRE ATLAS, OWASP LLM Top 10→ Federal compliance — RMF, NIST 800-53, FedRAMP, FISMA, continuous monitoring→ DevSecOps — CI/CD pipeline security, IaC scanning, shift-left adoption→ Security operations — SIEM/SOAR, threat hunting, detection engineering, MITRE ATT&CKCertified: AWS Security Specialty | AWS Solutions Architect | CASP+ | CISA | CEH | Security+
United States
Silver Spring
Information Technology & Services
POA&M, ISCP, ConMon, ATO Processes, Risk Assessment, Gap Analysis, Security Architecture Reviews, Audit Readiness, SOPs, Linux (Ubuntu, CentOS, RedHat), Hardening & Security Auditing, Windows Server Security, Endpoint Protection, CrowdStrike, SentinelOne, Microsoft Defender, Power BI, ServiceNow, Jira, Confluence
Experience

Cloud & AI Security Architect
K2CyberTek
• Re-architected Zero Trust identity across 300+ AWS/Azure accounts, integrating IAM Identity Center, Azure Entra ID, Okta SAML/SCIM federation, and CyberArk PAM — eliminating 100% of standing privileged access and reducing identity-related risk exposure to near zero. • Designed hub-and-spoke cloud security architecture across 15+ AWS accounts using Organizations, SCPs, centralized GuardDuty/Security Hub, and automated Config remediation — reducing infrastructure misconfigurations by 80% before production deployment. • Built end-to-end DevSecOps pipeline security integrating Checkov, tfsec, Snyk, Trivy, and OWASP ZAP into GitHub Actions CI/CD workflows, enforcing policy-as-code guardrails at every deployment gate. • Led RMF authorization for 8+ mission-critical federal systems (FISMA High/Moderate), maintaining uninterrupted ATO status with zero authorization lapses across the full portfolio. • Architected centralized security monitoring leveraging Security Hub, GuardDuty, CloudTrail, Defender for Cloud, and Azure Sentinel — enabling real-time threat detection and continuous compliance validation. • Evaluated cloud-hosted AI/ML workloads using NIST AI RMF, MITRE ATLAS, and OWASP LLM Top 10 — contributing to the agency’s first AI system authorization package under FedRAMP and FISMA. • Engineered enterprise SSO federation integrating Okta with AWS IAM Identity Center and Azure AD via SAML/SCIM, supporting 1,000+ users across cloud and SaaS platforms. • Mentor and train junior ISSOs on RMF processes, SSP development, POA&M management, and NIST 800-53 control implementation.

Adjunct Cybersecurity Faculty
Prince George’s Community College (NSA/DHS CAE-CD)
• Manage 4–5 course sections annually (60–80+ students) in Network Security, Linux Administration, Ethical Hacking, and SOC Operations at an NSA/DHS Center of Academic Excellence in Cyber Defense. • Redesigned the SOC Operations course integrating the NICE Challenge cyber range, measurably improving student pass rates on incident response assessments. • Developed 12+ hands-on cybersecurity labs adopted by peer faculty for program-wide delivery.

Senior Cloud Security & FedRAMP Engineer
• Architected and governed cloud security posture for AWS environments under FedRAMP Moderate/High and NIST SP 800-53 — sustaining ATO status across all assigned systems with zero authorization lapses. • Validated cloud architectures, authorization boundaries, and data flows — assessing EC2, S3, VPC, IAM, and encryption controls against NIST 800-53 and the shared responsibility model. • Built CI/CD security pipelines using GitHub Actions and Jenkins with Terraform validation, IaC scanning (Checkov, tfsec), and automated compliance checks across multiple AWS accounts. • Translated CIS Benchmarks and NIST 800-53 controls into policy-as-code guardrails (Terraform, CloudFormation Guard), establishing repeatable, audit-ready security baselines enforced automatically. • Applied NIST AI RMF and MITRE ATLAS threat modeling to assess AI/ML workloads on GSA AWS environments — reviewing model access controls, training data integrity risks, and API exposure. • Managed GRC workflows tracking control inheritance, remediation status, and authorization artifacts — directly supporting federal audit preparation and continuous monitoring.

Cloud Security Engineer
• Led the buildout of enterprise cloud security and compliance programs aligned with ISO 27001, SOC 2, and FedRAMP Moderate — establishing the organization's first formalized cloud security posture across AWS environments. • Reduced exploitable risks by 50% through automated patch management using AWS Patch Manager, Nessus, and Inspector, aligning remediation workflows with FedRAMP RA and SI control requirements. • Operationalized IAM governance through RBAC, ABAC, and SSO (SAML, OIDC, SCIM), strengthening identity assurance and access control consistency across multi-cloud platforms. • Delivered compliance automation workshops and proof-of-concepts demonstrating secure deployment practices and automated evidence generation using Terraform, Ansible, and AWS Config Rules.

Senior Cyber Defense Analyst (SOC Tier III)
• Led Tier III advanced incident analysis and response across cloud, hybrid, and on-premise enterprise systems, coordinating containment and recovery for high-impact security events. • Built and optimized SIEM-based monitoring using Splunk, CloudTrail, and GuardDuty — engineering detection rules and correlation logic to reduce alert noise and accelerate mean-time-to-detect. • Conducted proactive threat hunting using MITRE ATT&CK techniques, identifying stealthy adversarial behaviors and previously undetected indicators of compromise across the enterprise.

Network Security Engineer & SOC Analyst
• Monitored and triaged security alerts across enterprise networks, supporting incident escalation with log analysis, packet captures, and initial forensic review. • Configured and maintained network infrastructure including firewalls, switches, routers, and VPN connections while enforcing security baselines and hardening standards. • Supported vulnerability scanning and remediation workflows, collaborating with infrastructure teams to prioritize patching and reduce exposure across production systems.

Operations & Workforce Manager
• Managed hiring, onboarding, training, coaching, and performance evaluations for a multi-department retail operation. Built team capability through structured development programs, reduced turnover through targeted coaching, and drove process improvements across workforce operations. • Completed a Linux Administration bootcamp and earned CompTIA Security+ while working full-time — executing a deliberate career pivot into cybersecurity.
TCHINDA M.'s Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.


