Bradley Josephs
Senior Manager Information Security @ Netskope
About
High-performing information security professional with 17 years of diverse experience in the public and private sector leading security and privacy programs for companies with a proven track record of integrity, diligence, and excellence. Provides expert FedRAMP knowledge and leadership to achieve and maintain FedRAMP Agency, JAB authorizations, and DoD Provisional Authorizations (PAs). Manages multiple priorities with a coordinated, organized style and proactively resolves challenges. Respected by peers, partners, and customers for simplifying complex tasks, balancing a driven approach and collaborative style, and delivering results in a dynamic environment under tight deadlines.
United States
Denver Metropolitan Area
Information Technology & Services
Security, NIST, Program Management, Leadership, Computer Security, Project Management, Risk Assessment, Disaster Recovery, Integration, Management, Information Assurance, CISSP, DoD, Programming, FISMA, Vulnerability Assessment, Networking, Information Security, Security+, System Deployment
Experience

Founder, GRC Consultant
Josephs Consulting
Littleton, Colorado, United States
• Leads client through ISO 27001/27701 certification, including management of GRC tool. • Prepares and presents reports to senior management, highlighting key security risks, compliance status, and recommended actions for continuous improvement.

Principal FedRAMP Advisor, 3PAO Assessor
Greater Denver Area
• Represents CSP in meetings with the JAB, FedRAMP (FR) PMO, and Agencies during ATO and ConMon reviews. • Leads CSP to obtain multiple ATOs: FR JAB High, FR Agency Moderate, DoD IL5, and StateRAMP (SR) • Develops Rev. 5 security authorization packages and addendums for multiple CSPs. • Builds and leads CSP FR ConMon program: POA&M, deviation requests, SCRs, and managing risk mgmt. triggers. • Performs CSP FR Rev. 4 to Rev. 5 gap analysis, prioritizes remediation, transition to FR Rev. 5 compliance. • Performs 3PAO assessments and gap analyses of FR Moderate, High, and DoD IL5 cloud service offerings (CSOs). • Specalized in performing vulnerability scan analysis across all applicable layers. • Partners with SecOps to implement CSP IR Workflow and response to CISA Emergency Directives (EDs).

Global Privacy Lead
Broomfield, CO
• Led enterprise-wise GDPR gap assessment and remediation; obtained $1M budget for compliance initiatives. • Developed and performed PIAs and DPIAs on third parties, projects and products. • Designed and implemented GDPR data breach IR process and Data Subject Access Rights (DSAR) process. • Developed and managed information security and privacy awareness training program.

Global Security and Privacy Manager
Greater Denver Area
• Performed role of action CISO and Privacy Officer for 4 months, leading the company through a CFIUS audit. • Managed all external-facing customer audits; designed and implemented 3rd party risk management program. • Onboarded Managed Security Service Provider (MSSP) and QRadar and designed enterprise IR process. • Led InfoSec program management of SOC, McAfee Web Proxy, Palo Alto Networks, and DLP.

Deputy Project Manager, ISSO
Barling Bay
Washington D.C. Metro Area
• Wrote security plan and supported construction, implementation, and deployment of a facility housing ICE mission essential functions (MEFs) and a continuity of operations site; managed costs, project plan, functional and security requirements. • Performed project management oversight of the transition of Service Desk operations and gathered functional requirements for the development of an enterprise telephone system, communicating these requirements to the vendor prior to design. • Developed, documented, and implemented continuity of operations, contingency, and disaster recovery strategy, plans, and training material • Led tabletop contingency and incident response tests and documents lessons learned.

Senior Security Analyst
Reston, VA
• Documented the security control implementation, as appropriate in SSP from various VA sites, providing a functional description of the control implementation. • Monitored Security Controls by interviewing system owners, network/system/application administrators and other key personnel and developing/updating contingency plans, configuration management plans, privacy impact assessments (PIA), incident response plans, and security configuration checklists.

Senior Information Assurance Analyst
Washington D.C. Metro Area
• Performed security assessments/audit of SBA third-party provider systems and facilities and internal systems using organizational security policy and NIST SP 800-53 Rev. 3/800-53A Rev. 1 • Wrote the SBA Enterprise Information Security Policy in accordance with NIST SP 800-53 Rev. 4. • Collaborated with SBA executive management to develop a monitoring plan for third-party providers and vendors for new and existing information systems. • Provided security oversight for SBA acquisitions by reviewing acquisition documentation, interconnection security agreements (ISAs) and memorandums of understanding/agreements (MOU/A).

Security Analyst
Barling Bay
Washington D.C. Metro Area
Security Analyst, Bureau of Indian Affairs (BIA) • Performed Security, Test and Evaluation (ST&E) of BIA information systems and facilities in accordance with NIST SP 800-53 Rev. 2 for 34 Major Applications (MAs) and 4 General Support Systems (GSS) using the NIST SP 800-53A assessment methodology. • Provided technical vulnerability analysis (TVA) of BIA information systems using Nessus and nCircle IP360 and evaluated the patch management program using MS SCCM, MBSA and Gold Disk. Research Analyst, Networx Transition Team, Department of Commerce (DoC) • Provided program management strategy for the transition of telecommunications services from the FTS2001 contract to the Networx contract. • Conducted Networx transition risk management meeting with 28 DOC Bureaus and stakeholders Information Assurance Analyst, Department of Commerce (DoC) • Performed C&A/ST&E of the CSC General Support System (GSS), ST&E in accordance with NIST SP 800-53, Rev. 2 and NIST SP-800-53A. • Provided DoC Technical Support Division (TSD) Director with recommendations for POA&M closure and for Residual Risk Acceptance and Mitigation Strategies.

Certification and Accreditation Specialist, FDA
Bethesda, MD
• Conducted C&A of the FDA Consolidated Infrastructure (CI), consisting of the following modules: UNIX, Windows, Perimeter Security Infrastructure, Extranet, VoIP, Internal Network Infrastructure, Storage Area Network (SAN), VMS, Active Directory (AD), ePolicy Orchestrator (ePO), Microsoft System Management Server (SMS) • Conducted C&A Interviews with CI module SMEs.
Bradley Josephs's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.




