Microsoft
Critical Environment Technician
Supporting mission-critical data center infrastructure where procedures, documentation, operational controls, monitoring, escalation, compliance, and risk reduction are essential.
CYBERSECURITY PORTFOLIO
Applying cybersecurity experience, operational risk management, security controls, governance principles, and technical analysis to identify, assess, communicate, and reduce cyber risk.
01 / EXPERIENCE
My background spans cybersecurity operations, mission-critical infrastructure, military leadership, security documentation, vulnerability management, and structured operational environments.
Supporting mission-critical data center infrastructure where procedures, documentation, operational controls, monitoring, escalation, compliance, and risk reduction are essential.
Supported security alert triage, phishing investigations, endpoint protection, vulnerability remediation, Linux hardening, and cybersecurity documentation.
Developed experience in accountability, security, leadership, standardized procedures, documentation, mission execution, and controlled operating environments.
02 / GRC LAB
Practical portfolio projects demonstrating governance, risk assessment, control evaluation, compliance mapping, access governance, third-party risk, security posture, and remediation planning.
End-to-end cybersecurity risk assessment identifying assets, threats, vulnerabilities, existing controls, likelihood, impact, inherent risk, residual risk, and risk treatment options.
Structured risk register documenting risk owners, likelihood, impact, inherent risk, controls, residual risk, treatment decisions, and remediation status.
Current-state assessment against NIST CSF 2.0 identifying cybersecurity control gaps, evidence, maturity differences, target-state objectives, remediation priorities, and governance actions.
Vendor cybersecurity assessment evaluating business criticality, sensitive data exposure, system access, security controls, due diligence evidence, findings, residual risk, and remediation requirements.
Simulated access governance review evaluating user access, privileged accounts, role-based access, least privilege, terminated accounts, segregation of duties, access certification, and remediation.
Cybersecurity posture initiative organized around 15 security capability areas to evaluate defensive coverage, identify control gaps, prioritize risk reduction, and communicate security improvement.
03 / RISK DASHBOARD
Sample dashboard showing how cybersecurity risk information can be communicated clearly to technical and business stakeholders.
04 / FRAMEWORKS
Cybersecurity risk management and governance outcomes.
Structured lifecycle for managing information security risk.
Security and privacy controls for information systems.
Prioritized safeguards for reducing cybersecurity risk.
05 / ABOUT
I am a U.S. Army veteran and cybersecurity professional with experience spanning security operations, mission-critical infrastructure, technical documentation, vulnerability remediation, leadership, and operational risk.
My goal is to bring that operational and technical perspective into Governance, Risk, and Compliance work by helping organizations understand cybersecurity risk, evaluate controls, communicate findings, and track remediation.
This portfolio demonstrates practical GRC skills through hands-on projects rather than simply listing frameworks and terminology.
CORE GRC FOCUS
Risk Assessments
Control Evaluation
Policy & Governance
Compliance Mapping
Risk Treatment
Third-Party Risk
06 / CONTACT
Interested in discussing cybersecurity governance, risk management, compliance, information security, or security operations.