Jeffrey Threat
@jeffreythreat
Senior cybersecurity & GRC professional translating NIST RMF into actionable cloud risk solutions.
What I'm looking for
Results-driven Senior Cybersecurity & GRC Professional with 10+ years of experience translating NIST Risk Management Framework (RMF) requirements into actionable business solutions. I lead security control assessments and enterprise risk authorization programs across hybrid cloud environments, grounding governance in data-driven vulnerability management and clear stakeholder narratives.
In recent roles, I’ve reduced critical findings by 35% through automated remediation workflows in Xacta GRC, accelerated POA&M timelines by 40%, and supported executive buy-in for $2M+ in security investments. I also built compliance monitoring with ACAS/Tenable—remediating 500+ vulnerabilities—and delivered standardized accreditation documentation that cut audit preparation time by 25%, while mentoring teams to improve RMF execution and productivity.
Experience
Work history, roles, and key accomplishments
Senior Security Control Assessor
Delviom, LLC
Sep 2024 - Present (1 year 9 months)
Led security control assessments and risk authorization programs for U.S. Treasury financial systems, ensuring NIST 800-53 and FISMA compliance across hybrid cloud environments. Reduced critical findings by 35% using automated Xacta GRC workflows and accelerated POA&M remediation timelines by 40%.
Served as Information Assurance Lead for DISA Advanced Acquisitions Analytics Dashboard, managing A&A lifecycle activities for DoD enterprise systems processing $50B+ in procurement data. Implemented STIG/SRG compliance monitoring with ACAS/Tenable and remediated 500+ vulnerabilities prior to production deployment.
Conducted A&A and Authority to Connect (ATC) assessments for Joint Staff Provider and Pentagon enterprise networks supporting 15,000+ users across classified and unclassified environments. Reduced critical infrastructure exposure by 60% by designing risk mitigation strategies and delivered executive risk briefings with quantified impact.
Security Control Assessor
Oasis Systems (Astrion)
Mar 2018 - Jul 2019 (1 year 4 months)
Executed security assessments for DHS Office of Inspector General and Nuclear Regulatory Commission to support critical infrastructure protection compliance. Validated controls with Xacta, generating automated compliance reports that reduced manual audit time by 50% and drove remediation within 30-day authorization windows.
Cybersecurity Analyst
ECS Federal
Mar 2015 - Mar 2018 (3 years)
Performed C&A for U.S. Navy Commander Navy Installations Command (CNIC) Public Safety Network, securing 80+ workstations across global installations. Conducted vulnerability assessments using SecurityCenter/Tenable across 1,000+ devices and created accreditation documentation (ConOps, SSPs, DRPs) while establishing SCIF physical security policies with 100% compliance.
Education
Degrees, certifications, and relevant coursework
University of Maryland Global Campus
Bachelor of Science, Cybersecurity
2013 -
Earned a Bachelor of Science in Cybersecurity from the University of Maryland Global Campus in 2013.
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Jeffrey?
You can contact Jeffrey and 90k+ other talented remote workers on Himalayas.
Message JeffreyFind your dream job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
