Kevin FanbergKF
Open to opportunities

Kevin Fanberg

@kevinfanberg

Certified Information Systems Security Professional with 20+ years experience.

United States

What I'm looking for

I am looking for a role that allows me to lead security initiatives, mentor teams, and drive organizational security strategies in a collaborative environment.

As a Certified Information Systems Security Professional (CISSP) with over twenty years of experience, I have dedicated my career to enhancing organizational security postures and developing future security leaders. My journey has taken me through various roles, from leading security initiatives for federal contracts to founding my own consulting firm, where I provide fractional CISO services. My passion lies in navigating complex cybersecurity challenges and ensuring compliance with industry standards.

Throughout my career, I have achieved significant milestones, such as guiding teams to secure a $57M program's migration to the cloud and receiving accolades for my leadership in security efforts on multi-million dollar contracts. I thrive in dynamic environments, working closely with C-Level executives to craft high-level security strategies that align with business goals. My proactive approach and ability to communicate effectively with both technical and non-technical stakeholders have been key to my success in fostering collaborative work relationships.

Experience

Work history, roles, and key accomplishments

SM
Current

Founder and Virtual CISO

Securing the Minute

Jun 2023 - Present (1 year 11 months)

Provided Fractional and Virtual CISO and Security Consultant guidance to Executive Staff, Cloud Architects, and Engineering Teams. Defined, implemented, and managed strategic Security Roadmaps, conducted Security Risk Assessments, and supported First to Market initiatives in various industries. Validated security postures to meet compliance requirements including NIST RMF, ISO 27001, SOC 2, PCI, H

IC
Current

Information Security Officer

ICF

Nov 2023 - Present (1 year 6 months)

Managed all activities related to designing, implementing, documenting, and maintaining the appropriate security posture for Federal Government contracts. Provided guidance to Senior Project Managers and Team Members to ensure applicable security requirements were incorporated in systems. Created and published key authorization package documentation for compliance with NIST 800-53, FIPS, FedRAMP,

SM
Current

Founder and vCISO

Securing the Minute

Jun 2023 - Present (1 year 11 months)

Provided Fractional and Virtual CISO and Security Consultant guidance to Executive Staff and Engineering Teams. Defined, implemented, and managed strategic Security Roadmaps, conducted Security Risk Assessments, and supported First to Market initiatives in various industries. Validated security postures to meet compliance requirements including NIST RMF, ISO 27001, SOC 2 Type 2, PCI, HIPAA, FedRAM

IC
Current

Information Security Officer

ICF

Nov 2023 - Present (1 year 6 months)

Managed all activities related to designing, implementing, documenting, and maintaining the appropriate security posture for DHS/FEMA, HHS/ACF, and Department of Transportation Federal Government contracts. Provided guidance to Senior Project Managers and Team Members for incorporating security requirements and attaining Authorization to Operate (ATO). Created and published key authorization packa

SS

Sr. Information Security Consultant

Security Risk Solutions

Apr 2010 - Present (15 years 1 month)

Led Client Engagements for technical and non-technical personnel, providing Vulnerability Assessments, Penetration Testing, System Security Testing and Certification and Accreditation (C&A). Provided Application Security and Software Development Consultation within the Agile Software Development process and implemented security protocols in various business sector regulations including Healthcare,

EN

Systems Security Engineer

Engility/TASC

Jun 2004 - Present (20 years 11 months)

As the Lead Project Security Manager, provided Systems Security Engineering technical consultation to Senior Management for a variety of government programs. Developed and presented to Air Force Space Command (AFSPC) Certification and Accreditation System Security Authorization Agreements (SSAA) and detailed Vulnerability Risk Analyses for DAA C&A Final Approvals. Performed in-depth functional ana

EN

Systems Security Engineer

Engility/TASC

Jun 2004 - Apr 2010 (5 years 10 months)

Provided Systems Security Engineering technical consultation to Senior Management for a variety of government programs. Developed and presented Certification and Accreditation System Security Authorization Agreements (SSAA) and detailed Vulnerability Risk Analyses for DAA Final Approvals. Performed in-depth functional analysis and hands-on security testing and network vulnerability Risk Assessment

NG

IT Security Manager and Security Architect

Northrop Grumman

Jan 2013 - Present (12 years 4 months)

Effectively Managed the IT Security Team initiatives for the creation of secure environments in alignment with corporate objectives. Managed Facility Security Team with direct reports and assisted in the build out of a new secure facility. Provided Application Security and Infrastructure development design for customized Web Applications and executed Web Application security testing, static code a

NG

IT Security Manager and Security Architect

Northrop Grumman

Jan 2013 - Aug 2013 (7 months)

Effectively managed the IT Security Team initiatives for the creation of secure environments in alignment with corporate objectives. Managed the Facility Security Team and assisted in the build out of a new secure facility. Provided Application Security and Infrastructure development design for customized Web Applications and executed various security testing methods.

NA

Sr. IT Security and Compliance Analyst

National Association of State Boards of Accountancy

Sep 2013 - Present (11 years 8 months)

Spearheaded the development and implementation of meeting PCI-DSS, SOC 2, SSAE 16, and ISO 27000 series security controls to ensure that organizational assets are properly protected. Led organization’s Incident Response policies and procedures to meet identified business goals regarding chain of custody and breach reporting standards. Managed the LogRhythm Security Information and Event Management

NA

Sr. IT Security and Compliance Analyst

National Association of State Boards of Accountancy

Sep 2013 - Apr 2014 (7 months)

Spearheaded the development and implementation of meeting PCI-DSS, SOC 2, SSAE 16, and ISO 27000 series security controls. Led organization’s Incident Response policies and procedures to meet business goals regarding chain of custody and breach reporting. Managed the LogRhythm Security Information and Event Management (SIEM) and provided Web Application Security Testing.

TI

Sr. IT Security Analyst

The General Insurance

Apr 2014 - Present (11 years 1 month)

Led the Information Security Team on improvement initiatives in an E-commerce Retail environment, governed by PCI-DSS and ISO 27000 series security requirements. Created maintenance processes for Partner Connectivity Agreements to ensure secure confidentiality for Data in Transit and Data at Rest. Developed and Published Security Awareness training, conducted regular Network and Web Application Vu

CO

Information Security Officer

Cognosante

Aug 2017 - Present (7 years 9 months)

Managed a team of Security Engineers in the development and submission of security documentation needed to obtain formal Authorization to Operate (ATO) in FedRAMP approved AWS Cloud and Microsoft Azure environments. Managed all activities related to designing, implementing, documenting, and maintaining the appropriate security posture for Veteran Affairs (VA), Federal and State Government contract

BA

Cyber Threat Intelligence Security Engineer

Bridgestone Americas

Apr 2015 - Present (10 years 1 month)

Defined, Developed and Managed a large-scale Cyber Threat Intelligence and Analysis Program to proactively protect the overall integrity of the system. Managed the Splunk Security Information and Event Management (SIEM) System for optimal performance and effective compliance and monitor reporting. Identified new threat techniques and procedures utilized by threat actors and conducted correlation a

BA

Cyber Threat Intelligence Security Engineer

Bridgestone Americas

Apr 2015 - Jun 2017 (2 years 2 months)

Defined, developed, and managed a large-scale Cyber Threat Intelligence and Analysis Program to proactively protect system integrity. Managed the Splunk Security Information and Event Management (SIEM) System for optimal performance and reporting. Identified new threat techniques and procedures and developed Weekly Threat Intelligence Reports detailing origin, attack types, and recon activity.

SS

Sr. Information Security Consultant

Security Risk Solutions

Apr 2010 - Dec 2012 (2 years 8 months)

Led client engagements for technical and non-technical personnel, providing Vulnerability Assessments, Penetration Testing, and System Security Testing. Implemented security protocols across various business sectors including Healthcare, DoD, FISMA, NIST, HIPAA, SOX, and PCI DSS. Developed and managed System Security Plans (SSP) and orchestrated enterprise-wide Business Continuity, IT Contingency,

TI

Sr. IT Security Analyst

The General Insurance

Apr 2014 - Apr 2015 (1 year)

Led the Information Security Team on improvement initiatives in an E-commerce Retail environment governed by PCI-DSS and ISO 27000 series requirements. Created maintenance processes for Partner Connectivity Agreements to ensure secure confidentiality for Data in Transit and Data at Rest. Conducted regular Network and Web Application Vulnerability Security Testing and managed the Security Informati

CO

Information Security Officer

Cognosante

Aug 2017 - Oct 2023 (6 years 2 months)

Managed a team of Security Engineers in the development and submission of security documentation needed to obtain formal Authorization to Operate (ATO). Managed activities related to designing, implementing, and maintaining the security posture for Veteran Affairs and Federal/State Government contracts. Reviewed System Architecture and Design Documentation and performed initial and ongoing Risk As

Education

Degrees, certifications, and relevant coursework

Colorado Technical University logoCU

Colorado Technical University

M.S., Computer Science

0

Focused on advanced topics in computer science with a specialization in computer systems security. Gained in-depth knowledge of securing computer systems and networks.

Colorado State University logoCU

Colorado State University

B.A., Economics

0

Studied economic principles with a focus on business and economic forecasting. Developed analytical skills applicable to various business environments.

Colorado Technical University logoCU

Colorado Technical University

Master of Science, Computer Science

0

Focused on Computer Systems Security within the Computer Science program. Gained advanced knowledge in securing computer systems and networks.

Colorado State University logoCU

Colorado State University

Bachelor of Arts, Economics

0

Concentrated on Business and Economic Forecasting as part of the Economics degree. Developed analytical skills in economic trends and business predictions.

Tech stack

Software and tools used professionally

Find your dream job

Sign up now and join over 85,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan
Kevin Fanberg - Founder and Virtual CISO - Securing the Minute | Himalayas