Kevin Fanberg
@kevinfanberg
Certified Information Systems Security Professional with 20+ years experience.
What I'm looking for
As a Certified Information Systems Security Professional (CISSP) with over twenty years of experience, I have dedicated my career to enhancing organizational security postures and developing future security leaders. My journey has taken me through various roles, from leading security initiatives for federal contracts to founding my own consulting firm, where I provide fractional CISO services. My passion lies in navigating complex cybersecurity challenges and ensuring compliance with industry standards.
Throughout my career, I have achieved significant milestones, such as guiding teams to secure a $57M program's migration to the cloud and receiving accolades for my leadership in security efforts on multi-million dollar contracts. I thrive in dynamic environments, working closely with C-Level executives to craft high-level security strategies that align with business goals. My proactive approach and ability to communicate effectively with both technical and non-technical stakeholders have been key to my success in fostering collaborative work relationships.
Experience
Work history, roles, and key accomplishments
Founder and Virtual CISO
Securing the Minute
Jun 2023 - Present (1 year 11 months)
Provided Fractional and Virtual CISO and Security Consultant guidance to Executive Staff, Cloud Architects, and Engineering Teams. Defined, implemented, and managed strategic Security Roadmaps, conducted Security Risk Assessments, and supported First to Market initiatives in various industries. Validated security postures to meet compliance requirements including NIST RMF, ISO 27001, SOC 2, PCI, H
Information Security Officer
ICF
Nov 2023 - Present (1 year 6 months)
Managed all activities related to designing, implementing, documenting, and maintaining the appropriate security posture for Federal Government contracts. Provided guidance to Senior Project Managers and Team Members to ensure applicable security requirements were incorporated in systems. Created and published key authorization package documentation for compliance with NIST 800-53, FIPS, FedRAMP,
Founder and vCISO
Securing the Minute
Jun 2023 - Present (1 year 11 months)
Provided Fractional and Virtual CISO and Security Consultant guidance to Executive Staff and Engineering Teams. Defined, implemented, and managed strategic Security Roadmaps, conducted Security Risk Assessments, and supported First to Market initiatives in various industries. Validated security postures to meet compliance requirements including NIST RMF, ISO 27001, SOC 2 Type 2, PCI, HIPAA, FedRAM
Information Security Officer
ICF
Nov 2023 - Present (1 year 6 months)
Managed all activities related to designing, implementing, documenting, and maintaining the appropriate security posture for DHS/FEMA, HHS/ACF, and Department of Transportation Federal Government contracts. Provided guidance to Senior Project Managers and Team Members for incorporating security requirements and attaining Authorization to Operate (ATO). Created and published key authorization packa
Sr. Information Security Consultant
Security Risk Solutions
Apr 2010 - Present (15 years 1 month)
Led Client Engagements for technical and non-technical personnel, providing Vulnerability Assessments, Penetration Testing, System Security Testing and Certification and Accreditation (C&A). Provided Application Security and Software Development Consultation within the Agile Software Development process and implemented security protocols in various business sector regulations including Healthcare,
Systems Security Engineer
Engility/TASC
Jun 2004 - Present (20 years 11 months)
As the Lead Project Security Manager, provided Systems Security Engineering technical consultation to Senior Management for a variety of government programs. Developed and presented to Air Force Space Command (AFSPC) Certification and Accreditation System Security Authorization Agreements (SSAA) and detailed Vulnerability Risk Analyses for DAA C&A Final Approvals. Performed in-depth functional ana
Systems Security Engineer
Engility/TASC
Jun 2004 - Apr 2010 (5 years 10 months)
Provided Systems Security Engineering technical consultation to Senior Management for a variety of government programs. Developed and presented Certification and Accreditation System Security Authorization Agreements (SSAA) and detailed Vulnerability Risk Analyses for DAA Final Approvals. Performed in-depth functional analysis and hands-on security testing and network vulnerability Risk Assessment
IT Security Manager and Security Architect
Northrop Grumman
Jan 2013 - Present (12 years 4 months)
Effectively Managed the IT Security Team initiatives for the creation of secure environments in alignment with corporate objectives. Managed Facility Security Team with direct reports and assisted in the build out of a new secure facility. Provided Application Security and Infrastructure development design for customized Web Applications and executed Web Application security testing, static code a
IT Security Manager and Security Architect
Northrop Grumman
Jan 2013 - Aug 2013 (7 months)
Effectively managed the IT Security Team initiatives for the creation of secure environments in alignment with corporate objectives. Managed the Facility Security Team and assisted in the build out of a new secure facility. Provided Application Security and Infrastructure development design for customized Web Applications and executed various security testing methods.
Sr. IT Security and Compliance Analyst
National Association of State Boards of Accountancy
Sep 2013 - Present (11 years 8 months)
Spearheaded the development and implementation of meeting PCI-DSS, SOC 2, SSAE 16, and ISO 27000 series security controls to ensure that organizational assets are properly protected. Led organization’s Incident Response policies and procedures to meet identified business goals regarding chain of custody and breach reporting standards. Managed the LogRhythm Security Information and Event Management
Sr. IT Security and Compliance Analyst
National Association of State Boards of Accountancy
Sep 2013 - Apr 2014 (7 months)
Spearheaded the development and implementation of meeting PCI-DSS, SOC 2, SSAE 16, and ISO 27000 series security controls. Led organization’s Incident Response policies and procedures to meet business goals regarding chain of custody and breach reporting. Managed the LogRhythm Security Information and Event Management (SIEM) and provided Web Application Security Testing.
Sr. IT Security Analyst
The General Insurance
Apr 2014 - Present (11 years 1 month)
Led the Information Security Team on improvement initiatives in an E-commerce Retail environment, governed by PCI-DSS and ISO 27000 series security requirements. Created maintenance processes for Partner Connectivity Agreements to ensure secure confidentiality for Data in Transit and Data at Rest. Developed and Published Security Awareness training, conducted regular Network and Web Application Vu
Information Security Officer
Cognosante
Aug 2017 - Present (7 years 9 months)
Managed a team of Security Engineers in the development and submission of security documentation needed to obtain formal Authorization to Operate (ATO) in FedRAMP approved AWS Cloud and Microsoft Azure environments. Managed all activities related to designing, implementing, documenting, and maintaining the appropriate security posture for Veteran Affairs (VA), Federal and State Government contract
Cyber Threat Intelligence Security Engineer
Bridgestone Americas
Apr 2015 - Present (10 years 1 month)
Defined, Developed and Managed a large-scale Cyber Threat Intelligence and Analysis Program to proactively protect the overall integrity of the system. Managed the Splunk Security Information and Event Management (SIEM) System for optimal performance and effective compliance and monitor reporting. Identified new threat techniques and procedures utilized by threat actors and conducted correlation a
Cyber Threat Intelligence Security Engineer
Bridgestone Americas
Apr 2015 - Jun 2017 (2 years 2 months)
Defined, developed, and managed a large-scale Cyber Threat Intelligence and Analysis Program to proactively protect system integrity. Managed the Splunk Security Information and Event Management (SIEM) System for optimal performance and reporting. Identified new threat techniques and procedures and developed Weekly Threat Intelligence Reports detailing origin, attack types, and recon activity.
Sr. Information Security Consultant
Security Risk Solutions
Apr 2010 - Dec 2012 (2 years 8 months)
Led client engagements for technical and non-technical personnel, providing Vulnerability Assessments, Penetration Testing, and System Security Testing. Implemented security protocols across various business sectors including Healthcare, DoD, FISMA, NIST, HIPAA, SOX, and PCI DSS. Developed and managed System Security Plans (SSP) and orchestrated enterprise-wide Business Continuity, IT Contingency,
Sr. IT Security Analyst
The General Insurance
Apr 2014 - Apr 2015 (1 year)
Led the Information Security Team on improvement initiatives in an E-commerce Retail environment governed by PCI-DSS and ISO 27000 series requirements. Created maintenance processes for Partner Connectivity Agreements to ensure secure confidentiality for Data in Transit and Data at Rest. Conducted regular Network and Web Application Vulnerability Security Testing and managed the Security Informati
Information Security Officer
Cognosante
Aug 2017 - Oct 2023 (6 years 2 months)
Managed a team of Security Engineers in the development and submission of security documentation needed to obtain formal Authorization to Operate (ATO). Managed activities related to designing, implementing, and maintaining the security posture for Veteran Affairs and Federal/State Government contracts. Reviewed System Architecture and Design Documentation and performed initial and ongoing Risk As
Education
Degrees, certifications, and relevant coursework
Colorado Technical University
M.S., Computer Science
Focused on advanced topics in computer science with a specialization in computer systems security. Gained in-depth knowledge of securing computer systems and networks.
Colorado State University
B.A., Economics
Studied economic principles with a focus on business and economic forecasting. Developed analytical skills applicable to various business environments.
Colorado Technical University
Master of Science, Computer Science
Focused on Computer Systems Security within the Computer Science program. Gained advanced knowledge in securing computer systems and networks.
Colorado State University
Bachelor of Arts, Economics
Concentrated on Business and Economic Forecasting as part of the Economics degree. Developed analytical skills in economic trends and business predictions.
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Job categories
Interested in hiring Kevin?
You can contact Kevin and 90k+ other talented remote workers on Himalayas.
Message KevinFind your dream job
Sign up now and join over 85,000 remote workers who receive personalized job alerts, curated job matches, and more for free!
