Skip to main content
HimalayasHimalayas logo
RC
Open to opportunities

Richard Carlton

@richardcarlton

CISSP-certified information security professional who leads RMF/DOD cybersecurity authorizations, audits, and risk management for Navy systems.

United States
Message

What I'm looking for

I’m looking to lead RMF/NIST A&A and continuous monitoring for mission-critical government systems, partnering with senior leadership to reduce risk, produce POA&Ms that move the needle, and strengthen the cybersecurity posture.

I’m an active CISSP-certified Information System Security Officer who delivers Defense Information Assurance Risk Management Framework (DIARMF) execution and NIST-based Authorization & Accreditation (A&A) for mission-focused government systems. I’m known for translating Cybersecurity/Information Assurance (CS/IA) requirements into clear deliverables for ISSM and senior leadership.

At Rollout Systems supporting the US Navy/NAVAIR, I facilitate Cybersecurity/Information Assurance requirements for assigned information systems and projects. I perform DIARMF/NIST A&A as an ISSE/ISSO using eMASS and security tooling such as Tenable Nessus ACAS, STIG Viewer, VRAM, and Trellix ESS, and I compose Security Control Assessment Reports, System Security Plans (SSPs), Risk Assessment Reports (RARs), and POA&M reviews.

Earlier in my career, I served as a Senior Cyber Security Analyst/CS/IA Team Lead while moving DoD programs from DIACAP to DIARMF, and I led engineering support efforts including IA-certified laboratory spaces and system administration for lab laptops and servers. I also held DHS and OSD-aligned roles where I authored directorate-level SOPs, guided RMF transitions, advised on incident response and computer network defense challenges, and managed POA&M processes using Xacta.

Beyond pure assurance work, I bring leadership and operational discipline from having been a CEO managing budgets, contracts, PCI-DSS compliance, and company-wide systems. I’ve helped organizations strengthen security posture through risk-informed architecture, guidance for RMF introduction and eMASS updates for FISMA reporting, and Security-as-a-Service (SECaaS) design recommendations grounded in NIST guidance and DISA STIGs.

Experience

Work history, roles, and key accomplishments

RS

Information System Security Officer

Rollout Systems

Oct 2023 - Jan 2026 (2 years 3 months)

Provided ISSO/ISSE subject matter expertise for US Navy/NAVAIR DIARMF/NIST RMF authorization and accreditation for assigned computer systems. Produced security control assessment reports, SSPs, risk assessment reports, and conducted monthly POA&M reviews using eMASS and Tenable Nessus/ACAS.

SI

RATS IA Team Lead

Sabre Systems, Inc.

Feb 2018 - Nov 2018 (9 months)

Supported US Navy/NAWC-AD Rapid Capability engineering as an Information Assurance lead for the RATS team. Designed IA-certified laboratory spaces and served as ISSM and system administrator for lab laptops and servers.

RS

Senior Cyber Security Analyst

Rollout Systems

Oct 2016 - Feb 2018 (1 year 4 months)

Served as an Echelon II IA Analyst/Senior Cyber Security Analyst and CS/IA team lead supporting US Navy/NAVAIR efforts to transition from DIACAP to DIARMF. Facilitated NIST/DIARMF-based authorization and accreditation as ISSE/ISSO for Navy computer systems.

CACI logoCA

Functional Analyst - Principal

Dec 2015 - Sep 2016 (9 months)

Supported DHS NPPD as a functional analyst for the Chief Information Security Office (CISO), authoring SOPs, policies, guidance, and training plans for directorate-level security needs. Performed POA&M management and security control assessments aligned to NIST 800-37/800-39 using Xacta.

DM

Information System Security Manager

DMI

May 2014 - Dec 2015 (1 year 7 months)

Supported US Navy JTDI 2.0 as an ISSM/IAM, providing weekly FISMA reporting and producing POA&M actions from vulnerability scan results. Managed DIACAP and RMF certification and accreditation activities and maintained system vulnerability and mitigation documentation using VRAM.

VI

Cyber Security Architect

VAE IT

Sep 2013 - May 2014 (8 months)

Implemented the transition of DIACAP C&A processes to DIARMF to support an OSD environment while maintaining secure ATO posture. Audited security controls for existing systems, advised engineers on security requirements, and supported DAA/VMS vulnerability management and reporting.

NA

Cyber Project Specialist

National Nuclear Security Administration

Nov 2012 - Apr 2013 (5 months)

Developed department-level cyber risk management policy for NNSA headquarters and subordinate facilities in alignment with NIST 800-37 and NIST 800-39. Supported interviews and documentation using NIST SP 500-53 and NIST SP 800-53A guidance.

IC

Security Specialist

ICS Corporation

Oct 2012 - Nov 2012 (1 month)

Ensured FISMA compliance by providing DIACAP/RMF-based certification and accreditation support in accordance with applicable DoD and Navy guidance. Interpreted Gold Disk and Retina scan data and mitigated POA&M findings to address system weaknesses.

SAIC logoSA

Information Security Analyst

Mar 2011 - Oct 2011 (7 months)

Provided RMF-based authorization and accreditation support for U.S. State Department systems to meet FISMA requirements. Tracked updates using Remedy, supported continuous monitoring using IPost data, and used DISA Gold Disk scan data for security posture review.

UF

Maintenance Liaison

United States Air Force

Oct 2008 - Feb 2011 (2 years 4 months)

Served as Chief of Helicopter Maintenance Branch logistician functional area manager, managing personnel and equipment for AFDW helicopter maintenance. Participated in VIPSAM planning and the source selection team, and coordinated and tracked annual training requirements for 200+ personnel.

Education

Degrees, certifications, and relevant coursework

University of Maryland University College logoUC

University of Maryland University College

Bachelor of Science, Information Assurance

Earned a Bachelor of Science in Information Assurance from the University of Maryland University College (College Park, MD).

CF

Community College of the Air Force

Associate of Science, Aviation Maintenance Technology

Earned an Associate of Science in Aviation Maintenance Technology from the Community College of the Air Force (Maxwell AFB, AL).

College of Southern Maryland logoCM

College of Southern Maryland

Associate of Arts, General Studies

Earned an Associate of Arts in General Studies from the College of Southern Maryland (La Plata, MD).

Tech stack

Software and tools used professionally

Find your dream job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan