Richard Carlton
@richardcarlton
CISSP-certified information security professional who leads RMF/DOD cybersecurity authorizations, audits, and risk management for Navy systems.
What I'm looking for
I’m an active CISSP-certified Information System Security Officer who delivers Defense Information Assurance Risk Management Framework (DIARMF) execution and NIST-based Authorization & Accreditation (A&A) for mission-focused government systems. I’m known for translating Cybersecurity/Information Assurance (CS/IA) requirements into clear deliverables for ISSM and senior leadership.
At Rollout Systems supporting the US Navy/NAVAIR, I facilitate Cybersecurity/Information Assurance requirements for assigned information systems and projects. I perform DIARMF/NIST A&A as an ISSE/ISSO using eMASS and security tooling such as Tenable Nessus ACAS, STIG Viewer, VRAM, and Trellix ESS, and I compose Security Control Assessment Reports, System Security Plans (SSPs), Risk Assessment Reports (RARs), and POA&M reviews.
Earlier in my career, I served as a Senior Cyber Security Analyst/CS/IA Team Lead while moving DoD programs from DIACAP to DIARMF, and I led engineering support efforts including IA-certified laboratory spaces and system administration for lab laptops and servers. I also held DHS and OSD-aligned roles where I authored directorate-level SOPs, guided RMF transitions, advised on incident response and computer network defense challenges, and managed POA&M processes using Xacta.
Beyond pure assurance work, I bring leadership and operational discipline from having been a CEO managing budgets, contracts, PCI-DSS compliance, and company-wide systems. I’ve helped organizations strengthen security posture through risk-informed architecture, guidance for RMF introduction and eMASS updates for FISMA reporting, and Security-as-a-Service (SECaaS) design recommendations grounded in NIST guidance and DISA STIGs.
Experience
Work history, roles, and key accomplishments
Information System Security Officer
Rollout Systems
Oct 2023 - Jan 2026 (2 years 3 months)
Provided ISSO/ISSE subject matter expertise for US Navy/NAVAIR DIARMF/NIST RMF authorization and accreditation for assigned computer systems. Produced security control assessment reports, SSPs, risk assessment reports, and conducted monthly POA&M reviews using eMASS and Tenable Nessus/ACAS.
Chief Executive Officer
Performance Automatic
Nov 2018 - Oct 2023 (4 years 11 months)
Led an automotive transmission re-manufacturing business, managing employees, assets, operating budgets, contracts, and PCI-DSS compliance. Built manufacturer relationships and delivered training to wholesale distributor sales teams, increasing sales by 22%.
RATS IA Team Lead
Sabre Systems, Inc.
Feb 2018 - Nov 2018 (9 months)
Supported US Navy/NAWC-AD Rapid Capability engineering as an Information Assurance lead for the RATS team. Designed IA-certified laboratory spaces and served as ISSM and system administrator for lab laptops and servers.
Senior Cyber Security Analyst
Rollout Systems
Oct 2016 - Feb 2018 (1 year 4 months)
Served as an Echelon II IA Analyst/Senior Cyber Security Analyst and CS/IA team lead supporting US Navy/NAVAIR efforts to transition from DIACAP to DIARMF. Facilitated NIST/DIARMF-based authorization and accreditation as ISSE/ISSO for Navy computer systems.
Supported DHS NPPD as a functional analyst for the Chief Information Security Office (CISO), authoring SOPs, policies, guidance, and training plans for directorate-level security needs. Performed POA&M management and security control assessments aligned to NIST 800-37/800-39 using Xacta.
Information System Security Manager
DMI
May 2014 - Dec 2015 (1 year 7 months)
Supported US Navy JTDI 2.0 as an ISSM/IAM, providing weekly FISMA reporting and producing POA&M actions from vulnerability scan results. Managed DIACAP and RMF certification and accreditation activities and maintained system vulnerability and mitigation documentation using VRAM.
Cyber Security Architect
VAE IT
Sep 2013 - May 2014 (8 months)
Implemented the transition of DIACAP C&A processes to DIARMF to support an OSD environment while maintaining secure ATO posture. Audited security controls for existing systems, advised engineers on security requirements, and supported DAA/VMS vulnerability management and reporting.
Cyber Security Architect
Cloudburst Security
Apr 2013 - Aug 2013 (4 months)
Served as a cyber risk management SME for OSD OCIO, producing system security architectures and guidance using Nessus scanning and client interactions. Developed RMF introduction guidance for DoD and supported updates to eMASS for FISMA reporting, including SECaaS design support.
Cyber Project Specialist
National Nuclear Security Administration
Nov 2012 - Apr 2013 (5 months)
Developed department-level cyber risk management policy for NNSA headquarters and subordinate facilities in alignment with NIST 800-37 and NIST 800-39. Supported interviews and documentation using NIST SP 500-53 and NIST SP 800-53A guidance.
Security Specialist
ICS Corporation
Oct 2012 - Nov 2012 (1 month)
Ensured FISMA compliance by providing DIACAP/RMF-based certification and accreditation support in accordance with applicable DoD and Navy guidance. Interpreted Gold Disk and Retina scan data and mitigated POA&M findings to address system weaknesses.
Supported government clients with DIACAP/RMF-based C&A to meet FISMA requirements using NIST 800-37/800-53/800-53A and related guidance. Researched allowable devices for engineering teams and created and submitted C&A documentation using approved templates.
Provided RMF-based authorization and accreditation support for U.S. State Department systems to meet FISMA requirements. Tracked updates using Remedy, supported continuous monitoring using IPost data, and used DISA Gold Disk scan data for security posture review.
Maintenance Liaison
United States Air Force
Oct 2008 - Feb 2011 (2 years 4 months)
Served as Chief of Helicopter Maintenance Branch logistician functional area manager, managing personnel and equipment for AFDW helicopter maintenance. Participated in VIPSAM planning and the source selection team, and coordinated and tracked annual training requirements for 200+ personnel.
Education
Degrees, certifications, and relevant coursework
University of Maryland University College
Bachelor of Science, Information Assurance
Earned a Bachelor of Science in Information Assurance from the University of Maryland University College (College Park, MD).
Community College of the Air Force
Associate of Science, Aviation Maintenance Technology
Earned an Associate of Science in Aviation Maintenance Technology from the Community College of the Air Force (Maxwell AFB, AL).
College of Southern Maryland
Associate of Arts, General Studies
Earned an Associate of Arts in General Studies from the College of Southern Maryland (La Plata, MD).
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Richard?
You can contact Richard and 90k+ other talented remote workers on Himalayas.
Message RichardFind your dream job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
