From:                              route@monster.com

Sent:                               Friday, November 4, 2016 8:51 AM

To:                                   hg@apeironinc.com

Subject:                          Please review this candidate for: PaloAlto

 

This resume has been forwarded to you at the request of Monster User xapeix03

Tuan Q. Tram 

Last updated:  08/17/15

Job Title:  no specified

Company:  Apeiron, Inc.

Rating:  Not Rated

Screening score:  no specified

Status:  Resume Received


Arlington, VA  22202
US

Mobile: 703.868.0782   
TuanQTram@comcast.net
Contact Preference:  Email

Quick View Links:

Resume Section

Summary Section

 

 

RESUME

  

Resume Headline: Tuan Q. Tram -- Sr. Cybersecurity Engineer

Resume Value: 6y3g6cqr598ug7a3   

  

 

TUAN Q. TRAM

3650 South Glebe Road, Unit 256Mobile:  703.868.0782

Arlington, VA  22202-2394E-Mail:  TuanQTram@comcast.net

 

 

U.S. Citizen    /    DHS Trusted Agent    /    DoD Top Secret (SCI Eligible)    /    NATO & COMSEC Briefed

 

 

 

 

Professional

Experience

Thirty years’ total experience – with Government & Industry – in project management & staff supervision, digital/cyber security & operations, security policies & procedures, security auditing & penetration testing, systems engineering & analysis, hardware & software test & evaluation, code walk-throughs & reviews, independent verification & validation, networks & systems design.

 

§   Policies & Regulations, Standards & Requirements:  NISPOM, Section 508,
HSPD-12; FISMA, NIST SP 800x Series, DHS 4300x, DoD 8500x; DIACAP, RMF, PII, HIPAA, PCI, ISO 27001 & 27002, ISO 9000 & 9001.

 

§   Principles & Techniques, Methodologies & Tools:  Digital/Cyber Security, DIACAP & C&A, RMF & A&A; PPSM, CAP, CDS; TTPs, STIGs, SRGs, Checklists; computer & mobile forensics, penetration testing, network defense; video surveillance design & implementation; integrated systems modeling & simulation; project & task planning, scheduling & resource tracking –

ú      Security/System/Software T&E, DII COE, GCCS/GCSS; BeyondTrust Retina & REM, Tenable Nessus & SecurityCenter, McAfee ePO & HBSS; Security Technology Integrated Program (STIP), TSA Systems Integration Facility (TSIF), Chemicals & Explosives Trace Detection Systems;

ú      C2 & C4ISR and Weapon systems, application & database systems; programming & scripting, code reviews; QA, CM, IV&V, integration testing; business development, managing clients, coaching staff, technical writing & editing.

 

 

 

 

 

Recent Work History

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Recent Work History (cont’d)

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Recent Work History (cont’d)

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Recent Work History (cont’d)

2015 – PresentDirector of Digital SecurityDMS Int’l – Silver Spring, MD

§                                                                                                                                                                                                                                                                     Contributing to Enterprise Improvement, Business Development, Proposal Writing efforts at DMSI Corporate level.

 

§                                                                                                                                                                                                                                                                     Department of State – Diplomatic Security (DS) & Information Resource Management (IRM)

ú      Working with System Owner to compile data, gather information, develop RMF documents & artifacts to submit for A&A action.  Supporting DS & IRM leadership and Vendor management directly.

 

2009 – 2015Director of Cyber OperationsEpsilon – Washington, DC

(Transitioned from part-time Consultant (Dec 2009) to full-time Employee (Oct 2011))

§                                                                                                                                                                                                                                                                     Contributed significantly to Enterprise Improvement, Business Development, Proposal Writing efforts at Epsilon Corporate level.  Over five year tenure, responsible for up to one-third of all contract wins in areas of DIACAP, IA, C&A.

 

§                                                                                                                                                                                                                                                                     Naval Sea Systems Command (NAVSEA) – Certification & Accreditation Team
(Dec 2013 – Feb 2014) then again (Oct 2014 – Aug 2015)

ú      Worked with System Owners to compile data, gather information, develop DIACAP documents & artifacts to submit for C&A action.  Supported IA & C&A Branch Chiefs directly to develop & revise team processes, procedures, workflows to reflect NAVSEA’s new way of doing business.

ú      Led effort to test (security & functionality) then deploy & manage iPhone 5s & iPad Air 2 by end of FY2015.  Developed white papers for review & consideration by NAVSEA Senior Leadership:  Wireless Networking Implementation, RMF Transition & Conversion Process, ACAS Deployment & Utilization.

 

§                                                                                                                                                                                                                                                                    Army Software Engineering Center (SEC) Software Assurance Division (SwAD)
Security Assessment & Compliance Test Team(Jun 2014 – Sep 2014)

ú      Conducted security assessment & compliance testing on Army networks & systems on behalf of ACA.  Made use of Retina, SCAP Tool, STIG Viewer, Vulnerator for testing; and SwAD’s own DIACAP Package Generator (DPG) for reporting.  Specialized in VMware ESXi and McAfee ePO & HBSS compliance auditing.  Developed processes & workflows, captured instructions & lessons learned, compiled tips & tricks – to educate & inform Test Team, reduce confusion, minimize risk to both Epsilon and Army SEC.

 

§                                                                                                                                                                                                                                                                     REI Systems – Health Resources & Services Administration (HRSA)
Corporate System Admin & HRSA DB Admin Teams(May 2014 – Aug 2014)

ú      On Corporate SysAdmin Team, worked directly under Vice President to:  update equipment inventory in both Telecom Closet and Server Room; catalog all hardware & software in use; update rack elevation diagrams to reflect current state of networks & systems.  Also, developed templates for policies & procedures, such as Launch Management Plan, System Declaration & Registration Form, System Operations Guide.

ú      On HRSA DB Admin Team, worked directly under Director to:  develop procedures & instructions for configuring SQL Server 2012 on virtual servers; then execute such procedures & instructions to configure 25 new servers in eight weeks.  Also, assisted in developing semi-automated scripts to reduce work time for configuration of each server from approximately 60 minutes to only 15 minutes.

 

§                                                                                                                                                                                                                                                                    F-35 Lightning II (Joint Strike Fighter) Program Office (JPO)
Information Assurance & System Admin Teams(Oct 2012 – Dec 2013)

ú      Co-led IA team on SABI & SAP activities.  Assigned by CIO and IAM to oversee high-visibility efforts across JSF Enterprise, to include:  weekly vulnerability scanning & patching of NIPR & SIPR assets; ongoing testing & patching of Java vulnerabilities per US CYBERCOM IAVM Program; hosting 24th Air Force Scope EDGE NHA event in February 2013; hosting DISA CCRI event in June 2013; conducting hardware & software security assessments; monitoring McAfee ePO & HBSS installations on servers & workstations; investigating data & information spillage or suspect user activity; managing team & staff expectation and morale during transition and recompete periods.

 

§                                                                                                                                                                                                                                                                    U.S. Marine Corps University (MCU)
Certification & Accreditation Team(Nov 2012 – May 2013)

ú      Provided background guidance & support to onsite IA & C&A teams in short-term effort to re-accredit four major networks & systems simultaneously:  Gray Research Center (GRC), DoN Heritage Asset Management System (DONHAMS), Expeditionary War School (EWS), and CampusNet.  After 150-day effort, achieved completion & submission of all four C&A Packages by mid-April for successful Navy CA review & system re-accreditation.

 

§                                                                                                                                                                                                                                                                    U.S. Army Information Technology Agency (ITA)
Enterprise Information & Mission Assurance (EIMA) Team(Oct 2011 – Oct 2012)

ú      Supported large-scale transition & migration activities after multiple organizational, team, & staff realignment initiatives by both GOV and CTR teams over six month period.  Participated in McAfee ePO & HBSS implementation & rollout efforts.  Managed team & staff expectation and morale during tumultuous times.

ú      Led CAP & C&A teams to refine systems & processes, policies & procedures to realign and rejuvenate EIMA.  Successfully supported and passed in-house Penetration Test activities, DISA CNDSP Audit, accreditation/re-accreditation of multiple networks & systems (Pentagon backbones of NIPR, SIPR, Top Secret, as well as multiple Clients & Tenants).

 

2011Systems Engineer, Lead PrincipalPragmatics – Reston, VA

§   Transportation Security Administration (TSA) – Enterprise Architecture, Secure Infrastructure

ú      Assisted Branch Chief in leading “security technologies” task to test & evaluate new appliances & tools, then design & develop physical & logical safeguards to protect assets on TSANet.  Led efforts to test functionality and perform “basic” hacking & forensics on mobile computing devices, to include:  iPhone 4, iPad 2, Motorola Xoom, BlackBerry Smartphones, BlackBerry PlayBook.  Worked with Good Device Server and Good Messaging Server to manage mobile devices in support of “Secure Mobile Computing” initiative for both TSA Senior Leadership Team and Federal Air Marshal Service (FAMS).

ú      Due to prior experience, was designated to review C&A documents & artifacts for TSA Security Technology Integrated Program (STIP), and provided inputs to C&A Team for pending re-accreditation activities.

 

2009 – 2011Vice President, OperationsInfoSecure Tech – Washington, DC

§   Department of Homeland Security (DHS) – U.S. Citizenship & Immigration Services (USCIS) – Incident Response & Digital Analysis (IRDA) Team

ú      In direct support of Branch Chief, conducted security investigations and data extractions on networks, systems, mobile devices in cooperation with CIS Security & Network Operations Center (CIS SNOC):

-- Complied with DHS 4300A & 4300B policies & procedures, as well as those established by USCIS OCIO.  Enforced QA & CM on IRDA hardware & software assets.  Managed McAfee ePO & HBSS installations on servers & workstations.

-- Utilized AccessData Forensic ToolKit, Guidance Software EnCase Forensic, WireShark, inSSIDer, WirelessMon, various COTS & Open Source applications & utilities.

 

§   DHS – USCIS – Infrastructure Protection Team & FISMA Compliance Team

ú      In direct support of Branch Chief, installed & configured diverse vendor hardware & software for demonstration and T&E use, as follows:

-- Barracuda Spam & Virus Firewall, ArcSight NSP & Logger, Splunk HW & SW, NetWitness Broker/Concentrator/Decoder/Informer à for integration with existing Infrastructure, NIDS, HIDS at strategic nodes with CIS SNOC.

-- IBM Tivoli NetCool, EMC2 VoyenceControl, Cisco MARS, Cisco Works, Cisco Security Manager à for network monitoring & control, as well as network traffic analysis.

-- AppSec DbProtect, HP AppDetective & WebInspect, Core Impact, Coverity Static & Dynamic Analysis, IBM AppScan, Nessus, Retina, McAfee ePO à for web, application, database development & testing, as well as security auditing and compliance tracking.

 

2009Principal Member, Engineering StaffMTS Tech – Arlington, VA

§   Department of Navy & U.S. Marine Corps – US101 Program

ú      Led IV&V and IA C&A tasks to ensure DIACAP compliance of all IA-enabled navigation, electronic, communication, IT systems.  Conducted face-to-face interviews and hands-on vulnerability scans and security assessments of systems to verify & validate compliance with DoD 8500.x and DCID 6/3 IA Controls.  Evaluated IA requirements and applied C&A procedures per DCIDs 6/3 & 6/9 and JAFANs 6/3 & 6/9.  Coordinated & worked directly with client/partner Engineering and IA teams to track vulnerabilities and report status on POA&Ms.

 

2008Sr. Project EngineerJorge Scientific Corp – Arlington, VA

§   U.S. Army Research Laboratory (ARL) – Constant Hawk Program

ú      Co-led Systems Engineering efforts in designing & documenting requirements for persistent surveillance systems in Iraq Theater of Operations, to include imagery sensor & gimbals, aircraft platform & payloads, data processing systems.  (Also, was responsible for technical elements of bid & proposal effort to implement similar program in Afghanistan Theater of Operations.)

ú      Developed CONOPS and performed feasibility analysis for entire system, plus components.  Developed SOWs and tracked subsystem requirements for vendors & subcontractors.  Contributed to DIACAP and C&A efforts to secure networks & systems, including imagery processing servers, data storage arrays, INTEL analysis workstations.  Coordinated & worked directly with partner/client Engineering & IA teams across 12-hour time difference.

 

2006 to 2008Staff Engineer, ITDSCI – Mays Landing, NJ

§   Transportation Security Laboratory (TSL) – FAA, DHS, TSA Programs

ú      Tested & validated Transportation Security Equipment (TSE); gained SCAP certification & authorization/accreditation for TSE before deploying to airports nationwide.

 

2003 to 2006Lead Member, Engineering StaffLM MS2 – Moorestown, NJ

§   Deepwater Test & Integration Laboratory (DTIL) – Coast Guard Deepwater

ú      Tested & validated communication & navigation systems for small & medium ships; gained DITSCAP certification & accreditation for systems before deploying on ships.

 

 


 

 

 

 

Prior Work History

2002 to 2003Senior IA Engineer – Army Military Transport Mgmt Command
DMS International – Silver Spring, MD

 

2000 to 2002Senior Systems Engineer – JPAS
Houston Associates – Arlington, VA

 

1998 to 2000Member of Technical Staff IV – Joint BMD and DISA COE
Logicon ISS – Reston, VA

 

1997 to 1998Senior Communications Engineer – Army Pentagon IT Mgmt
SenCom Corporation – Arlington, VA

 

1996 to 1997Senior Systems Engineer – IT & HelpDesk Support
American Society for Training & Development –               Alexandria, VA

 

1990 to 1996Senior Consultant, Level III – NASA, INTEL, Air Force,
Commercial Programs

Booz·Allen Hamilton – McLean, VA (Government & Commercial
Business Groups)

 

1988 to 1990Associate Technical Specialist II – NASA Goddard
Computer Sciences Corporation – Beltsville, MD

 

1985 to 1988Wind Tunnel Operator – Co-Operative Engineering
Glenn L. Martin Wind Tunnel – UMCP

 

 

 

 

 

Education & Certification

§   Certified Information System Security Professional – Member in good standing

(ISC)2 Certificate Number:  365226 – since March 2010

 

§   Member of InfraGard, Nation’s Capital Chapter – Member in good standing

InfraGard Membership Number:  10037344 – since March 2009

 

§   Bachelor of Science Degree in Aerospace Engineering

(2.5 years in Co-Op Engr Program, Glenn L. Martin Wind Tunnel, UMCP)

University of Maryland, College Park, MD (UMCP)

 

 

§   InterNetwork Defense – CISSP Boot Camp

Knowledge Consulting Group, Reston, VA

 

§   George Washington University – Fundamentals of Project Management & Requirements Management

ESI & Transportation Security Administration, Atlantic City, NJ

 

§   Numerous DoD & DHS Internal Training & Certification Courses – ACAS, HBSS, eMASS, Retina, VMS, IDS/IPS, CND, Incident Handling, IT Forensics, etc.

IASE.DISA.mil  &  fedVTE.USAlearning.gov

 

 

 

 

Page -1- of -5-Last Updated:  11 Aug 2015



Experience

BACK TO TOP

 

Job Title

Company

Experience

Director of Digital Security

DMS International

- Present

 

Additional Info

BACK TO TOP

 

Desired Salary/Wage:

150,000.00 - 170,000.00 USD yr

Current Career Level:

Manager (Manager/Supervisor of Staff)

Years of relevant work experience:

More than 15 Years

Date of Availability:

Immediately

Work Status:

US - I am authorized to work in this country for any employer.

Active Security Clearance:

Active Top Secret

US Military Service:

Citizenship:

US citizen

 

 

Target Job:

Target Job Title:

Sr. Cybersecurity Engineer

Desired Job Type:

Employee
Temporary/Contract/Project

Desired Status:

Full-Time

 

Target Company:

Company Size:

Industry:

Computer/IT Services

Occupation:

IT/Software Development

·         Computer/Network Security

 

Target Locations:

Selected Locations:

US-VA-McLean/Arlington

Relocate:

Yes

Willingness to travel:

Up to 50% travel

 

Languages:

Languages

Proficiency Level

English

Fluent

French

Intermediate

Vietnamese

Fluent