Ernest Grossmann, CISSP
Details
Security Engineering
Southern Methodist University
2015 : 2018
Bachelor of Science - BS
Information Systems Technology
Southern Illinois University, Carbondale
2005 : 2011
Associate of Arts and Sciences (AAS)
Military Information Systems Technology
Community College of the Air Force
1993 : 2001
2020 : Present
Raytheon Intelligence & Space
Western Region Cybersecurity Sr. Manager
Manage and lead a team of cybersecurity professionals across the business in the execution of a comprehensive Cybersecurity (CS)/Information Assurance (IA) program as stipulated in various government customer requirements documents to include (but not limited to) : NISPOM, DAAPM, associated NIST documents, and other customer-specific implementation policies. Cybersecurity management oversight responsibilities encompasses the entire Raytheon Intelligence, Information, and Services (IIS) business in support of the DoD collateral portfolio in IIS. Responsible for the effective and efficient execution of all facets of the CS/IA program for DoD programs, to include (but not limited to) : Information System Portfolio Management : Managing Assessment and Authorization, Sustainment, and Continuous Monitoring activities across the enterprise; collecting and maintaining accurate status and metrics for all systems; developing and executing plans to remedy problem areas, etc. Supervises individuals and teams and conducts Performance Development, coaching, and mentoring. Develops and manages budget and staffing plans. Ensures thorough preparation for assessments (self, peer, and Customer) and manages remediation of findings.
2017 : 2020
Raytheon Intelligence, Information, and Services
Cybersecurity Regional Manager
Prepare/maintain authorization & assessment (A&A) plans for multiple information systems (IS) supporting federal and international customers. Draft/update system security plans (SSP) complying with Risk Management Framework standards. Ensure all National Industrial Security Program Operations Manual (NISPOM), ICD 503, NIST special publications, and corporate IS requirements are implemented and functional. Validate technical configuration settings based on the NISPOM, NIST publications, and industry standards for various hardware platforms. Manage general & privileged user accounts; conduct software and system vulnerability checks; conduct file transfers between different security levels; provide security awareness and education briefings; perform system auditing; conduct system security testing and self-inspections.
2013 : 2017
Raytheon Intelligence, Information, and Services
Information Systems Security Manager (ISSM)
Managed Information Assurance (IA) teams that monitored, evaluated and maintained information technology (IT) systems, policy and procedures to protect from unauthorized activity. Identified potential threats and managed resolution of security violations. Enforced national, DoD and Air Force security policies and directives; employed hardware and software tools to enhance security to ensure Confidentiality, Integrity and Availability (CIA) of IT resources.
Also oversaw IT Quality Assurance programs at 4 primary Operations Centers and 9 support sites. Conducted site visits and reported health/status of programs to directors. Reviewed IT programs for compliance with DoD and AF regulations. Authored 3 policy instructions and several operations aides to clarify and improve network operations. Monitored enterprise devices for intrusions and attacks; watched perimeter and internal infrastructure devices for loss of connectivity; oversaw sanitization of classified information spillage. Ensured regional & local network service centers were compliant with all DoD, AF, and unit cyber directives. Managed 45-member operations and support crew monitoring $50M+ enterprise network, keeping 99% uptime; developed master training plan and 20 operations procedures guides used to qualify 85 cyber technicians.
Managed Communications, Computer, Personnel, and Physical Security programs. Served as IA Manager responsible for certifying and accrediting two enterprise networks supporting 56 locations & 300K+ users. Validated IA configuration change management activities across Air Force classified/unclassified enterprise networks, reducing attack vectors to the networks. Developed policy/training guide used by 20 IA professionals at multiple sites to standardize the IA program.
1998 : 2013
United States Air Force
Cyber Security Manager
About
Cybersecurity professional with 30+ years of enterprise network operations and cybersecurity experience. Oversee classified information system security across multiple Raytheon sites. Designed, configured, and secured local area networks and managed/secured enterprise networks. Validated/implemented Information Assurance (IA)/Cybersecurity (CS) programs. Managed security operations at several locations. Prepared system security plans under the Risk Management Framework (RMF). Past positions include ISSM, COMSEC Manager, IA Manager, Firewall Administrator, QA Manager, Stan/Eval Manager.
Specialties: Information System Security * Risk Management Framework * COMSEC Management * Information Assurance * IT Quality Assurance * IT Standards & Evaluations * Operations Management * Network Security * Physical Security * Information Security * Personnel Security * UNIX/Linux Administration * CISSP