{"id":2,"date":"2026-03-26T12:26:52","date_gmt":"2026-03-26T12:26:52","guid":{"rendered":"http:\/\/127.0.0.1\/?page_id=2"},"modified":"2026-05-21T12:43:07","modified_gmt":"2026-05-21T12:43:07","slug":"sample-page","status":"publish","type":"page","link":"https:\/\/www.garycoulter.com\/?page_id=2","title":{"rendered":"About Me"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">My name is Gary Coulter, and I&#8217;m passionate about cloud security. I&#8217;m fascinated by the possibilities that the cloud offers, and I want to use my knowledge and talents to make the cloud more secure. I&#8217;m currently working in Governance, Risk, and Compliance (GRC) and want to transition into cloud security engineering. This blog will be a place for me to document that transition and demonstrate my knowledge of building secure environments in the cloud.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Clearance<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Information available upon request.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Certifications<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), Certified in Governance Risk and Compliance (CGRC), Security+<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Skills<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Audit log reviews and security incident response, risk analysis, Assessment &amp; Authorization, technical writing, customer service<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Experience<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>TDI, Washington, DC &#8211; Information System Security Officer<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">May 2025 &#8211; Present<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Served as the primary IT security and compliance advisor for seven authorization boundaries for a federal customer. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Analyzed Nessus vulnerability and Tripwire compliance scan reports and worked with system administrators and engineers to triage scan results and identify true positives in order to develop risk-based remediation plans. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Documented risk acceptance requests for security controls that could not be implemented as required, and documented the implementation of compensating controls that would mitigate the risk from the proposed risk acceptance. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Provided briefings to system owners, the Chief Information Security Officer, and Chief Information Officer on IT security risks present in my assigned authorization boundaries <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Used the Archer Governance, Risk and Compliance (GRC) tool to create system security and privacy plans (SSPPs) and plans of action and milestones (POA&amp;Ms) for my assigned authorization boundaries.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Coalfire Federal, Arlington, VA &#8211; Security control assessor <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">March 2023 &#8211; May 2025 <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Served as a contractor security control assessor at two federal agencies where I led security control assessments of complex systems with hundreds of controls from NIST SP 800-53 Rev. 4 and Rev. 5. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Produced security assessment reports (SARs) using the CSAM and Xacta 360 GRC tools, executive summaries, risk assessments, and weekly assessment status updates to help agencies understand the risks from assessment findings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Mentored junior security control assessors on how to effectively perform security control assessments in accordance with customer requirements. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Contributed to the efficient operation of the security control assessor team by making suggestions for process improvements, including ways that the team could more easily collaborate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Coalfire Federal, Washington, DC &#8211; ISSO <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">September 2020 &#8211; March 2023 <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Maintained the appropriate operational security posture for the agency financial system and a FedRAMP SaaS solution. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Worked with system administrators, developers, and system owners to perform system security categorization, select appropriate security controls, and document the security posture of the system in system security plans using the CSAM GRC tool.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Gathered artifacts to demonstrate that the system&#8217;s security controls were implemented as required and operating as intended.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Reviewed the findings of security control assessments and worked with system administrators, developers, and system owners to develop POA&amp;Ms to remediate assessment findings. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Briefed the CISO, CIO, and DCIO on security control assessment findings to help them understand risk. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Performed continuous monitoring of implementation of NIST SP 800-53 Rev. 4 security controls and reviewed Nessus vulnerability scans with system administrators, developers, and system owners to remediate vulnerabilities. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Worked with system administrators, developers, and system owners to remediate vulnerabilities and close POA&amp;Ms. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Developed contingency plans and scenarios for tabletop tests of contingency plans. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Gave a brown bag presentation to other ISSOs on effectively working with system personnel to brief them on vulnerabilities identified in Nessus scans and develop plans to remediate vulnerabilities. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Researched vulnerabilities and worked with system personnel to document false positives and risk acceptance requests.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>ManTech, Washington, DC \u2014 Sr. A&amp;A Analyst <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">March 2020 &#8211; September 2020 <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Served as the primary IT security and compliance advisor for five authorization boundaries for a federal customer. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Analyzed Nessus vulnerability and Tripwire compliance scan reports and worked with system administrators and engineers to triage scan results and identify true positives in order to develop risk-based remediation plans. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Documented risk acceptance requests for security controls that could not be implemented as required, and documented the implementation of compensating controls that would mitigate the risk from the proposed risk acceptance. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Provided briefings to system owners, CISO, and CIO on IT security risks present in my assigned authorization boundaries <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Used Archer GRC to create SSPPs and POA&amp;Ms for my assigned authorization boundaries.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Zermount, Washington, DC \u2014 ISSO<\/strong> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">July 2017 &#8211; March 2020 <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Used Archer GRC to write SSPs, SARs, and POA&amp;Ms for 14 systems, including applications hosted in cloud environments, internal Web applications, a video surveillance system, and a fi ngerprinting system containing PII. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Used Splunk to review audit logs to identify potential security breaches.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"> \u25cf Ensured operating systems and databases were hardened in accordance with policy and CIS benchmarks. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Performed continuous monitoring and self-assessments and reported security issues to CISO and AO. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Performed security impact analyses for proposed changes and provided recommendations for approval\/disapproval. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Wrote contingency plans, Incident Response Plans, and AARs. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Facilitated Incident Response Plan and Contingency Plan tabletop exercises. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Worked with stakeholders to promptly address security vulnerabilities. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Reviewed FedRAMP packages and reported risks to senior management. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u25cf Analyzed Qualys vulnerability and hardening scan reports to assess risk and report issues to system stakeholders and senior management.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>My name is Gary Coulter, and I&#8217;m passionate about cloud security. I&#8217;m fascinated by the possibilities that the cloud offers, and I want to use my knowledge and talents to make the cloud more secure. I&#8217;m currently working in Governance, Risk, and Compliance (GRC) and want to transition into cloud security engineering. This blog will<\/p>\n<div class=\"more-link\">\n\t\t\t\t <a href=\"https:\/\/www.garycoulter.com\/?page_id=2\" class=\"link-btn theme-btn\"><span>Read More <\/span> <i class=\"fa fa-caret-right\"><\/i><\/a>\n\t\t\t<\/div>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"open","template":"","meta":{"footnotes":""},"class_list":["post-2","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/www.garycoulter.com\/index.php?rest_route=\/wp\/v2\/pages\/2","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.garycoulter.com\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.garycoulter.com\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.garycoulter.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.garycoulter.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2"}],"version-history":[{"count":9,"href":"https:\/\/www.garycoulter.com\/index.php?rest_route=\/wp\/v2\/pages\/2\/revisions"}],"predecessor-version":[{"id":29,"href":"https:\/\/www.garycoulter.com\/index.php?rest_route=\/wp\/v2\/pages\/2\/revisions\/29"}],"wp:attachment":[{"href":"https:\/\/www.garycoulter.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}