Channing Thomas
AeroLeads people directory · profile

Channing Thomas Email & Phone Number

Cyber Incident Analyst and Forensics at Prime-Time/Leidos
Location: Gainesville, Virginia, United States 13 work roles 5 schools
1 work email found @mantech.com 1 phone found area 781 LinkedIn matched
✓ Verified August 2026 4 data sources Profile completeness 100%

Contact Signals · 1 work email · 1 phone

Work email c****@mantech.com
Direct phone (781) ***-****
LinkedIn Profile matched
3 free lookups remaining · No credit card
Current company
Prime-Time/Leidos
Role
Cyber Incident Analyst and Forensics
Location
Gainesville, Virginia, United States

Who is Channing Thomas? Overview

A concise factual answer block for searchers comparing this professional profile.

Quick answer

Channing Thomas is listed as Cyber Incident Analyst and Forensics at Prime-Time/Leidos, based in Gainesville, Virginia, United States. AeroLeads shows a work email signal at mantech.com, phone signal with area code 781, and a matched LinkedIn profile for Channing Thomas.

Channing Thomas previously worked as Cyber Incident Analyst/Forensics at Prime-Time/Leidos and Data Integration Engineer at Deutsche Bank. Channing Thomas holds Ms, Information Systems Management from Univeristy Of Phoenix.

Company email context

Email format at Prime-Time/Leidos

This section adds company-level context without repeating Channing Thomas's masked contact details.

{first}.{last}@mantech.com
86% confidence

AeroLeads found 1 current-domain work email signal for Channing Thomas. Compare company email patterns before reaching out.

Profile bio

About Channing Thomas

Dynamic ProfessionalProven ability in Enterprise Information Systems Management, Network Operations and Defense, Cyber Security, Incident Response, Systems Analysis, and Forensics Program Management, Security; Information Assurance (IA) Engineering, Drafting Policy, Governance, and Business Optimization and Streamlining. Decorated professional with over 26 years of experience with a solid track record in Computer Network Defense Network Communications, Operations, Operations Research Analysis, Program Management, Resource Management, Contracting, and Financial Management.Problem Solving• Identified methods and strategies providing Network Monitoring Security (NMS) using existing networking equipment into a consolidated Security Operations Center (SOC) providing a Tier II, Regional Computer Network Defense Provider• Capitalized on SOC design saving over $3M annually in Telecommunications Service Resources and reducing Communication Security (COMSEC) requirements in newly constructed, $370M state-of-the-art Information Systems Facility for Defense Information Systems Agency, Ft Meade• Recognized as Information Systems, Department of Defense, and Office of Management and Budget (OMB) Policy expert regarding information systems development, funding, resourcing, management, certification and accreditation, system network defense, and collaborative network connections• Specialized in Operational Research Systems Analysis (ORSA) for systems and operations analysis using Extract, Transform, and Load (ETL) tools such as Splunk, ArcSight, ACAS Security Center, and other dashboard facilitated network monitoring and analysis tools.

Listed skills include Information Assurance, Dod, Security, Defense, and 30 others.

Current workplace

Channing Thomas's current company

Company context helps verify the profile and gives searchers a useful next step.

Prime-Time/Leidos
Prime-Time/Leidos
Cyber Incident Analyst and Forensics
Gainesville, VA, US
13 roles

Channing Thomas work experience

A career timeline built from the work history available for this profile.

Cyber Incident Analyst And Forensics

Prime-Time/Leidos

Gainesville, Va, Us

Cyber Incident Analyst/Forensics

Prime-Time/Leidos

Provide Cyber Security Analysis and Incident Response in accordance with local guides, standard operating proceedure, and policy supporting the National Capital Region's Joint Service Provider.- Used endpoint tools, Host Based Security System (McAfee), Windows Defender, Tanium, and Applocker to monitor endpoints and report on any suspicious activity.- HBSS 301, Tanium, and Splunk 7.3 Power User certified- Used Splunk as the System Information Event Manager (SIEM) first Alert system, followed up using monitoring devices such as Tipping Point, CISCO FirePower, system Proxies for Web and Email to further analyze any activity- Created reports, kept standard turn-over logs, to local Program Manager and senior Government Representative.- Provided rudimentary Forensics support for compromised enpoint's needing Malware Analysis.

Data Integration Engineer

Frankfurt Am Main, Hessen, De

• Provided Architectural direction and technical implementation of Cyber Security Analytics Platform using Splunk and Enterprise Security Manager as the primary Security Information Event Management (SIEM) across a global commercial banking organization. • Directly engaged network, analysts and Data System owners' and effectively on-boarded data sources to meet and exceed current Purchase Card Information (PCI), Sorbanes Oxley (SOX) regulations and requirements for various systems to include: Network Traffic using CISCO NetFlow and Splunk Stream; Intrusion Detection using Window’s Defender and Semantic EndPoint Protection (SEP), Tanium; and Vulnerability Management using Windows Server Update Service (WSUS), Yellowdog Updater, Modifier (YUM) for *NIX devices; Malware Detection using Window’s Defender, Tanium, Symantec End Point (SEP), and Change Analysis using AppLocker. • Harnessed effective and streamlined strategies of onboarding data sources using a compliment of RSYSLOG, Windows Event Collectors (WEC), and other direct data source streams, reducing end point client agents and additional software installations by utilizing existing OS functionalities. • Provided in-depth analysis on ELK (Elastic Search, LogStash, and Kabana) advising management on flexibility and cost savings. • Implemented RSYSLOG and Microsoft Windows Event Collector (WEC) capabilities to deliver real-time logs from remote devices to a collection of Windows and Linux servers for further forwarding to Indexers.

Dec 2017 - May 2020

Security Operations Center Technical Lead

København, Dk

Responsible Information Systems, hosted in a cloud environment VMWare, including Security Engineering Planning, Implementation, and Operations of various products within the Security Operations Center. • Supervised 25 Analysts for a 24/7 Monitoring and Incident Response. • Successfully defended the network against multi-agency penetration testers certifying the Systems Security Compliance, Audit AppLocker and Nessus and Monitoring Functions using Window’s Defender and Symantec EndPoint Protection (SEP) and Tanium, Malware Detection using Tanium, Window’s Defender, Semantic EndPoint Protection (SEP) and Remediation; and Incident Response using EnCase, Splunk Enterprise Security Manager. Obtained a Mean-Time to Detect (MtD) of 30min and Mean-Time to Respond (MtR) in 40 min with Isolating and Remediating soon to follow. • (DoD) Architectural Framework (DoDAF) infrastructure to include CISCO Intrusion Prevention Systems (Source Fire) and Advanced Security Appliances (ASA) and SidewinderFirewalls, coupled with Cisco Fire Power that coordinates Intrusion Prevention Systems (Source Fire IPS) using SNORT and Advance Malware Protection (AMP) and ASAs throughout the network; as well as Network Monitoring Systems and Web Proxies. • Created, implemented, and managed Splunk Searches and Dashboards to facilitate Analysts in: Incident Response; Vulnerability Management; Malware Detection, Isolation, and Remediation; Systems Analysis; monitoring the enterprise. Log sources included: Windows Event System Logs, Linux Red Hat System Logs, McAfee ePO system log notifications, Firewall system logs, Nessus and Tenable Security Center scanning data and logs, CISCO net flow, nGenius, Active Directory. • Worked with Systems Architect to implement standard Federal Enterprise Architecture (FEA)/ Department of Defense

Dec 2016 - Dec 2017

Senior Information Security Engineer

David Hale Associates

Security Engineer, DHA-Inc, July 2016 – December 2016• Responsible for Security Information Event Management (SIEM)s into an Enterprise Security Management (ESM) using Splunk and handling various Common Event Format (CEF), which include: Intrusion Prevention Systems/ Intrusion Detection Systems (IDS/IPS), Fire Walls (CISCO ASA’s), Syslogs (Windows and Linux), Security Application Notifications.• Monitors Network Management System, EM7 Science logic for SNMP feeds and various other SIEM like feeds into an enterprise executive dash boards for network operations.• Administers CISCO Fire Power that coordinates Intrusion Prevention Systems (Source Fire IPS) throughout the network. Updates community signatures, Geo-location data, and Advanced Malware Protection (AMP) feeds from CISO. Creates local signatures for blocking malware and Intelligence Community and US CERT warnings and alerts.• Sole point of contact, administration, and engineering for Raytheon Trusted Gateway Solution (TGS) Cross Domain Solutions.

Jul 2016 - Dec 2016

Senior Information Security Engineer

Arlington, Va, Us

• Responsible for the integration of various Security Information Event Management (SIEM)s into an Enterprise Security Management (ESM) handling various Common Event Format (CEF), which include: Intrusion Prevention Systems/ Intrusion Detection Systems (IDS/IPS), Fire Walls (CISCO ASA’s), Syslogs (Windows and Linux), Security Application Notifications like TripWire, Symantec EndPoint Manager, Nessus Vulnerability Management asset scans. • Helped Identify optimization in architecture enabling a recovery of $750K in capital while delivering commensurate enhancement to information flow and utilization.• Oversaw the implementation of two ESM suites governing infrastructure and feeds comprising a Computer Emergency Response Team (CERT) governing over identified Critical Infrastructure and Key Resources (CIKR).• Proficient in ArcSight and Splunk architecture, SNORT, Source Fire, nGenius (NetFlow), Secure Socket Layer Man In the Middle Monitoring.

Sep 2015 - Jul 2016

Senior Information System Security Engineer (Isse)

Herndon, Virginia, Us

• Ensured cyber security requirements were effectively integrated into information systems through purposeful security architecting, design, development, and configuration. • Defined, plans, designs, and evaluates information security systems and architecture• Conducted certification, testing, and reporting per Risk Management Framework (RMF) and NIST 800-53; identified deficiencies (POA&M) and provided recommendations for remediation• Performed system administration, conducted audits, analyzed logs and reporting systems, vulnerability management applications, and continuous monitoring capabilities• Participated in the change management process (CMP), and assessed security impact of proposed changes• Created and maintained existing information system security documentation, including System Security Plans (SSP), SCTM (Security Control Testing and Monitoring)

Jun 2015 - Sep 2015

Senior Threat Analyst

Herndon, Virginia, Us

• Senior Threat Analyst supporting Director of National Intelligence (DNI), Intelligence Community Security Coordination Center (IC SCC). Serves as a Senior Watch Officer providing Incident Response for 17 Intelligence Community partners, supporting ICD 502, "Integrated Defense of the Intelligence Community Information Environment", for Top Secret, Secret (Classified), Sensitive But Unclassified (SBU), and Unclassified National Intelligence Program (NIP) Funded networks.• Provided Intelligence Community Vulnerability Management reports, documents, and advisories of emergent threats, notifications, and Information Systems Vulnerabilities or Exploits.• Served as an Incident Case Management System Administrator, entered and managed Incident Reports and oversight of Creation, Updates, and Closings for the IC Information Environment (IC IE).• Provided Technical Reports, Executive Summaries, and various managerial reports with respect to Community Partners (Tier 1) Computer Incident Response Teams (CIRTs), Chief Information Security Officers (CISOs), and Chief Information Officers (CIOs).

Mar 2014 - Jun 2015

Information Systems Security Officer

Mclean, Va, Us

• Applied the Risk Management Framework, NIST 800-53, ICD 503, and/or DJSIG for Accreditation and Authorization of Sensitive Compartment Information Local Area Network.• Worked with an analyzed network security configurations, operating systems, and application vulnerability detection, analysis, and eradication of malicious intrusions into network architecture and Security Operation Center Design.• Performed Vulnerability Assessment scanning tools (e.g. ACAS -preferred(Nessus and Security Center), Retina, WASSP, SECSCN, SRR, Nessus, SCAP Compliance Checker (SCC) in tandem with DISA Secure Technical Implementation Guide (STIG) Viewer)• Reviewed and Analyzed security configurations of OS, DBMS, network infrastructure, and custom GOTS tools• Prepared and Reviewed SSPs, Responses to CONOPS, POA&Ms, and other Body of Evidence documentation• Provided briefing summaries of new or changes to Government standards and mandated regulations• Created documentation to support sites and system Authorization and Accreditations (e.g., SSAA short and long forms, supporting diagrams and documentation, findings reports)• Provided briefings, white papers, security recommendations, and suggestions for process improvement

Dec 2014 - Jun 2015

Lead Senior Cyber Security Sme

Johns Creek, Ga, Us

• Served as Senior Information Analyst for 14 IA professionals delivering Incident Response, Network Monitoring, Forensics, Vulnerability Management, Security Engineering, Public Key Infrastructure/Public Key Encryption, Certification and Accreditation (C&A) or now known as Authorization & Accreditations (A&A), and Risk Management services to the Joint Chief of Staff, network hosting over 60 Information Systems and Applications serving over 7,000 users.• Facilitated the security engineering and hardening of the current network. Proposed the installation of network Intrusion Prevention System, CISCO Network Access Control, and Remediation System, DoD’s Assured Compliance Assessment System (ACAS), consisting of Security Center; Nessus Scanner; Passive Vulnerability Sensors, and 3D Map.• Served on Configuration Control Board and Engineering Review Board as senior IA Analyst.• Lead the effort for transition to DoD RMF based NIST 800-53, 53a, 37 and CNSSI 1253 from DoD DIACAP.

Jun 2013 - Mar 2014

Senior Information Assurance Engineer

Mclean, Va, Us

• Supported development of Data Center Security Architecture (DCSA) frame work with emphasis on Data Storage and Data Management Protection for the DoD Wide effort comprising the Joint Information Environment (JIE).• Served as main representative in Committee on National Security Systems Architectural Working Group, facilitating Engineering for Federal SECRET Fabric through use of Defense Information Systems Network (DISN) connections, including COMSEC and Network Encryption and Protocols, and establishment of Minimum Information Security Engineering elements and security posture for connections.• Engaged in National Security Automation Strategy effort led by National Security Agency (NSA), Department of Defense Automation, Technology & Logistics (AT&L), National Institute for Standards and Technology (NIST), and Department of Homeland Security (DHS) senior IA Engineers.• Collaborated on Tactical Edge Computing Center, Independent Computing Nodes, and Core Data Center architecture of the Joint Information Enterprise (JIE) componentry as well as Resiliency Framework.• Provided guidance, technical analysis, and support to Committee of National Security Systems Risk Management Board and DoD Federal connections between DoD & DoD Partners: NSA, DNI, DHS, FBI, DOJ, DOE, MDA, etc.• Collaborated on drafting Policy concerning the DoDI 8510.1, Risk Management Framework, DoDI 8500.1, Cyber Security as well as several CNSS instructions, CNSSI 1253, CNSSP 29, National Secret Enclave Connection Policy, CNSSI 1300, Instruction for National Security Systems, Public Key Infrastructure X.509 Certificate Policy.

Jun 2012 - Jun 2013

Branch Chief Certification & Accreditation; Disanet Service Mgmnt Cntr

Us

• Served as Branch Chief for DISA Network Management Center, providing 24 X7 hour help-desk, network monitoring, incident reporting, response, and network maintenance throughout 22 worldwide, DISANet locations. • Served as Branch Chief for the Information Assurance, Certification and Accreditation (C&A) DISA. Managed C&A for 308 systems through Defense IA C&A Process (DIACAP), as well as their Connection Approval Process (CAP) networked-interconnectivity include Network Encryption and Communication Security (COMSEC) Management. • Selectively chosen as Officer In Charge (OIC) of DISA Support Element – Iraq during Operation New Dawn facilitating and supporting communications for U.S. Forces Iraq (USFI) during the drawdown and subsequent transition to Department of State US Mission – Iraq (USMI). • Supervised Seven (7) GS2210-14’s, Three (3) GS2210-13’s, Two (2) GS2210-11, and 55 contractors performing network management, Certification and Accreditation, and DISA Support Element Iraq Network Services management.• Selectively chosen as DISA’s DoD/IA Security Accreditation Working Group (DSAWG) member; DoD Information Systems Network (DISN) FLAG Panel O6/GS15 working group; DIACAP– Technical Advisory Group (DIACAP -TAG) representative.• Identified methods and strategies providing Network Monitoring Security using existing networking equipment into a consolidated network operations center Regional Computer Network Defense (CND) recapturing over $30M per year in out-sourced CND Service provider costs.• Capitalized on Network Operations Center design saving over $3M annually in Command Signal Service Designator (CCSD) resources in newly constructed, $370M dollar, state-of-the-art Information Systems Facility for DISA• Helped instrument Data Center consolidation of DISA’s five Arlington locations into new FT Meade complex, guided C&A of 90+ systems.

Jan 2009 - Feb 2012

Logistics Officer

United States Navy

- Certified Operational Research Systems Analysis (ORSA) and Certified Logistic Management championed and implemented procedure capitalizing on over $1M in annual transportation expenditures.- Headed and directed line item inventory from decommissioning ships to fill shortfalls within other area ships, saved over $3M in transportation and procurement cost for 7 regional vessels.- Served as Regional Y2K, Information Systems coordinator for Commander Pacific Naval Surface Group Pacific Northwest and 11 vessels and three shore stations reporting to Commander Naval Surface Pacific.• Navy Logistics Officer specialized in business and logistics management, including supply chain management, integrated logistics support, systems inventory management, transportation, information systems and technology, operational analysis, acquisition and contract management, financial management, operational logistics, and program management. • Specifically served as OIC Finance for an Organization annually executing $20M of 0100 (O&M) appropriated funds supporting 57 reporting units across the United States and territories. Provided complex Operational Research Systems Analysis (ORSA) and budgetary Programming, Planning, Budgeting and Execution (PPB&E) formulation and correlation of reports required in the Future Years Defense Program (FYDP) and financial plan for the Program Objective Memorandum (POM).

Jul 1994 - Jan 2009
5 education records

Channing Thomas education

Ms, Information Systems Management

Univeristy Of Phoenix

Operational Systems Research Ananalysis, Data Modeling/Warehousing And Database Administration

Naval Postgraduate School

Bs, Civil Engineering

University Of Arizona

College Prepatory

Boost San Diego, Ca

Gen Education, General Education

Steamboat Springs High School
FAQ

Frequently asked questions about Channing Thomas

Quick answers generated from the profile data available on this page.

What company does Channing Thomas work for?

Channing Thomas works for Prime-Time/Leidos.

What is Channing Thomas's role at Prime-Time/Leidos?

Channing Thomas is listed as Cyber Incident Analyst and Forensics at Prime-Time/Leidos.

What is Channing Thomas's email address?

AeroLeads has found 1 work email signal at @mantech.com for Channing Thomas at Prime-Time/Leidos.

What is Channing Thomas's phone number?

AeroLeads has found 1 phone signal(s) with area code 781 for Channing Thomas at Prime-Time/Leidos.

Where is Channing Thomas based?

Channing Thomas is based in Gainesville, Virginia, United States while working with Prime-Time/Leidos.

What companies has Channing Thomas worked for?

Channing Thomas has worked for Prime-Time/Leidos, Deutsche Bank, Bae Systems Information And Electronic Systems Integration Inc., David Hale Associates, and Raytheon Iis.

How can I contact Channing Thomas?

You can use AeroLeads to view verified contact signals for Channing Thomas at Prime-Time/Leidos, including work email, phone, and LinkedIn data when available.

What schools did Channing Thomas attend?

Channing Thomas holds Ms, Information Systems Management from Univeristy Of Phoenix.

What skills is Channing Thomas known for?

Channing Thomas is listed with skills including Information Assurance, Dod, Security, Defense, Diacap, Program Management, Military, and Vulnerability Management.

Find 750M verified contacts

Search by job title, company, industry, location, and seniority. Export verified B2B contact data when you need it.