David Olkowski

David Olkowski Email and Phone Number

Information Assurance SME and Security Controls Assessor @ Tunuva Technologies, Inc.
Washington, DC, US
David Olkowski's Location
Washington DC-Baltimore Area, United States, United States
About David Olkowski

• Twenty-four years experience as an information assurance analyst performing federal government agency information security program support and security reviews for information system Assessment and Authorization (A&A) (also known as Certification and Accreditation (C&A)).• In-depth understanding of methodologies used to assess and test federal government information system security strengths and vulnerabilities as measured against National Institute for Standards and Technology (NIST) and Department of Defense (DoD) computer security guidance and standards. • Six years experience as network engineer building Pentagon systems as a DoD contractor and a United States Air Force computer communications officer.Specialties: Certified Information System Security Professional (CISSP); Certificate of Cloud Security Knowledge (CCSK) Certified Ethical Hacker (C|EH);GIAC Security Essentials (GSEC);Project Management Professional (PMP);National Security Agency-Information Assurance Methodology (NSA-IAM);NIST Certification and Accreditation;DIACAP; and Security Test & Evaluation (ST&E) with DoDI 8500.2 IA Control Validation Procedures, DISA Security Technical Implementation Guides (STIGs), NIST SP 800-53a, andTenable Nessus Vulnerability Scanner

David Olkowski's Current Company Details
Tunuva Technologies, Inc.

Tunuva Technologies, Inc.

View
Information Assurance SME and Security Controls Assessor
Washington, DC, US
Website:
tunuva.com
Employees:
34
David Olkowski Work Experience Details
  • Tunuva Technologies, Inc.
    Tunuva Technologies, Inc.
    Washington, Dc, Us
  • Tunuva Technologies, Inc.
    Cybersecurity And Risk Management Subject Matter Expert
    Tunuva Technologies, Inc. Sep 2024 - Present
    Leesburg, Virginia, Us
  • Modern Technology Solutions, Inc. (Mtsi)
    Cybersecurity Engineer
    Modern Technology Solutions, Inc. (Mtsi) Apr 2024 - Sep 2024
    Alexandria, Va, Us
  • Mcintire Solutions, Llc
    Security Controls Assessor
    Mcintire Solutions, Llc Sep 2022 - Apr 2024
    Chantilly, Virginia, Us
    Senior Security Controls Assessor (SCA) for a Federal government client. Performs assessment of security controls against six enterprise service systems and applications against Committee on National Security Systems Instruction (CNSSI) Number 1253, Security Categorization and Control Selection for National Security Systems, and NIST Special Publication (SP) 800-53, Security and Privacy Controls for Information Systems and Organizations. Prepares risk recommendations in Security Assessment Reports (SARs) based on results of interviews and demonstration on implementation of security controls with risk recommendation for the client Authorization Official (AO).
  • Tiag®
    Information Assurance Task Lead
    Tiag® Jul 2021 - Sep 2022
    Reston, Va, Us
    Leads team of information assurance analysts at the Office of Naval Research (ONR).Responsible for developing and executing effective initiatives for information assurance and management options to oversee ONR enterprise and AWS hybrid cloud enclaves.Leads risk management tasks including internal security controls assessment to attain and maintain Authorization to Operate (ATO) of ONR enclaves and business applications.Ensures the IA and Cybersecurity requirements for ONR systems are integrated into the system development lifecycle and are applied through the Risk Management Framework (RMF) lifecycle.Monitors and reports Command compliance with the Federal Information Security Management Act (FISMA), which includes providing Cybersecurity Awareness training, maintaining annual security plan, testing contingency plans, and performing annual security reviews, Privacy Impact Assessment (PIAs) and gaining and maintaining ATOs.
  • System High Corporation
    Senior Security Controls Assessor
    System High Corporation Jan 2020 - May 2021
    Chantilly, Virginia, Us
    Security controls assessor (SCA) for the Defense Advanced Research Projects Agency (DARPA) Strategic Technology Office (STO).Responsible for the assessment of 25 performer and partner Wide Area Networks (WANs), Local Area Networks (LANs), and stand alone systems at classified Special Access Program (SAP) against Joint Special Access Program (SAP) Implementation Guide (JSIG) for SAP systems and DoDI 8510.01, “Risk Management Framework for DoD Information Technology.”Provides risk recommendations of performer systems for Authorization to Operated (ATO) decisions for the DARPA Senior Authorization Official (SAO) and STO Program Security Officer (PSO). Evaluation of risk includes briefing the SAO and PSO with consideration of Department of Defense SAP, JSIG, and DARPA policies and mandates with consideration of mission success and risk appetite.Prior to internal promotion to STO SCA, served as lead DARPA SCA for classified enterprise information systems and networks.Responsibilities included oversight evaluation and continuous monitoring of secure configuration and compliance for the DARPA Authorization Official and Chief Information Security Officer (CISO) on the SAVANNAH SAP, ASCEND SAP, DARPA cyber range enterprise SAP network, DARPA Secret Network (DSN), and DARPA Secret Wide Area Network (DSWAN).Managed database reporting for a DARPA inventory of approximately 150 performer SAP systems for reporting to the DARPA AO. Tracks security control issues on performer SAP systems for failed compliance and current ATO status.Provided Subject Matter Expert (SME) representation and ad hoc risk analyses for the AO and CISO through participation in DARPA Information Technology Directorate (ITD) operations and security status meetings.
  • Saic
    Senior Security Controls Assessor
    Saic Mar 2018 - Jan 2020
    Reston, Va, Us
    Performs security control assessment at the Defense Advanced Research Projects Agency (DARPA) ranging in scope and scale from large agency enterprise networks to specialized SAP systems.
  • Engility Corporation
    Information Security Engineer
    Engility Corporation Jun 2016 - Mar 2018
    Reston, Virginia, Us
    Served as the security engineer on the Army Intelligence Campaign Initiatives Group (AICIG) project to build, operate, and maintain the Analytic Assessment Tool (A2T) application for the Department of the Army, Office of the Deputy Chief of Staff (ODCS) G-2 (Military Intelligence).Primary role involved evaluation of the security risk and compliance for the A2T application version currently in development through the Risk Management Framework (RMF) process. A2T is a multi-tier web application, business logic, data store, and report generation tool designed with RESTful architecture and a MongoDB database hosted on a Red Hat Enterprise Linux operating system.Functioned as the information security officer (ISO) and expert for assessing current application controls in compliance with DoDI 8500.01, "Cybersecurity," and DoDI 8510.01, "Risk Management Framework for DoD Information Technology." Categorized information sensitivity and selects, provides guidance for implementation, and assesses effective implementation for validation by the Army NETCOM Security Control Assessment Validator (SCA-V) and G2 Authorization recommendation.Served as liaison for AICIG to the Army INSCOM infrastructure hosting and G2 client organization through which he obtains support for inheritance and implementation of required security controls.Collaborates with the AICIG software development, quality assurance, and system administration teams in identifying vulnerabilities and directing mitigation actions to build and maintain the A2T system within security requirements.Managed A2T's integration in the Enterprise Mission Assurance Support Service (eMASS) Governance Risk Compliance (GRC) tool for entry, validation, management, and Plan of Action and Milestones (POA&M) of security controls, supporting artifacts, and vulnerabilities.
  • Lunarline, Inc
    Senior Security Engineer
    Lunarline, Inc Aug 2015 - Jun 2016
    Ashburn, Virginia, Us
    Security Engineer and Analyst for the BNY Mellon client in support of Ginnie Mae.Performed FISMA analysis on the Ginnie Mae General Support System (GSS), GinnieNet, Integrated Pool Management System (IPMS), and Unclaimed Funds System.Prepared analysis and briefs senior BNY Mellon management for tactical and strategic security program planning and budgeting to provide optimum risk management and continuous monitoring.Provided guidance and mentoring to Lunarline technical team at BNY Mellon to integrate their technical vulnerability scanning, audit analysis, and planning with Splunk and Nessus with client security program.Reviewed security controls on Ginnie Mae systems for compliance with NIST SP 800-53 R4 and FISCAM standards.Authored, drafted, edited, and reviewed required security documentation including the System Security Plan for the GSS.Prepared security control review and security documentation development for BNY Mellon’s Small Business Administration Fiscal Transfer Agent (FTA) system.
  • Tantus Technologies, Inc.
    Information Assurance Analyst
    Tantus Technologies, Inc. Aug 2011 - Aug 2015
    Arlington, Va, Us
    Information Assurance Analyst assigned to the U.S. Department of State (DoS) Bureau of Human Resources, Executive Office (HR/EX) System Development Division.Provided guidance and task management for the HR/EX Director and Government Program Managers for security of three internal and two external applications. Performed the annual security control assessments on all internal HR/EX systems including the Integrated Personnel Management System (IPMS), Human Resource Network (HRNet), Personnel Reporting and Statistics (PRAS) systems using the NIST SP 800-53A test cases against the system’s critical, vulnerable controls annually and a sampling of one third of all other controls. Communicated annual assessment results to the system owner, Information System Security Officer (ISSO), operations team lead, and system development lead formulating clear and measurable Plans of Action and Milestones (POA&Ms) for mitigation. Analyzed the security impact and required security control changes to support proposed introduction of changes to HR/EX production environment applications, software subsystems, and interconnections through the development of planned change comparative analysis reports.Coordinated the mitigation of vulnerabilities from A&A Security Assessment Reports (SAR) into and through POA&Ms and serves as the liaison between the independent assessment teams from the State Information Resource Management (IRM) Bureau, Information Assurance (IA) Assessment and Authorization division and the HR/EX system owner in order to manage the process to authorize, re-authorize, and report on the status of system owner designated continuous monitoring tasks. Prepared system administrators, database administrators and developers for security assessments through analysis of configuration settings at the operating system, database, and application levels.
  • Information Systems Security Association (Issa)
    Vp For Education, Northern Virginia Chapter
    Information Systems Security Association (Issa) Jan 2013 - Dec 2014
    Woburn, Massachusetts, Us
    • Serves in an elected position for the Northern Virginia Chapter of one of the premier professional associations with over 500 members in the information assurance/security career field.• Promotes, manages, and coordinates a 13-week study group for aspiring CISSP candidates.• Works with chapter membership in the information security field to assist in their career development through arranging effective instruction and learning methods and providing exam preparation guidance in the CISSP study group.• Reports and coordinates programs, scheduling, and budgeting with other elected and appoitned positions to promote the ISSA International and Northern Virginia chapter goals of growing the professional knowledge of our membership through networking and speaker events.• Coordinates the development of presentation materials for additional study groups within the information assurance career field including Certifed Ethical Hacker (CEH), Certified Secure Software Lifecycle Professional (CSSLP), and Certified Information Privacy Professional (CIPP).
  • Knowledge Consulting Group
    Primary Certifier
    Knowledge Consulting Group Sep 2009 - Aug 2011
    Reston, Va, Us
    Performed security control assessments and compliance monitoring for the TSA Chief Information Security Officer (CISO) and Information Assurance and Cyber Security Division.Evaluated, analyzed, monitored, and reported on the status of TSA information systems in accordance with the Federal Information Security Management Act (FISMA), National Institute for Standards and Technology (NIST) SP 800-53, Department of Homeland Security (DHS) Management Directive (MD) 4300A, and TSA MD 1400.3.Held security assessor responsibilities on critical, high visibility systems including TSANet, which is the administration’s primary General Support System (GSS); the TSA Security Operations Center (TSA SOC); Crew Vetting Program (CVP); and the TSA Contact Center (TCC). Managed security engineer teams in performance of technical vulnerability scans during security control assessments of systems to prepare for initial or renewal of authorizations to operate.Conveyed findings of managerial, operational, and technical vulnerabilities through a combination of briefing and written reporting for the CISO to determine the system’s operational risk and to support the Authorization Official’s authorization decision making.Represented the TSA Information Assurance and Cyber Security Division assessor team for ongoing efforts including the IT Security Technical Standards Working Group, System Configuration Control Board (SCCB), and U.S. airport regional outreach support. Assisted information system owners and management in understanding risks to system operation “as is” and develops strategies for risk mitigation and resolution.Provided leadership and oversight for TSA Information System Security Officers (ISSOs) through assigned system’s engineering and security lifecycles.
  • Nortel Government Solutions
    Sr. Information Assurance Analyst
    Nortel Government Solutions Sep 2006 - Sep 2009
    Fairfax, Virginia, Us
  • Sra International
    Information Assurance Analyst
    Sra International 2000 - 2006
    Falls Church, Va, Us
  • Sra International
    Network Engineer
    Sra International 1998 - 2000
    Falls Church, Va, Us
  • U.S. Air Force
    Network Engineer - Computer Communications Officer
    U.S. Air Force Jul 1994 - Sep 1998
    Randolph Afb, Tx, Us

David Olkowski Skills

Cissp Information Assurance Security Nist Vulnerability Assessment Computer Security Information Security Testing Fisma Network Security Dod Diacap Software Documentation Analysis Policy Pmp Networking Penetration Testing Program Management Auditing C&a Information Security Management Integration Disaster Recovery Ceh Information Technology Enterprise Architecture Security Clearance Nessus Firewalls Risk Assessment Computer Forensics Vulnerability Management Intrusion Detection U.s. Federal Information Security Management Act Compliance Itil Security Audits Risk Management Security+ Security Policy Vulnerability Ids Technical Training Project Management U.s. Department Of Defense Documentation

David Olkowski Education Details

  • George Mason University – Costello College Of Business
    George Mason University – Costello College Of Business
    Mba
  • University Of Notre Dame
    University Of Notre Dame
    Bachelor'S Of Computer Science
  • Canisius High School
    Canisius High School
  • Ccsk Plus
    Ccsk Plus
  • University Of Notre Dame
    University Of Notre Dame
    Computer Science

Frequently Asked Questions about David Olkowski

What company does David Olkowski work for?

David Olkowski works for Tunuva Technologies, Inc.

What is David Olkowski's role at the current company?

David Olkowski's current role is Information Assurance SME and Security Controls Assessor.

What is David Olkowski's email address?

David Olkowski's email address is ol****@****aic.com

What is David Olkowski's direct phone number?

David Olkowski's direct phone number is +157148*****

What schools did David Olkowski attend?

David Olkowski attended George Mason University – Costello College Of Business, University Of Notre Dame, Canisius High School, Ccsk Plus, University Of Notre Dame.

What skills is David Olkowski known for?

David Olkowski has skills like Cissp, Information Assurance, Security, Nist, Vulnerability Assessment, Computer Security, Information Security, Testing, Fisma, Network Security, Dod, Diacap.

Who are David Olkowski's colleagues?

David Olkowski's colleagues are Douglass Mcpherson, Winston Kim, Cj Waldron, Pmp, Tim Poppen, Robert Lamon, Jennifer Hales, Scott Spencer.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.