Keith Pham

Keith Pham Email and Phone Number

Senior Manager, Tech and Data Risk and Oversight @ Capital One
Fairfax, VA, US
Keith Pham's Location
Fairfax, Virginia, United States, United States
Keith Pham's Contact Details

Keith Pham personal email

About Keith Pham

Cyber risk and AI leader whose career journey has traversed border stations, aerospace, the Pentagon, and the US Intelligence Community. More recently, I have served the Big Four, MBB, and the Financial sector in a variety of cyber roles, managing multiple security programs to include establishing strategic direction, overseeing implementation, and evolving the programs over time to contend with the shifting cybersecurity landscape, including implementation of artificial intelligence (AI) cyber risk management.I'm also an Information Security Ph.D. with an academic focus in deploying Adaptive Cyber Defenses (ACD) to mitigate advanced persistent threats (APTs). I have received honors both professional and academic, including Employee of the Year and the Best Paper Award of the international SECRYPT security conference. In my post-doctorate work, I have collaborated on several publications on quantum computing, blockchain/NFTs and AI. I am an I3P Cyber Fellow.

Keith Pham's Current Company Details
Capital One

Capital One

View
Senior Manager, Tech and Data Risk and Oversight
Fairfax, VA, US
Website:
capitalone.com
Employees:
63917
Keith Pham Work Experience Details
  • Capital One
    Senior Manager, Tech And Data Risk And Oversight
    Capital One
    Fairfax, Va, Us
  • Capital One
    Senior Manager, Technology Risk And Oversight
    Capital One May 2024 - Present
    Responsible for Capital One programs in Workforce Productivity, Asset Management, and High Risk Tech Change under the IMPACT Technology Risk Managment (TRM) organization.
  • Mckinsey & Company
    Cyber Practice Lead - Global Energy And Materials (Gem)
    Mckinsey & Company Jun 2022 - May 2024
    Responsible for overseeing the security posture of the McKinsey Global Energy and Materials (GEM) practice using internal frameworks based on the NIST CSF.Directed program vision, roadmap, secure product design and maintenance, control implementation and compliance, and organizational risk governance. Collaborated across engineering, risk, privacy, and legal, both at Firm and practice levels. Lead practice audits and security testing. Represented security in client and partner interactions, growing firm-client security engagement practice and relationships. Drove firm development and implementation of artificial intelligence cyber risk management framework.
  • Deloitte
    Lead Cyber Enterprise Architect And Specialist Master
    Deloitte Jan 2019 - Jun 2022
    Lead the team which developed Department of State (DOS) official Risk Governance, coordinating with disparate DOS agency sub-organizations in collaboration with the DoS Director of Assessment and Authorization, leveraged experience and subject matter expertise, serving as the authoritative department-wide standard for RMF implementation. Enterprise Architect and Delegated Authorizing Official Representative (DAOR) at a US Intelligence Community (IC) Agency supporting the security accreditation process in accordance with the NIST Risk Management Framework (RMF) in a DevOps CI/CD environment. Responsible for advising the Designated Authorizing Official (DAO) of cybersecurity risks associated with information systems.Privacy RMF Lead at the Defense Health Agency (DHA) conducting Privacy Risk Assessments (PRAs) and HIPAA Safeguard Reviews (HSRs) in accordance with the OMB Circular A-130. Responsible for briefing senior personnel (e.g. Chief of Privacy) on security matters and emerging trends.Cybersecurity Subject Matter Expert serving the US Agency for International Development (USAID), conducting security architecture reviews.Onsite Project Lead at the Pentagon supporting the US Joint Staff (JS) J6 Command, Control, Communications, and Computers Cyber Directorate, reporting to the J6 Chief of Cybersecurity/Enterprise Risk Management. Responsible for the JS security accreditation process in accordance with the NIST SP 800-37 Risk Management Framework (RMF). Team CPAR performance was evaluated and rated as Exceptional, noting deliverables were of the highest quality.
  • Northrop Grumman Corporation
    Lead Sr Cyber Information Assurance Analyst And Cyber Software Engineer
    Northrop Grumman Corporation Feb 2014 - Dec 2018
    Fair Lakes, Va And Herndon, Va
    Led DHS Trusted Internet Connection (TIC), Security Architecture Review (SAR), F-CND/FIRE, and assessments in support of the Enterprise Network Service Support (ENSS) program for the DHS Federal Network Resilience (FNR) branch. Conducted assessments in accordance with the FedRAMP Security Assessment Framework and the NIST Cybersecurity Framework.Lead Northrop Grumman FNR Cybersecurity Reference Architecture development efforts to provide federal agency guidance to securely implement technologies. New material included cloud computing guidance, utilization of FedRAMP, and the negotiation of service-level agreements (SLAs) with external service providers.Subject matter expert for NGTS Strategic Programs Support (SPS) for systems compliance with the DFARS/CMMC, NIST SPs (800-53, 800-171), and supported Continuous Monitoring and Diagnostics (CMD) as a service (CMDaaS) guidance, incorporating cloud-based guidance and developing the Concept of Operations (CONOPS).Subject matter expert supporting Resilient Systems Independent Research and Development (IRAD), presenting solutions to potential customers and clients, with emphasis on advanced MTD-related research and implementation. Speaker at the Northrup Grumman TechFest and TechExpo showcase.
  • Global Network Systems
    Deputy Program Manager
    Global Network Systems Mar 2011 - Feb 2014
    Mclean, Va
    Deputy Program Manager and Principal Security Specialist serving the Security and Technology Policy (STP) Branch ST&E team, leading ST&Es in support of DHS CBP in order to ensure compliance with the Federal Information Security Management Act (FISMA) of 2002. Independently responsible for testing development and operational systems for compliance with defined NIST SP 800-53 and DHS Sensitive Systems Handbook (SSH) 4300A security requirements as documented with the security Requirements Traceability Matrix (RTM). Provided recommended technical, operational and management mitigations to address vulnerabilities exposed through assessment.Awarded Employee of the Year (2012)
  • Pragmatics, Inc.
    Security Engineer
    Pragmatics, Inc. Sep 2009 - Mar 2011
    Mclean, Va
    As a member of an IV&V team, performed Security Test and Evaluations (ST&Es) in support of DHS USCIS. Independently responsible for testing development and operational systems for compliance with defined NIST 800-53 and DHS SSH 4300A security requirements as documented with the security requirements traceability matrix. Presented with the Chairman's Award for Outstanding Technical Service for the ST&E automation work performed on behalf of USCIS.
  • Pragmatics, Inc.
    Systems Engineer
    Pragmatics, Inc. Aug 2008 - Sep 2009
    Mclean, Va
    Responsible for management of asset resources, including installation and secure configuration of DHS Science and Technology (S&T) server equipment. Developed prototype SharePoint 2007 portal for tracking and to aid in Operations and Maintenance activities. Produced regular network status-related reports using enterprise tools: McAfee Web Gateway, Tripwire Enterprise, and Altris CMDB. Developed and documented Standard Operating procedures for these tools and the use of the portal.

Keith Pham Skills

Information Security Information Assurance Security Network Security Vulnerability Assessment Nist Nessus Computer Security Software Engineering Fisma Penetration Testing Sdlc St&e Windows Server Top Secret Nmap Webinspect Nist 800 53 Enterprise Architecture Integration Python Xml Dhs Risk Management Framework Active Top Secret Dfars 252.204 7012 Compliance Networking Defense U.s. Department Of Defense Information Technology Sharepoint Data Visualization Java Visual Basic Data Science Machine Learning Security Risk Operational Risk Operational Risk Management

Keith Pham Education Details

Frequently Asked Questions about Keith Pham

What company does Keith Pham work for?

Keith Pham works for Capital One

What is Keith Pham's role at the current company?

Keith Pham's current role is Senior Manager, Tech and Data Risk and Oversight.

What is Keith Pham's email address?

Keith Pham's email address is lu****@****ail.com

What schools did Keith Pham attend?

Keith Pham attended George Mason University, George Mason University, George Mason University.

What are some of Keith Pham's interests?

Keith Pham has interest in Rock Climbing, Fencing, Tennis.

What skills is Keith Pham known for?

Keith Pham has skills like Information Security, Information Assurance, Security, Network Security, Vulnerability Assessment, Nist, Nessus, Computer Security, Software Engineering, Fisma, Penetration Testing, Sdlc.

Who are Keith Pham's colleagues?

Keith Pham's colleagues are Jessica Martinez, Ronette Robinson, Frank Bednarz, Grayson Thomas, Cpa, Craig Lenders, Rory Moloney, Sangita Shah.

Not the Keith Pham you were looking for?

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.