Summary
Overview
Work History
Education
Skills
Timeline
Generic

Charli Tompkins

Bellevue

Summary

Seasoned Information Systems Security Manager with 18 years of experience in strengthening cybersecurity for mission-critical systems. Led cross-functional teams in developing security documentation and executing CI/CD pipeline security assessments. Expertise in delivering secure solutions that enhance operational readiness for warfighters, including six years supporting the Air Force Weather System Branch.

Overview

10
10
years of professional experience

Work History

ISSM-Information Systems Security Manager

Apogee Engineering, LLC
Bellevue
08.2023 - Current
  • Acted as strategic lead ISSM and security advisor for five operational weather squadrons, strengthening security posture across 23 networked systems.
  • Led creation of critical security documentation including System Security Plans (SSP) and Incident Response Plans (IRP) to ensure compliance with government policies.
  • Performed vulnerability and risk analyses during all phases of the System Development Life Cycle (SDLC) to identify and mitigate potential threats.
  • Implemented new authorizing infrastructure for cloud environments, including Certificate to Field (CTF) authorization processes.
  • Applied OWASP Top 10 best practices to secure coding within cloud environments, mitigating vulnerabilities.
  • Provided cybersecurity leadership for mission-critical weather systems, including Joint Environmental Toolkit (JET).
  • Assisted in migrating global on-premise JET systems to the INC5 cloud environment with CI/CD pipelines.
  • Collaborated with cyber engineering and operational teams to develop and implement integrated security solutions.

Cybersecurity Analyst

Booz Allen Hamilton, BAH
Bellevue
06.2018 - 08.2023
  • Analyzed security incidents, identifying vulnerabilities and recommending targeted remediation strategies.
  • Conducted risk assessments to evaluate threats, recommending specific mitigation plans to enhance security.
  • Monitored network traffic for suspicious activities using advanced security tools.
  • Responded to breaches by investigating incidents and coordinating response efforts.
  • Collaborated with teams to implement security measures and enhance cybersecurity posture.
  • Developed and maintained security policies for organizational compliance.
  • Provided training on cybersecurity best practices and awareness programs.
  • Generated detailed reports on security findings, informing management and guiding decision-making processes.

ISSO - Information Systems Security Officer

Lockheed Martin
Colorado Springs
05.2016 - 07.2018
  • Conducted risk assessments to identify vulnerabilities in information systems.
  • Implemented security controls to safeguard data from unauthorized access.
  • Collaborated with teams to ensure compliance with industry security standards.
  • Responded to security incidents and coordinated recovery efforts effectively.
  • Evaluated new security technologies to enhance organizational defenses.
  • Performed risk assessments of existing IT infrastructure.
  • Evaluated network architecture designs to identify potential vulnerabilities.
  • Coordinated incident response efforts when a breach was detected.
  • Documented all changes made to the organization's IT infrastructure to ensure compliance with industry regulations.
  • Provided training sessions on cybersecurity best practices for employees.
  • Monitored network traffic for suspicious activities and potential threats.
  • Developed security policies to protect sensitive information and systems.
  • Supported Lockheed Martin’s GPS III Control Segment contract under SMC/SATAF.
  • Managed three junior ISSOs during 18-month medical leave of ISSM.
  • Participated in all stakeholder meetings and forums to ensure alignment.
  • Applied risk management framework and system development life cycle principles, creating supporting artifacts.
  • Executed vulnerability assessments, self-inspections, and continuous monitoring for effective risk management.
  • Utilized Splunk for auditing and dashboard creation to enhance visibility into system performance.
  • Configured IA audit tools, performing weekly audits on certification and accreditation activities.
  • Conducted routine network vulnerability scans using Nessus and SCC security tools.

Education

Bachelor of Science - Informations Systems Security

ITT Technical Institute
Omaha, NE
03-2012

Associate of Applied Science - Information Technology

ITT Technical Institute
Omaha, NE
03-2009

Skills

  • system security plans
  • incident response planning
  • vulnerability assessments
  • cloud security architecture
  • AWS cloud
  • NIST RMF compliance
  • NIST standards
  • OWASP and zero trust
  • Pipeline security assessments
  • Policy development
  • Access management
  • cybersecurity leadership
  • Access management
  • Risk analysis
  • Cloud security management
  • Security compliance monitoring
  • Vulnerability assessment
  • Team collaboration
  • Project leadership
  • Third-party risk management
  • Attention to detail
  • Digital forensics
  • Threat research
  • Cloud security
  • Security metrics
  • Vulnerability assessments
  • Intrusion detection
  • Cybersecurity strategy
  • SIEM management
  • Two-factor authentication
  • Secure coding practices

Timeline

ISSM-Information Systems Security Manager

Apogee Engineering, LLC
08.2023 - Current

Cybersecurity Analyst

Booz Allen Hamilton, BAH
06.2018 - 08.2023

ISSO - Information Systems Security Officer

Lockheed Martin
05.2016 - 07.2018

Bachelor of Science - Informations Systems Security

ITT Technical Institute

Associate of Applied Science - Information Technology

ITT Technical Institute
Charli Tompkins