15+ years translating complex security, compliance, and change management requirements into clear, audit-ready documentation — across FedRAMP, ISO/IEC 27001, HIPAA, GDPR, and beyond. Currently expanding into blockchain, Web3, and decentralized security.
Wrote and maintained security documentation across commercial and government cloud products on AWS, Azure, and GCP. Delivered FedRAMP Readiness Assessment Reports, led ISO/IEC 27001 certification efforts, and compiled compliance documentation for NIST SP 800-53, RMF, SOC II, and CCPA audits — ensuring every control is traceable and defensible.
Supported DevSecOps documentation, CI/CD pipeline governance, and cloud environment compliance across three hyperscalers. Proficient in DITA/XML structured authoring in Adobe Experience Manager, with deep experience translating AI and cybersecurity concepts into actionable operational content for engineers and auditors alike.
Led the migration of documentation from legacy systems to cloud-based applications on AWS GovCloud and GCP, ensuring seamless transition and maintaining compliance with NIST 800-53 baselines and Section 508.
Designed and maintained knowledge base systems using AEM, Confluence, SharePoint, and Online Help Systems (Flare/RoboHelp). Curated technical articles, troubleshooting guides, and best practices for internal and customer use, improving search efficiency, reducing support ticket volume, and introducing AI (primarily ChatGPT and Gemini).
Wrote, updated, and managed FedRAMP documentation including System Security Plans (SSPs), security policies and procedures, Configuration Management Plan, Continuous Monitoring Plan, and supporting artifacts for SaaS cloud offerings. Mapped controls to NIST 800-53 baselines and supported ATO processes across AWS and GCP environments.
Created clear, accessible end-user manuals, quick-start guides, and API documentation for SaaS platforms and cloud services. Ensured 508 compliance and translated complex features into user-friendly content for technical and non-technical audiences.
Evaluate the current security posture and documentation landscape, identify compliance gaps, and map existing controls to FedRAMP, NIST SP 800-53, ISO/IEC 27001, HIPAA, and SOC II requirements.
Author structured XML/DITA content in Adobe Experience Manager — policies, SOPs, runbooks, playbooks, and Agile user stories — using style guides and templates that reduce review cycles by up to 25%.
Lead change lifecycle execution — coordinating cloud migrations (AWS, Azure, GCP), CI/CD pipeline documentation, and cross-functional knowledge transfer aligned with ITIL Change, Incident, and Problem Management frameworks.
Maintain living documentation through Agile sprint cycles, recurring compliance audits, and continuous content governance — keeping security posture current, auditable, and ready for FedRAMP, SOC II, or ISO review at any time.
Let's build documentation, governance, and security programs that hold up under audit, under pressure, and under threat.