Drew Marmo

Drew Marmo

About

Detail

Cloud Certification and Compliance Leader
Puyallup, Washington, United States

Timeline


work
Job
school
Education
folder
Project
flag
Award

Résumé


Jobs verified_user 0% verified
  • Exabeam
    Product Line Manager, Engineering Compliance
    Exabeam
    Jan 2023 - Current (3 years 9 months)
    Leading and supporting Exabeam's product development efforts from inception to delivery with a focus on compliance, as well as advancing Exabeam's own certification journey into new domestic and global markets (e.g., FedRAMP, SOC 2, ISO, IRAP, ISMAP, etc.). In addition to maintaining and pursuing new certifications, this role was tasked to setup a GRC application, create 'common control' model for scalability, and work with other internal stakeholders for certification-related process improvement.
  • Cisco
    Leader, Federal Compliance Strategy
    Cisco
    Apr 2021 - Oct 2022 (1 year 7 months)
    Built and led the Global Cloud Certification's public sector group with efforts related to FedRAMP, CMMC, and SLEd (StateRAMP). Ensures the team of engineers, cloud architects, third-party vendors, and program managers support a broad range of compliance objectives. These objectives include but are not limited to certification readiness exercises, documentation development, program management, annual certification renewals, and ad-hoc advisory services for the entirety of Cisco's XaaS portfolio.
  • Cisco
    Cloud Authorization Engineer
    Cisco
    Jun 2020 - Apr 2021 (11 months)
    Supported the Global Cloud Certification team with global regulatory cloud certifications as well as annual renewals for Cisco cloud offering certifications. Additionally, provided technical guidance on
    the implementation and documentation of the cloud certification requirements, ensuring each certification was compliant with relevant regulatory and certification security requirements (e.g. FedRAMP, SOC2, ISO 27001, ISO 27017, ISO 27018, etc.). Cisco offers upwards of 70+ unique product offerings of which ~30 were addressed by the Global Cloud Compliance team.
  • Coalfire
    Consultant | SOC Assurance
    Coalfire
    Feb 2020 - Jun 2020 (5 months)
    Conducts audits/assessments including audit plan preparation, review of documentation and evidence, evaluation of procedures, and client interviews with small, medium, and large enterprises. Prepares, reviews, and approves advisory or assessment reports (SOC 2 Type 1/2) as well as advise clients on compliance activities as they pertain to AICPA's Trusted Services Criteria (TSC). Proficient with on-premise collocation and cloud-based environments (e.g., AWS, Azure, and GCP) in regards to examination, implementation, and ongoing compliance requirements. Thorough knowledge of cloud architecture components such as but not limited to Server/OS management, multi-tenancy, virtualization, orchestration, SDLC processes, disaster recovery, and third-
  • Coalfire
    Consultant - FedRAMP & Assurance Services
    Coalfire
    Apr 2018 - Jan 2020 (1 year 10 months)
    Lead information security consultation within on-premises and cloud-based environments in accordance with NIST SP 800-53 (e.g., FedRAMP/FISMA), NIST SP 800-171 (DFARS & ITAR). Provided cloud (e.g., AWS, Azure, GCP) architecture advisory to support client initiatives and to assist with ongoing regulatory demands.

    Developed system security plans, change management plans, disaster recovery & contingency plans, incident response plans, and continuous monitoring programs. Provided direction for scheduling, project sequencing, and resource management; assisted with managing client expectations and project management. Prepared, reviewed, and/or updated, and maintained IT Security supporting artifacts for ongoing assessments. Provided in
  • Z
    Sr. Information Security Consultant
    Z7 Networks
    May 2014 - Mar 2018 (3 years 11 months)
    Provided government-focused information security consulting to both financial and defense industries. Developed and coordinated information security programs. Conducted risk assessments and remediation efforts. Extensive use of NIST SP 800-53/171 control language for FARS/DFARS, and the ITAR guidance. Developed and enforced vendor management policies and procedures. Developed and delivered presentations on defense regulations and cybersecurity strategy to Washington State defense contractors. Led small teams of engineers and technical SMEs to ensure compliance.
  • H
    IT Manager
    Hampton Roads Chamber of Commerce
    Jul 2012 - May 2014 (1 year 11 months)
    Managed the organization’s IT infrastructure, ensuring quality service delivery to 30+ end users and educated staff on information security best practices. Utilized Windows SBS 2008 R2’s components such as: Active Directory, Exchange 2007, SQL, WSS 3.0, to perform daily functions. Worked with managed service provider to triage IT-related incidents.
  • Old Dominion University
    Finance Director
    Old Dominion University
    Jan 2010 - Jan 2011 (1 year 1 month)
  • S
    Telecommunications Specialist
    Sunwest Management
    Mar 2007 - Mar 2009 (2 years 1 month)
  • Educational Services, Inc.
    Corporate Assistant
    Educational Services, Inc.
    Jun 2002 - Jul 2003 (1 year 2 months)
Education verified_user 0% verified
  • Strome College of Business
    B.S. Political Science, Political Science and Government / Management
    Strome College of Business
    Jan 2010 - Jan 2013 (3 years 1 month)
  • J Sargeant Reynolds Community College
    Transfer, Business Administration and Management, General
    J Sargeant Reynolds Community College
    Jan 2007 - Jan 2010 (3 years 1 month)
Projects (professional or personal) verified_user 0% verified
  • #
    #humanfirewall
    Sep 2017 - Current (9 years 1 month)
    The #humanfirewall project was created to bring cyber awareness into the community. For now the community is limited to Olympia and Lacey Washington; however, it is my goal that someday our message, the model in which we will build a coalition upon, can be implemented within communities nationwide.

    The general model, simply put, is this:
    - Promote information security best practices to SMBs
    - Encourage the dissemination of knowledge among peers across multiple industries
    - Empower business leaders by providing resources that may otherwise be unavailable
    - Prevent malicious cyber activity within communities

    The #humanproject is not too different from successful programs like 'Neighborhood Watch' o
Awards verified_user 0% verified
  • H
    Employee of the Month
    Hampton Roads Chamber of Commerce
    Oct 2012
    Awarded the Employee of the Month award for handling a company-wide infrastructure outage (IT).
This is a community-created genome.