D

Drew Marmo

About

Detail

GRC Strategist and Leader
United States

Contact Drew regarding: 
work
Full-time jobs

Timeline


work
Job
school
Education

Résumé


Jobs verified_user 0% verified
  • Exabeam
    Product Line Manager
    Exabeam
    Jan 2023 - Dec 2023 (1 year)
    Leading and supporting Exabeam's product development efforts from inception to delivery with a focus on compliance, as well as advancing Exabeam's own certification journey into new domestic and global markets (e.g., FedRAMP, SOC 2, ISO, GDPR, IRAP, ISMAP, etc.). In addition to maintaining and pursuing new certifications, this role was tasked to setup a GRC application, create 'common control' model for scalability, and work with other internal stakeholders for certification-related process improvement.
  • Cisco
    Leader, Public Sector Compliance Strategy
    Cisco
    Apr 2021 - Oct 2022 (1 year 7 months)
    Built and led the Global Cloud Certification's public sector group with efforts related to FedRAMP, CMMC, and SLEd (StateRAMP). Ensured the team of engineers, cloud architects, third-party vendors, and program managers supported a broad range of compliance objectives. These objectives included but were not limited to: certification readiness exercises, documentation development, program management, annual certification renewals, and ad-hoc advisory services for the entirety of Cisco's XaaS portfolio.
  • Cisco
    Cloud Authorization Engineer
    Cisco
    Jun 2020 - Apr 2021 (11 months)
    Supported the Global Cloud Certification team with global regulatory cloud certifications as well as annual renewals for Cisco cloud offering certifications. Additionally, provided technical guidance on the implementation and documentation of the cloud certification requirements, ensuring each certification was compliant with relevant regulatory and certification security requirements (e.g. FedRAMP, SOC2, ISO 27001, ISO 27017, ISO 27018, etc.). Cisco offers upwards of 70+ unique product offerings of which ~30 were addressed by the Global Cloud Compliance team.
  • Coalfire
    Assessor
    Coalfire
    Feb 2020 - Jun 2020 (5 months)
    Conducted audits/assessments including audit plan preparation, review of documentation and evidence, evaluation of procedures, and client interviews. Prepared, reviewed, and approved advisory or assessment reports (SOC 2 Type 1/2). Proficient with on-premise collocation and cloud-based environments (e.g., AWS, Azure, and GCP)
  • Coalfire
    Consultant
    Coalfire
    Apr 2018 - Feb 2020 (1 year 11 months)
    Lead information security consultation within on-premises and cloud-based environments in accordance with NIST SP 800-53 (e.g., FedRAMP/FISMA), NIST SP 800-171 (DFARS & ITAR). Provided cloud (e.g., AWS, Azure, GCP) architecture advisory to support client initiatives and to assist with ongoing regulatory demands. Gained experience with FedRAMP System Security Plan development and end-to-end FedRAMP knowledge.
  • Z
    Sr. Information Consultant
    Z7 Networks
    May 2014 - Mar 2018 (3 years 11 months)
    Provided government-focused information security consulting to both financial and defense industries. Developed and coordinated information security programs. Conducted risk assessments and remediation efforts. Extensive use of NIST SP 800-53/171 control language for FARS/DFARS, and the ITAR guidance.
  • H
    IT Manager
    Hampton Roads Chamber of Commerce
    Jul 2012 - May 2014 (1 year 11 months)
  • S
    Telecommunications Specialist
    Sunwest Management, Inc.
    Mar 2007 - Mar 2009 (2 years 1 month)
Education verified_user 0% verified
  • Old Dominion University
    Bachelor of Science in Political Science
    Old Dominion University
    Aug 2010 - May 2013 (2 years 10 months)