Francis Opoku-Frimpong
Lead Cybersecurity Architect Engineer @Astrion
Signup · Get unlimited contacts
WORK HISTORY
Lead Cybersecurity Architect Engineer @Astrion
Hanscom Air Force Base, MA, US
Ensure the security posture is maintained and compliant with Air Force cybersecurity policies.• Assist in developing system security documents (e.g, Security Risk Analyses, OPSEC Plans, etc.) per DoD and Air Force standards.• Support system Authorization and Accreditation (A&A) efforts, ensuring quality and completeness of RMF tasks.• Oversee system security configurations and PKI identification/authorization.• Manage user access control documentation per AFRIMS guidelines.• Ensure software, hardware, and firmware meet security configuration standards (e.g, STIGs/SRGs).• Follow configuration management procedures and obtain necessary approvals before implementation.• Coordinate changes with the ISSM and/or SCA.• Initiate cybersecurity exceptions, deviations, or waivers as needed.• Support the ISSM in fulfilling responsibilities.• Implement DoD cybersecurity policies and corrective actions for incidents and vulnerabilities.• Keep cybersecurity documentation current and accessible to authorized personnel.• Apply RMF across programs in alignment with NIST and Air Force policies.• Develop RMF documentation and update the POA & M to address vulnerabilities.• Manage system accreditation and ATOs via eMASS.
EDUCATION
University of Maryland Global Campus
Master of Science - MS, Cybersecurity Management and Policy
Kwame Nkrumah University of Science and Technology, Kumasi
Bachelor's degree, Banking and Finance
ABOUT FRANCIS OPOKU-FRIMPONG
An IT Security Assessor with immense years of combined experience in Federal Information Security Management Act (FISMA), Federal Risk and Authorization Management Program (FedRAMP), National Institute of Standards and Technology (NIST), Risk Management Framework (RMF) processes, Risk Assessment (RA), System Development Life Cycle (SDLC), as well as Contingency planning. Thorough understanding of NIST 800-53 Rev 4 and 5 security controls. Audit projects including Security Audit, RMF, COBIT, PCI DSS, HIPAA, SAS 70 SSAE 16/SOC and SSAE18. Knowledge of the process to obtain a system ATO and requirements to maintain the ATO. An IT professional with experience in vulnerability management, security control implementation, assessment and authorization, POA & M management, continuous monitoring, as well as risk assessment. Understanding of information technology concepts, cloud computing models (PaaS, SaaS, IaaS).
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.