Simon Goldenberg
I help clients understand and meet cybersecurity requirements. Cyber Risk Specialist Senior at Deloitte Advisory
- Role
- Specialist Senior at 德勤
- Location
- Arlington, VA, US
- LinkedIn followers
- 500 followers
About Simon Goldenberg
I use my love of teaching and my 20 years’ experience to clearly explain cybersecurity requirements to development teams and managers, so they can bring their systems into compliance. I have performed over sixty successful Assessment and Authorization (A&A) efforts for Federal information systems, the process that leads to an Authorization To Operate (ATO) certification, using the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) and the DoD DIACAP framework. I’ve also worked with the HIPAA Security Rule (HSR). I helped one commercial organization prepare for its first A&A under the NIST RMF, and another update its cybersecurity continuous monitoring program. I’m a co-author of a white paper on cybersecurity issues in 3D printing, which leveraged my science education with my cyber experience. I hold the Security+ce and CISSP certifications.
Experience
Specialist Senior
Dec 2009 — Present · Rosslyn, VA, US
Current Client is US Census Bureau Office of Information Security• Role is to assess how well computer systems are meeting security requirements• Under National Institute of Standards and Technology (NIST) Risk Management Framework (RMF)• Requirements from NIST Special Publication 800-53, Revisions 3 and 4. Assessment types:• Initial Assessment & Authorization (A&A) for Authority To Operate (ATO) certification• Re-assessments of security findings and remediation• Information Security Continuous Monitoring (ISCM)Provide detailed and timely feedback to development teamsPerformed over 60 system A&A assessments for ATO, to date, for current client Leading team of four assessors for Information System Continuous Monitoring, since March 2017Innovations/Improvements: • Developed and maintained ISCM schedule, developed ISCM scheduling tools, documented processes for A&A and ISCM, made process improvements• Supported addition of vulnerabilities to RMF risk scoring methodology. Prior scoring was based solely on NIST RMF A&A compliance.• Supported development of an evidence guide for assessments of NIST RMF controlsGovernment client team won a gold medal from Department of Commerce for the RMF work I supported.Awards: Deloitte Applause Award: July 2015, “Moments That Matter” November 2014
Education
Admiral Farragut Academy
High School Diploma
1973 — 1977
The University of North Carolina at Chapel Hill
BS, Physics
1977 — 1981
The University of North Carolina at Chapel Hill
PhD, Physics
1981 — 1988
Skills
- IT Strategy
- Defense
- Dod
- Technical Writing
- Unix
- Information Security
- Information Security Management
- System Administration
- Analytical Skills
- Linux
- Systems Engineering
- Government
- Governance
- Vulnerability Management
- IT Management
- Integration
- Policy
- Diacap
- Information Technology
- Security Clearance
- Risk Assessment
- Computer Security
- Security Policy
- Cissp
- Nist
- Cyber Security
- Training
- Vulnerability Assessment
- Testing
- Government Contracting
- Risk Management
- Software Documentation
- U.s. Department of Defense
- Information Assurance
- Military
- Security
- Pmo
- Analysis
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.