I am a U.S. Air Force veteran and federal IT professional who spent years making systems work before I started making them defensible. WellScript is where I document what that bridge actually looks like.
My background is in systems administration, Identity and Access Management, vulnerability remediation, endpoint compliance, and Splunk-based investigation — all within a federal healthcare IT environment. That technical foundation is what makes the compliance side make sense to me. I am not approaching RMF and GRC from a policy document. I am approaching it from the inside of the systems those policies are meant to protect.
I am currently building deeper expertise in RMF, eMASS, POA&M development, and ISSO-aligned cyber compliance work. WellScript is where I document the practical lessons — the ones that do not show up in a study guide but do show up in the work.
Everything published here is sanitized, generalized, or built from training and pilot environments. Nothing from this site reflects internal systems, personnel, or non-public operational details.
If the content here is useful to you — whether you are a sysadmin trying to understand where compliance fits, a new ISSO looking for plain-language explanations, or someone hiring for federal cybersecurity roles — then it is doing exactly what it is supposed to do.
Certifications and Training
- CompTIA Security+
- Splunk Core Certified User
- Security Blue Team Level 1 (BTL1)
- ICT ISSM/ISSO
- DHA RMF Process Training
- DHA Security Planning Course
- DHA eMASS Asset Module Course
- ESS Administrator 201 and Advanced 301 (ePO 5.10)
- J-6 CIO Lifeline (CIO 1000) and Mission Advance (CIO 2000)
- DHA Data Analysis and Visualization with Microsoft Excel