Experience & credentials
Andrew Lowe
CISSP · CCSP · GRC & Information Security
Profile
20+ years across system administration, information security, GRC, and IT consulting. Experienced across nonprofit, private, public, and defense/government sectors, with working knowledge of NIST, CSF, FedRAMP, CMMC, PCI-DSS, HIPAA, and ISO frameworks.
Recent work
Manager, Frameworks & Certifications / Sr. Information Security Consultant
- Serve as ISSPO for two FedRAMP moderate/Class C certified programs, including the TiGRIS GRC platform.
- Lead and advise on FedRAMP 3PAO assessments, preparation, continuous monitoring, and client security programs.
- Function as a virtual CISO supporting HIPAA security rules and FISMA requirements.
- Lead AI use-case research and develop Python automation for vulnerability analysis and security tasks.
- Align TiGRIS with FedRAMP 20x Class C requirements while maintaining 800-53 Rev. 5 accreditation.
- Participate in FedRAMP 20x and Rev. 5 Collaboration Working Groups.
Research Architect
- Conducted qualitative and quantitative research to build technical data sheets that helped clients select appropriate security technologies.
- Consulted with clients on SIEM, configuration management, and related security technology decisions.
- Translated complex security and compliance topics into accessible technical blogs, analysis, and research papers for the wider community.
Program Manager
- Managed business clients launching and maintaining bug bounty programs for ethical hackers and security researchers.
- Advised clients on program startup, vulnerability report management, asset scoping, and long-term program expansion.
- Helped organizations improve researcher engagement and establish responsible vulnerability disclosure practices.
IT Risk & Vulnerability Management Analyst
- Managed vulnerability disclosure programs across AlienVault public domains and products, coordinating responsible handling, remediation, and disclosure.
- Contributed to HIPAA, PCI-DSS 3.2, SOC 2 Type 1 and 2, ISO 27001, and GDPR compliance for USM Anywhere and Central.
- Partnered with R&D on Ubuntu security hardening, AWS security best practices, penetration testing, and network segmentation testing.
- Owned inventory controls, log anomaly follow-up, vulnerability management workflows, control and document audits, and security configuration reviews.
- Supported security training content and served as a resource for the network security team on penetration testing, log analysis, and vulnerability testing.
Information System Security Manager / Operations System Engineer
- Established, documented, implemented, and monitored the information system security program in a multi-platform Linux and Windows environment.
- Maintained NISP compliance and supported accreditation using NISPOM, ISFO, DIACAP, and RMF processes.
- Operated and administered security tooling including Nessus, Graylog, McAfee ESM SIEM, and McAfee ePolicy Orchestrator.
- Trained Information System Security Officers, system administrators, and users on security posture, information integrity, and compliance practices.
- Received three consecutive Superior DSS inspection ratings and the 2016 James S. Cogswell Outstanding Industrial Security Achievement Award.
Information Management Officer / Information Assurance Engineer
- Led information assurance engineering for the 36th Infantry Division at Camp Mabry and established compliance practices aligned to DoD 8500 and RMF standards.
- Trained soldiers and IA team members in social engineering defense, vulnerability scanning and patching, network monitoring, Wi-Fi analysis, and system trend analysis.
- Standardized SOC procedures, gathered counterintelligence on social engineering threats, and prepared cyber intelligence briefings for commanders.
- Deployed in support of OEF from 2009—2010 as the unit Information Management Officer, maintaining automated systems for military police and field artillery units.