Summary
Overview
Work History
Education
Clearance Level
Certification
Core Competencies
Accomplishments
Timeline
Generic

Nathaniel Torney

Alexandria

Summary

Senior GRC and Security Controls Assessor (SCA) with over 10 years of experience supporting enterprise information security, GRC, RMF, ATO, audit, and continuous monitoring efforts across government and regulated industries. Expertise in assessing and implementing security controls aligned with NIST SP 800-53, NIST RMF, ISO 27001, SOC 1/2, HITRUST, COBIT, GDPR, FedRAMP, and HIPAA. Hands-on experience developing SSPs, SARs, and POA&Ms; conducting security control assessments, audits, and risk assessments. Trusted advisor recognized for bridging technical and business stakeholders to drive risk-informed security decisions, and authorization readiness.

Overview

10
10
years of professional experience
1
1
Certification

Work History

Security Control Assessor

M9 Solutions
01.2025 - Current
  • Executed Security Control Assessments (SCA) and Security Test & Evaluation (ST&E) activities in alignment with the NIST RMF for federal information systems.
  • Supported system accreditation, continuous monitoring, and ongoing authorization efforts to maintain ATO status.
  • Developed and maintained comprehensive security authorization artifacts, including SSPs, SARs, and POA&Ms.
  • Conducted risk analysis and produced tailored security documentation to inform federal authorization decisions.
  • Leveraged automated assessment tools and RMF workflows to validate NIST SP 800‑53 control implementation and effectiveness.
  • Collaborated with system owners, engineers, and stakeholders to ensure secure technical design and control implementation.
  • Performed vulnerability assessments using Nessus and DISA STIGs, tracking remediation through POA&M processes.
  • Supported privacy compliance activities, including PIAs, PTAs, and SORNs.
  • Advised leadership on system risk posture, control deficiencies, and mitigation strategies.

Senior Security Analyst

KGS
Washington
01.2023 - 01.2025
  • Led USDA’s risk management program improvements, leading system audits and enhancing security protocols to exceed federal compliance standards.
  • Directed Cyber Risk Register management, developing KPIs and taxonomy to strengthen enterprise-wide risk reporting and monitoring.
  • Assessed and developed authorization packages for technical solutions.
  • Aligned security audits and compliance assessments with NIST 800-53 and FedRAMP, ensuring federal compliance readiness.
  • Partnered with stakeholders across departments to remediate critical risks, embedding risk governance practices into business objectives.
  • Guided federal clients through control implementation and assessment processes aligned with NIST 800-53, FISMA, and other federal frameworks.
  • Led vulnerability assessments using Nessus and DISA STIGs, coordinating remediation planning to reduce enterprise risk exposure.
  • Develop and maintain System Security Plan, Security Assessment Report (SAR), and Plans of Action and Milestones and other security documentation.
  • Supported security automation initiatives by documenting workflows and integrating tools to reduce manual compliance effort.
  • Developed and refined security policies and procedures, ensuring consistency with federal requirements and client-specific objectives.

Senior Governance Risk & IT Compliance Analyst II

Blue Cross Blue Shield
Michigan
01.2021 - 01.2023
  • Developed and implemented enterprise-wide security policies, procedures, and standards to ensure regulatory compliance with SOC 2, ISO 27001, and HIPAA.
  • Led vendor/third-party risk management activities, reviewing security due diligence, contracts, and compliance with regulatory frameworks.
  • Coordinated internal and external audit responses, maintaining timely and accurate evidence collection aligned with audit requirements.
  • Conducted risk assessments and managed corrective action plans (CAPs), driving continuous compliance improvements across business units.
  • Administered GRC platforms (LogicGate, MetricStream) to monitor audit tracking, risk register updates, and compliance workflows.
  • Partnered with Compliance and IT to align internal security controls with NIST 800-53, ISO, and HITRUST, ensuring readiness for external audits.
  • Improved compliance tracking by contributing to automated audit dashboards and developing streamlined processes for evidence collection.
  • Delivered concise risk and compliance reports to leadership, enabling informed decisions under strict deadlines and resource constraints.
  • Supported vulnerability management programs, coordinating remediation of high-risk findings with IT and application teams.
  • Developed dashboards and reports visualizing vulnerability and compliance trends for senior leadership decision-making.

Cyber Security & ERM Analyst

Federal Contract Engagements
Washington
01.2018 - 01.2021
  • Implemented NIST 800-53 controls and Provided audit evidence of scans, risk assessments, and remediation efforts to OIG, GAO, and external auditors.
  • Conducted client readiness assessments for FISMA audits and developed risk-based compliance roadmaps.
  • Facilitated enterprise risk workshops, reviews, and reporting to enhance risk governance and leadership oversight.
  • Managed Department of Navy OMB A-123 internal control testing and developed the MICP Plan, improving accountability and compliance with federal standards.
  • Developed the Department of Navy Enterprise Risk Profile and ERM Playbook to standardize enterprise risk practices across the organization.
  • Conducted security internal control reviews providing recommendations to strengthen baseline system security.
  • Supported security automation initiatives by documenting workflows and integrating tools to reduce manual compliance effort.
  • Developed and refined security policies and procedures, ensuring consistency with federal requirements and client-specific objectives.
  • Authored and updated vulnerability management policies, risk assessment templates, and reporting standards aligned with GDPR, HIPAA, PCI DSS, and SOX.

Systems Analyst (Windows/Linux)

Analyst Oracle
Columbia
01.2016 - 01.2018
  • Performed PCI/PII compliance risk assessments, ensuring regulatory alignment in system operations and security controls.
  • Conducted vulnerability scans, applied patches, and managed Active Directory as part of secure configuration and access control management.
  • Developed business continuity and disaster recovery strategies, mitigating operational risk and ensuring compliance with continuity standards.
  • Monitored logs and system events to identify risks and implement remediation measures consistent with compliance policies.
  • Conducted vulnerability scans and patching in Windows/Linux environments, supporting PCI/PII compliance requirements.

Education

Master of Science - Computer Forensics & Cyber Security

University of Baltimore
Baltimore, MD
05-2019

Associate of Science - Criminal Justice & Sociology

Morgan State University
Baltimore, MD
05-2015

undefined

undefined

undefined

Clearance Level

Secret

Certification

  • CompTIA Security + ce
  • CISSP
  • HITRUST

Core Competencies

HITRUST, ISO 27001, SOC 2 Type 2, GDPR, PCI-DSS, FedRAMP, OMB Circular A-123, NIST Publications (Controls, RMF, CRM & Governance), Risk assessments, Vulnerability analysis, Internal controls, Risk mitigation, CAPs, Cross-functional team leadership, Mentorship, Stakeholder engagement, Microsoft Office Suite, G-Suite, SQL, Active Directory, ServiceNow, Nessus, Wireshark, Encase, Autopsy, Remedy, Venminder, Logic Gate, Metric Stream, eMASS, PKI, Cryptanalysis, Malware Analysis, System Vulnerability Assessment, Incident Response

Accomplishments

  • Developed and implemented a risk management framework for the Department of State’s ERM Cyber Team.
  • Developed the Enterprise Risk Management Playbook for the Department of the Navy, a strategic resource now used to guide risk management practices organization wide.
  • Designed and implemented an organization-wide policy for Emergent Holdings that standardized cybersecurity practices, improving security compliance by 25%.
  • Contributed to cybersecurity awareness and training programs for over 200 employees, enhancing organizational understanding of cyber risk and best practices.

Timeline

Security Control Assessor

M9 Solutions
01.2025 - Current

Senior Security Analyst

KGS
01.2023 - 01.2025

Senior Governance Risk & IT Compliance Analyst II

Blue Cross Blue Shield
01.2021 - 01.2023

Cyber Security & ERM Analyst

Federal Contract Engagements
01.2018 - 01.2021

Systems Analyst (Windows/Linux)

Analyst Oracle
01.2016 - 01.2018

Master of Science - Computer Forensics & Cyber Security

University of Baltimore

Associate of Science - Criminal Justice & Sociology

Morgan State University
Nathaniel Torney