About
In the Navy I'm the IT systems technician and security manager liaison for Navy Band Great Lakes, a 35 to 40 person organization. Formally designated the command's NMCI telecommunications officer and security manager liaison in November 2025, doing the work since 2024. It runs inside a federal system governed by RMF.
The job comes down to four questions about every person in the command. Who are they, what can they get to, who said they could, and is that still true.
System authorization requests come to me first. I check each SAAR-N for completeness and for the right access level, verify need-to-know before I route anything, and screen the package against the person's clearance status before it goes to the NSTC security manager. Adjudication authority sits there, not with me. That split is deliberate and I'm the gate in front of it.
Day to day the rest is entitlement provisioning across SharePoint and the file shares, granted by rank and collateral duty, and account lifecycle through NMCI. MAC actions, dormancy requests, principal-user changes, distribution list changes as people arrive and leave, all tracked to closure. I keep the clearance expiration roster current for the whole command. Most of it moves SSNs around, so all of it runs under the Privacy Act.
I also train incoming members on the enterprise systems and the security expectations attached to them. I have an M.S. in Education and 8 years of running instruction for adults, which is the half of security awareness work that's actually hard. Writing the content is easy. Getting it to land on someone who didn't ask for it is not.
I'm the first call when something stops working, too, which is more turning it off and back on again than I'd care to admit. Anything that has to touch the network itself goes to NMCI field services.
The other thing on my plate is the command's migration to the Navy's Nautilus environment, 32 enterprise workstations, which I own as its only IT resource. 15 were converted before the role came to me. The other 17 are mine through cutover.
On my own time I build security tools and write down what I learn doing them. The last one was a Python tool that reads SSH authentication logs and watches for brute-force attempts. I finished it as scoped, cut the milestones that would have been me rewriting fail2ban badly, and derived its detection threshold from 34 days of real auth logs rather than picking a number that looked reasonable. The write-ups cover what broke and what the data wouldn't support.
The civilian name for the day job is identity and access management, and past that, the risk and compliance side it answers to. That's the work I'm looking for in Chicago.
I hold a Secret clearance. Tier 3R investigation, adjudicated January 2023, Continuous Evaluation since January 2025. My Navy career ends June 30, 2027, and I'm available from late February 2027 through SkillBridge. Chicago area after that, hopefully the west or northwest suburbs.
How I got here
After my first tour with the Navy Fleet Bands, a supervisor gave me a line I've repeated to everyone I've mentored since. Prepare to stay in. Prepare to get out.
I was planning to get out at the time. Around 2008 I tried an online Information Systems program, which today would just be called development. The school did its best. I'd have learned more by building broken projects and letting the IDE tell me what was wrong with them.
The part that stuck happened outside the coursework anyway. I was rooting my Android phone, wiping cheap netbooks to put Ubuntu on them, and feeling extremely clever about running OpenOffice and Thunderbird. Somewhere in there I worked out that I wanted to work on the machines rather than write software for them.
I was about to put the Navy's tuition assistance toward ITT Tech when a coworker mentioned that a master's in education was open to me regardless of what my bachelor's was in. Mine is a Bachelor of Music in Jazz Performance. I took the master's.
Then a family situation made staying in the Navy the right call, so I stayed for a full career. I finished the degree, but I've decided not to teach K-12. What I learned about how adults take in new material has been useful anyway, and I expect it to keep being useful.
As my Navy career started winding down, I went back to computers. I looked at web development first and got talked out of it by two friends in the field. Sarcastic person that I am, I asked what I should be doing instead. Someone else at the table said cybersecurity.
The word scared me. It brought up hacking and counterhacking, about which I was as naive as anyone outside the field.
The argument that landed was about noticing. A musician spends decades hearing the one note that's out of tune, or the player whose time is sitting a hair behind. Nobody hands you a report saying so. You hear it, and then you go find it. That has turned out to be most of what log analysis is.
So far this has been a blast, and I'm looking forward to what's next.