Trevor Lowing, CISSP, CCSP, CSSLP, PMP, CSM
CISO | Cybersecurity/Information Security Manager
Contact Information
Professional Status
Professional Summary
As the Chief Information Security Officer (CISO) at the U.S. International Development Finance Corporation (DFC), I am an award-winning Senior Information Technology Cybersecurity and Management Specialist with over 25 years of experience managing mission-critical enterprise and system programs for federal agencies and the Department of Defense.
I hold key certifications including Project Management Professional (FAC P/PM III & PMP) and Contracting Officer Representative (FAC COR III IT), and currently lead a team of more than 20 cybersecurity professionals.
My diverse skill set encompasses cybersecurity, compliance, enterprise risk management, disaster recovery, and continuity of operations planning. At DFC, I have spearheaded the development and implementation of our comprehensive cybersecurity program, including conducting security assessments across on-premise, mobile, and cloud-based architectures; managing vulnerability assessments and remediation; and developing agency-wide cybersecurity training initiatives.
With my extensive experience in federal IT security and proven track record of implementing enterprise-wide cybersecurity programs, I am well-positioned to take on roles requiring FedRAMP expertise to drive modernization, enhance efficiency, and maintain trusted cybersecurity leadership for government-wide cloud service adoption.
Career Highlights
Department of Commerce Bronze Medal Award
Received while serving as the Cybersecurity Program Manager at the United States Patent and Trademark Office (USPTO) for enhancing the agency's cybersecurity posture. This recognition highlighted my leadership in implementing innovative security measures, streamlining compliance processes, and fostering a culture of cybersecurity awareness to protect critical intellectual property assets.
FISMA Score Transformation
As CISO of DFC, moved FISMA score from "Defined (Ineffective)" to "Managed and Measurable (Effective)" within six months of onboarding, demonstrating rapid organizational improvement and security program maturity.
Core Competencies
Professional Experience
25+ years of proven leadership in federal cybersecurity, enterprise IT management, and mission-critical system implementations.
Chief Information Security Officer (CISO)
Contact Supervisor: Yes, Tina Donbeck
Official responsible for carrying out the Chief Information Officer responsibilities under the Federal Information Security Management Act (FISMA) and serving as the Chief Information Officer's primary liaison to the agency's authorizing officials, information system owners, and information systems security officers.
Key Responsibilities & Achievements
- Reorganized team into three distinct support teams to meet Agency Information Security and Compliance needs: Authorizations and Assessments (A&A), Privacy, and Security Operations
- Within six months of onboarding managed OIT organization to move score from "Defined (Ineffective)" to "Managed and Measurable (Effective)"FISMA score from "Defined (Ineffective)" to "Managed and Measurable (Effective)"
- Led the development and implementation of comprehensive information security policies and procedures aligned with federal requirements, overseeing the systems authorization process under FISMA
- Prioritized the use of FedRAMP-equivalent security frameworks whenever possible, implementing risk-based approaches for alternative security frameworks such as SOC2, PCI, and ISO 27001
- Transitioned organization to utilizing DOJ Cyber Security Assessment and Management (CSAM) to automate assessments and authorizations
- Transitioned organization to utilize DOJ Security Operations Center (JSOC) as the first provider of Security Operations Center as a Service (SOCaaS)
Cybersecurity Program Manager, Senior IT Cybersecurity Specialist (INFOSEC/PLCYPLNS)
Contact Supervisor: Yes, Don Watson, Supervisor, 571-272-8130
Developed vision, strategy, and roadmap for security and compliance products while ensuring alignment with DoC, USPTO, and OCIO overarching vision, goals, and strategies.
Key Responsibilities & Achievements
- Facilitated the development of cybersecurity and privacy policies, processes, and related training per requirements using NIST Risk Management Framework (RMF)FISMA
- Performed Chief Information Officer responsibilities under and served as primary liaison to authorizing officials and system security officersFISMA
- Managed lifecycle selection and implementation of cybersecurity technologies while migrating to FedRAMP cloud-based enterprise systems
- Managed implementation of CISA Continuous Diagnostics and Mitigation (CDM) program phases, including IAM, EDR, SIEM systems
- Tested and evaluated cloud migration technologies such as Secure Access Service Edge (SASE) and Cloud Access Security Broker (CASB)
- Wrote business cases for cybersecurity investments and participated in USPTO's Capital Planning and Investment Control (CPIC) IT process
Senior Information Technology Specialist (PLCYPLN)
Contact Supervisor: Yes, Kris Hillstrom, Supervisor, 571-272-0642
Managed the Trademarks program with a $30M budget, directing all Capital Planning and Investment Control (CPIC) reporting, annual IT planning, and data calls.
Key Responsibilities & Achievements
- Implemented continuous integration and delivery (CI/CD) pipelines across development teams, integrating automated security testing including SAST/DAST
- Established DevSecOps culture, embedding security practices throughout the software development lifecycle
- Deployed infrastructure-as-code practices to version control and automate infrastructure deployments
- Implemented comprehensive logging and monitoring solutions for real-time visibility into applications and infrastructure
- Developed key IT policies including Non-Functional Requirements, Technical Debt management, and Cybersecurity POA&Ms
- Served as expert advisor to agency leadership on complex technical IT initiatives and large-scale development projects
Information Technology Program Manager
Contact Supervisor: Yes, Kris Hillstrom, Supervisor, 571-272-0642
Developed, prepared, implemented and managed information technology (IT) initiatives, programs and projects for large scale complex IT software and infrastructure revitalization and upgrades.
Key Responsibilities & Achievements
- Supervised Senior IT staff and Program Managers, completed performance reviews, and made recommendations for professional development
- Managed Enterprise Project Management System (EPMS) service support team and performed PMD Project Management Office functions
- Developed and revised SDLC documentation, MS Project schedule templates, and drafted policies to support PMO activities
- Performed IT program/project budget forecasting and execution in accordance with financial guidelines
- Coached Waterfall and Agile Scrum/Kanban methodologies and managed multiple major programs on time and on budget
- Demonstrated expert ability to translate business requirements into system solutions while developing multi-disciplinary teams
Senior Information Technology Project Manager
Contact Supervisor: Yes, Jim Hennessey, Supervisor, 540-222-5462
Led the development and deployment of cloud-based infrastructure and software, implementing robust information security design and architecture principles in commercial and government cloud environments.
Key Responsibilities & Achievements
- Ensured agency's cloud initiatives adhered to federal security standards, including FedRAMP and requirementsFISMA
- Architected secure cloud solutions incorporating essential security controls such as encryption, access management, and continuous monitoring
- Maintained focus on risk management and compliance, working closely with cloud service providers on shared responsibility model
- Delivered resilient and secure cloud architecture that supported agency mission while protecting sensitive government data
Information Technology Project Manager
Contact Supervisor: Yes, Aaron Focacci, Supervisor, 321-724-3256
Responsible for transforming mission-critical enterprise services from stovepipe legacy systems to modern cloud-based solutions with highly available architectures.
Key Responsibilities & Achievements
- Managed multiple complex, enterprise-scale IT technical projects supporting over 12,000 employees and contractors
- Planned, directed, and implemented large-scale enterprise projects, managing senior IT program staff and subordinate teams
- Analyzed key systems such as CRM, email, and collaboration for migration to cloud-based SaaS solutions in collaboration with CIO
- Developed system designs and conducted security design analysis and security reviews for on-premise and off-premise solutions
- Managed projects including Office 365, physical to virtual cloud server migrations, VDI, OpenStack, Microsoft Azure, Lync, and SharePoint
- Architected five enterprise systems to ensure high availability and produced operations guidelines for the organization
Technical Expertise & Skills
25+ years of comprehensive experience in federal cybersecurity, enterprise IT management, and mission-critical system implementations.
Cybersecurity & Compliance
Federal IT Management
Software Development & Architecture
Cloud & Infrastructure
Database & Systems
Professional Certifications
Certified Information Systems Security Professional
ISC2 • 2017
Certified Cloud Security Professional
ISC2 • 2016
Certified Secure Software Lifecycle Professional
ISC2 • 2019
Project Management Professional
PMI • Current
Certified Scrum Master
Scrum Alliance • 2007
Federal Acquisition Certified - Contracting Officer Representative Level III
Federal Government • 2014
Federal Acquisition Certified - Program/Project Managers Level III
Federal Government • 2014
Computer & Related Skills
Project Management & Office Applications
Programming & Web Development
Database Technologies
Security-First Leadership Philosophy
Federal Compliance Excellence
Dedicated to maintaining the highest standards of federal cybersecurity compliance while enabling mission success. Every security decision balances protection requirements with operational efficiency to support agency objectives.
Team Development Focus
Committed to building high-performing cybersecurity teams through continuous professional development and mentorship. Foster collaborative environments where team members can grow their expertise and advance their federal careers.
Education & Certifications
Comprehensive academic background and professional certifications supporting 25+ years of federal cybersecurity leadership.
Academic Background
Master's Certificate in Federal Government Program Management
Master of Business Administration (MBA)
Bachelor of Science in Business Management
U.S. Navy, Nuclear Machinist's Mate
Professional Certifications
Certified Information Systems Security Professional
Certified Cloud Security Professional
Certified Secure Software Lifecycle Professional
Project Management Professional
PMI PMP #1345054
Certified Scrum Master
Contracting Officer's Representative Level III
Program and Project Managers Level III IT
Selected Recent Training
Certified Secure Software Lifecycle Professional (CSSLP) Training
Implementing SAFe 4.6
CPIC & The Annual IT Budget & Management Report Training
CPIC Forum
CISSP Training Program
Cisco Live Training Sessions
Certified Cloud Security Professional (CCSP) Training
Continuous Learning Commitment
Federal Technology Leadership
Committed to staying current with federal cybersecurity frameworks and emerging government technology initiatives to maintain leadership in federal IT security.
Industry Engagement
Active participation in federal cybersecurity communities, maintaining professional certifications, and sharing knowledge through mentorship and professional development initiatives.
Team Development
Focused on building high-performing cybersecurity teams through continuous professional development and creating pathways for team members to advance their federal careers.
Federal Cybersecurity Leadership
Ready to enhance your organization's cybersecurity posture and drive federal IT innovation? With 25+ years of experience in federal agencies and DoD, I'm passionate about protecting critical infrastructure while enabling mission success.
Get In Touch
Areas of Expertise
"Security is not just about protecting systems—it's about enabling mission success while safeguarding the trust placed in us."
— Trevor Lowing, CISSP, CCSP, CSSLP, PMP, CSM