Trevor Lowing, CISSP, CCSP, CSSLP, PMP, CSM

    CISO | Cybersecurity/Information Security Manager

    Active Top Secret ClearanceU.S. Navy Veteran 🇺🇸GS-15, Step-6FAC P/PM III & PMPFAC COR III IT

    Contact Information

    Trevor.Lowing@gmail.com
    321-427-4315
    5647 Ravenel Lane, Springfield, Virginia 22151

    Professional Status

    U.S. Citizen 🇺🇸
    Veteran & Disability Preference: Yes
    30% Disability Status

    Professional Summary

    As the Chief Information Security Officer (CISO) at the U.S. International Development Finance Corporation (DFC), I am an award-winning Senior Information Technology Cybersecurity and Management Specialist with over 25 years of experience managing mission-critical enterprise and system programs for federal agencies and the Department of Defense.

    I hold key certifications including Project Management Professional (FAC P/PM III & PMP) and Contracting Officer Representative (FAC COR III IT), and currently lead a team of more than 20 cybersecurity professionals.

    My diverse skill set encompasses cybersecurity, compliance, enterprise risk management, disaster recovery, and continuity of operations planning. At DFC, I have spearheaded the development and implementation of our comprehensive cybersecurity program, including conducting security assessments across on-premise, mobile, and cloud-based architectures; managing vulnerability assessments and remediation; and developing agency-wide cybersecurity training initiatives.

    With my extensive experience in federal IT security and proven track record of implementing enterprise-wide cybersecurity programs, I am well-positioned to take on roles requiring FedRAMP expertise to drive modernization, enhance efficiency, and maintain trusted cybersecurity leadership for government-wide cloud service adoption.

    Career Highlights

    Department of Commerce Bronze Medal Award

    Received while serving as the Cybersecurity Program Manager at the United States Patent and Trademark Office (USPTO) for enhancing the agency's cybersecurity posture. This recognition highlighted my leadership in implementing innovative security measures, streamlining compliance processes, and fostering a culture of cybersecurity awareness to protect critical intellectual property assets.

    FISMA Score Transformation

    As CISO of DFC, moved FISMA score from "Defined (Ineffective)" to "Managed and Measurable (Effective)" within six months of onboarding, demonstrating rapid organizational improvement and security program maturity.

    Core Competencies

    Cybersecurity LeadershipFISMA ComplianceFedRAMP ImplementationRisk ManagementTeam LeadershipEnterprise SecurityPrivacy ProtectionCloud SecurityDoD ProgramsFederal IT Systems

    Professional Experience

    25+ years of proven leadership in federal cybersecurity, enterprise IT management, and mission-critical system implementations.

    Chief Information Security Officer (CISO)

    U.S. International Development Finance Corporation (DFC)
    1100 New York Ave NW, Washington, DC 20527
    12/2022 - Present
    GS-15, Step 640+ hours, M-F, 7-5

    Contact Supervisor: Yes, Tina Donbeck

    Official responsible for carrying out the Chief Information Officer responsibilities under the Federal Information Security Management Act (FISMA) and serving as the Chief Information Officer's primary liaison to the agency's authorizing officials, information system owners, and information systems security officers.

    Key Responsibilities & Achievements

    • Reorganized team into three distinct support teams to meet Agency Information Security and Compliance needs: Authorizations and Assessments (A&A), Privacy, and Security Operations
    • Within six months of onboarding managed OIT organization to move score from "Defined (Ineffective)" to "Managed and Measurable (Effective)"FISMA score from "Defined (Ineffective)" to "Managed and Measurable (Effective)"
    • Led the development and implementation of comprehensive information security policies and procedures aligned with federal requirements, overseeing the systems authorization process under FISMA
    • Prioritized the use of FedRAMP-equivalent security frameworks whenever possible, implementing risk-based approaches for alternative security frameworks such as SOC2, PCI, and ISO 27001
    • Transitioned organization to utilizing DOJ Cyber Security Assessment and Management (CSAM) to automate assessments and authorizations
    • Transitioned organization to utilize DOJ Security Operations Center (JSOC) as the first provider of Security Operations Center as a Service (SOCaaS)

    Cybersecurity Program Manager, Senior IT Cybersecurity Specialist (INFOSEC/PLCYPLNS)

    United States Patent and Trademark Office (USPTO)
    600 Dulany Street, Madison West, Room 4D24, Alexandria, VA 22314
    9/2020 - 12/2022
    GS-14, Step 10$164,10240+ hours, M-F, 7-5

    Contact Supervisor: Yes, Don Watson, Supervisor, 571-272-8130

    Developed vision, strategy, and roadmap for security and compliance products while ensuring alignment with DoC, USPTO, and OCIO overarching vision, goals, and strategies.

    Key Responsibilities & Achievements

    • Facilitated the development of cybersecurity and privacy policies, processes, and related training per requirements using NIST Risk Management Framework (RMF)FISMA
    • Performed Chief Information Officer responsibilities under and served as primary liaison to authorizing officials and system security officersFISMA
    • Managed lifecycle selection and implementation of cybersecurity technologies while migrating to FedRAMP cloud-based enterprise systems
    • Managed implementation of CISA Continuous Diagnostics and Mitigation (CDM) program phases, including IAM, EDR, SIEM systems
    • Tested and evaluated cloud migration technologies such as Secure Access Service Edge (SASE) and Cloud Access Security Broker (CASB)
    • Wrote business cases for cybersecurity investments and participated in USPTO's Capital Planning and Investment Control (CPIC) IT process

    Senior Information Technology Specialist (PLCYPLN)

    United States Patent and Trademark Office (USPTO)
    600 Dulany Street, Madison West, Room 4D24, Alexandria, VA 22314
    10/2017 - 9/2020
    GS-14, Step 8$144,53840+ hours, M-F, 7-5

    Contact Supervisor: Yes, Kris Hillstrom, Supervisor, 571-272-0642

    Managed the Trademarks program with a $30M budget, directing all Capital Planning and Investment Control (CPIC) reporting, annual IT planning, and data calls.

    Key Responsibilities & Achievements

    • Implemented continuous integration and delivery (CI/CD) pipelines across development teams, integrating automated security testing including SAST/DAST
    • Established DevSecOps culture, embedding security practices throughout the software development lifecycle
    • Deployed infrastructure-as-code practices to version control and automate infrastructure deployments
    • Implemented comprehensive logging and monitoring solutions for real-time visibility into applications and infrastructure
    • Developed key IT policies including Non-Functional Requirements, Technical Debt management, and Cybersecurity POA&Ms
    • Served as expert advisor to agency leadership on complex technical IT initiatives and large-scale development projects

    Information Technology Program Manager

    United States Patent and Trademark Office (USPTO)
    600 Dulany Street, Madison West, Room 4D24, Alexandria, VA 22314
    04/2016 - 10/2017
    GS-14, Step 5$126,95840+ hours, M-F, 7-5

    Contact Supervisor: Yes, Kris Hillstrom, Supervisor, 571-272-0642

    Developed, prepared, implemented and managed information technology (IT) initiatives, programs and projects for large scale complex IT software and infrastructure revitalization and upgrades.

    Key Responsibilities & Achievements

    • Supervised Senior IT staff and Program Managers, completed performance reviews, and made recommendations for professional development
    • Managed Enterprise Project Management System (EPMS) service support team and performed PMD Project Management Office functions
    • Developed and revised SDLC documentation, MS Project schedule templates, and drafted policies to support PMO activities
    • Performed IT program/project budget forecasting and execution in accordance with financial guidelines
    • Coached Waterfall and Agile Scrum/Kanban methodologies and managed multiple major programs on time and on budget
    • Demonstrated expert ability to translate business requirements into system solutions while developing multi-disciplinary teams

    Senior Information Technology Project Manager

    United States Patent and Trademark Office (USPTO)
    600 Dulany Street, Madison West, Room 4D24, Alexandria, VA 22314
    01/2014 - 04/2016
    GS-14, Step 4$123,22340+ hours, M-F, 7-5

    Contact Supervisor: Yes, Jim Hennessey, Supervisor, 540-222-5462

    Led the development and deployment of cloud-based infrastructure and software, implementing robust information security design and architecture principles in commercial and government cloud environments.

    Key Responsibilities & Achievements

    • Ensured agency's cloud initiatives adhered to federal security standards, including FedRAMP and requirementsFISMA
    • Architected secure cloud solutions incorporating essential security controls such as encryption, access management, and continuous monitoring
    • Maintained focus on risk management and compliance, working closely with cloud service providers on shared responsibility model
    • Delivered resilient and secure cloud architecture that supported agency mission while protecting sensitive government data

    Information Technology Project Manager

    Harris Corporation, Harris IT Services
    1025 W. Nasa Boulevard, Melbourne, Florida 32919
    09/2012 - 01/2014

    Contact Supervisor: Yes, Aaron Focacci, Supervisor, 321-724-3256

    Responsible for transforming mission-critical enterprise services from stovepipe legacy systems to modern cloud-based solutions with highly available architectures.

    Key Responsibilities & Achievements

    • Managed multiple complex, enterprise-scale IT technical projects supporting over 12,000 employees and contractors
    • Planned, directed, and implemented large-scale enterprise projects, managing senior IT program staff and subordinate teams
    • Analyzed key systems such as CRM, email, and collaboration for migration to cloud-based SaaS solutions in collaboration with CIO
    • Developed system designs and conducted security design analysis and security reviews for on-premise and off-premise solutions
    • Managed projects including Office 365, physical to virtual cloud server migrations, VDI, OpenStack, Microsoft Azure, Lync, and SharePoint
    • Architected five enterprise systems to ensure high availability and produced operations guidelines for the organization

    Technical Expertise & Skills

    25+ years of comprehensive experience in federal cybersecurity, enterprise IT management, and mission-critical system implementations.

    Cybersecurity & Compliance

    FISMA Implementation98%
    FedRAMP Authorization95%
    NIST RMF96%
    Zero Trust Architecture92%
    SOC 2 Compliance90%
    Vulnerability Management94%

    Federal IT Management

    CPIC Process95%
    Team Leadership98%
    Budget Management93%
    Agile/Scrum Leadership91%
    Stakeholder Management96%
    Performance Management89%

    Software Development & Architecture

    Java Development92%
    JavaScript/Node.js88%
    C# / .NET85%
    Python83%
    DevSecOps94%
    CI/CD Pipelines90%

    Cloud & Infrastructure

    AWS Federal93%
    Microsoft Azure88%
    Cloud Security96%
    Infrastructure as Code87%
    SASE/CASB84%
    Hybrid Cloud91%

    Database & Systems

    Oracle Database90%
    MS SQL Server88%
    MySQL/PostgreSQL85%
    PL/SQL Development87%
    Enterprise Architecture93%
    System Integration91%

    Professional Certifications

    CISSP

    Certified Information Systems Security Professional

    ISC2 • 2017

    CCSP

    Certified Cloud Security Professional

    ISC2 • 2016

    CSSLP

    Certified Secure Software Lifecycle Professional

    ISC2 • 2019

    PMP

    Project Management Professional

    PMI • Current

    CSM

    Certified Scrum Master

    Scrum Alliance • 2007

    FAC-COR III

    Federal Acquisition Certified - Contracting Officer Representative Level III

    Federal Government • 2014

    FAC-P/PM III

    Federal Acquisition Certified - Program/Project Managers Level III

    Federal Government • 2014

    Computer & Related Skills

    Project Management & Office Applications

    Microsoft Office SuiteMicrosoft ProjectMicrosoft Project ServerAMS RealtimeArtemisVisio

    Programming & Web Development

    JavaJavaScriptC#ASP.NETPHPColdFusionVisual BasicPerlJSPHTML/XHTML/XML/CSS

    Database Technologies

    Oracle DatabaseMicrosoft SQL ServerMySQLPostgreSQLPL/SQLT-SQLMS Access

    Security-First Leadership Philosophy

    Federal Compliance Excellence

    Dedicated to maintaining the highest standards of federal cybersecurity compliance while enabling mission success. Every security decision balances protection requirements with operational efficiency to support agency objectives.

    Team Development Focus

    Committed to building high-performing cybersecurity teams through continuous professional development and mentorship. Foster collaborative environments where team members can grow their expertise and advance their federal careers.

    Education & Certifications

    Comprehensive academic background and professional certifications supporting 25+ years of federal cybersecurity leadership.

    Academic Background

    Master's Certificate in Federal Government Program Management

    George Washington University
    2015

    Master of Business Administration (MBA)

    Florida Institute of Technology
    2009

    Bachelor of Science in Business Management

    University of Maryland
    1996

    U.S. Navy, Nuclear Machinist's Mate

    United States Navy
    1987-1993

    Professional Certifications

    CISSPActive

    Certified Information Systems Security Professional

    ISC2•2017
    CCSPActive

    Certified Cloud Security Professional

    ISC2•2016
    CSSLPActive

    Certified Secure Software Lifecycle Professional

    ISC2•2019
    PMPActive

    Project Management Professional

    Project Management Institute•Current

    PMI PMP #1345054

    CSMActive

    Certified Scrum Master

    Scrum Alliance•2007
    FAC-COR IIIActive

    Contracting Officer's Representative Level III

    Federal Government•2014
    FAC-P/PM IIIActive

    Program and Project Managers Level III IT

    Federal Government•2014

    Selected Recent Training

    July 2019

    Certified Secure Software Lifecycle Professional (CSSLP) Training

    January 2019

    Implementing SAFe 4.6

    March 2018

    CPIC & The Annual IT Budget & Management Report Training

    May 2017

    CPIC Forum

    April 2017

    CISSP Training Program

    July 2016

    Cisco Live Training Sessions

    December 2015

    Certified Cloud Security Professional (CCSP) Training

    Continuous Learning Commitment

    Federal Technology Leadership

    Committed to staying current with federal cybersecurity frameworks and emerging government technology initiatives to maintain leadership in federal IT security.

    Industry Engagement

    Active participation in federal cybersecurity communities, maintaining professional certifications, and sharing knowledge through mentorship and professional development initiatives.

    Team Development

    Focused on building high-performing cybersecurity teams through continuous professional development and creating pathways for team members to advance their federal careers.

    Federal Cybersecurity Leadership

    Ready to enhance your organization's cybersecurity posture and drive federal IT innovation? With 25+ years of experience in federal agencies and DoD, I'm passionate about protecting critical infrastructure while enabling mission success.

    Get In Touch

    Email
    Trevor.Lowing@gmail.com
    Phone
    321-427-4315
    Schedule a Meeting
    Available for consultations

    Areas of Expertise

    Federal CybersecurityFedRAMP AuthorizationFederal IT LeadershipRisk ManagementTeam LeadershipEnterprise Security
    "Security is not just about protecting systems—it's about enabling mission success while safeguarding the trust placed in us."

    — Trevor Lowing, CISSP, CCSP, CSSLP, PMP, CSM