Carl McMillin

Senior Information System Security Engineer at New Directions Technologies Inc.
  • Claim this Profile
Contact Information
us****@****om
(386) 825-5501
Location
Oxnard, California, United States, US

Topline Score

Topline score feature will be out soon.

Bio

Generated by
Topline AI

You need to have a working account to view this content.
You need to have a working account to view this content.

Experience

    • United States
    • Defense and Space Manufacturing
    • 100 - 200 Employee
    • Senior Information System Security Engineer
      • Mar 2020 - Present

      Continuing to operate onsite and remotely under movement and work limitations due to the COVID19 disease response, as Information Systems Security Engineer (ISSE) with additional duties of Systems Network Engineer, I designed and implemented a replacement enterprise-scale network architecture for the Logistics Management System (LMS) in the ongoing effort to obtain an official Authority-To-Operate (ATO) designation. Developed and delivered the LMS Domain Controllers using Windows Server 2016 having Windows Server Update Services (WSUS) and Active Directory roles, and multilayered the WSUS scheme with a mobile upstream update server. Using server-supplied GPO’s, I allowed servers and Windows 10 client computers to be scanned by ACAS/Nessus without time-consuming, per-machine configuration modifications. After designing the network and testing it, I performed – under an extremely compressed schedule – all of the requisite ISSE RMF actions to warrant the subsequently awarded 3-year ATO, the only one granted with that duration in a number of other ATO submissions, some of which I also contributed to • Continued the development of productivity enhancement, report generation, and quality-assurance tools using fully featured Excel-hosted VBA 6 applications and customized Visual Studio 2017/2019 C# command-line components. Functionality included: 1) Automatic execution of Windows Registry queries derived directly from CKL’s to aid in STIG’ing Microsoft Office products on multiple hosts; 2) Automated processing of ACAS scans and STIG CKLs to both comply with validation requirements and to generate eMASS compatible POAM imports; and 3) Methods which facilitated eMASS artifact cross-reference and traceability data processing and which reduced the time spent on other manually intensive, repetitive, activities • Refined the UNIX/Linux STIG process by writing BASH shell enhancements to help with addressing complex vulnerability enquiries. Show less

    • Senior Information Systems Security Engineer
      • Sep 2019 - Mar 2020

      Continuing to work with NDTI in Oxnard, I shifted focus from Software Development/Business Analysis to Information Assurance, taking on the role of Information Systems Security Engineer (ISSE) with the 1043 Cyber-Security department • Performed multiple duties under the Department of Navy’s Risk Management Framework (RMF) on an accelerated, high-priority, multiple system Authority-To-Operate (ATO) effort: 1) Created and modified Enterprise Mission Assurance Support Service (eMASS) artifacts such as the Security Plan and Security Assessment Plan; 2) Assisted with System Administrator roles such as evaluating Security Technical Implementation Guides (STIGs) and assembling an installable DoD Windows 10 Enterprise Secure Host Baseline (SHB) image; 3) Executed – and performed quality checks against – Tenable NESSUS Assured Compliance Assessment Solution (ACAS) scans; 4) Installed and ran Security Content Automation Protocol (SCAP) software and integrated multiple baselines with manual STIG findings; and 5) Wrote and refined Project Objectives and Milestones (POA&Ms). • Managed time and effort, both onsite and at home, during the severe movement and work limitations placed both local and DOD authorities due to the Coronavirus (COVID19) disease. Show less

    • Senior Database Engineer
      • Oct 2018 - Sep 2019

      As employee with New Directions Technologies Incorporated (NDTI), on contract to the Department of the Navy, Naval Base Ventura County, Port Hueneme CA, I obtained my CompTIA Security+ CE SY0-501 certification and assisted in the preparation for the 2019 Command Cyber Readiness Inspection (CCRI) by learning the use of the Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIG) and Checklist (CKL) Viewer/Editor and by helping write system documentation. • In support of the CCRI effort, I designed, coded, and delivered a C# subsystem to aid in the management of STIG and CKL compliance information. The subsystem parsed the STIG/CKL XML documents representing the state of the system under-test, stored the results in a SQL Server database, and provided multiple diagnostic and quality reports in XML and HTML formats. • In addition to the C# subsystem, I developed a simplified version in Excel 2013 that permitted the 1043 Information Assurance group to batch-process CKL’s for the ongoing eMASS Authority-To-Operate (ATO) activity. • For 4 months, performed Business Analyst duties on the NAVAIR SMART-T migration effort for the Naval Systems Data Support Activity (NSDSA). Show less

    • Information Technology & Services
    • Software Developer
      • Jun 2018 - Sep 2018

      Contractor with Kelly IT Resources (http://www.kellyit.com), on contract to Transamerica (https://www.transamerica.com), was primarily responsible for converting portions of a complicated distributed, hybrid Enterprise RDMS/Access 2013 database system, within an Agile delivery model under very demanding time constraints. While performing these duties I developed a strategy and a software tool which significantly sped up the Access DB documentation and conversion process. The tool, constructed as a collection of VBA classes and macros and incorporating the BeyondCompare application, could be executed against a collection of target Access databases, allowing detailed differences for a given database before and after the conversion process. This work directly contributed to completing the overall task load significantly ahead of schedule. Show less

    • United States
    • Construction
    • 1 - 100 Employee
    • Private Consultant
      • May 2018 - Jun 2018

      I work in both the software and hardware realms, directly addressing customer needs with innovative technologies that solves problems correctly and completely. I work in both the software and hardware realms, directly addressing customer needs with innovative technologies that solves problems correctly and completely.

    • United States
    • IT Services and IT Consulting
    • 700 & Above Employee
    • Team Lead/Project Support Consultant
      • May 2017 - May 2018

      Contractor with Genesis10 (https://www.genesis10.com), sub-contractor to Capgemini (https://www.capgemini.com), on contract to Raytheon (http://www.raytheon.com), was Team Lead of the Commercial-Off-The-Shelf team for first 4 months; Support Consultant, and UNIX, SQL, ASP.NET, C#.NET, and VB.NET based application developer for the remaining time. • During the startup of a 360+ application support project, 1) planned team activities, 2) scheduled and conducted Knowledge Transfer conferences, 3) documented information obtained during meetings, and 4) helped other teams develop common tools to better use our time and track our project statuses. • Helped Capgemini developers and management and Raytheon Configuration Management team to define and improve build and deployment processes using TFS 2013. • Worked on multiple application codebases in ASP.NET, troubleshot and fixed problems with software behavior and interaction with SQL and Oracle databases. • Acted as mentor for junior developers in multiple skill areas including ASP.NET, MySQL, SSIS, SQL Server, and Oracle database activities. • Developed an innovative command-line C# processing pipeline utility using VS2017 to robustly disassemble Twitter Tweet’s into text and images for display in Omnivex Moxie Studio Players. The same pipeline sanitized the XML from multiple website endpoints and generated test data useful for troubleshooting. • Using C#, SSIS packages, and T-SQL, I wrote and delivered a CSV to SQL process that greatly simplified the batch generation of 1) secure passwords, 2) remote filesystem objects, 3) PGP encrypted files, and 4) mail-merge boilerplate for delivery to vendors. Show less

    • United States
    • Information Technology & Services
    • 1 - 100 Employee
    • Configuration/Release Manager
      • Sep 2016 - Jan 2017

      Contractor with Cogent Solutions Inc. (http://cogent-2000.com), sub-contractor to Science Applications International Corporation (SAIC, http://www.saic.com/about/about-saic), on contract to the United States Department of Agriculture’s (USDA) Risk Management Agency (RMA) as a member of the Configuration Management and Release Management team. Interacted and coordinated with Enterprise Architecture, Development, Server Hosting, and Database Management staff to deploy complex production and test software systems under a customized version of an Agile/DevOps/Continuous Integration regime using Microsoft Team Foundation Server (TFS) 2013 and 2015 management tool-chains. Using Visual Studio (VS) 2010 and 2013 and SQL Server Management Studio (SSMS) 2012, built and deployed web-based applications, windows services, and database solutions to various platforms and environments. Designed specialized C# command-line utilities incorporating the TFS 2013 WorkItem API to perform batch updates on SQL Server 2012 databases. Designed, used, and modified customized PowerShell 4 to automate routine file-system operations. Show less

    • United States
    • Industrial Machinery Manufacturing
    • 200 - 300 Employee
    • Electronics/Software/Test Engineer
      • Oct 2007 - Jul 2013

      Evangelist for engineering process improvements, I brought into the shop the a) open-source Subversion approach to Software Version Control, b) use of Atlassian’s JIRA for issue tracking, and c) inclusion of low- and high-level software and hardware design reviews • Developed electrical test circuitry, test-data processing software, and automation scripts for ATS-2 Audio Analyzer to ease U/L listing of 50 Watt Audio Amplifier • Picked up 10 Ampere NAC (Notification Appliance Circuit) switched-mode Booster/Power Supply design and carried it through U/L listing process • Used Altium Designer to modify schematic and printed-circuit board layout and rewrote 10 Amp NAC booster firmware to support multiple, concurrent, NAC protocols for Wheelock, Gentex, and System Sensor devices • Developed Object-Oriented LabVIEW ‘G’ applications to further hardware test automation goals • Using Java for the GUI frontend/controller and customized Visual Studio 2012 C# and C++ helper modules for the installer, designed, implemented, and packaged a “bare metal” embedded firmware update tool that supported many different microcontroller families • Maintained legacy VB and VB.NET applications using Team Foundation Server 2012 hosted projects. Show less

    • United States
    • Security and Investigations
    • 200 - 300 Employee
    • Electronics/Software Engineer
      • Sep 2005 - May 2007

      While Air Force Ready Reservist, participated in hardware and software design-review committees • Developed advanced analytical software tools to reduce the total number of electronic components used in the manufacture of Surface Mount Technology-based products • Aided manufacturing personnel in the simplification and optimization of numerous Surface Mount manufacturing processes, saving per-board assembly time and reducing man-hours spent in machine reconfiguration • Used CADSTAR schematic and printed-circuit board software to design, prototype, and take to market innovative alarm-system products • Developed new products and maintained legacy ‘C’ and assembly-language software for embedded systems based on Intel 80C51 and Texas Instruments MSP430 microcontrollers • Maintained Java applet for web-based ePad virtual keypad • Designed and maintained desktop reporting software using C++. Show less

    • Systems Engineer/Consultant
      • Apr 2002 - May 2005

      Architected and implemented an immersive 2D environment for the web-based, multimedia, Cybertory Virtual Laboratory. Using Java and Scalable Vector Graphics (SVG) components, the environment took advantage of distributed computing and advanced client-server technologies, making provisions for multi-user collaboration • Evaluated OpenGL, Virtual Reality (VR), and high-end multiplayer game platforms for candidates in the construction of an engaging 3D version of the Virtual Laboratory • Architected and implemented a client/server system providing a first-order solution to the simulation of the Polymerase Chain Reaction (PCR) involving multiple human-scale genomes. Powered by a Java-based simulation engine and operating on BLAST databases it coordinated the operation of Perl simulation scripts and custom-written National Center for Biotechnology Information (NCBI) command-line tools. The engine was backed by a PostgreSQL database which “short circuited” lengthy simulation runs, delivering results in a fraction of the time normally required. Show less

    • United States
    • Defense and Space Manufacturing
    • 700 & Above Employee
    • Journeyman Technician, Maintenance Controller, Programmer/Analyst
      • Nov 1982 - Jul 1990

      Active Duty, E-5, SSgt, Worked on B52-G Avionics System, guided flightline maintenance activities, and worked on mainframe and desktop software. Active Duty, E-5, SSgt, Worked on B52-G Avionics System, guided flightline maintenance activities, and worked on mainframe and desktop software.

Education

  • California State University-Sacramento
    Bachelor’s Degree, Computer Engineering
    1998 - 2001

Community

You need to have a working account to view this content. Click here to join now