See How Many Clients You're Missing Each Month

Simply enter your business email & Topline AI Agent will show you.

Bio

Generated by
Topline AI
Tiffany Spann is a seasoned cybersecurity professional with extensive experience in information security, risk management, and program management. She has worked with various government agencies, including the Federal Highway Administration and NOAA’s Information Technology Center. Spann holds multiple certifications, including CISM, CISA, PMP, ITIL v3, and Security+. She currently serves as Co-Founder and Managing Partner at Crown Capital.

Credentials

  • Certified Information Security Manager (CISM)
    ISACA
    Oct, 2020
    - Apr, 2026
  • Certified Information Systems Auditor (CISA)
    ISACA
    Oct, 2019
    - Apr, 2026
  • Project Management Professional (PMP)
    Project Management Institute
    Feb, 2014
    - Apr, 2026
  • ITIL v3 Certification
    AXELOS Global Best Practice
  • Security+
    CompTIA

Experience

    • Co-Founder, Managing Partner
      • Jan 2021 - Present

      Founded to serve passive investors that are looking for opportunities to invest in value-add apartments for a healthy return.

    • Cyber Security Specialist
      • Mar 2018 - Present
      • Remote

      • Conducting FISMA Annual Security Controls Assessments (ASCAs) on FISMA reportable systems.• Scheduling and facilitating ad-hoc discovery sessions with the applicable stakeholders.• Scheduling and facilitating the Control Selection Meeting (CSM), Control Assessment Meeting (CAM) and findings review meetings with the system stakeholders.• Preparing a customized Assessment Plan based on the Control Selection Memo (CSM) and working closely with the System Owner to coordinate the data gathering effort.• Reviewing and analyzing evidence to ensure each assessment objective is achieved.• Developing Security Assessment Report (SAR) based on assessment results.• Updating and maintaining System Security Plan (SSP) to latest templates for the assessment based on NIST 800-53 Revision 4.• Utilize NIST 800-37 guidelines to apply Risk Management Framework (RMF) to include conducting the activities of security categorization, security control selection and implementation, security control

    • Spann Properties
      • Jan 2017 - Present

      Spann Properties is a single family acquisition company based out of Baltimore that effectively applies the BRRRR strategy to acquire properties. This strategy allowed Spann Properties to scale their presence in Baltimore as an aggressive buyer.

  • ActioNet, Inc.
    • Largo, Maryland, United States
    • Program Manager
      • Aug 2015 - Mar 2018
      • Largo, Maryland, United States

      Served as a Program Manager providing information system security and engineering support for NOAA’s Information Technology Center (ITC) and Web Operations Center (WOC). Primary areas of support for the ITC and WOC included: managing $10M contract budget, managing a team of system administrators, system engineers and network engineers, analyzing and providing vulnerability remediation recommendations; running weekly vulnerability scans; serving as the primary point of contact for security-incident response; creating security artifacts; leading special security projects; acting as the primary point of contact for the Annual Assessments and Authorization (A&A); provide expert-level knowledge of NIST standards and security framework and providing continuous monitoring support.

  • SEVATEC
    • Washington DC-Baltimore Area
    • Field Operations Task Manager
      • Jun 2014 - Jul 2015
      • Washington DC-Baltimore Area

      Served as a Information System Security Officer (ISSO) for the Federal Highway Administration (FHWA). Primary areas of support included: coordinating and implementing security controls for over 65 Federal Highway Administration (FHWA) field offices; providing management and over site of the FHWA IT team, managing all cybersecurity incident response support in both headquarters and field offices; providing verification, validation, and compliance services; providing security requirements services; serving as the primary interface between contract personnel and government counterparts; and providing all necessary weekly and monthly contract deliverables.

  • ActioNet, Inc.
    • Washington DC-Baltimore Area
    • Project Manager
      • Jul 2011 - Jun 2013
      • Washington DC-Baltimore Area

      Worked in the Office of the Secretary (OST) IT Shared Services (ITSS) organization as a project manager.

  • Freddie Mac
    • McLean, Virginia, United States
    • Analyst
      • Aug 2010 - Jul 2011
      • McLean, Virginia, United States

      Served as an analyst for the Customer Outreach Department.

  • Corinthian Colleges, Inc.
    • Silver Spring, Maryland, United States
    • Junior Security Analyst
      • Dec 2009 - Aug 2010
      • Silver Spring, Maryland, United States

      Worked as a Junior Business Analyst in compiling and analyzing security artifacts for the Everest Institute financial reporting system.

Education

  • University of Maryland
    Bachelor of Science - BS, Economics

Suggested Services

This profile is unclaimed. These are suggested service rates with 0% commision upon successful connection

Industry Focus. “Computer and Network Security”

Looking to Create a Custom Project?

Need a custom project? We'll create a solution designed specifically for your project.

Get Started

References

Community

You need to have a working account to view this content. Click here to join now

Similar Profiles