Security and compliance
10 FedRAMP authorization experts
These ten compliance, security and operations professionals have worked on FedRAMP inside the companies they worked for, in roles that covered authorization efforts, audit coordination, continuous monitoring and FedRAMP operations. They can explain how to prepare a cloud offering for authorization and keep it compliant afterwards.
Professionals to explore
01—10Brad Williams
LinkedInExperience: FEDRamp Incident Manager · Oracle
FEDRamp Incident Manager at Oracle (2020–2021), and Federal Operations Manager at Oracle since January 2021, where his profile describes managing a team that solves complex infrastructure problems. His headline describes him as a FedRAMP operations leader covering SaaS, IL4 compliance, and incident, change and release management. He was earlier a Cloud Solution Engineer at Oracle (2016–2020).
Christopher Wright
LinkedInExperience: FedRAMP Compliance Lead · ASM Research
FedRAMP Compliance Lead at ASM Research (2019–2020), where he was also Cybersecurity Supervisor (2014–2019). He later served as Security and Compliance Lead at Accenture Federal Services (2021–2023), where his profile says he managed all security and compliance activities for the AIP multi-cloud project, a platform supporting over 6 federal agencies. He has been a Security Assurance Consultant at Fortreum since 2024.
Emily Cummins
LinkedInExperience: Chief Information Security Officer · NextStage - GovCon Growth Platform
Chief Information Security Officer at NextStage - GovCon Growth Platform since November 2025, where her profile says she stabilized and advanced FedRAMP Moderate Equivalency readiness within four effective working weeks. She was previously Director of Security & Compliance Services and then Director of Compliance at Anitian (2019–2025), and Principal Security Consultant at Kratos Defense and Security Solutions (2014–2019).
Eric Terwilliger
LinkedInExperience: Information System Security Officer (Public Sector Compliance Analyst) · Cisco
Information System Security Officer (Public Sector Compliance Analyst) at Cisco (2022–2023), after serving as Global Cloud Compliance Engineer at Cisco (2018–2022); he was then Sr Program Mgr., Federal Programs at Zscaler (2023–2025). His profile describes him as a security compliance analyst specializing in FedRAMP/NIST 800-53 controls and process.
Joseph Ely
LinkedInExperience: Senior Cloud Security and Compliance Program Manager · RingCentral
Senior Cloud Security and Compliance Program Manager at RingCentral (2023–2025), where his profile says he led the Continuous Monitoring Team supporting RingCentral's FedRAMP and StateRAMP efforts, reported to CISA on project status and risks, and assessed controls for FedRAMP moderate certification. He has been Director of GRC at Inkit since March 2025.
Melanie Huffman
LinkedInExperience: Director, Governance, Risk, and Compliance (GRC) · Devo
Former Director, Governance, Risk, and Compliance (GRC) at Devo (2025–2026), after Devo roles as Manager, Federal and Security Services, Director, Federal and Public Sector Services and Director, Federal Product Management and Operations (2021–2025). In the GRC role her profile describes leading FedRAMP authorization efforts and ongoing SOC 2 and PCI DSS compliance for a cloud-native security platform.
Rashad Munawar
LinkedInExperience: Director, FedRAMP Security Compliance & Operations · BlackBerry
Former Director, FedRAMP Security Compliance & Operations at BlackBerry (2022–2026), after serving as Senior Manager, FedRAMP Compliance and Audit there (2016–2022). His profile lists FedRAMP, security operations, IL4/5, CMMC and StateRAMP for the director role. Since July 2026 he has held the role Security Risk& Compliance Leader Federal ISSO Apptio at IBM.
Scott Collins
LinkedInExperience: FedRAMP Compliance Technical Lead · Everlaw
FedRAMP Compliance Technical Lead at Everlaw, a cloud-native ediscovery software company, since June 2025, where his profile says he leads, manages and matures security compliance programs for public sector certifications. He was previously Head of Risk & Compliance at Crux (2023–2025) and Director, Information Security GRC at Root Inc. (2021–2022).
Thomas S.
LinkedInExperience: FedRAMP Program Director · IBM
FedRAMP Program Director at IBM since July 2025. He was previously Sr. Director, Information Security at Appian (2021–2023) and Director Of SaaS Architecture at VMware (2015–2021), and was Senior Vice President of Technology at SHzoom (2024–2025). His profile describes 20+ years of experience across enterprise IT systems and building and developing teams.
Todd Yenche
LinkedInExperience: FedRAMP Compliance Lead · IBM cloud for government
FedRAMP Compliance Lead for IBM cloud for government since April 2018, after security and compliance team lead roles at IBM Watson Customer Engagement (2015–2018) and IBM Analytics (2006–2015). His profile says he maintained and managed the System Security Plan and supporting documentation for the IBM Cloud for Government offering to keep it aligned with FedRAMP and NIST SP 800-53 requirements, and led FedRAMP High audit coordination.
Choose the right perspective
For a first authorization, look for someone whose note describes leading authorization or audit work; for life after authorization, favor people who ran continuous monitoring or FedRAMP operations. Also match the impact level you are targeting, such as Moderate or High, where a note mentions it.
Questions to take into the conversation
- 01How did you choose your authorization path, such as agency sponsorship, and what drove the timeline?
- 02Which NIST 800-53 control families required the most engineering change to your cloud environment, and how did you plan that work?
- 03How did you staff and run continuous monitoring after authorization, including monthly scanning and POA&M management?
About this directory
This is a professional research starting point based on business profile data retrieved on . Titles and companies reflect that source snapshot and may describe past or present roles. Check the linked profiles for current details. Inclusion does not imply Instant Expert membership or availability.
Request a correction or removal