Government and public sector
10 FedRAMP consultants
Each FedRAMP consultant on this list has advised organizations on FedRAMP work, either at a consulting or advisory firm or through their own practice. A reader can learn how FedRAMP consultants guide cloud service providers toward authorization and what that work involves.
Professionals to explore
01—10Andrew Hennigan
LinkedInExperience: FedRAMP Advisor · 38North Security
Former FedRAMP Advisor at 38North Security (2021–2024) and Manager, Cloud Security Advisory there since 2024. The profile describes helping cloud service providers and defense contractors navigate federal authorization environments, including FedRAMP Moderate/High, DISA Impact Levels and CMMC Level 2. Former Senior Cybersecurity Policy and Compliance Analyst at Booz Allen Hamilton (2020–2021).
Brandon Zais, CISA, CISSP
LinkedInExperience: FedRAMP Consultant · Coalfire
Former FedRAMP Consultant at Coalfire (2022–2025) and Senior Consultant at Coalfire since 2025. The FedRAMP Consultant role on the profile covers authoring documentation and recommendations tailored to FedRAMP and NIST 800-53 standards, and leading FedRAMP audits and assessments, including planning, documentation review, client interviews and technical testing.
Caitlyn Martin
LinkedInExperience: Managing Director, FedRAMP Advisory · SecureIT
At SecureIT since 2011, where the current title is Managing Director, FedRAMP Advisory, and former Senior Consultant at Deloitte & Touche LLP (2008–2011). The profile describes a director at SecureIT who is a security, audit and compliance professional focused on FedRAMP, and the current title places that work in FedRAMP advisory.
Celia Baker
LinkedInExperience: President Principal Consultant · IntelliGRACS Group, Inc.
President Principal Consultant at IntelliGRACS Group, Inc. since 2008, and Security & Compliance Advisor at SecureIT since 2017. The profile describes a security, risk and compliance advisor specializing in regulatory and FedRAMP compliance who helps cloud-based service providers strengthen their security and compliance programs.
Christine Miller Biggs
LinkedInExperience: Principal · Fortreum
Principal at Fortreum since 2024, and former Principal at Coalfire (2015–2024). The profile describes a principal specializing in developing computer security and compliance strategies for cloud service providers seeking to become FedRAMP authorized, particularly those hosted on Amazon Web Services. Former Senior Technical Writer, AWS Security at Amazon Web Services (AWS) (2012–2015).
Elizabeth Foster
LinkedInExperience: Cyber Security Consultant · Tyalk LLC
Cyber Security Consultant at Tyalk LLC since 2014, and former Senior Security Consultant - Various Companies (2002–2014). The profile describes a CMMC and FedRAMP Security Consultant who provides strategic advisory and hands-on support to organizations seeking compliance with CMMC, FedRAMP, ISO 27001 and DoD RMF.
Jason Oksenhendler, CISM, CGRC
LinkedInExperience: Cybersecurity Director, FedRAMP GovRAMP · Baker Tilly US
Cybersecurity Director, FedRAMP GovRAMP at Baker Tilly US since 2025. Former Cybersecurity Director - FedRAMP at Moss Adams (2024–2025), Vice President, Cloud Compliance at CGC (2023–2024) and Director, FedRAMP StateRAMP NIST Advisory Subject Matter Expert at Coalfire (2020–2023). The profile describes a NIST, FedRAMP and GovRAMP subject matter expert.
Matthew Donkin
LinkedInExperience: Principal Consultant & Managing Director · Forseti Intelligent Compliance
Principal Consultant & Managing Director at Forseti Intelligent Compliance since 2026, and former Principal Security Consultant at Kratos Defense and Security Solutions (2023–2026). The profile says this work advises enterprise tech, fintech and defense organizations on how to architect, automate and achieve federal cloud authorizations such as FedRAMP High, DoD IL5/IL6 and CMMC. Former AWS SecAssurance Gov FedRAMP at Amazon Web Services (AWS) (2020–2023).
Stanley McCray
LinkedInExperience: Senior Security Consultant Director, FedRAMP & Cloud Security · Coalfire
Senior Security Consultant Director, FedRAMP & Cloud Security at Coalfire since 2024, and former Senior Security Consultant Director, Cloud & A&A Programs at Take2it (2023–2024). The profile describes a FedRAMP SME who has led enterprise and federal security programs across cloud security, NIST SP 800-53 Rev5, RMF and risk governance, helping organizations achieve authorization.
Virginia Suazo
LinkedInExperience: Vice President, Cloud Security Advisory · 38North Security
Vice President, Cloud Security Advisory at 38North Security since 2024, and former Senior Director, Cloud Security Advisory there (2019–2024). The profile says this work helps cloud providers break into the US and global public sector, working hands-on with security and engineering teams at software, SaaS and infrastructure providers to clear programs such as FedRAMP (Rev5 and 20x), DoD Cloud SRG and CMMC.
Choose the right perspective
Decide first whether you need advisory help, assessment experience or ongoing compliance support, since the profiles differ in which of these they emphasize. Ask which FedRAMP impact levels and related federal programs they have worked on and how recent that work is.
Questions to take into the conversation
- 01How do you scope a FedRAMP readiness effort for a cloud product, and what do you need from our team in the first few weeks?
- 02Which security controls and documentation gaps most often slow down a FedRAMP authorization, and how should we fix them first?
- 03How should we choose between FedRAMP impact levels and plan for continuous monitoring after authorization?
Reaching FedRAMP consultants
How can I contact one of these FedRAMP consultants?
Pick one of the 10 people on this page and choose "Book a paid call", or describe your project to find others. You offer a fee for a 15-minute call or a written answer, Instant Expert finds the person's work email and sends the invitation, and they decide whether to accept. The list covers 8 companies, including 38North Security, Coalfire and SecureIT, based on profile data retrieved on October 5, 2026. Being listed here doesn't mean someone has agreed to take calls.
How much does it cost to reach FedRAMP consultants?
You choose the offer, starting at $5 per person. It includes Instant Expert's 20% fee, so an offer that pays the person $100 costs you $125. You're charged only when the person books the call or sends the answer.
What if they don't reply?
You pay nothing. Instant Expert sends follow-up reminders, and if the person hasn't booked or answered within 7 days, the request expires and any hold on your card is released. You can invite several of the 10 people on this list at once and cap your total spend, so you pay only for the ones who accept.
About this directory
This is a professional research starting point based on business profile data retrieved on . Titles and companies reflect that source snapshot and may describe past or present roles. Check the linked profiles for current details. Inclusion does not imply Instant Expert membership or availability.
Request a correction or removal