![]() |
| Source: Reddit |
Lawyer ⚖️, Historian, Navy vet ✈️, Philly and Penn State sports fanatic 🏈⚾🏀, Dad and Husband. Blogging at the intersection of state power and civil liberties.
Showing posts with label job. Show all posts
Showing posts with label job. Show all posts
14 September 2013
27 May 2011
The new job
Almost four years ago, my time in the Navy was quickly coming to a close and I was anxious to find a job. I gave my first-ever talk at DEFCON about my counter-IED work in Iraq, and in the small crowd of people asking questions, a man flashed his Navy ID card, handed me his contact information, and told me that we needed to talk.
I have to admit at the time I was slightly frightened that somehow my talk had attracted the wrong sort of attention (I was still on active duty at the time, and my talk, while unclassified, was nonetheless pretty aggressive). Ultimately, my apprehension was misplaced; he was in the Navy Reserves but more importantly, he worked for Booz Allen and he was offering me an interview. I went through a couple of interviews (my first one didn't go so well, but they saw potential and invited me back for a second), and by December I was thrilled to get (and accept) a job with Booz Allen.
Over the past three plus years I have worked with an amazing team of analysts that would be difficult to top. Through the highs and lows, this team has done amazing work and I am proud to have been a small part of it. Over the course of barely two years, our six member team grew by leaps and bounds (we're about to pass 40 by next month), and it has been a remarkable run. That being said, it was time for a change.
Today, I am happy to announce that I've accepted a new challenge. Effective June 20, I will be working as a Security Engineer and Penetration Tester with TDI Security, a computer security consulting firm based in Washington, DC. I'm working not as an employee of TDI, but as a independent contractor. Going out on my own and being self-employed is a step I've been looking to make for some time now. While my business (Leverage Consulting & Associates) has been around for over a year now, this move effectively marks the beginning of full-scale operations.
For a while now, I have been looking for the right opportunity to move into more direct full-scope penetration testing work, and I believe that this is that opportunity. Additionally, I already know some of the people I will be working with and I am extremely excited for this new direction.
I've very much enjoyed my time at Booz Allen, and I hope to be able stay in touch with those of you who I've met during that time. I am especially looking forward to meeting new folks through this new role.
See you in Vegas!
I have to admit at the time I was slightly frightened that somehow my talk had attracted the wrong sort of attention (I was still on active duty at the time, and my talk, while unclassified, was nonetheless pretty aggressive). Ultimately, my apprehension was misplaced; he was in the Navy Reserves but more importantly, he worked for Booz Allen and he was offering me an interview. I went through a couple of interviews (my first one didn't go so well, but they saw potential and invited me back for a second), and by December I was thrilled to get (and accept) a job with Booz Allen.
Over the past three plus years I have worked with an amazing team of analysts that would be difficult to top. Through the highs and lows, this team has done amazing work and I am proud to have been a small part of it. Over the course of barely two years, our six member team grew by leaps and bounds (we're about to pass 40 by next month), and it has been a remarkable run. That being said, it was time for a change.
Today, I am happy to announce that I've accepted a new challenge. Effective June 20, I will be working as a Security Engineer and Penetration Tester with TDI Security, a computer security consulting firm based in Washington, DC. I'm working not as an employee of TDI, but as a independent contractor. Going out on my own and being self-employed is a step I've been looking to make for some time now. While my business (Leverage Consulting & Associates) has been around for over a year now, this move effectively marks the beginning of full-scale operations.
For a while now, I have been looking for the right opportunity to move into more direct full-scope penetration testing work, and I believe that this is that opportunity. Additionally, I already know some of the people I will be working with and I am extremely excited for this new direction.
I've very much enjoyed my time at Booz Allen, and I hope to be able stay in touch with those of you who I've met during that time. I am especially looking forward to meeting new folks through this new role.
See you in Vegas!
17 November 2010
Booz Allen going public today under NYSE ticker symbol BAH
From the Booz Allen website:
Booz Allen Hamilton Holding Corporation announced today that it has priced its initial public offering of 14,000,000 shares of Class A common stock at $17 per share. The shares are expected to begin trading tomorrow, November 17 on the New York Stock Exchange under the ticker symbol “BAH”. The underwriters may purchase up to 2,100,000 additional shares at the initial offering price less the underwriting discounts and commissions to cover over-allotments, if any.
Morgan Stanley & Co. Incorporated, Barclays Capital Inc., BofA Merrill Lynch and Credit Suisse Securities (USA) LLC are acting as joint book-running managers of this offering with Stifel, Nicolaus & Company, Incorporated acting as co-lead manager and BB&T Capital Markets LLC, Lazard Capital Markets LLC and Raymond James & Associates, Inc. acting as co-managers.
A registration statement relating to these securities has been filed with and declared effective on November 16, 2010 by the Securities and Exchange Commission. The offering of these securities is being made only by means of a written prospectus forming part of the effective registration statement. A copy of the final prospectus related to the offering will be filed with the Securities and Exchange Commission, which may be obtained, when available, from Morgan Stanley & Co. Incorporated, Attention: Prospectus Department, 180 Varick Street, 2nd Floor, New York, NY 10014, or by email at prospectus@morganstanley.com, or by calling 866-718-1649; or Barclays Capital Inc. c/o Broadridge Financial Solutions, 1155 Long Island Avenue, Edgewood, New York 11717, or by email at barclaysprospectus@broadridge.com, or by calling 888-603-5847.
This press release shall not constitute an offer to sell or the solicitation of an offer to buy nor shall there be any sale of these securities in any state in which such offer, solicitation or sale would be unlawful prior to registration or qualification under the securities laws of any state.
About Booz Allen Hamilton
Booz Allen Hamilton is a leading provider of management and technology consulting services to the U.S. government in the defense, intelligence and civil markets. Booz Allen Hamilton is headquartered in McLean, Virginia, employs more than 25,100 people, and had revenue of approximately $5 billion in its latest fiscal year.
21 August 2010
About me
Last updated: January 23 2020
As of January 2020, I am a Ph.D. student in History at Liberty University.
In December 2019, I received my M.A. in History from Liberty University (Graduate with High Distinction).
Since July 2017, I have been a CNO Analyst and Attorney for Fortego LLC.
As of January 2020, I am a Ph.D. student in History at Liberty University.
In December 2019, I received my M.A. in History from Liberty University (Graduate with High Distinction).
Since July 2017, I have been a CNO Analyst and Attorney for Fortego LLC.
From January 2016 until July 2017, I was a law clerk and then an attorney for DLA Piper in Washington, DC.
From 2008-2011 and 2013-2015, I worked for Booz Allen Hamilton as a Senior Penetration Tester and as a Network Analyst.
From 2008-2011 and 2013-2015, I worked for Booz Allen Hamilton as a Senior Penetration Tester and as a Network Analyst.
In May 2016, I graduated Magna Cum Laude and Order of the Coif from the University of Maryland Francis King Carey School of Law (legal resume).
I previously started and owned a small business, Leverage Consulting & Associates, and through this I worked as a Penetration Tester. My clients included a major international newspaper, the Department of Defense, various other government agencies, private sector businesses, and a number of small businesses in the Washington, DC metro area.
I have contributed to three Syngress books: Penetration Tester's Open Source Toolkit, Vol. 2, Netcat Power Tools, and Kismet Hacking. I also contributed a chapter for a fourth book: Defense against the Black Arts: How Hackers Do What They Do and How to Protect against It.
At my core, I am a hacker at heart. We enjoy breaking things and taking them apart to figure out how they work, how they might do something different, or to discover new ways to use things. We break things not just to break them or for our personal gain, we break them so that they can be made better and more secure. I was a founding member of Unallocated Space, a central Maryland hackerspace; although I am no longer active there.
Military
I spent nearly 9 years in the United States Navy as an EA-6B Prowler Electronic Countermeasures Officer. During that time, I flew combat missions over Afghanistan and Iraq and participated in Operations Southern Watch, Enduring Freedom, and Iraqi Freedom. I also spent 9 months on the ground in Iraq supporting the Army as an Electronic Warfare Officer supporting the C-IED effort. My awards include the Air Medal (individual action award with Combat V; and strike/flight award), Navy and Marine Corps Commendation Medal (with Combat V), Army Commendation Medal, Navy Achievement Medal, Navy Unit Citation, Navy "E", National Defense Service Medal, Armed Forces Expeditionary Medal, Iraq Campaign Medal, Global War on Terrorism Expeditionary Medal, Global War on Terrorism Service Medal, Sea Service Deployment Ribbon, and the Navy Rifleman and Pistol ribbons. I am also a lifetime member of the Veterans of Foreign Wars (VFW).
Politics
The best description of my politics is that I am a right libertarian. As a young political idealist, I frequently threw ideological bombs with the best of them, but as I have become older I find myself more frequently seeking to promote civility in political discourse (which is increasingly more difficult to find). What's missing, I think, is a basic level of respect for someone else's opinions even if you disagree with them. To use one recent example, Senate Majority Leader Harry Reid (D-NV) said: "I don't know how anyone of Hispanic heritage could be a Republican." This is just pure ignorance, considering that anywhere from 25-30% of Hispanics consider themselves Republican, and upwards of 40% often vote as such. This ignorance exists on both sides of the aisle. You also see it on forums and message boards where people use words like "re-thug" or "demo-rat". In my opinion, you cannot use these words and expect to be taken seriously in any real discussion.
Sports
I am a Philadelphia and Penn State sports fanatic. While I am a fan of all of the major sports teams, I am far more fanatical about the Phillies and Eagles, and less so about the Flyers and Sixers. I held Penn State football season tickets for five years (just gave them up this year, unfortunately). I played football in high school and have been a football coach at the high school level for several years. In addition, I follow some professional cycling, primarily during the Tour de France in July but less so during the rest of the year. I also watch golf (and play very irregularly, and poorly) and most any Olympic sports interest me now and then (even, and especially, curling).
Philomath
I consider myself a practicing philomath, which means that I am a lover of learning, a seeker of knowledge and facts. Learning something new on a regular basis is perhaps deeper to the core of who I am than anything else.
I often spend time searching for things that fascinate me. This is usually a result of reading something on Wikipedia, and then following links to something else, and eventually I end up going off on a tangent and learning about something completely unrelated to what I was originally looking for. Is there a name for this? Wikistumbling. There, I made one. :-)
When I'm reading a book or watching a TV show, I often spend time researching about the locations in the stories. A while back I started watching The Wire (which is a fantastic TV show, by the way), so of course I was fascinated by everything I could find that's related to the show; culture, crime, the neighborhoods, photographs of locations, etc. I tend to invest a lot of time in something until I feel like I have a better understanding of it. Then, I often move on to something else.
Dad and Husband
Last but certainly not least, I am the father of four children and husband to the most wonderful woman in the world. Years ago, before I was married, I often wondered how in the world people could go about their jobs and have a family too. Now I wonder how I could do without it. There is nothing better than coming home from a long day at work to kids yelling "Daddy's home!" and getting a kiss from my wife.
01 January 2010
The Year in Review: My Top Ten Moments
2009 was a crappy year for a lot of people. Despite this, I was very fortunate and blessed to have a pretty good year. Here are my top ten moments, in no particular order except for #1 (which truly is #1 for me). Some of them are specific to me and my family, while others are general in nature and will relate to others.
1. Our son Michael was born on January 16th! Despite some early scares and a few more days in the hospital than we would have liked, Michael the Moose is doing great. God has truly blessed us. If this list stopped here, I would still be grateful for an amazing year.
2. 2009 was my first full year out of the military, and it was nice going the entire year without any worries of deployments, individual augmentations or any unplanned travel. So this moment is actually being able to spend the entire year with my amazing wife and kids. We took trips to Gettysburg and Fredericksburg. In 2010, hopefully a family vacation!
3. Over the summer, we traveled up to Pennsylvania and got to see my entire family.
4. I traveled to Norway and Poland to speak at HackCon and CONFidence, two internationally recognized security conferences. I got to spend some quality time with some of my amazing friends.
5. Chesley Sullenberger lands US Airways Flight 1549 safely on the Hudson River without any casualties. A true American hero.
6. Phillies return to the World Series. Losing to the Yankees was bittersweet, but lifetime Phillies fans recognize the greatness of this team. Jimmy Rollins' game-winning hit in Game 4 of the NLDS will go down among my all-time favorite sports moments.
7. The Blind Side becomes the sleeper hit of 2009. I cannot say enough about this phenomenal movie which is my favorite of the entire year. I knew a little bit about the story of Michael Oher, but this movie will bring tears to your eyes. Even recommended for guys. ;-)
8. Lots of friends deployed overseas to Iraq, Afghanistan and other places. Here's a moment for them coming home safely to their families.
9. Mark Martin makes a run for the ages. He comes up just short in his bid for the Cup, but this has to be his most satisfying season ever. For a long time Mark Martin fan, it amazing to witness. He is on my short list of those people you'd like to meet if you had the opportunity. One of the classiest guys in all sports.
10. I got promoted! But in all honesty, this one wasn't about me, it is about the great people that I get to work with everyday. I couldn't ask for a better bunch.
I'm pretty sure I missed something important, so they're probably be an edit or two forthcoming. But, please note: no reality TV stories, no celebrity stories. :-)
1. Our son Michael was born on January 16th! Despite some early scares and a few more days in the hospital than we would have liked, Michael the Moose is doing great. God has truly blessed us. If this list stopped here, I would still be grateful for an amazing year.
2. 2009 was my first full year out of the military, and it was nice going the entire year without any worries of deployments, individual augmentations or any unplanned travel. So this moment is actually being able to spend the entire year with my amazing wife and kids. We took trips to Gettysburg and Fredericksburg. In 2010, hopefully a family vacation!
3. Over the summer, we traveled up to Pennsylvania and got to see my entire family.
4. I traveled to Norway and Poland to speak at HackCon and CONFidence, two internationally recognized security conferences. I got to spend some quality time with some of my amazing friends.
5. Chesley Sullenberger lands US Airways Flight 1549 safely on the Hudson River without any casualties. A true American hero.
6. Phillies return to the World Series. Losing to the Yankees was bittersweet, but lifetime Phillies fans recognize the greatness of this team. Jimmy Rollins' game-winning hit in Game 4 of the NLDS will go down among my all-time favorite sports moments.
7. The Blind Side becomes the sleeper hit of 2009. I cannot say enough about this phenomenal movie which is my favorite of the entire year. I knew a little bit about the story of Michael Oher, but this movie will bring tears to your eyes. Even recommended for guys. ;-)
8. Lots of friends deployed overseas to Iraq, Afghanistan and other places. Here's a moment for them coming home safely to their families.
9. Mark Martin makes a run for the ages. He comes up just short in his bid for the Cup, but this has to be his most satisfying season ever. For a long time Mark Martin fan, it amazing to witness. He is on my short list of those people you'd like to meet if you had the opportunity. One of the classiest guys in all sports.
10. I got promoted! But in all honesty, this one wasn't about me, it is about the great people that I get to work with everyday. I couldn't ask for a better bunch.
I'm pretty sure I missed something important, so they're probably be an edit or two forthcoming. But, please note: no reality TV stories, no celebrity stories. :-)
02 December 2009
"Your account has been locked. Please contact your system administrator."
When I arrived at work this morning I attempted to log onto my desktop and got the dreaded "Your account has been locked. Please contact your system administrator."
Calling the "help desk" the technician cheerfully confirmed that my account had indeed been locked, and that there was a note not to enable it, but to contact the "security center."
Calling the "security center" the person answering the phone also confirmed that my account had been locked (thanks!) and claimed that it had been done on behalf of someone in another security office.
Calling the next security office it was confirmed a third time that my account had been locked, and the kind gentleman let me know that he would have it unlocked in no time.
But wait, I asked. What had I done to warrant my account being locked? He said he was looking into it. Really? They lock my account, is readily prepared to unlock it, but is still looking into why it was locked in the first place?
About ten minutes later my phone rang and the nice lady on the other end told me she was writing up an "incident report." Oh, great. Well, I figured, I would at least figure out what I had done wrong.
She asked me if I had visited a site called CoTweet. Well, of course I had. I use CoTweet at work to manage my Twitter account, and had been using it every day for at least six months or so. She kindly informed me that CoTweet was on the "prohibited sites" list. She then asked, "What do you use the site for? Is it work-related?" I explained that I use CoTweet (or Twitter for that matter) to keep in contact with other people in the security community. And that yes, it was work-related, but if they insisted, I could live without going to this site (while you might see this as backing down, from my perspective as a contractor it would not be a good idea to pick such a fight with a client's IT staff).
The phone call was short and sweet, and I politely mentioned that if CoTweet was indeed prohibited they should actually block it, which they do not. (Some other sites like Facebook and YouTube are in fact blocked, but neither CoTweet, nor Twitter for that matter, are blocked). She finished up the incident report and my account was active again within 15 minutes or so.
The incident brings up a few questions:
1. Why lock someone's account but not provide them with the information that it had actually been locked, and a means to contact someone for it to be unlocked? I had to figure out everything myself, which clearly wasn't rocket science, but surely there should be some notification procedure in place.
2. Why isn't Twitter, or CoTweet, actually blocked? If you were to go to Facebook, YouTube, or any number of other sites, you would be greeted with a bright red warning screen (affectionately called the "red screen of death") explaining that the site was blocked (incidentally, this seems to happen fairly regularly for most users; mostly by accident, and doesn't ever seen to result in any "incidents"). However, Twitter is generally accessible (at least it has been; lately it errors out but the RSOD is never displayed); and CoTweet works.
3. What sites are actually on the prohibited list? Clearly the blocked sites are on this list, but apparently other non-blocked sites (like Twitter and CoTweet) are also on the list). You might be wondering at this point (as I was), would it be possible to see this list so that we know what sites to avoid? Well, of course not. No one has ever claimed to have seen such a prohibited list, but it apparently does exist. I am not suggesting that my place of work does not have the right to block whatever sites they see fit; they clearly do have this right. But I think they also have a responsibility to their users to let them know the specific policy. Social networking sites are embraced by some businesses, but under fire by many others. So I understand the issues with these sites. But educating your users on such policies is key.
One could argue that Twitter is not really necessary, or "work-related," but I find it invaluable on a number of fronts. With Twitter and CoTweet effectively out of bounds (and third party clients like TweetDeck would just been seen as attempting to bypass their apparent restrictions, or a violation by installing unapproved software. So for the time being (during the day at least), I'm out...
Calling the "help desk" the technician cheerfully confirmed that my account had indeed been locked, and that there was a note not to enable it, but to contact the "security center."
Calling the "security center" the person answering the phone also confirmed that my account had been locked (thanks!) and claimed that it had been done on behalf of someone in another security office.
Calling the next security office it was confirmed a third time that my account had been locked, and the kind gentleman let me know that he would have it unlocked in no time.
But wait, I asked. What had I done to warrant my account being locked? He said he was looking into it. Really? They lock my account, is readily prepared to unlock it, but is still looking into why it was locked in the first place?
About ten minutes later my phone rang and the nice lady on the other end told me she was writing up an "incident report." Oh, great. Well, I figured, I would at least figure out what I had done wrong.
She asked me if I had visited a site called CoTweet. Well, of course I had. I use CoTweet at work to manage my Twitter account, and had been using it every day for at least six months or so. She kindly informed me that CoTweet was on the "prohibited sites" list. She then asked, "What do you use the site for? Is it work-related?" I explained that I use CoTweet (or Twitter for that matter) to keep in contact with other people in the security community. And that yes, it was work-related, but if they insisted, I could live without going to this site (while you might see this as backing down, from my perspective as a contractor it would not be a good idea to pick such a fight with a client's IT staff).
The phone call was short and sweet, and I politely mentioned that if CoTweet was indeed prohibited they should actually block it, which they do not. (Some other sites like Facebook and YouTube are in fact blocked, but neither CoTweet, nor Twitter for that matter, are blocked). She finished up the incident report and my account was active again within 15 minutes or so.
The incident brings up a few questions:
1. Why lock someone's account but not provide them with the information that it had actually been locked, and a means to contact someone for it to be unlocked? I had to figure out everything myself, which clearly wasn't rocket science, but surely there should be some notification procedure in place.
2. Why isn't Twitter, or CoTweet, actually blocked? If you were to go to Facebook, YouTube, or any number of other sites, you would be greeted with a bright red warning screen (affectionately called the "red screen of death") explaining that the site was blocked (incidentally, this seems to happen fairly regularly for most users; mostly by accident, and doesn't ever seen to result in any "incidents"). However, Twitter is generally accessible (at least it has been; lately it errors out but the RSOD is never displayed); and CoTweet works.
3. What sites are actually on the prohibited list? Clearly the blocked sites are on this list, but apparently other non-blocked sites (like Twitter and CoTweet) are also on the list). You might be wondering at this point (as I was), would it be possible to see this list so that we know what sites to avoid? Well, of course not. No one has ever claimed to have seen such a prohibited list, but it apparently does exist. I am not suggesting that my place of work does not have the right to block whatever sites they see fit; they clearly do have this right. But I think they also have a responsibility to their users to let them know the specific policy. Social networking sites are embraced by some businesses, but under fire by many others. So I understand the issues with these sites. But educating your users on such policies is key.
One could argue that Twitter is not really necessary, or "work-related," but I find it invaluable on a number of fronts. With Twitter and CoTweet effectively out of bounds (and third party clients like TweetDeck would just been seen as attempting to bypass their apparent restrictions, or a violation by installing unapproved software. So for the time being (during the day at least), I'm out...
06 March 2008
The new job
Last week I started my new job as a Senior Consultant at Booz Allen Hamilton. Without going into a very long and detailed story, I can't really do the job I was hired for until my security clearance is updated. Until then, I'm in a status called "Awaiting Clearance (AWC)." So I'm spending my days doing Computer-Based Training (CBT), lots of reading, and any other sort of training. The goal here is to prepare myself so that I can hit the ground running when I can actually do "the job."
Moving from military to corporate takes some getting used to. I have worn a uniform to work every day of my life for the past 8+ years. Formal functions didn't require formal clothes, because there were always formal uniforms to wear. The end result is that I did not (ever) have very many clothes that were suitable for the corporate environment.
Over the past few months, with the able assistance of my wife, I've finally been able to start assembling some nice clothes. Furthermore, rather than wearing the same uniform every day, I now have to waste brainpower figuring out just exactly what will I wear today? Ok, I admit it, it doesn't require all that much brainpower, but it's still something I am not yet used to doing. And on that thought, it is going to take a while to get used to wearing a dress shirt and tie to work everyday!
Moving from military to corporate takes some getting used to. I have worn a uniform to work every day of my life for the past 8+ years. Formal functions didn't require formal clothes, because there were always formal uniforms to wear. The end result is that I did not (ever) have very many clothes that were suitable for the corporate environment.
Over the past few months, with the able assistance of my wife, I've finally been able to start assembling some nice clothes. Furthermore, rather than wearing the same uniform every day, I now have to waste brainpower figuring out just exactly what will I wear today? Ok, I admit it, it doesn't require all that much brainpower, but it's still something I am not yet used to doing. And on that thought, it is going to take a while to get used to wearing a dress shirt and tie to work everyday!
26 December 2007
End of the line...and the start of something new
First update in a very long while...
I am now on terminal leave from the U.S. Navy and will be officially separating on February 1st. I've known for a while that I wanted to separate, but now the time has finally come.
I'll be changing the name of the blog, although I'm not quite sure what it will be called. The Narmy theme just isn't necessary anymore (and that's a good thing)! Any suggestions?
I had been looking for new jobs since April, and almost reached panic mode this month. Fortunately, I was recently hired to work for Booz Allen Hamilton in Maryland. I'll be starting in February. Cool!
I am now on terminal leave from the U.S. Navy and will be officially separating on February 1st. I've known for a while that I wanted to separate, but now the time has finally come.
I'll be changing the name of the blog, although I'm not quite sure what it will be called. The Narmy theme just isn't necessary anymore (and that's a good thing)! Any suggestions?
I had been looking for new jobs since April, and almost reached panic mode this month. Fortunately, I was recently hired to work for Booz Allen Hamilton in Maryland. I'll be starting in February. Cool!
Subscribe to:
Posts (Atom)
