Security engineering for federal programs and commercial teams.
I’m Greg Gutman. I take ISSO / AISSO / SCA coverage, ATO and NIST 800-53 work, cloud and network architecture, and scoped assessments — as a 1099 or W2 contractor, a sub to a prime, or a short fixed engagement. No company paperwork in the way: you hire me.
Reply typically within one business day. CONUS / remote. Current certification: CompTIA SecurityX. Lifetime CompTIA A+, Network+, Security+, CIOS, and CSIS are current too.
Two doors, same engineer
Say which seat you need. The work is the same quality; the packaging is different.
Federal programs & primes
Contract coverage
Staff a gap or a surge without standing up a vendor vehicle. Typical work: control implementation and assessment, SSP / POA&M / evidence, GRC platform work, cATO readiness, Xacta-style packages, GovCloud architecture.
A week of architecture review, a control-gap pass, hardening help, or a small engineering build — without a six-month SOW. Useful when you need a senior pair of hands, not a retained firm.
ATO path, not slideware
Helped systems reach and renew authorization, including AWS GovCloud-hosted FISMA systems.
GRC and continuous authorization
AISSO / SCA work, GRC platform migration, SSPs, POA&Ms, and cATO readiness on DOI-supporting programs.
800-53 r4 → r5 in Xacta
Migrated control implementations, SSPs, and evidence for multiple FedRAMP / FISMA systems.
Green scorecards and assessments
Security engineering and SCA work on CONUS federal programs, including DHS- and DOI-supporting systems.
Architecture that survives review
Network, cloud, and TIC-aware design with the documentation assessors actually ask for.
Transport someone has actually run
Enterprise LAN/WAN, fiber, and SATCOM O&M in 24/7 CONUS and OCONUS environments — classified and unclassified — before the cloud years.
Open source projects
Public work that is currently published and installable.
Spark / Agentic Audit Tools
Local-first workstation audit tooling
A practical toolkit for identifying and reviewing agentic workflow artifacts on macOS, Linux, and Windows without reading file contents for discovery or exfiltrating data.
inputdrive/homebrew-tap is the public package source for current inputdrive projects. It is the route by which the Spark package is distributed to end users.