About

Greg Gutman

Independent security engineer with 20+ years on mission-critical communications and cloud. Input Drive Security is the name I use for this work. You are hiring a person, not an entity listing.

How I work

Federal contractor roles (CONUS) cover the recent years: AISSO / SCA, GRC, and cloud architecture on systems that had to hold an ATO. Before that I ran enterprise networks, then SATCOM and telecom for DoD missions.

The path is the proof: SATCOM, microwave, and fiber in high-consequence theaters; classified and unclassified network O&M CONUS and OCONUS; AWS GovCloud architecture for DHS-supporting agencies; then GRC, SSPs, POA&Ms, and continuous authorization (cATO) readiness at DOI’s IA/ACIO office.

I still like building small, privacy-respecting tools. Calculators and lab pages on this domain are demos, not the product. No ads, no analytics. Theme preference is the only thing stored in your browser.

Focus areas

  • SSPs, assessments, POA&Ms, and cATO / continuous authorization evidence
  • NIST 800-53, RMF, FedRAMP, and GRC platform work (including r4→r5)
  • AWS GovCloud design: IAM, segmentation, encryption, logging and monitoring
  • Hands-on review: identity, Zero Trust principles, vulnerability process
  • Enterprise transport when the job needs it — LAN/WAN, fiber, SATCOM background
  • Python and automation where it saves an assessor or operator time

Credentials

Only current certifications are listed. Expired vendor certs are not advertised as current.

Current

  • CompTIA SecurityX ce Active 20 May 2024 – 20 May 2027 · formerly CASP+
  • CompTIA Security+ (2008 edition) Issued September 2009 · does not expire
  • CompTIA Network+ (2009 edition) Issued July 2009 · does not expire
  • CompTIA A+ (IT Technician) Issued July 2009 · does not expire
  • CompTIA IT Operations Specialist (CIOS) Issued July 2009 · does not expire
  • CompTIA Secure Infrastructure Specialist (CSIS) Issued September 2009 · does not expire

Open to new certification exams, including when a program or prime sponsors the exam. That is work, not a visitor donation.

Education & training

B.S., Information Systems Management — University of Maryland Global Campus. A.S., Electronic Systems Technology — Community College of the Air Force.

SANS cybersecurity coursework. Short courses (MIT, FIRST CVSS v4.0, Digital Forensics Essentials) stay in the training column, not the cert column.

I previously held CISSP (expired August 2024), SSCP (expired June 2025), Microsoft, Cisco, Juniper, and AWS certifications. They are expired, so they are not listed as current. (ISC)² Non-Member ID 444470. The underlying work — enterprise routing, GovCloud, and operations — is still in scope.

Open source projects

Public work that is currently published and installable.

Spark / Agentic Audit Tools

Local-first workstation audit tooling

A practical toolkit for identifying and reviewing agentic workflow artifacts on macOS, Linux, and Windows without reading file contents for discovery or exfiltrating data.

brew install inputdrive/tap/agentic-audit-tools

GitHub repo · Homebrew tap

Homebrew tap

Published distribution channel

inputdrive/homebrew-tap is the public package source for current inputdrive projects. It is the route by which the Spark package is distributed to end users.

Open tap repository

Public profiles

Work with me