Shaun A. Marshall

Information Technology Professional & Technical Program Manager
505-510-1495 | shaun@shaunmarshall.com
Clearance: Previously held Top Secret (SSBI)

Executive Summary

Forward-thinking Technologist, Chief Information Security Officer (CISO), and Systems Architect with over 30 years of cross-sector experience. A proven force-multiplier uniquely blending stringent cybersecurity governance (CCISO/CISSP) with modern "day-2" infrastructure and AI productivity operations.

Cross-Sector Leadership

  • Diverse Environments: Academia (UCF), Corporate Enterprise, DoD, Gov (NASA), Non-Profit, and Small Businesses.
  • Executive Enablement: Dedicated technical advisory for VP-level leadership, rapid crisis deployment, and policy modernization.
  • Program Management: Directing IT strategy, hardware/software procurement, and averting SLA penalties across large enterprises.

Security & Governance

  • Frameworks: CCISO/CISSP aligned architectures, strict RBAC, and HIPAA-compliant localized deployments.
  • Risk Management: Digital forensics, incident response, eDiscovery, and continuous digital asset auditing (CIA Triad).
  • Access & Perimeter: IAM, OAuth2, SSO/SCIM integrations, network segmentation, and advanced VPS hardening.

AI & Infrastructure

  • Agentic Engineering: Localized LLMs (llama.cpp), multi-agent swarms (C.A.R.S.O.N.), and RAG vector DBs (Qdrant).
  • Core Infrastructure: Type-1 Hypervisors (ProxMox), highly secured LAMP/LEMP stacks, and bare-metal environments.
  • Secure Automation: Self-healing DevSecOps pipelines, BASH/Python wrappers, and FastA2A communications.

Core Competencies & Security Alignment

AI & Productivity Operations

  • Agentic Engineering: Development of cognitive agent workflows, localized LLM management (llama.cpp, Qwen, DeepSeek, Gemma), and RAG vector DBs (Qdrant).
  • Pilot & Tool Governance: Provisioning AI tools, creating SOPs, and ensuring least-privilege administrative access models for AI deployments.
  • Automation: Python, BASH, PowerShell, n8n webhook triggers, and secure API execution wrappers.

Cybersecurity & Governance (CCISO/CISSP)

  • IAM & Access Control: OAuth2, SSO/SCIM integrations, Active Directory, Google Workspace, and strict RBAC enforcement. (CISSP Domain 5)
  • Security Architecture: Cloud/VPS hardening, ProxMox virtualization, Fail2Ban, network segmentation, pfSense/OPNsense. (CISSP Domain 3)
  • Risk & Compliance: Policy authoring, HIPAA compliance architecture, disaster recovery, eDiscovery, and digital forensics. (CCISO Domain 1 & 4)

Professional Experience

Agentic AI Developer & Systems Architect
Agentic Engineering & AI Operations | 2025 – Present

Leading the design, deployment, and orchestration of advanced cognitive AI systems across multiple sectors, prioritizing local-first data privacy and compliance standards.

  • Agentic Engineering Framework Orchestration: Developing autonomous agentic workflows (including the C.A.R.S.O.N. architecture), utilizing memory architecture, MCP Gateways, and dynamic routing to specialized local models.
  • Healthcare AI EHS & LUMI Integration: Architecting 'Lumi', a highly secure, microservices-based AI system for the EHS (Electronic Health System). Orchestrating HIPAA-compliant, local-first execution for medical records.
  • Cyber Automation Agent JEFFREY: Created and integrated 'JEFFREY', a specialized autonomous agent responsible for secure operational tasks, including DevOps responsibilities, A2A communication, and systems auditing.
  • Infrastructure Florida Armored Combat (FAC): Directing the AI and IT strategy for FAC, deploying secure local LLMs and knowledge agents to assist in creating a rulebook, policy, and modern knowledge systems to multiply organizational productivity in a secure system.
  • Strategic Vision Future Plans: Pioneering the next phase of localized Agentic OS environments, driving towards fully autonomous, self-healing DevOps pipelines, continuous learning integrations, and multi-agent collaborative swarms.
Lead DevOps Architect & AI Integration Consultant (Contract/Project)
GlamourMed EMR System & Independent Consulting | 2025 – Present

Pioneering the integration of cognitive AI agents into secure, compliant enterprise environments, acting as the primary orchestrator for complex system deployments.

  • CISSP Domain 8 Secure Software Ecosystems: Designed the technical architecture for 'Lumi', a sophisticated, microservices-based Electronic Medical Record (EMR) system. Orchestrated FastA2A communication between localized AI nodes (Rust/NestJS/Python) ensuring HIPAA-compliant execution.
  • CCISO Domain 2 Data Privacy & Local-First Execution: Developed secure data ingestion pipelines for highly sensitive tax and healthcare documents, utilizing Qdrant vector databases and offline reasoning models to prevent PII leakage to public cloud endpoints.
  • CISSP Domain 7 Operational Excellence: Created "ready-to-run" AI pilot kits and autonomous DevOps scripts (e.g., anti-hang wrappers, dynamic model routers) to professionalize workflows and reduce operational risk across distributed tech stacks.
President & Chief Technology and Information Security Officer (CTO/CISO)
Florida Armored Combat (FAC) | Florida | 2023 – Present

Lead the technological and operational strategy for a 501c3 sports organization, architecting the entire digital infrastructure from the ground up with a "Security First" mandate.

  • CISSP Domain 3 Virtualization & Cloud Infrastructure: Architected and deployed bare-metal Type 1 hypervisor environments (ProxMox) scaling to robust cloud infrastructure platforms utilizing LAMP/LEMP stacks.
  • CCISO Domain 3 AI Productivity & Agentic Engineering: Deployed and governed local LLMs (llama.cpp) to ensure data privacy. Engineered Jr.-level agentic automation workflows (utilizing the C.A.R.S.O.N. framework) to handle secure email processing, Discord bot knowledge bases (Rulebook & Policy Bot), and routine administration tasks.
  • CISSP Domain 5 Identity & Access Governance: Enforced least-privileged access through OAuth2 integrations, Google Workspace/Groups provisioning, and continuous seat utilization reviews for distributed personnel.
  • CISSP Domain 4 Network & Communications Security: Configured VPS perimeters, Fail2Ban, and advanced email account security (DKIM, SPF, DMARC) to guarantee deliverability and prevent spoofing. Administered secure communication platforms including NextCloud.
  • CCISO Domain 5 Strategic Management & Enablement: Led requirements meetings, directed software/hardware procurement, and established comprehensive digital security requirements. Acted as an organizational force-multiplier by teaching interns basic agentic engineering and automation techniques to accelerate workflows.
Senior Systems Analyst, Executive Support
Walt Disney World (WDW) Enterprise Technology | Orlando, FL | October 2013 – Present

Provide dedicated technical advisory and complex systems administration for Executives (VP level and above), acting as the crucial liaison between leadership and Global Information Security.

  • CCISO Domain 1 Governance & Policy: Advised on the modernization of BYOD policies and partnered with WDW Legal and eDiscovery to preserve digital evidence and enforce data retention utilizing NetDocuments.
  • CISSP Domain 7 Access & Integrations: Coordinated with internal teams to configure enterprise app integrations (SSO/SCIM) across Active Directory/Azure, Exchange Online, SCCM, and major VTC platforms (Zoom, BlueJeans).
  • CCISO Domain 4 Risk Mitigation: Proposed and executed reviews of Digital Assets utilizing the CIA Triad principles; developed and executed advanced training protocols to counter targeted spear-phishing campaigns.
  • Rapid Deployment: Devised solutions to rapidly transition executives to remote work environments during crisis periods (COVID-19), securing home networks and deploying 2FA/Citrix architectures.
IT Consultant - Small Business / Digital Forensics
Shaun Marshall Consulting | Florida | February 2006 – Present
  • CISSP Domain 7 Digital Forensics & Recovery: Provide basic digital forensics, data recovery, and incident response services for small businesses, recovering critical business records from failing arrays and compromised systems.
  • CISSP Domain 3 Infrastructure Architect: Design and deploy segmented, secured networks with robust remote access. Author tailored policies for Business Operations, Disaster Recovery (DR), and Business Information Security.
Systems & Support Analyst
Roetzel & Andress (Law Firm) | Orlando, FL | January 2008 – December 2009
  • Resolved critical infrastructure and software issues for legal end-users utilizing Citrix and WestLaw, administering Active Directory for user account and security group management.
Senior Field Service Technician (NMCI)
Dept. of the Navy, NAVAIR | Orlando, FL | April 2001 – February 2006
  • CCISO Domain 4 Forensic Investigation: Assisted DoD Information Assurance (IA) personnel with critical forensic investigations on the Navy/Marine Corps Intranet (NMCI), ensuring the chain of custody and adherence to federal evidentiary laws.
  • Enterprise Support: Provided hardware/software support for over 1,100 clients, utilizing Active Directory, SMS, and Tivoli for widespread software deployment and role-based access control.
  • Project Leadership: Led research remediation teams to resolve major software deployment issues, preventing costly SLA penalties. Received Command Master Chief Award for Excellent Service.
Electronics Lab Manager
University of Central Florida, Dept. of Nursing | Orlando, FL | August 1998 – January 2001
  • Pioneered the first digital Nursing electronics lab. Designed, assembled, and administered a network of 28 workstations and Virtual IV simulation stations.
  • Championed and authored the transition to Computer Based Training (CBT) and established SOPs via the "Best Practices & Lab Maintenance" guide.
Safety Engineer & Computer Specialist
NASA Kennedy Space Center | Titusville, FL | May 1996 – August 1998
  • Safety Engineer - Pressure Vessels and Systems (PV/S). Performed audits on contracting companies responsible for specific safety requirements for their respective PV/S. Directly inspected PV/S to ensure compliance and safety.
  • Developed and maintained the first comprehensive Pressure Vessels & Systems (PV/S) tracking database within Safety & Mission Assurance, building a secure web portal for DoD contractors to verify system integrity.
  • Shuttle Upgrades Project: Conducted crucial feasibility studies and specific impulse analysis for the Liquid FlyBack Booster (LFBB) project to assess reusable KerOx engine viability.

Education & Certifications