StartToolsPatternsNotesAboutContact
RESUME

David R. Gillispie III

Cybersecurity engineer with close to a decade of experience across application security, cloud security, identity, vulnerability management, and penetration testing.

Public-safe resume. Internal metrics, exact environment details, and employer-specific information are excluded. Full resume available on LinkedIn or as a PDF on request.
Contact
Location
St. Augustine, FL · Remote
Technical Skills
Security domains
AppSecAI securityCloud securityIAMVuln managementIncident responsePenetration testing
Cloud & platforms
AzureAWSMicrosoft 365Entra IDGitHub
Detection & VM
Defender XDRSentinelSplunkElastic / Security OnionRapid7QualysNessus
Scripting
PythonPowerShellBashSQL
Pen Testing
Kali LinuxBurp SuiteMetasploitNmapBloodhound
IaC
TerraformAzure PolicyPolicy as Code
Frameworks
HITRUST CSFNIST CSFNIST 800-53CIS BenchmarksMITRE ATT&CKOWASPSOC 2HIPAAPCI DSS
Certifications
CompTIA
A+ · Network+ · Security+ · CySA+ · PenTest+
CIOS · CSIS · CSAP · CNSP · CNVP
ISC2
SSCP, Systems Security Certified Practitioner
CC, Certified in Cybersecurity
Other
Cisco Network Defense · Cybersecurity Essentials
MTA: Security Fundamentals · MTA: Windows OS
AI Security (Securiti AI)
Education
Western Governors University
B.S. in Cybersecurity and Information Assurance
Cincinnati State
A.S. in Cybersecurity and Network Engineering
Butler Tech Career Center
Information Technology Program, IT Tech Prep
Professional Summary

Cybersecurity Engineer with close to a decade of experience across application security, cloud security, identity and access management, vulnerability management, penetration testing, and enterprise security engineering. Drives internal AI security and penetration testing programs, validates exploitable weaknesses across cloud, SaaS, web application, and hybrid environments, and turns technical findings into practical remediation plans. Proven record improving external attack surface posture, reducing enterprise vulnerability risk, strengthening Zero Trust controls, and supporting secure adoption of AI-enabled workflows.

Selected Impact
AI
Internal AI Security Program. Evaluates LLM-enabled workflows, AI-assisted development patterns, sensitive data exposure paths, approved tool boundaries, DLP controls, prompt handling, and secure adoption requirements.
PT
Internal Penetration Testing Program. Leads repeatable assessment activity across cloud, identity, SaaS, application, and hybrid environments with evidence capture, exploitability analysis, remediation validation, and stakeholder-ready reporting.
72%
Vulnerability Management Modernization. Transformed enterprise vulnerability operations around exploitability and business impact, contributing to a 72% reduction in enterprise vulnerabilities.
External Attack Surface Improvement. Achieved highest-ever BitSight and SecurityScorecard ratings through exposure analysis, remediation coordination, and continuous validation of externally visible assets.
350K
Large-Scale Identity Resilience. Owned and migrated Duo MFA for 350,000+ identities, improving availability, recovery, policy control, and response readiness.
Experience
Cybersecurity Engineer
TherapyNotes
December 2024 – Present · Remote
Building out the internal penetration testing program, running iterative assessments across Azure, Microsoft 365, AWS, SaaS, identity systems, enterprise applications, and externally exposed assets. Findings address exploitable misconfigurations, privilege escalation paths, excessive permissions, authentication weaknesses, and attack surface exposure.
Core stakeholder in the internal AI security program, helping shape assessment scope, evaluate LLM-enabled workflows, identify data exposure risks, and define secure adoption boundaries around AI tooling, DLP controls, and prompt handling.
Advancing Zero Trust architecture across Microsoft 365 and Azure through Conditional Access hardening, Azure Policy and policy-as-code enforcement, privileged access reviews, PIM administration, least-privilege enforcement, and identity governance improvements.
Improving detection and response capabilities by tuning Microsoft Defender XDR and Sentinel analytics, refining suppression logic, building investigation workflows, and improving triage consistency.
Driving vulnerability validation and remediation through Rapid7 and Microsoft Defender findings, assessing exploitability and business impact, and working directly with system owners on risk-based remediation planning.
Developing Terraform and infrastructure-as-code security standards, reviewing module configurations, validating deployment risk, and defining enforceable cloud security guardrails through Azure Policy.
Contributing to cloud and network architecture reviews, including Azure NSG configurations, network segmentation design, and security engineering input on the network backbone rearchitecture.
Independent Security Consultant
DeepDream Security / Freelance
2025 – Present · Remote
Provide practical security consulting through external exposure reviews, web application security assessments, AI security reviews, and risk-based remediation planning.
Assess AI-created and AI-powered web applications for authentication, authorization, API exposure, secrets handling, and data protection gaps.
Senior Information Security Analyst
EssilorLuxottica (EyeMed)
April 2023 – December 2024 · Mason, OH
Achieved highest BitSight and SecurityScorecard ratings in company history.
Led overhaul of vulnerability management program, reducing enterprise vulnerabilities by 72% through exploitability-based prioritization, SLA enforcement, and validation workflows.
Partnered with penetration testers and engineering teams to reproduce vulnerabilities, validate findings, and assess exploitability.
Information Security Analyst
University of Cincinnati
October 2021 – April 2023 · Cincinnati, OH
Primary Duo MFA administrator and SME across a 350,000+ identity environment, owning configuration, policy enforcement, monitoring, integration health, and tier-3 escalations.
Led re-architecture and cloud migration of the Duo MFA platform, designing high availability, backup, failover, and recovery procedures to improve enterprise resilience.
Supported identity security, endpoint security, access control, and incident response.
Network & Security Engineer
Nexus Wifi
August 2019 – October 2021 · West Chester, OH (Promoted from Network Administrator)
Engineered and operated wired and wireless networks for 800+ router, switch, and access point environments.
Hardened client environments through internal security policies, practical security assessments, and improved network segmentation.
Teaching & Leadership
Adjunct IT Instructor
Cincinnati State Technical and Community College
Current · Online
Teaches networking and cybersecurity concepts, translating technical material into clear, practical instruction.
Advisory Board Member
NETA/CSA Program, Cincinnati State
Provides industry input on networking and cybersecurity curriculum alignment with current security engineering practice.
Public Work
Volunteer & Service
Cyber Incident Responder
Ohio Cyber Reserve · State of Ohio
March 2024 – March 2026
State-validated cyber incident responder supporting incident response operations for Ohio state agencies and critical infrastructure organizations through the Ohio Cyber Reserve program.
Responded to active cyber incidents, conducted triage and containment support, and contributed to post-incident analysis as part of a structured reserve unit.