Anthony Villanueva
Senior Security Administrator | 7+ Years of Experience
I am a cybersecurity professional with a diverse background spanning both military and civilian sectors. My career began in the military, where I developed strong leadership, problem-solving, and operational security skills in high-pressure environments. After transitioning to the civilian workforce, I built a successful career as a Security Administrator and Information Security Auditor, focusing on network management, policy development, and incident response.
As the founder of a cyber consulting company, I secured government contracts and delivered specialized technical services, demonstrating my ability to excel in both technical execution and business strategy.
Work experience
Senior Security Administrator
Edelson PC / Jan 2021 - Present
IT Security Auditor
FIS / May 2019 - January 2021
Network Security Engineer
United States Air Force / November 2016 - April 2023
CTO/Co-Founder
Zeroday Talent / February 2023 - Present
Areas of expertise
01
Cybersecurity Risk Management
02
Policy Development and Compliance
03
Incident Response and Threat Detection
04
Managed IT and Cybersecurity Services
Recent projects
Multi-layered network Deployment for Nationwide Remote Offices
Led and performed the design, deployment, and management of multi-tiered network infrastructure at various remote office locations nationwide. The project involved configuring and implementing secure, scalable networks from end to end that fit each location's particular needs.
Key Contributions:
Network Design and Configuration: Developed a comprehensive design for the network, including firewalls, VPNs, and security Wi-Fi, to establish connectivity smoothly with high security at all sites.
Deployment & Implementation: Coordinated and executed the installation of network equipment, including routers, switches, and access points, in a manner that minimized business disruption.
Centralized Management: A mechanism for a centralized monitoring and management system that can allow real-time performance tracking, proactive issue resolution, and so on should be provided.
Security Integration: Integrated several layers of security, intrusion prevention, endpoint protection, and periodic vulnerability assessments to attain the integrity of sensitive data while maintaining compliance.
Ongoing Support: Provided ongoing support and maintenance for its network, ensuring maximum optimization of performance and addressing any technical challenges arising on time
Development and Implementation of Information Security Policies
The end-to-end development and implementation of a comprehensive information security policy framework led an organization to create policies from scratch and map them to CIS Control Matrices in laying a very strong foundation of security and best practices of the industry.
Key Contributions:
Policy Framework Development:
Develop a full suite of information security policies that include, but are not limited to:
Access Control Policy
Data Protection Policy
Incident Response Plan
Acceptable Use Policy
Change Management Policy
CIS Control Mapping:
Mapped each policy with relevant CIS Controls to ensure cover-off for everything. Designed a full Risk and Control Matrix that would connect organizational risks with proper controls and policies, hence providing clarity on what needed to be done in order to mitigate such risks.
Stakeholder Collaboration:
Collaborated with cross-functional teams: IT, Legal, and Compliance to ensure policies were adapted to business objectives and regulatory requirements.
Training and Awareness:
Developed and delivered training programs to inform employees regarding new policies, embedding the culture of security awareness for smooth adoption at all levels of the organization.
Implementation and Monitoring:
The implementation of the policy and setting up of processes for continuous monitoring were carried out to ensure compliance and effectiveness. This included reviewing and updating the policies periodically for both emerging threats and the changing regulatory landscape.