About
Marcus Coleman
Senior Information Security Specialist · Open to remote roles internationally and anywhere in the US
I'm a security engineer. For 14+ years I've worked across federal, higher-education, and payment-processing environments, and for the last 8+ I've focused on application security — SAST and DAST triage, secure-SDLC partnership with engineering teams, and penetration test programs from scope to sign-off.
The other half of the work is data. I run enterprise vulnerability-management programs the way an analyst would: Python pipelines that ingest scanner and ticket exports, blended risk scores built from CVSS, EPSS, and CISA KEV, and executive dashboards that turn tens of thousands of findings into a short, ranked list of what to fix first. An M.S. in Data Analytics sits behind that — machine learning and statistical modeling applied to severity prediction and remediation forecasting.
I build things, not just operate them: a Splunk SIEM stood up from nothing, the first enterprise-wide DAST rollout in a federal research environment, an automation pipeline that cut manual assessment time by roughly 40%.
Capabilities
The full range
-
Vulnerability Management
Run the program end to end: risk-based SLAs, triage, remediation tracking, MTTR reduction.
- Tenable Nessus
- Tenable.sc
- Invicti
- Qualys
- Nexpose
- GHAS
- CVSS
- EPSS
- CISA KEV
-
Application Security
SAST and DAST triage with source-code comprehension, false-positive analysis, retest and fix verification, secure SDLC, developer remediation guidance.
- OWASP Testing Guide
- SAST
- DAST
- secret scanning
- dependency review
- CI/CD integration
-
Security Automation & Engineering
Python pipelines that ingest scanner and ticket data, produce KPI dashboards, and shift scanning left into CI/CD.
- Python
- pandas
- NumPy
- scikit-learn
- Git
- ServiceNow integration
- API / data pipelines
-
Offensive Security
Web-app and network penetration testing, scope and methodology definition, exploitation validation, custom Python tooling.
- Kali Linux
- Nmap
- NIST SP 800-115
- CPTE
-
Data Analytics & Machine Learning
Supervised and unsupervised learning, time series, NLP, hypothesis testing, and predictive modeling applied to risk scoring and remediation forecasting.
- Tableau
- dashboard design
- data storytelling
- M.S. Data Analytics
-
Security Operations & Detection
SIEM build, administration, dashboards, and log onboarding; EDR; incident response, malware investigation, alert triage and tuning.
- Splunk
- CrowdStrike
- incident response
- threat intelligence
-
Cloud & Infrastructure Security
AWS vulnerability assessment, firewall management, network segmentation, and Linux server administration.
- AWS Inspector
- GuardDuty
- Security Hub
- Cisco ASA
-
Compliance & Frameworks
Assessment and audit support against federal and industry standards, ATO packages, and continuous monitoring.
- FISMA
- NIST SP 800-53
- NIST SP 800-115
- CISA directives / KEV
- PCI-DSS
- CIS Benchmarks
-
Communication & Leadership
Executive and technical reporting, C-suite briefings, Statements of Work, remediation runbooks, and cross-functional program leadership.
- executive reporting
- SOW authoring
- developer enablement
- security-awareness training
Credentials
Certifications & clearance
- Certified Penetration Testing Engineer (CPTE) — Mile2
- Public Trust security clearance — active
Fit
What I’m looking for
I'm open to senior individual-contributor and lead roles in application security, vulnerability management, or security automation / detection engineering — especially where a data-analytics background is an asset rather than a curiosity. I work fully remote and take remote roles internationally and anywhere in the US. Active Public Trust clearance.