United States Postal Service Office of the Inspector General
Cloud Security Engineer, FedRAMP — General Services Administration (GSA)
Chief of Staff, FedRAMP — General Services Administration (GSA)
Manager, Security Engineering and Risk Management Group — National Institute of Standards and Technology (NIST)
Security Director, FedRAMP — General Services Administration (GSA)
Director, FedRAMP — General Services Administration (GSA)
CISO — Knox Systems
Technical Fellow — Schellman
CISO — Second Front Systems
Founder & CEO — InfusionPoints
GRC Technical Lead — OpenAI
VP of Operations — Fortreum
Global Head of Government Affairs — Wiz
Managing Principal — Schellman
Chief Technology Officer — Knox Systems
Head of Public Sector — Vanta
Director of Quality Management — A-LIGN
COO — Paramify
Founder & CEO — Paramify
Senior Security Engineer — Paramify
CTO — stackArmor
The CSP-AB Summit is a high-impact forum bringing together Federal policy leaders, industry stakeholders, and security experts around a single mission: accelerating secure cloud adoption across the Federal enterprise.
United States Postal Service Office of the Inspector General
Biography
Matthew joined the USPS OIG in January 2022 and has worked on a variety of audits including Network Processing, Cyber Security & Technology and Transportation. He currently works in Audit Services supporting training programs.
Prior to this, Matthew worked for the Naval Audit Service since 2002, including as an Audit Manager since 2010. He led a variety of audits as an audit manager including audits on Naval SEAL training, IT system controls, diversity and inclusion training for Officers, and compliance with Congressional Budget requirements.
He is a Certified Internal Auditor and holds a B.S. in Business Administration from the University of Pittsburgh. In his spare time, Matthew enjoys spending time with his wife and two children and spends a lot of time at baseball and softball games.
Biography
Dan Chandler is a cloud security engineer on the FedRAMP team, where he provides policy guidance and technical expertise.
Before joining the FedRAMP team, Dan worked at the Office of Management and Budget (OMB) from 2007 – 2025. He served in multiple roles, including as the Program Manager for MAX.gov and as the first OMB CISO. Dan has the unique distinction of being the first person to complete the FedRAMP “trifecta”: managing a Cloud Service Provider (CSP), working as an Agency CISO authorizing FedRAMP CSPs, and now working on the FedRAMP team.
Dan is passionate about public service and cybersecurity. When he is not protecting the government’s data, he enjoys woodworking, playing with dogs, and spending time with his children.
Biography
Ryan joined FedRAMP in December 2016 as a business analyst with the goal of finding and building out more efficiencies in the FedRAMP A&A processes.
With over 10 years of direct engagement with FedRAMP customers, both agencies and cloud service providers, Ryan has ensured agencies and CSPs have the guidance they need to successfully complete the FedRAMP Authorization process. Ryan developed and continues to lead FedRAMP’s Agency Liaison program educating agencies on new FedRAMP initiatives.
Ryan holds a B.A. in Business Administration from the University of Nebraska-Lincoln and a M.S. in Cybersecurity Management and Policy. Additionally to his outward facing role supporting FedRAMP stakeholders, Ryan is a Contract Officer’s Representative (COR) Level III and helps guide internal acquisition and business strategies for FedRAMP.
Biography
Ms. Victoria Yan Pillitteri is a supervisory computer scientist in the Computer Security Division at the National Institute of Standards and Technology (NIST). Ms. Pillitteri is the Manager of the Security Engineering and Risk Management Group and leads the Risk Management Framework team/Federal Information Security Modernization Act (FISMA) Implementation Project. In that role, she develops the suite of risk management guidance used for managing cybersecurity risk in the federal government and coordinates the associated stakeholder outreach and public-private sector collaboration efforts. Ms. Pillitteri leads the Joint Task Force working group, a partnership with the Department of Defense, the Intelligence Community, and Civilian Agencies to develop a unified security framework to protect the U.S. Government from cyber-attacks, and is co-chair of the Federal Cybersecurity and Privacy Professionals Forum hosted by NIST.
Ms. Pillitteri previously led programs in smart grid and cyber-physical systems cybersecurity, worked on the Framework for Improving Critical Infrastructure Cybersecurity, the Privacy Framework, and served as a program analyst in the NIST Office of the Director.
Ms. Pillitteri holds a B.S. in Electrical Engineering from the University of Maryland and an M.S. in Computer Science with a concentration in Information Assurance from The George Washington University. She has completed the Key Executive Leadership Program at American University and the Office of Personnel Management (OPM) Senior Executive Service Candidate Development Program, receiving an SES certification by the OPM Qualifications Review Board. Ms. Pillitteri is a Certified Information Systems Security Professional (CISSP).
Biography
Nicole joined FedRAMP in January 2025 as the FedRAMP Security Director. She has over 15 years of experience in cybersecurity, specializing in hardware/software integration, vulnerability management and remediation, and penetration testing.
Nicole previously worked at the Defense Digital Service as the cybersecurity engineer running the Hack the Pentagon program.
She is passionate about improving risk management decision processes by relying on more meaningful security metrics.
Biography
Pete brings decades of experience in the development and adoption of technology services in both the private and public sector.
He joined federal service in 2019 with the US Digital Service where he became deeply familiar with the complex web of laws, regulations, policies and standards that make deploying technology in government entirely different from the private sector. Prior to public service, he led engineering teams that delivered internet based services at various size software companies.
Outside of work, Pete likes to explore and has traveled across much of the world by motorcycle or other vehicles – he once turned down a reality tv show because it would limit his ability to just go where the road takes him.
Biography
Hemant Baidwan is the Chief Information Security Officer (CISO) at Knox Systems, where he leads enterprise cybersecurity strategy and the development of AI-driven, cloud-native security platforms. He is responsible for building a next-generation Cyber Fusion Center that integrates automation, real-time analytics, and advanced threat detection across multi-cloud environments. His work focuses on operationalizing Zero Trust at scale, enabling rapid FedRAMP and IL4/IL5 authorizations, and embedding security directly into DevSecOps pipelines to deliver continuous compliance and near real-time risk visibility. He is also driving the adoption of AI to enhance response automation and predictive risk modeling across government and commercial workloads.
Previously, Mr. Baidwan served as the CISO and Acting Deputy Chief Information Officer at the U.S. Department of Homeland Security (DHS), where he was responsible for securing one of the largest and most complex civilian federal environments. He oversaw the Department’s Information Security Program, including FISMA compliance, risk management, security operations, and continuous monitoring across a multi-billion-dollar IT portfolio. During his tenure, he led major initiatives such as the Hack DHS program, the Unified Cybersecurity Maturity Model (UCMM), Cyber Supply Chain Risk Management (C-SCRM), and enterprise Zero Trust implementation. He also served as Vice Chair of the Federal CISO Council and as a Board Member of the FedRAMP Board, helping shape government-wide cybersecurity and cloud security policy. He played a key role in advancing AI-driven cybersecurity capabilities and modernizing security operations across the Department.
Mr. Baidwan brings over 20 years of leadership experience across cybersecurity, cloud security, governance, and large-scale digital transformation in both the public and private sectors. He has led the modernization of Risk Management Framework (RMF) processes, implemented continuous authorization and monitoring at scale, and driven automation to improve security outcomes and reduce operational burden. He is known for aligning cybersecurity strategy with mission outcomes and delivering measurable improvements in enterprise risk posture.
Earlier in his career, Mr. Baidwan held senior leadership roles in the private sector, where he led global IT and security organizations, scaled secure infrastructure across multiple regions, and drove innovation in secure application development and enterprise architecture.
Mr. Baidwan holds a bachelor’s degree in information systems and has completed executive leadership programs at Cornell University and Johns Hopkins University.
Biography
Matt Conner joined Second Front as the Chief Information Security Officer (CISO) in May 2024 after previously serving as an independent Board Director. Mr. Conner leads the cybersecurity program at Second Front, and is responsible for cyber defense, risk management, policy, and cybersecurity governance.
Prior to joining Second Front, Matt served as the CISO for Westinghouse Electric Company, a global nuclear energy firm operating in more than 20 countries. Mr. Conner previously served as the CISO of the US Intelligence Community and was the principal advisor to the Director of National Intelligence and Chief Information Officer for cybersecurity risk and governance. He was responsible for orchestrating the cybersecurity program for the eighteen agencies of the IC and defined the strategy and implementation plan for the people, processes, and technology to lead the IC into the future.
Matt was the Chief Information Security Officer for the National Geospatial-Intelligence Agency in Springfield, VA between 2015 and 2020 and formerly held senior leadership roles with General Dynamics Mission Systems and Information Technology. Mr. Conner and his family live in Northern Virginia.
Biography
Gary Daemer is the CEO and Founder of InfusionPoints, a cybersecurity, cloud engineering, and compliance firm that helps organizations build, operate, prove, and defend secure cloud environments. With nearly 40 years of experience spanning federal, commercial, and defense sectors, Gary has built and operated security programs, Security Operations Centers (SOCs), continuous monitoring capabilities, and cloud security platforms supporting some of the nation’s most demanding missions.
Since founding InfusionPoints in 2007, Gary has led the company’s growth into a trusted advisor for federal agencies, cloud service providers, and regulated organizations seeking to accelerate secure cloud adoption. His work focuses on FedRAMP modernization, continuous compliance, authorization automation, and measurable trust through machine-verifiable evidence and continuous assurance.
A long-time advocate for reducing compliance burden while improving security outcomes, Gary brings a practitioner’s perspective to the evolving cloud security landscape. He has supported dozens of cloud authorization efforts, designed secure cloud architectures, and helped organizations operationalize security at scale through automation and outcome-driven approaches.
Prior to InfusionPoints, Gary held leadership and technical roles with AT&T, American Management Systems, Booz Allen Hamilton, Lowe’s Companies, and the North Carolina Army National Guard. He holds a Master of Science in Systems Engineering from Virginia Tech, a Bachelor of Science in Electrical Engineering from UNC Charlotte, and maintains numerous industry certifications including CISSP and multiple AWS certifications.
GRC Technical Lead — OpenAI
Biography
John Gallagher works on U.S. government compliance at OpenAI, with a focus on FedRAMP and DoW cloud security requirements. He previously served as Director of U.S. Government Cloud Compliance for Azure at Microsoft.
Biography
Gary Guercio is a Governance, Risk management and Compliance (GRC) professional with over 20 years of cybersecurity assessment and advisory experience. Federal Risk and Authorization Management Program (FedRAMP) Subject Matter Expert (SME) including the last 12 years in direct support of the FedRAMP program across three leading 3PAO’s. Over his career he has delivered FISCAM, FISMA, HIPAA, HiTRUST, ISO, SOC, SOX, and various other assessment and advisory services. He is a results-oriented leader responsible for the overall success of Fortreum services and products to include the FedRAMP Independent Assessment Services, the CMMC Certified Third-Party Assessment Organization (C3PAO) practice, the ISO certification body, CPA affiliate, all technical testing and advisory support services.
Biography
Mitch Herckis is Global Head of Government Affairs for Wiz, a cloud cybersecurity company. Prior to joining Wiz, Mitch served as Branch Director for Federal Cybersecurity at the White House Office of Management and Budget, where his team led implementation of the Executive Order on Improving the Nation’s Cybersecurity on behalf of the Office of the Federal CIO.
Before joining federal service, Mitch served as a Senior Advisor for New York City Cyber Command, driving cybersecurity implementations across 100+ agencies, and leading public initiatives to increase the digital security of City residents. Mitch also led federal technology policy and advocacy efforts for the National Association of State Chief Information Officers and National League of Cities.
Biography
Matt Hungate is a Managing Principal with Schellman based in Richmond, VA. Matt specializes in Federal Assessments at Schellman, including compliance with standards such as FedRAMP, GovRAMP, CMMC, and FISMA. Prior to joining Schellman in 2019, Matt worked as a Cybersecurity Consultant for a large advisory firm where he specialized in strategy and assessment services for the Department of Defense. Matt’s credentials include the CISSP, CISA, and CPA.
Biography
Chris Johnson is the Co-Founder and Chief Technology Officer of Knox Systems, a technology company pioneering secure, compliant cloud services purpose-built for the federal sector. At Knox, Chris leads the design and development of the Knox Cloud — a fully automated boundary framework that accelerates authorization and continuous monitoring across the three major hyperscalers, AWS, Azure, and GCP.
With over two decades of experience spanning DevSecOps, cloud infrastructure, and cybersecurity compliance, Chris has helped transform how agencies and SaaS providers achieve and maintain FedRAMP authorization. Under his leadership, Knox has developed advanced automation capabilities that reduce authorization timelines, unify control inheritance, and integrate directly with assessment tools and continuous monitoring pipelines.
Chris also oversees the company’s KnoxAI initiative, an applied research and engineering program focused on AI-driven compliance automation. KnoxAI integrates LLM-based agents and knowledge retrieval models to analyze configurations, assess risks, and generate evidence artifacts mapped to NIST 800-53 and FedRAMP controls. This capability forms the foundation of Knox’s next-generation compliance engine, enabling faster, data-driven ATO decisions.
Prior to co-founding Knox Systems, Chris served as Chief Services Officer at CoSo Cloud, where he led managed services, cloud operations, and large-scale FedRAMP deployments for major federal agencies and enterprise partners. His background combines deep technical expertise with a practical understanding of federal authorization processes, bridging the gap between innovation and compliance.
Chris is a recognized voice in the GovCloud and compliance automation community, contributing thought leadership on topics such as continuous authorization, secure boundary orchestration, and AI governance for regulated environments.
Biography
Morgan Kaplan is the Head of Public Sector at Vanta, leading the delivery of AI and automation-based GRC solutions to Federal, SLED, and industry end-users. Working at the intersection of public policy and technology modernization, Morgan has a strong passion for how advanced software, AI systems, and emerging technology can have a positive impact on government, business, and societal outcomes at-large.
Prior to Vanta, Morgan was a Senior Policy & Communications Lead at Palantir Technologies, a Fellow at the Carnegie Endowment for International Peace, the Executive Editor of the quarterly journal “International Security” at the Harvard Kennedy School, and before that an academic focused on the foreign policies of rebel groups. Morgan holds a Ph.D. and M.A. in political science from the University of Chicago, as well as a B.A. in International Affairs from the George Washington University.
Biography
Lee Neeper is a Federal Director at A-LIGN, a leading cybersecurity compliance and audit firm, where he draws on over 15 years of federal cybersecurity experience to advise cloud service providers and defense contractors on FedRAMP, CMMC, and related certification frameworks. His work spans technical compliance strategy and business development, helping organizations translate complex regulatory requirements into practical paths to authorization.
Beyond client advisory work, Lee is active in federal cybersecurity policy, participating in Capitol Hill discussions on FedRAMP reauthorization and contributing to the drafting of the next FedRAMP Authorization Act. He brings a rare combination of hands-on compliance expertise and policy-level perspective to the future of federal cloud security and defense industrial base requirements.
Biography
Mike Schreiner is a business leader, entrepreneur, investor, and currently Chief Operating Officer at Paramify, a platform that simplifies risk management and streamlines compliance across frameworks like FedRAMP, CMMC, GovRAMP, and more. Paramify helps teams continuously plan, implement, report, and monitor their security programs, reducing complexity, saving time, and improving audit outcomes.
Biography
Kenny Scott is the Founder and CEO of Paramify, a platform that automates modern security and compliance package management for enterprise organizations. Two decades across audit, GRC, and security engineering have given him a deep appreciation for the many ways the same control can be documented.
Biography
Isaac is a Senior Security Engineer at Paramify, leading the technical implementation of cloud and AI-driven security initiatives. His work focuses on cloud-native environments, including infrastructure hardening, Kubernetes deployments, and SIEM integration for continuous monitoring. He also manages corporate cybersecurity functions such as risk management, compliance, and endpoint security, supporting initiatives aligned with NIST 800-53 and FedRAMP. Isaac collaborates with executive teams to build practical, scalable security programs that meet the highest federal compliance standards.
Recently, Isaac helped design and implement Paramify’s AWS GovCloud environment, enabling the company to reach FedRAMP High Ready status in under four months. He also led FedRAMP 20x pilot programs leading to one of the first FedRAMP 20x Moderate authorizations. His approach prioritizes real security over checkbox compliance by applying risk-based hardening, threat modeling, and automation to ensure systems are both secure and audit-ready. He has been invited to speak on panels, webinars, podcasts, and at national conferences on risk management and compliance automation.
Biography
Matthew Venne is CTO and Distinguished Engineer at StackArmor, a subsidiary of Quantum Sky, where he leads 40+ engineers across AWS, GCP, and AI innovation. He is Chief Architect of record on three FedRAMP-authorized systems and technical SME on 20+ others, His current work centers on FedRAMP vulnerability disposition: a five-paper methodology series introducing PAIN, a deterministic, CVSS-Environmental-derived severity model that replaces subjective deviation requests with derivation logic locked before the scan and auditable by the AO.