00 // mission_briefing · RHCE · Security+ · Federal SOC

Security Platform
Engineering.
AI Automation.

Federal-grade security engineering and AI automation — from a practitioner actively running Tenable VM, Ansible, CIS/STIG compliance, and AI chatbot deployments. Available for security advisory contracts and local business AI builds.

root@rootandsecure ~ %
$whoami
security-platform-engineer — RHCE certified
$cat credentials.txt
✓ RHCE · RHCSA · CompTIA Security+
✓ 10+ yrs Linux & federal infrastructure
✓ CIS / STIG / FISMA / CISA KEV · Zero Trust
✓ Tenable VM · Ansible · Armis · Axonius · Dtex · Sentinel
$cat engagement_scope.txt
VM Engineering · Linux Hardening · Platform Integration
Federal SOC · Hybrid Cloud · RHEL 7/8/9
$cat availability.txt
✓ Available for short-term contracts
✓ Remote-first · DMV on-site available
✓ 30–120 day engagements
$./initiate_engagement.sh
10+
yrs_linux_exp
6
platforms_owned
1,500+
servers_hardened
3
active_certs
01 // services

Two Tracks. One Standard.

Security infrastructure for technical teams. AI automation for local businesses. Both built the same way — no templates, no shortcuts.  ·  info@rootandsecure.io

TRACK_01
Security & Infrastructure
TRACK_02  // new
AI Chatbot Development
SVC_001 // fractional · track_01

Vulnerability Management Engineering

Tenable deployed but findings aren't actionable. Scan coverage gaps, POAMs out of sync, audits approaching. This engagement closes those gaps — credentialed coverage validated, findings prioritized, reporting audit-ready.

Discuss engagement ▶ Currently unavailable
SVC_002 // project · track_01

Linux Hardening & Compliance Automation

CIS/STIG baseline delivered at scale with Ansible. Assessment, playbook development, Tenable compliance validation, and documented exceptions. Built for RHEL environments. Evidence-ready on day one.

Discuss engagement ▶ Currently unavailable
SVC_003 // project · track_01

Security Platform Integration

Enterprise tools deployed but not operationalized. Armis, Axonius, Sentinel, DTEX — platform configuration, asset inventory integration, alerting workflows, and operator documentation. From installed to running.

Discuss engagement ▶ Currently unavailable
SVC_004 // project · track_02

Appointment Booking & FAQ Bot

Dental practices, medical offices, and service businesses. Trained on your real content — hours, services, insurance, emergency routing. Live on your site in 2–4 weeks. Captures leads while your office is closed.

View AI services ▶
SVC_005 // project · track_02

Lead Qualification Bot

Law firms, real estate agencies, and high-inquiry businesses. Qualifies leads 24/7, collects intake information, and routes hot prospects to your team before a competitor responds. Builds on your existing website.

View AI services ▶
SVC_006 // retainer · track_02

Tenant & Customer Support Bot

Property managers and e-commerce brands. Routes maintenance requests, answers policy questions, handles order status — all without staff involvement. Monthly optimization retainer keeps it current.

View AI services ▶
Discuss a Project AI Chatbot Services ▶
03 // lab_output

Real Work. Production Grade.

CIS RHEL 9 benchmark automation — Level 1 & Level 2. Ansible-driven. Validated against Tenable VM. 213 controls. 191 implemented.

cis-rhel9-l1.yml ANSIBLE
1# CIS RHEL9 L1 — SSH Hardening
2- name: "5.1.1 | Ensure sshd config permissions"
3  ansible.builtin.file:
4    path: /etc/ssh/sshd_config
5    owner: root
6    group: root
7    mode: '0600'
8  tags: [ssh_hardening]
9- name: "5.1.20 | Disable X11 forwarding"
10  ansible.builtin.lineinfile:
11    path: /etc/ssh/sshd_config
12    regexp: '^X11Forwarding'
13    line: 'X11Forwarding no'
14    state: present
15  notify: Reload sshd
16  tags: [ssh_hardening]
17- name: "5.1.22 | Disable TCP forwarding"
18  ansible.builtin.lineinfile:
19    path: /etc/ssh/sshd_config
20    regexp: '^DisableForwarding'
21    line: 'DisableForwarding yes'
22  notify: Reload sshd
23  tags: [ssh_hardening]
cis_summary.py — control output TENABLE
Control Category Risk Result
1.4.2 Bootloader configBootloaderCRITICAL✓ PASSED
1.6.1 Crypto policyCrypto PolicyCRITICAL✓ PASSED
1.6.5 Disable CBC SSHCrypto PolicyCRITICAL✓ PASSED
1.3.1.6 Unconfined svcsSELinuxCRITICAL✗ FAILED
4.2.2 Firewalld loopbackFirewallCRITICAL✗ FAILED
5.1.10 DisableForwardingSSH ConfigCRITICAL✗ FAILED
5.4.2.7 System acct shellsAccountsHIGH✗ FAILED
6.1.3 AIDE integrityFile IntegrityHIGH✗ FAILED
213
total controls
191
implemented
89%
pass rate
L1+L2
CIS level
04 // field_evidence

Numbers From Production.

Federal SOC environment. Active engagements. Not a lab.

VM Program
5,400+
assets under active vulnerability management across hybrid on-prem and cloud infrastructure
CIS Hardening
213
CIS RHEL9 controls automated via Ansible — L1 and L2 — validated against Tenable compliance scans
Platform Ownership
6
enterprise security platforms owned and operated simultaneously — Tenable, Armis, Axonius, DTEX, Ansible, EnCase
Scan Coverage
RHEL
7, 8, and 9 environments under active credentialed scanning with plugin coverage validated per asset class
Compliance Frameworks
FISMA
CISA KEV, FISMA, and Zero Trust alignment across federal SOC — POAMs and RAs maintained and reported
Infrastructure
Hybrid
on-prem and Azure cloud — Windows and Linux fleets — integrated across security tooling and SIEM pipelines
05 // about
Not a Trainer.
A Practitioner.

Built in federal SOC environments, not classrooms. Every control, playbook, and remediation workflow here runs in production against real government infrastructure — daily.

A decade-plus of hands-on work across RHEL 7/8/9, VMware, Azure, and hybrid cloud. 1,500+ servers hardened, CIS and STIG pipelines automated with Ansible, and vulnerability operations run across six enterprise platforms under FISMA and CISA KEV frameworks.

Root & Secure is the external face of that work — available for fractional security platform engineering, vulnerability management engagements, and compliance automation projects for organizations that need senior-level execution without a full-time hire.

Certification
Red Hat Certified Engineer (RHCE)
✓ Active
Certification
Red Hat Certified System Administrator (RHCSA)
✓ Active
Certification
CompTIA Security+
✓ Active
Current Role
Security Platform Engineer
Federal SOC Environment
06 // initiate_engagement

Ready to Execute?

Engagements are scoped to your environment, timeline, and deliverables. Start with a brief email outlining your need — we'll respond within one business day.

01.

Send a project brief

Email info@rootandsecure.io with scope and timeline
02.

Scoping call

30 minutes — define deliverables, timeline, and fit
03.

Engagement agreement

SOW issued — clear scope, rate, and start date
04.

Execution begins

Production-ready from day one — no ramp-up theater
>_ initiate_engagement.sh

Send a brief description of your project, environment, and timeline. Engagements typically run 30–120 days. Remote-first, available to federal contractors and private sector organizations.

▶▶ Email info@rootandsecure.io Read Field Notes
07 // faq

Common Questions

Federal contractors, mid-size organizations, and security teams that need senior-level Linux security engineering or vulnerability management execution without a full-time hire. Engagements are typically 30–120 days, scoped to specific deliverables.
RHEL 7/8/9, Ubuntu, hybrid on-prem and Azure environments. Tool stack includes Tenable VM, Tenable WAS, Armis, Ansible, Python, and Splunk/Sentinel. Familiar with FISMA, FedRAMP, CMMC, and CISA KEV compliance frameworks.
Engagements begin with a scoping call to define deliverables, timeline, and rate. A statement of work is issued before work begins. Remote-first with availability for DMV-area on-site work as needed.
Yes — most engagements are additive to an existing team, not replacement. Common scenarios include surge capacity for an ATO push, building out a VM reporting pipeline, or delivering a hardening project the internal team doesn't have bandwidth for.
Yes. Invoices and statements of work are available for direct employer or contracting vehicle engagement. Contact info@rootandsecure.io to discuss scope and contracting options.