Paul Gifford

Top-Secret Clearance  ·  Network Security Engineer  ·  Cloud / AI

Network and IT professional with 10 years of experience in enterprise and DoD environments spanning network engineering, systems administration, and infrastructure security. Supported 500+ workstations and 1,000+ endpoints, including classified SIPR/NIPR networks, with hands-on vulnerability remediation and adversary-simulation lab experience. Currently building a cloud/AI portfolio — AWS serverless architecture, Terraform IaC, and Anthropic Claude API applications — while pursuing AWS Solutions Architect Associate certification. Active Top Secret clearance.

Networking TCP/IP, DNS, VLANs, Subnetting, Routing & Switching, OSPF, BGP, SD-WAN, VPN, Aruba Controllers/APs, EdgeConnect, Cisco ISR/Catalyst, pfSense
Security & Compliance Vulnerability Assessment, STIG, ACAS/Tenable, POA&M, IAVM, Firewall Hardening, ACLs, RBAC, AD Security, 802.1X
Systems Windows Server, Active Directory, VMware, Linux, PowerShell, Bash, Python, Splunk, Wireshark
Cloud & AI AWS (S3, CloudFront, Route 53, Lambda, DynamoDB, API Gateway, IAM), Terraform, GitHub Actions CI/CD, Git/GitHub, Claude API, Tool Use/Function Calling, Agentic Workflows, REST APIs
Offensive Security Labs Nmap, Burp Suite Pro, Metasploit, Kali, SQL Injection, XSS, Auth Bypass, OWASP Top 10
Self-Directed Independent Study & Cloud/AI Portfolio Development January 2026 – Present
Virginia Beach, VA
  • Studying for AWS Solutions Architect Associate (SAA-C03) certification, targeting August 2026, covering VPC design, IAM policy, high availability, and cost optimization.
  • Built the AWS Cloud Resume Challenge (S3, CloudFront, Route 53, Lambda, DynamoDB, API Gateway, GitHub Actions CI/CD), live at paul-giff.com, including automated deployment on every commit.
  • Rebuilt the same architecture as reusable Terraform modules to practice Infrastructure as Code and repeatable, version-controlled deployments.
  • Built the Claude Task Agent, an autonomous Python agent using the Claude API with a tool registry (web search, file I/O, math evaluation) and session memory across multi-step reasoning loops.
  • Built Interview Copilot, a real-time AI interview assistant integrating Deepgram speech-to-text with the Claude API, packaged as a standalone Windows .exe via PyInstaller and published on GitHub.
  • Maintaining an active GitHub portfolio for both cloud/AI and DoD network engineering roles.
Network Engineer September 2025 – January 2026
Altagrove
  • Managed and maintained shipboard wireless networks across 4 vessels, supporting 40+ access points per ship and 100+ concurrent users in a maritime RF environment.
  • Configured, hardened, and monitored Aruba wireless controllers/APs and EdgeConnect SD-WAN appliances, maintaining 99.9% uptime across all vessels.
  • Designed and implemented 4-VLAN network segmentation to isolate operational, guest, and administrative traffic and reduce attack surface.
  • Conducted 2 shipboard site surveys to plan AP placement, identify RF interference, and validate coverage before deployment.
  • Troubleshot connectivity and performance issues in a challenging shipboard RF environment, coordinating with ship's crew and remote engineering support.
  • Documented network configurations and change history to support handoff and future maintenance.
Network Systems Administrator September 2023 – September 2025
Leidos — SURTASS
  • Administered NIPR, SIPR, and ICP networks supporting classified DoD surveillance operations, ensuring continuous availability and compliance with DoD security standards.
  • Managed 40 VMware ESXi virtual machines (20 NIPR / 20 SIPR), handling provisioning, patching, and resource allocation across both classification enclaves.
  • Applied STIG hardening and supported RMF compliance activities to keep systems audit-ready and aligned with DoD cybersecurity requirements.
  • Ran weekly ACAS/Tenable vulnerability scans and tracked remediation through POA&Ms, maintaining zero unresolved findings across all scan cycles.
  • Monitored network and system health via Splunk, using dashboards and alerts to proactively identify and resolve issues before they impacted operations.
  • Managed 30 user accounts across 10 security groups using role-based access control (RBAC), enforcing least-privilege access on classified networks.
  • Troubleshot satellite (SATCOM) connectivity issues affecting shipboard data links, achieving a 30–60 minute average recovery time.
  • Maintained IAVM compliance by tracking and applying required security patches and configuration changes on a recurring schedule.
  • Operated and maintained TACLANE encryption devices to secure classified data in transit between NIPR and SIPR enclaves.
Network Operations Specialist June 2022 – November 2022
Prime Technical Services
  • Monitored 10,000+ systems and endpoints across a distributed network, using monitoring tools to detect and triage outages and performance issues.
  • Resolved 10–20 tickets per week covering connectivity, hardware, and software issues, prioritizing based on operational impact.
  • Performed patching and remediation across the monitored environment to maintain security posture and system stability.
  • Authored standard operating procedures (SOPs) for recurring network operations tasks, improving consistency and onboarding for new team members.
Field Service Technician (NMCI) March 2017 – October 2021
Prime Technical Services
  • Provided on-site IT support for 500+ workstations and 1,000+ endpoints across NAS Oceana and Dam Neck under the Navy Marine Corps Intranet (NMCI) contract.
  • Resolved 50–100 tickets per week spanning hardware failures, software issues, account access, and network connectivity for a high-volume DoD user base.
  • Imaged and deployed 200+ systems as part of ongoing infrastructure refresh cycles, following DoD configuration and security baselines.
  • Diagnosed and repaired desktop, laptop, and peripheral hardware issues, minimizing user downtime in a fast-paced operational environment.
Hospital Corpsman (HM) May 2009 – August 2016
United States Navy
  • Served 7 years of active duty, supervising 3+ junior sailors and mentoring them on technical proficiency and military readiness standards.
  • Delivered medical training to unit personnel, ensuring readiness for both routine and emergency medical response.
  • Managed day-to-day administrative duties, including scheduling, documentation, and compliance reporting, in a high-tempo operational environment.

This page is one of the projects below — a serverless static site with a real-time request counter. Here's how it's wired.

GitHub Actions S3 CloudFront Route 53 You, now Your browser API Gateway Lambda DynamoDB count +1 per visit deploy & delivery ↳ push to main triggers CI/CD; edge network serves the static site visitor counter (right → left, this call happens on every page load)
Live visitor count · DynamoDB

AWS Cloud Resume Challenge

GitHub →

Built and deployed a fully serverless personal site and resume API, live at paul-giff.com.

S3CloudFrontRoute 53LambdaDynamoDBAPI GatewayGitHub Actions

Cloud Resume Challenge — Terraform IaC Rebuild

GitHub →

Rebuilt the Cloud Resume Challenge architecture as reusable Infrastructure as Code.

TerraformAWS

Claude Task Agent

GitHub →

Built an autonomous agent with a tool registry (web search, file I/O, math evaluation) and session memory across multi-step reasoning loops.

PythonClaude APIBrave Search APIGit

Interview Copilot

Windows .exe

Built a real-time AI interview assistant, packaged as a Windows .exe via PyInstaller and published on GitHub.

PythonDeepgramClaude APIPyQt5VB-Audio

Hybrid Virtual Pentest Lab

Home Lab

Built a 5-VM, 4-subnet lab with a DMZ and an Active Directory domain (Windows Server 2022, Windows 10, Kali, Metasploitable 2) for adversary-simulation practice.

VMwarepfSenseKaliMetasploitBurp Suite
B.S., Computer and Information Science — Cybersecurity Concentration Graduated July 2023
ECPI University
  • CompTIA Security+
  • CompTIA A+
  • AWS Certified Solutions Architect – Associate (SAA-C03) — in progress, target August 2026