Defense cloud & security engineer

Erik Cass

Twenty-five years in IT and cybersecurity, two decades in defense cloud and compliance. I author the controls and the authorization, engineer the systems and automation that satisfy them, and prove compliance with evidence and AI-assisted analysis — the whole arc, by one practitioner.

Mary Esther, FL  ·  U.S. Air Force veteran  ·  Former TS/SCI (inactive)

Available for select consulting & fractional security / compliance engagements

What I do

The work sits where security and compliance shift from paper to engineered, machine-readable artifacts.

01 Cloud & Security Engineering

AWS Commercial and GovCloud architecture across IL2–IL6 environments — hardened-AMI pipelines, Infrastructure as Code, DevSecOps/CI-CD, IAM/PKI, enterprise networking, DR and high availability. Nearly a decade of AWS. This is the core.

02 Compliance Automation & OSCAL

Centralized, NIST-aligned audit logging and monitoring on OpenSearch with AWS Config, Security Hub, GuardDuty, and Inspector; system-architecture-to-OSCAL control mapping; open-source OSCAL tooling that turns compliance into code.

03 RMF & Authorization

The RMF process end-to-end (NIST SP 800-37): control-implementation and SSP authoring, eMASS package development to ATO, NIST 800-53 implementation, assessment and POA&M workflow, OSCAL, FedRAMP.

04 Applied AI

Large-language-model application to compliance and document analysis — extracting control narratives into source-grounded, confidence-scored structured assertions.

Selected work

Palladium Innovations, LLC

Founder · 2022–present

An independent practice delivering AWS architecture, cybersecurity, and compliance-driven engineering to government and mission-focused customers — spanning P&L, business development, and end-to-end delivery.

AFSOC Cloud Computing Environments

Sr. Cloud Architect

Laid the foundational engineering for both the classified and unclassified Cloud Computing Environments at Air Force Special Operations Command — among the command's earliest AWS deployments, spanning unclassified through IL6, in direct support of the CTO.

DHRA Authority to Operate

RMF · ATO 2023

Developed a complete RMF authorization package end-to-end in eMASS for the Exhibit Arts Fulfillment System (DPFSO contract) — authored the control implementations and SSP, and earned the system's initial ATO under a designated Authorizing Official at the Defense Human Resources Activity.

Velsa

Builder · product

A source-available event-management platform built end-to-end and offered as a Palladium product — engineered as a security-and-compliance reference: server-enforced safe mode, scoped audit logging, and the same hardened-AWS deployment pattern I bring to client work.

fedramp-cr26-oscal

Open source · OSCAL

A dependency-free generator that turns the FedRAMP CR26 preview into machine-readable OSCAL artifacts (XML/JSON/YAML), profile shells, and NIST SP 800-53 Rev 5 mappings — compliance as code.

Writing

Practitioner notes — the kind I wish existed when I started.

Short field notes on OSCAL, the RMF in practice, and using language models for real compliance work. First pieces are in progress.

Turning an SSP into OSCAL without losing your mind What machine-readable control implementations actually buy you.
In progress
RMF for engineers The authorization process from the builder's seat, not the auditor's.
In progress
Grounding LLMs in the control catalog Source-cited, confidence-scored compliance analysis you can defend.
In progress

Experience

2022 – Present
Palladium Innovations, LLC — Managing Member
AWS architecture, cybersecurity, and compliance-driven engineering for government and mission-focused customers.
2023 – Present
Northwest Florida State College — Adjunct Professor
Undergraduate IT and computer science; CompTIA A+ and Tech+ (part-time).
2020 – 2023
GDIT / ARMA Global — Program Manager
Architecture & network engineering program supporting special-operations science & technology initiatives.
2012 – 2020
GDIT / ARMA Global — Principal Systems Engineer / Sr. Cloud Architect
Foundational engineering for AFSOC's classified and unclassified Cloud Computing Environments through IL6.
2009 – 2012
Intecon — Principal Systems Engineer
Air Operations Center weapon systems and mission applications in secure operational environments.
1997 – 2009
Earlier roles — Systems Administrator / Engineer / Instructor
Enterprise networks, virtualization, automation, and technical instruction.

Background

I started as an F-111 aircraft maintainer in the Air Force, spent two decades engineering secure cloud for defense, and now build the automation and evidence that make compliance provable rather than performative. I also teach — undergraduate computer science and IT, as an adjunct professor — and somewhere in there earned a culinary-arts degree, because the work of getting the details exactly right is the same in a kitchen as it is in a control catalog.

Off the clock I'm a husband and a father of two, and a perpetual tinkerer — gardening, woodworking, and coaxing vintage electronics back to life. Same instinct, different bench: figure out how a thing works, then make it work better.

Education

  • M.S., Management of Information Systems — Florida State University (2026, Cum Laude)
  • B.S., Computer Science — Florida State University (2018)
  • A.S., Culinary Arts — NWF State College (2021, Magna Cum Laude)

Service & Clearance

  • U.S. Air Force — Tactical Aircraft Maintenance (F-111), 1993–1997
  • Clearance — Former TS/SCI (inactive), eligible for reinstatement

Certifications

  • CompTIA CASP+ / SecurityX (Advanced Security Practitioner)
  • CompTIA A+ (lifetime) · LINBIT Certified Engineer
  • Coursework across AWS, Microsoft, VMware, and Red Hat

Also

  • Spanish (working proficiency)
  • Shipley-based proposal & capture development
  • DoD acquisition reviews (PDR / CDR / COA analysis)

Contact

Let's talk.

Compliance engineering, RMF and ATO work, secure cloud, or an OSCAL/AI problem worth solving — reach out, or grab a time directly.

Book Grab a time →
Email me@erikcass.com
LinkedIn linkedin.com/in/erikcass
Based in Mary Esther, Florida