IT Management · Cloud Security · AI Security · GRC · Federal Programs

Siddharth Maddali

Senior IT Manager with 18+ years across federal programs, cloud security, and GRC. Most of my work is helping teams get systems through ATO and build compliance programs that hold up over time.

Maryland, USA
01

About

I came up through development and freelance project work years ago, then moved into federal program management, security, and GRC. Recent work with CMS spanned security compliance, leading systems through ATO, and building programs that hold up to scrutiny. Along the way I’ve taken organizations through ISO 27001, ISO 9001, CMMI Level 3, and CMMC Level 2 — different frameworks, same discipline underneath. The newest area is AI security governance (ISACA’s AAISM): the same programs now have to account for AI systems. I stay close enough to the technical work to be useful in the room. The day-to-day is people, programs, and process. The thread across roles is the same: build things that work in production and survive an audit, then bring teams along for it.

02

Selected Outcomes

Federal System to ATO

Led an AWS-hosted federal Learning Management System through Security Control Assessment to full Authorization to Operate.

ISO 27001 & ISO 9001

Led the organization’s ISO 27001 and ISO 9001 certification efforts — policy, controls implementation, internal audits — maintained through successive annual recertifications.

CMMC Level 2

Led the organization's CMMC Level 2 initiative through to successful certification.

CMMI Level 3 — Dev & Services

Contributed to teams that passed CMMI Level 3 appraisals for both Development and Services constellations — artifacts, evidence, and process maturity.

From the Ground Up

Stood up GRC processes, security documentation, and review workflows from scratch — CFACTS, TRB/TRA cycles, and audit-ready evidence pipelines.

03

What I Do

Security & Compliance

FISMA, NIST 800-53, CMS ARS, RMF. Led systems through SCAs and achieved ATO. Multiple successful federal annual audits and recertifications.

GRC & Audits

RSA Archer, CFACTS. Led audits across regimes — ISO 27001, ISO 9001, CMMI L3, CMMC L2, federal SCAs — to successful certification. Risk registers, SSPs, PIAs.

Agile Delivery

Certified Scrum Master. Run sprint ceremonies, groom backlogs, keep stakeholders aligned.

Cloud & Identity

AWS (EC2, S3, RDS, ELB) and Azure. M365 administration and security — DLP, Azure Information Protection, Entra ID, Intune. Evaluate and recommend based on project requirements.

04

Experience

2025 — Present

Senior IT Manager

Swingtech Consulting · CMS

  • Ran program delivery for federal cloud-based applications under FISMA and RMF
  • Led ISO and quality audits to certification; managed annual recertifications
  • Led the organization’s CMMC Level 2 certification effort through successful completion
  • Oversaw security compliance, audit readiness, and technical governance
  • Coordinated cross-functional teams across engineering, security, and external stakeholders

2020 — 2025

Security Analyst / ISSOCS

Swingtech Consulting · CMS Learning Management System

  • ISSO Contractor Support for AWS-hosted LMS
  • Led Security Control Assessment; system achieved ATO
  • Managed security documentation in CFACTS
  • Led CMS ARS control baseline migrations (3.0 → 3.1 → 5.0); assessed ~521 controls for a FISMA Moderate system
  • Ran vulnerability scans with OWASP ZAP and SQLMap; tracked remediation via POA&Ms
  • Conducted PIAs, contingency planning, tabletop exercises, and incident response planning
  • Coordinated with TRB and TRA

2016 — 2020

IT Program Specialist / Scrum Master

Swingtech Consulting · CMS National Training Program

  • Artifacts for Level 3 complexity projects
  • Part of team that passed CMMI Level 3 appraisal
  • Sprint facilitation and stakeholder communication

2010 — 2016

Freelance Developer & Technical Lead

Self-Employed · Area17 Studios · Southern Illinois University

  • Ran projects from requirements through deployment
  • Led a small team of developers and designers
  • Delivered eCommerce platforms with payment integration
  • Taught front-end development at SIU

2007 — 2010

Web Developer

Tripura Technologies · Hyderabad

  • Full-stack work across ASP, PHP, C#, VB.NET, SQL Server
05

Certifications

CISM

ISACA

AAISM

ISACA

COBIT

ISACA

Security+

CompTIA

CSM

Scrum Alliance

ITIL

Foundation

In Progress

CISSP
06

Education

2015

MS, Computer Science

Southern Illinois University, Carbondale

2006

MCA

Bankatlal Badruka College of IT

07

Skills

NIST 800-53 / 800-171 FISMA RMF ATO Delivery CMS ARS ISO 27001 ISO 9001 CMMI L3 (Dev & Services) CMMC Level 2 Audit & Assessment Leadership Risk Assessment AI Security Governance Incident Response & Contingency Planning Privacy Impact Assessments RSA Archer / CFACTS AWS Azure M365 Security & Administration Agile / Scrum Program Management Team Leadership Training & Enablement