Cybersecurity Portfolio Rev. 1.0  /  2026

M. Allison Manning

Cybersecurity — security operations and governance, risk & compliance.

FocusSecurity operations · Threat detection & IR · GRC BasedAmsterdam, Netherlands · EU work-authorized StatusOpen to cybersecurity roles

I’m a cybersecurity professional with a master’s in cybersecurity engineering, working across two tracks: hands-on security operations — detection, investigation, and testing — and the governance, risk, and compliance side that turns findings into decisions a business can act on.

The work below is drawn from my graduate program and independent projects. Each piece links to the full document.

Security Operations & Technical03
DFIR · Autopsy / RegRipperIncident Investigation

Digital Forensic Investigation

Determined whether system users communicated with and transferred files to remote parties. Acquired a forensic disk image and analyzed user profiles, installed software, program-execution artifacts, file access, Outlook (PST) email, and instant-messaging traces using Autopsy, RegRipper, FRED, and PST Viewer Pro — then established and documented evidence of the file transfers.

Open document
Offensive · Nmap / Nessus / MetasploitPenetration Test Report

End-to-End Penetration Test

Full engagement against a target VM: host discovery and enumeration, TCP/UDP scanning with service and OS fingerprinting, a Nessus vulnerability assessment triaging critical / high / medium findings with remediations, and exploitation of two vulnerabilities (vsFTPd and UnrealIRCd backdoors) to a root shell, including credential cracking.

Open document
Cryptography · Secure DesignCryptographic Services Design

Lightweight Cryptography for a Sensor Network

Designed cryptographic services to protect a resource-constrained IoT sensor network against interception, replay, and tampering. Specified ASCON-128 lightweight authenticated encryption with nonce-based key derivation, HSM integration, key rotation, and at-rest encryption — with the rationale written to be clear to a non-technical stakeholder.

Open document
Governance, Risk & Compliance04
Compliance · NIST SP 800-171System Security Plan

Information System Security Plan (ISSP)

A full ISSP mapping a fictional cloud environment against all 14 NIST SP 800-171 control families — access control, audit & accountability, identification & authentication, incident response, media protection, and system & communications protection — documenting per-requirement implementation, N/A rationale, and system boundaries for CUI. Structured as a work sample on a fictional case-study client.

Open document
Architecture · Business-drivenSecurity Architecture

Business-Driven Security Architecture (SABSA)

A SABSA business-attribute profiling work sample deriving security requirements from business drivers rather than technology: contextual and conceptual layers for a fictional firm — business drivers, a full attribute profile across seven stakeholder dimensions, organizational process model, and asset assessment — showing traceability from what the business values to what security must deliver.

Open document
Quantitative Risk · FAIRRisk Quantification Report

Ransomware Risk Quantification (FAIR)

Applied the FAIR framework to quantify ransomware risk for a health-insurance provider. Decomposed loss event frequency into contact frequency, probability of action, threat capability, and resistance strength; modeled primary and secondary loss magnitude including regulatory fines and reputational fallout; and ran a Monte Carlo simulation in FAIR-U to produce an annualized loss-exceedance curve — translating technical risk into board-ready dollar figures.

Open document
Advisory · Risk-basedSecurity Recommendations

Defense-in-Depth for a Small Business

A risk-based security advisory for a small-to-medium software business: layered, cost-conscious recommendations spanning authentication hardening (password policy, TOTP MFA), VPN-based secure remote access, physical security controls, and honeypot-based intrusion detection — framed around real budget constraints and defense-in-depth.

Open document

// More GRC work in progress —a privacy-by-design case study.

Certifications03
CompTIA Security+ (ce) CompTIA Verify →
Blue Team Level 1 (BTL1) Security Blue Team · Centri Verify →
Security Analyst Level 1 (SAL1) TryHackMe Verify →

Get in touch