
Douglas Zipay
IT Systems Auditor/CMMC Assessor
..The Blueprint: Built, Not Born “Doug Was Built, Not Born” is more than a tagline—it is the definition of my professional life. My path was not inherited; it was deliberately constructed through discipline, experience, and continuous evolution. From the technical front lines to the rigor of high-level assessment, every transition was intentional and driven by a commitment to mastery. This is the story of a reputation forged by doing the work, learning from the field, and earning credibility at every stage.
The Foundation: Naval Service
My career began in the U.S. Navy, specializing in electronics and IT within high tempo environments. This service instilled the accountability and operational discipline required for mission critical work and lessons in leadership that continue to define my approach to technology and risk.
The Expansion: Federal & Defense Leadership
Supporting U.S. Special Operations Command (USSOCOM) and the Department of the Interior (DOI), I advanced from Field Service Engineer to Technical Project Manager. This evolution bridged the gap between hands on engineering and enterprise strategy, providing a deep, practical understanding of how federal IT environments actually operate.
The Pivot: IT Audit & CMMC Assessment
As an IT Systems Auditor and CMMC Assessor, I now focus on protecting systems rather than building them. I look beyond compliance checklists to help organizations manage risk, ensuring systems are defensible, secure, and truly ready for the missions they support.
The Strategic Balance: Business & Finance
Complementing this technical background is a deep proficiency in business operations. With an MBA in Finance and a focus on global economics, I view cybersecurity not just as a technical hurdle, but as a critical component of broader business health and financial viability.
Conclusion
Together, these experiences bridge the gap between technical execution and business strategy—turning compliance into a vital asset for organizational resilience.
Doug Was Built Not Born
The "Doug Was Built, Not Born" Blog
Here I share past and present experiences where I’ve grown professionally and personally – and some opinions along the way. There’s no particular order to my postings as I add subject matter often. Click HERE to go to my Blog page to see more.
I Let One Certification Go
Maitaining professional certifications not only cost you time, but also money. My Certified Federal Contractor Manager (CFCM) certification renewal came to an end on Dec 31st. I had enough CPEs to keep it, but decieded to forgo renewing it due to cost and lack of...
Adding Finance to the Doug Was Built Not Born Blog
After writing my last post, I've decieded to add some finance to the blog - so stay tuned and keep reading.
How I Got and Maintain Solid Financial Know-How
I was once told - The easiest and safest way to become rich, was to earn an MBA in Finance, because finance must become a second language. I earned that MBA, building those comprehensive spreadsheets, setting up a multitude of formulas to test predictions. Everyone in...
Mastering a New Discipline: My “Immersion + AI” Method
Have you ever wanted to dive into a new discipline but weren't sure where to start? I use a specific workflow to accelerate my learning, and I recently put it to the test this past summer. My goal was to add CMMC (Cybersecurity Maturity Model Certification) to my list...
No Bootcamps in my Educational History
II was a horrible student K-12. I wasn't good in my first couple technical schools in the navy either. But I earned the following professional certifications: CCNA, Sec+, Net+, PMP, CFCM, CISSP, CISM, CISA, ITIL, PSM, CEH, and most recently CMMC CCP & CCA. I...
Current Certifications