Bridging the Gap Between Compliance and Capability
I believe that robust cybersecurity isn’t just a checkbox—it’s the foundation of national security and business resilience. With over a decade of experience leading complex technical projects and securing enterprise environments, I’ve transitioned my focus to the front lines of the CMMC ecosystem.
As a current IT Systems Auditor with a deep-rooted background as a Cybersecurity Project Manager, I don’t just identify gaps; I understand the operational ‘why’ behind the controls. My mission is to help organizations navigate the complexities of CMMC certification by blending rigorous technical scrutiny with a collaborative, mission-focused approach. Whether I’m auditing a network architecture or translating compliance requirements for stakeholders, I am dedicated to ensuring that defense contractors are not just compliant, but truly secure.

Douglas Zipay
“Doug was Built not Born” is more than a tagline—it is the philosophy that governs my professional life. My expertise wasn’t inherited; it was deliberately constructed through discipline, field experience, and a relentless drive for evolution. From the technical front lines to the rigor of high-level auditing, every career transition has been an intentional step toward mastery. This is a reputation forged by doing the work and earning credibility at every stage.
The Foundation: Naval Service
My journey began in the U.S. Navy, specializing in electronics and IT within high-tempo, high-stakes environments. This service instilled in me the accountability and operational discipline required for mission-critical work. The lessons in leadership I learned at sea continue to define my approach to technology, risk, and the “no-fail” nature of national security.
The Expansion: Federal & Defense Leadership
Supporting U.S. Special Operations Command (USSOCOM) and the Department of the Interior (DOI), I advanced from Field Service Engineer to Technical Project Manager. This era was my bridge between hands-on engineering and enterprise strategy. It gave me a deep, practical understanding of how federal IT environments operate—not just on paper, but in the real world where uptime and security are non-negotiable.
The Pivot: IT Audit & CMMC Assessment
Today, as an IT Systems Auditor and CMMC Assessor, I have shifted my focus from building systems to protecting them. I look beyond the static checkboxes of a compliance list to help organizations manage genuine risk. My goal is to ensure that systems are not only compliant but defensible, secure, and truly ready to support the missions they serve.
The Strategic Balance: Business & Finance
Complementing this technical background is a deep proficiency in business operations. With an MBA in Finance and a focus on global economics, I view cybersecurity not just as a technical hurdle, but as a critical component of broader business health and financial viability.
Conclusion
By bridging the gap between technical execution and business strategy, I help organizations turn compliance into a vital asset for resilience.
Doug Was Built Not Born
The "Doug Was Built, Not Born" Blog
Here I share past and present experiences where I’ve grown professionally and personally – and some opinions along the way. There’s no particular order to my postings as I add subject matter often. Click HERE to go to my Blog page to see more.
Verdin/ISABPS – The Pivoting Point to my Career
🚀 How I Became one of the Navy's Top SME My Navy career began with specialized training in electronics and cryptographic equipment, leading to my first assignment at a critical communications station in Scotland. I was assigned to Technical Control, the hub for the...
My Journey in Amateur (Ham) Radio
I earned my Amateur (Ham) Radio license when I was stationed in Maine. Cell phones weren't really a thing back then, and it was rural country out there. The local community was great there and belonging to the local club offered a means to meet others. In the course...
Passed the CMMC Certified Assessor (CCA) Exam
Took and passed the exam. It was tough, but it was what I expected. I submitted my resume and certs since to the CyberAB. Pending the issuer to review my package and issue my certification. How did I study? I used the training material I received from Edwards via...
Don’t be afraid to change your mind
I spent my military career specializing in communications, and you’d think that would be the natural path to follow once I retired. But it wasn’t. By the time I transitioned out of active duty, I was ready for something completely different. I earned an MBA in Finance...
My Path Into Governance, Risk, and Compliance (GRC)
How did I learn and get experience in Governance Risk and Compliance (GRC)? I supported US Special Operations Command (USSOCOM) for many years. Inside and outside the Headquarters. The security on the communications systems is very secure and undergoe routine risk...
Current Certifications
