
Douglas Zipay
IT Systems Auditor/CMMC Assessor
The Blueprint: Built, Not Born “Doug Was Built, Not Born” is more than a tagline—it is the definition of my professional life. My path was not inherited; it was deliberately constructed through discipline, experience, and continuous evolution. From the technical front lines to the rigor of high-level assessment, every transition was intentional and driven by a commitment to mastery. This is the story of a reputation forged by doing the work, learning from the field, and earning credibility at every stage.
The Foundation: Naval Service
My career began in the U.S. Navy, specializing in electronics and IT within high tempo environments. This service instilled the accountability and operational discipline required for mission critical work and lessons in leadership that continue to define my approach to technology and risk.
The Expansion: Federal & Defense Leadership
Supporting U.S. Special Operations Command (USSOCOM) and the Department of the Interior (DOI), I advanced from Field Service Engineer to Technical Project Manager. This evolution bridged the gap between hands on engineering and enterprise strategy, providing a deep, practical understanding of how federal IT environments actually operate.
The Pivot: IT Audit & CMMC Assessment
As an IT Systems Auditor and CMMC Assessor, I now focus on protecting systems rather than building them. I look beyond compliance checklists to help organizations manage risk, ensuring systems are defensible, secure, and truly ready for the missions they support.
The Strategic Balance: Business & Finance
Complementing this technical background is a deep proficiency in business operations. With an MBA in Finance and a focus on global economics, I view cybersecurity not just as a technical hurdle, but as a critical component of broader business health and financial viability.
Conclusion
Together, these experiences bridge the gap between technical execution and business strategy—turning compliance into a vital asset for organizational resilience.
Doug Was Built Not Born
The "Doug Was Built, Not Born" Blog
Here I share past and present experiences where I’ve grown professionally and personally – and some opinions along the way. There’s no particular order to my postings as I add subject matter often. Click HERE to go to my Blog page to see more.
Passed the CMMC Certified Assessor (CCA) Exam
Took and passed the exam. It was tough, but it was what I expected. I submitted my resume and certs since to the CyberAB. Pending the issuer to review my package and issue my certification. How did I study? I used the training material I received from Edwards via...
Don’t be afraid to change your mind
I spent my military career specializing in communications, and you’d think that would be the natural path to follow once I retired. But it wasn’t. By the time I transitioned out of active duty, I was ready for something completely different. I earned an MBA in Finance...
My Path Into Governance, Risk, and Compliance (GRC)
How did I learn and get experience in Governance Risk and Compliance (GRC)? I supported US Special Operations Command (USSOCOM) for many years. Inside and outside the Headquarters. The security on the communications systems is very secure and undergoe routine risk...
From Shortwave Radios to Cybersecurity Signals: A Lesson in Global Awareness
I’m going to date myself here — but stay with me. It’s a good one. My first duty station was in northern Scotland, toward the end of the Cold War. The U.S. Naval Communications Station there served as a strategic post near what was then the Soviet Union. This was an...
Moving On to New Opportunities
Nine years ago (Halloween 2016) I submitted my two-week notice to an organization I worked at for nine years. The new job paid more, but that wasn’t the reason. I moved on for a new opportunity. More specifically – professional growth. I left a hybrid job (before that...
Current Certifications