Larry Hughes

Larry Hughes

GRC | Governance, Risk and Compliance | Cybersecurity | CMMC | FedRAMP | NIST

15 yrs experience · 30-40 hrs/week

About

With a wealth of experience in cybersecurity and compliance, I have a proven track record of leading and managing complex programs. My expertise includes FedRAMP, DFARS / CMMC, HITRUST, PCI DSS, and more. As the Owner and Director of LJH Cybersecurity LLC, I assist companies in complying with security standards and compliance frameworks. During my tenure as the Director of GRC at Equinix, I founded and led the organization's GRC program. Additionally, as FedRAMP Director / Program Manager, I successfully orchestrated an 8-figure multi-year security compliance initiative. My ability to drive strategic compliance initiatives has been instrumental in my career.

Skills

ComplianceCybersecurityCybersecurity frameworksPolicy Analysis

Experience

  • Owner and Principal · LJH Cybersecurity LLC01-01-2020

    I helped companies comply with complicated security standards while imparting hard-earned knowledge and wisdom along the way. My specialties included: Cybersecurity Maturity Model Compliance (CMMC), Federal Risk and Authorization Management Program (FedRAMP), NIST System Security Plans (SSP), DoD Confidential Unclassified Information (CUI), Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012, NIST 800-53, 800-171, 800-160, Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) and Consensus Assessment Initiative Questionnaire (CAIQ), Payment Card Industry Data Security Standard (PCI DSS), HITRUST.

  • Director of Governance, Risk and Compliance (GRC) · Equinix01-01-2019 – 01-01-2020

    I was the company's first cybersecurity Governance, Risk and Compliance (GRC) leader. I organized my team to deliver a rock solid four-pillar remit: Compliance Consulting, Policies and Common Control Framework (CCF), Vendor Risk Management (VRM), and Continuous Compliance GRC platform with automation. Selected Accomplishments: Combined disparate control frameworks into one for 20 companywide compliance programs, by narrowing more than 10K controls in Unified Control Framework (UCF) to 350. Guided gap analysis and remediation to comply with the US government's NIST 800-171 based Controlled Unclassified Information (CUI) program and preparing for Cyber Security Maturity Model Certification (CMMC), to promote federal sales channels. Interfaced with largest customers, explaining the company's security posture, in support of customer VRM programs.

  • FedRAMP Director / Program manager · Equinix01-01-2015 – 01-01-2019

    This was my first foray into heading a business-critical, multi-year security compliance initiative. It was a highly visible role with C-level accountability. My mission was to orchestrate a symphony of stakeholders from ten business units in technical and business harmony. I passionately championed the case to extend the security benefits to all customers, not just federal agencies, which had a profound impact on the company's overall security posture. The initiative involved ensuring that 300 logical security controls from NIST 800-53 were properly applied to 20 subsystems, in 25 overlapping work streams. Selected Accomplishments: Provided monthly status reports and SSP updates to authorizing officials from US General Services Administration, the agency sponsor, and government-authorized auditors. Yielded monetary savings by proving to auditors that 10% of controls were inapplicable despite appearance. Minimized testing required by third party assessment organization (3PAO) by designing and implementing a highly efficient architecture for inside the system boundary.

Similar talent on Pangea

Hire Larry through Pangea

Describe your project to the Pangea agent — see if Larry is a fit, with transparent pricing and interviews booked straight onto your calendar. No contact details change hands until you hire.

See if Larry is a fit