Skip to content

Cybersecurity / Public service

The work.
From strategy to everyday practice.

Municipal and federal cybersecurity, systems administration and technical leadership.

City of Yonkers

Building the program.
Doing the work.

My work covers cybersecurity governance, enterprise architecture, security operations, identity and endpoint protection, compliance, automation and employee awareness across City of Yonkers departments.

Strategic Leadership & Governance

  • Serve as the city’s principal cybersecurity authority, reporting to executive leadership and the Department of Information Technology Commissioner.
  • Built Yonkers’ cybersecurity governance framework from the ground up, aligning policy and control baselines with NIST SP 800-53, CJIS, HIPAA, and ISO 27001.
  • Developed comprehensive citywide security policies, risk assessment templates, encryption standards, and procurement security checklists to standardize practices across all departments.
  • Represent Yonkers in inter-agency collaboration with New York State Cyber Command (NYSOC), making Yonkers the first municipality in the nation to go live with a state-sponsored joint Security Operations Center (SOC).
  • Oversee municipal compliance readiness for audits, CJIS data exchanges, and state cybersecurity grant requirements.

Infrastructure Modernization & Enterprise Architecture

  • Directed modernization of the city’s entire security stack: FortiGate next-generation firewalls, FortiClient EMS, Duo MFA, CrowdStrike Falcon EDR, BitLocker encryption, and Microsoft Entra.
  • Designed and implemented redundant firewall clusters, integrating Zero Trust segmentation, posture-based access, and automated log forwarding.
  • Engineered a centralized syslog and SIEM pipeline forwarding from 200+ Windows and Linux servers into the NYSOC QRadar platform, establishing the state’s baseline architecture for municipal telemetry sharing.
  • Deployed enterprise-wide BitLocker encryption with AD/Azure AD key escrow, TPM enforcement, and compliance logging, ensuring encryption coverage across all agency endpoints.
  • Designed and rolled out a RADIUS-based network authentication system for switches and routers, replacing static credentials with centralized access control.

Threat Detection, Vulnerability Management & Incident Response

  • Lead all vulnerability management initiatives; achieved sustained reduction from 5 million to under 500,000 vulnerabilities through patch automation, configuration hardening, and asset lifecycle governance.
  • Manage 24/7 monitoring of the city’s CrowdStrike Falcon EDR platform, leveraging IOC detection, behavioral analytics, and threat hunting to reduce dwell time and contain lateral movement.
  • Conduct regular penetration testing, red-team simulations, and incident tabletop exercises, producing after-action reports for both technical and executive audiences.
  • Serve as primary incident commander for breach containment and forensics, coordinating between local departments, NYSOC analysts, and law enforcement when needed.

Identity, Access, and Endpoint Security

  • Designed and enforced the city’s Zero Trust Network Access (ZTNA) architecture, integrating Duo MFA, FortiClient EMS posture tags, geolocation policies, and conditional access for all privileged accounts.
  • Led deployment of Multi-Factor Authentication (MFA) and passwordless authentication pilots across city platforms, improving both security posture and user experience.
  • Managed implementation of the city’s first Mobile Device Management (MDM) solution, ensuring secure configuration, remote wipe, and policy enforcement across mobile assets and tablets.

Automation, Scripting & Operational Efficiency

  • Developed custom PowerShell and Python scripts for log aggregation, SSL renewal, BitLocker compliance verification, and asset inventory reconciliation, eliminating thousands of manual hours annually.
  • Automated patch management workflows, vulnerability scans, and compliance reporting, integrating output into the city’s executive dashboard.
  • Built internal tools for identity lifecycle automation, integrating Active Directory, Azure AD, and HR onboarding/offboarding data.

Training, Awareness & Public Sector Impact

  • Developed and implemented cyber awareness training for 3,000+ city employees, emphasizing phishing defense, incident reporting, and secure data handling.
  • Partnered with Yonkers Public Schools and local colleges to expand cybersecurity education pipelines and promote civic technology careers.
  • Regularly collaborate with NYS ITS, CISA, and regional task forces to improve municipal cyber intelligence sharing and coordinated response readiness.

Maximus Federal · 2020

Federal cybersecurity.
Accountability in practice.

Information Systems Security Officer work supporting security planning, risk management, authorization, continuous monitoring and technical teams.

Key Advisory Role

Key Advisory Role: Acted as a pivotal advisor to the Chief Information Security Officer (CISO)/Senior Agency Information Security Officer (SAISO) and System Owner (SO), providing insights on all security facets concerning the information system.

Operational Security Maintenance

Operational Security Maintenance: Upheld the requisite active security posture for the system, ensuring robust defenses against potential threats and vulnerabilities.

Security Planning

Security Planning:

  1. System Security Plans (SSP): Collaboratively contributed to the evolution and refinement of SSPs, ensuring they remained aligned with evolving threat landscapes.
  2. Plans of Action & Milestones (POA&M): Addressed and monitored vital action points, safeguarding against latent vulnerabilities and fortifying system resilience.

Change Management

Change Management: Undertook the essential duty of evaluating, controlling, and determining the security implications of modifications to the system, guaranteeing that updates didn't inadvertently introduce vulnerabilities.

System Categorization (as per FIPS 199)

System Categorization (as per FIPS 199): Shared the onus of system categorization, identifying the types of information processed, transmitted, and stored, thus ascertaining the potential impacts on confidentiality, integrity, and availability.

Risk Management & Compliance

Risk Management & Compliance:

  1. Implementation of NIST RMF: Spearheaded adoption and application of the National Institute of Standards and Technology Risk Management Framework.
  2. Continuous Monitoring: Established and perpetuated continuous monitoring protocols to underpin ongoing Authority to Operate (ATO) mandates.
  3. NIST-based Evaluations: Executed rigorous risk assessments on prospective system alterations, ensuring they aligned with NIST directives.
  4. Risk Analysis: Consistently gauged system operations and modifications risks, ensuring a proactive approach to potential threats.

Policy & Documentation

Policy & Documentation:

  1. Federal Program Oversight: Assisted with policy crafting, monitoring, and compliance assessments for federal authorization programs.
  2. Security Documentation: Composed various security documents, encapsulating policies, procedures, plans, and standards-aligned with NIST SP800-53 controls.

Audit & Vulnerability Assessment

Audit & Vulnerability Assessment: Conducted periodic and ad-hoc system audits and vulnerability evaluations, ensuring system adherence to stipulated standards and preempting potential threats.

Technical Mentorship

Technical Mentorship: Dispensed guidance and provided leadership to junior technical staff, fostering an environment of collective growth and knowledge sharing.

Professional experience

A career across
systems and people.

2023–present

City of Yonkers

Cybersecurity Coordinator

My work covers cybersecurity governance, enterprise architecture, security operations, identity and endpoint protection, compliance, automation and employee awareness across City of Yonkers departments.

Explore this work
2024–present

Bryant & Stratton College

Adjunct Professor & Faculty Mentor

Teach across a 14-course portfolio in computing, networking, systems administration, security, wireless technology and cloud computing. Support students through practical examples and constructive feedback, and help new faculty with course delivery and online teaching practices.

Explore this work
2025

Marconi International University / MIU City University Miami

Adjunct Professor & Course Content Developer

Developed English- and Spanish-language graduate course content for Cloud, Mobile, and Virtualized Environments, including academic units, activities, assessments and supporting instructional materials.

Explore this work
2022

New York University

Graduate Course Assistant

Supported graduate-level instruction in penetration testing and vulnerability analysis, and helped students work through discovery, assessment, reporting, remediation and validation.

Explore this work
2020

Maximus Federal

Senior Information Security Analyst / ISSO

Supported federal cybersecurity operations, risk assessments, security authorization and continuous monitoring. Developed security documentation, maintained system security plans and managed plans of action and milestones.

Explore this work
2014–2018

United States Marine Corps

Aviation Logistics Information Management Systems Specialist

Worked in aviation information systems, systems administration, information security and technical instruction. Developed a software-compatibility solution supporting aviation operations, prepared curriculum materials and helped restore a virtual training environment.

Explore this work

Applied experience

From professional practice
to the classroom.

Explore teaching and curriculum Read professional recommendations

Privacy

This site does not run its own advertising or analytics. Your motion preference can be saved on your device.

The profile guide uses prepared answers from the public information on this site. Questions remain in your browser and are cleared when you close it. It has no access to private emails, files or conversations.

Embedded university pages, Facebook, YouTube and document previews may load as you browse their pages. Those providers handle the information sent to them under their own policies. The host may process ordinary access logs.

Public-profile guide

Ask about Eduardo.

Prepared answers about my work, teaching and research. Please use sample questions, not sensitive information.

What would you like to know?