Mason Tuckett

Cyber Analyst • Information System Security Officer (ISSO)

Download GPG Key83A3 C07C 1C7D 8B6D 4A4A  781D 7155 6DFD B495 ACB7

Summary

Cybersecurity professional and ISSO contractor supporting the Department of the Air Force.

Focused on RMF, A&A documentation, security control evidence, POA&M tracking, STIG/SRG compliance, vulnerability management, and information system security requirements for mission-critical defense environments.

Skilled in Governance Risk and Compliance (GRC), Risk Management Framework (RMF), AI security and compliance, cloud infrastructure, systems administration, virtualization, networking, and Linux.

Qualified For: IAT III, IAM II, IASAE II, CSSP Analyst, CSSP Infrastructure Support, CSSP Incident Responder, and CSSP Auditor roles.

Experience

Cyber Analyst/Information System Security Officer (ISSO)

BAE Systems, Inc.
March, 2026 – Present

  • Supported the Department of the Airforce as an Information System Security Officer (ISSO), advising and implementing security requirements for sensitive information processed, stored, and transmitted by program systems.
  • Conducted RMF activities aligned to NIST SP 800-53 Rev. 5—including A&A support, security documentation, control evidence, compliance artifacts, program security plans, policies, procedures, and configuration management records.
  • Supported vulnerability and risk management, POA&M tracking, audit support, anomaly investigation, incident response coordination, corrective action tracking, and information security awareness efforts.

Skills

  • Security & Compliance: RMF, NIST 800-53 Rev. 5, A&A Support, POA&Ms, eMASS, STIGs/SRGs, Tenable Nessus
  • Systems: AWS, Proxmox, VMWare ESXi, RHEL, Podman/Docker, Active Directory/Entra ID, Git
  • Cloud & Networking: AWS VPC/Lattice, Cisco IOS/Meraki, SD-WAN, MPLS, BGP, VPN (IPsec/WireGuard), RSTP, OSPF, VXLAN/VLAN, DNS, DHCP, TCP/IP
  • Professional: Problem Solving, Troubleshooting, Collaboration, Communication, Adaptability, Leadership

Education

MS, Cybersecurity and Information Assurance

Western Governors University
February, 2026 – August, 2026

BS, Cybersecurity and Network Management

Weber State University
August, 2022 – August, 2025

AAS, Cybersecurity and Network Management

Weber State University
August, 2022 – August, 2025

AS, General Studies

Weber State University
August, 2022 – August, 2025

Certifications

Professional Certifications

Course Certifications

Educational Certificates

Projects

Home Lab — Proxmox Virtual Environment

  • Deployed OPNsense as the primary edge router and firewall, configuring VLAN segmentation, RFC1918 subnetting, DHCP scopes, NAT (SNAT/DNAT), DNS forwarding, and rule-based inter-VLAN access control.
  • Built a Proxmox virtualization environment using KVM virtual machines and LXC containers to host lab systems, infrastructure services, and security tooling with managed resource allocation, backups, and snapshot-based rollback.
  • Implemented strict firewall baselines in OPNsense to limit east-west traffic between VLANs, restrict management-plane access, and enforce service-specific allow rules.
  • Created a SOC lab using Kali Linux, Windows targets, and Wazuh to simulate vulnerability assessment, endpoint monitoring, alert generation, log collection, and detection workflows.
  • Configured attribute-based WireGuard tunnels to securely route selected self-hosted service traffic through a VPS reverse proxy—with TLS 1.2/1.3 termination and hardened Nginx proxy configuration.

Web Hosting — RHEL VPC

  • Deployed a hardened RHEL-based VPC/VPS environment using rootless Podman (Quadlet) containers, Firewalld zones, SELinux enforcing mode, and least-privilege service isolation for public web, Tor/I2P, and supporting services.
  • Implemented a strict network security baseline with default-deny inbound policy (WAF), IPSet-based geoblocking, tightly scoped Firewalld rich rules, non-standard IP-bound SSH access, and localhost-only Tor service binding.
  • Hardened Nginx with TLS 1.2/1.3, post-quantum hybrid AEAD cipher suites, HSTS, restrictive CAA records, DNSSEC, SNI/HTTP method restrictions, rate limiting, header size limits, and security-focused response headers.
  • Applied RHEL system hardening through sysctl tuning, unused kernel protocol/module blacklisting, SELinux policy enforcement, application confinement, Journald log review, and service-specific attack-surface reduction.
  • Established a verifiable trust chain using mirrored GPG public keys, signed darknet mirror statements, SHA-512 checksum proofs, DNS TXT validation records, and a public GitHub mirror for independent verification.

Highlights