ACCEPTING ENGAGEMENTS · FY26 27.9506° N / 82.4572° W · TAMPA, FL

Security and compliance for systems under scrutiny.

Penetration testing, CMMC readiness, RMF and ATO support, network architecture, and cloud security. Nine-plus years of work on federal systems that have to clear real review.

Veteran-Owned · Cleared Personnel
Designations
Veteran-Owned
UEI
U5DFU7U8GA54
CAGE
1ZVH6
NAICS Primary
541512 · Computer Systems Design Services
// 01 / Capabilities

Five service lines.
Built on a single specialty.

Offensive testing, assessment, architecture, implementation, and the documentation that ties them together. Five service lines across the federal authorization lifecycle.

01 SVC-01

Penetration Testing

Adversary-minded assessments against the actual attack surface. External, internal, web, and assumed-breach engagements.

  • External, internal, and assumed-breach engagements
  • Web application testing aligned to OWASP & NIST SP 800-115
  • Findings mapped to NIST SP 800-53 controls and POA&M-ready
$ pentest scope --type external,internal,assumed-breach
02 SVC-02

CMMC Readiness

Level 1 and Level 2 readiness for primes and subs working CUI. Gap to assessment-ready, scoped to the asset categories that count.

  • NIST SP 800-171 rev 2 / rev 3 gap assessment
  • SSP, POA&M, and asset categorization workbook
  • Pre-assessment dry run ahead of C3PAO engagement
$ cmmc scope --level 2 --assets cui,security
03 SVC-03

Security Engineering & Compliance

Control implementation and evidence work for federal cyber programs. RMF lifecycle, FISMA, ATO support.

  • SP 800-53 rev 5 control tailoring & SSP authoring
  • SAP, SAR, and POA&M authoring or remediation
  • ISSM / ISSO augmentation through authorization
$ rmf step --from 1 --to 6 --owner issm
04 SVC-04

Network Architecture

Segmented, defensible network designs. NGFW deployment, IPSec with FIPS-validated cryptography.

  • NGFW deployment (Fortinet, Cisco, Check Point) with HA configurations
  • IPSec VPN with DH Group 21 / SHA-512 / AES-256-GCM
  • Secure enclave patterns for CUI and tactical systems
$ design --ngfw cisco --ipsec aes256-gcm
05 SVC-05

Cloud & Hybrid Security

AWS, Azure, and GCP security baselines for federal workloads. Landing zones, identity, and continuous monitoring built to FedRAMP expectations.

  • GovCloud / Azure Gov landing zone design
  • Identity, key management, and logging baselines
  • ConMon tooling aligned to NIST SP 800-137
$ cloud baseline --gov aws --conmon on
// 02 / About

Where authorization work gets done.

Bald Man Technologies is a Tampa-based, Service-Disabled Veteran-Owned cybersecurity and network engineering practice. The work centers on federal authorization: RMF, ATO support, CMMC readiness, and the network architecture underneath.

The work tends to cluster around the harder stretches of the authorization lifecycle: pushing a system through ATO, reworking a network diagram that got ahead of itself, and closing out a POA&M that has been open too many fiscal quarters.

Deliverables are written to hold up under A&A review, with the evidence and cross-references an assessor will actually look for. If the shape of that work matches what you need, send a note.

9+
YEARS IN FEDERAL CYBER
Cleared
FOR SECURE PROGRAMS
// 03 / Engage

Send a note.

Send over the program, framework, and timeline. Reply will follow with next steps and whether the timing works.