Travis Duncan
Information Systems Security Manager
Las Vegas, NV
About Me
I've spent 9+ years in enterprise IT and cybersecurity, six of them with the Air Force at Scott AFB. My path into GRC wasn't a straight line — I started in IT support and operations, spent four years leading a 21-member technical team, and moved into ISSM work in 2023. That route shapes how I approach the work: before I was writing controls, I was on the receiving end of them, which makes me pretty allergic to governance that ignores what implementation actually costs the teams doing it.
Today I'm an ISSM for an AWS-hosted system supporting a $7B business unit, where I manage the full compliance lifecycle across 503 controls and roughly 1,100 NIST 800-53A assessment procedures. Over the past year I led a system-wide migration from 800-53 Rev. 4 to Rev. 5, authored the program's first SCRM Plan and updated its Implementation Plan and Continuous Monitoring Strategy, secured an ATO, and worked directly with auditors on control validation and remediation. It's substantive work — and a lot of it still runs on spreadsheets, manual evidence collection, and documentation cycles that eat time I'd rather spend on actual risk decisions.
That gap is what pulled me toward GRC Engineering. Somewhere around the two-hundredth control assessment I documented by hand in an Excel spreadsheet, it stopped feeling like compliance work and started feeling like data entry — and the worst part is that the spreadsheet is stale the moment you close it. I'm convinced most of that work is automatable, and I'm currently building skills in AWS Config, Security Hub, and compliance-as-code, with a focus on automated evidence collection and continuous control monitoring. I'm here to learn from people further down this road, and eventually to contribute tooling back rather than just consume it.
Experience Highlights
- Manage the full compliance lifecycle for 503 NIST 800-53 controls (~1,100 assessment procedures) on an AWS-hosted system supporting a $7B business unit
- Led a system-wide NIST 800-53 Rev. 4 → Rev. 5 migration across all 16 control families
- Secured an ATO by developing the full authorization package and remediating POA&Ms
- Authored the program's first SCRM Plan with no prior version to work from; reviewed and updated its Implementation Plan and Continuous Monitoring Strategy
- Ran a gap assessment across 16 control families, building new processes where none existed
- Partnered with external auditors on financial and supply chain overlay controls, closing a high-visibility finding
- Previously served as ISSM for a $350M portfolio serving 16,000 users, after several years supporting IT operations in the same environment
Get in Touch
DM me on LinkedIn or email travis@travisduncansecurity.com
Specializations
Languages & Tools
Frameworks
Certifications
Projects
IaC template deploying S3 buckets with public access blocked and AES-256 encryption enforced.
Built a workbook that auto-generates standardized assessment verbiage for documenting NIST 800-53 controls in eMASS, cutting the manual writing overhead across hundreds of assessment procedures. Not elegant, but it was the fastest path off the spreadsheet treadmill with the tools available — and it's the work that convinced me most of this process is automatable.
Built a Power Query pipeline to ingest and transform weekly enterprise vulnerability reports, filtering and structuring the data to support continuous monitoring and patch prioritization decisions.