Michael Schroeder

Director, FedRAMP Strategy and Market Development @ Excentium, Inc. | ex-VA | ex-Apple | ex-Comcast

Olympia, Washington, United States

About

Learner, teacher, and communicator. I build systems of action, develop effective organizations, and deliver on the mission of reducing the vulnerabilities of our nation's cyberspace. Led delivery and security for 60+ VA-sponsored FedRAMP Authorizations. 15+ years of experience building and supervising service delivery organizations, directing quality, governance, authorization, auditing, and continuous monitoring programs within high-visibility commercial and regulated environments. FedRAMP and cloud authorization leader with deep experience directing large-scale cloud authorization portfolios within a federal CIO environment, translating regulatory requirements into scalable governance systems that reduce friction, accelerate approval timelines, and strengthen audit readiness for cloud systems through complex Federal Agency ATOs. Architect of cross-functional security processes that align requirement and rigor with product delivery velocity. Trusted advisor to executive leadership, providing risk-informed decision support and building repeatable compliance models that enable regulated-market growth. Experienced in developing multidisciplinary teams and contractor resources, establishing performance expectations, and implementing structured compliance workflows that improve documentation integrity, delivery velocity, and regulatory compliance. Cybersecurity | FedRAMP Rev5 and 20x | ITIL | CSF | RMF | AI | Process | People | Results

Experience

  • Director, FedRAMP Strategy and Market Development at Excentium, Inc
    Apr 2026 - Present · 3 mos

    FedRAMP 20x is a new era for cloud security assessment, validation, and maintenance. Persistent compliance, automated evidence, machine-readable packages, the KSI framework across eleven domains. CMMC enforcement is accelerating in parallel. This is the moment Excentium's credential depth and delivery culture were built for. I'm here to lead Excentium's FedRAMP 20x thought leadership, build the relationships that connect the right CSPs and agencies with the right assessment partner, and ensure the market sees the full story of what this company has earned.

  • Armavel, LLC (Remote)
    • Cybersecurity Program Manager (contract: US Department of Veterans Affairs OMEGA)
      Jan 2025 - Jan 2026 · 1 yr 1 mo

      · Accelerated and directed the Agency ATO lifecycle for 60+ enterprise cloud deployments within VA OIT, enabling sponsored FedRAMP Authorization of high-visibility systems including: Palantir Federal Cloud Service - High, Nintex Automation GE Platform, Okta IDaaS Regulated Cloud, Juniper Mist, NetSkope GovCloud, CrowdStrike Falcon Platform for Gov, PagerDuty, and ECFax. · Served as principal liaison between Cloud Service Providers, Federal ISOs, DevSecOps teams, and VA executive leadership, aligning regulatory rigor with delivery realities. · Built durable cross-functional alignment with and between federal customers, authoritative entities, and CSP partners in a high-impact, high-demand, multi-stakeholder environment. · Delivered structured executive risk and status reporting to the OIT ISO Lead, DTC Director, and Deputy VA CIO, enabling informed authorization decisions across high-visibility initiatives. · Architected workflow improvements that removed systemic bottlenecks and accelerated authorization timelines across a portfolio representing $3.8B in federal contracts. · Designed and executed a FY25 enterprise-wide data integrity initiative that reduced the DTC Product Request error rate from 18% to under 1%, materially improving review quality and throughput. This role was a Contractor position providing service to the US Department of Veterans Affairs Office of Information Technology Product Engineering Services Onboarding, Management, Engineering, Governance, and Assurance (OMEGA) DTC.

    • Cybersecurity Program Manager (contract: US Department of Veterans Affairs DTC)
      May 2021 - Jan 2025 · 3 yrs 9 mos

      · Directed and managed technical security architecture, requirements, and compliance teams to ensure ongoing, regular progress in a hybrid Agile/Waterfall environment under an overarching scrum environment. · Institutionalized documentation, evidence validation, and review standards to improve audit readiness, continuous monitoring maturity, and stakeholder confidence. · Led VA's initial CISA High Value Asset (HVA) Program implementation for a Tier 1 Critical system (ECFax), achieving early 100% compliance across all required metrics. · Developed subject matter expertise on key guidance documents and Federal regulations, including NIST CSF, NIST RMF, NIST 800-53, NIST 800-60, NIST 800-63, NIST 800-171, NIST 800-172, VA Dir. 6500, and FIPS 199. This role was a Contractor position providing service to the US Department of Veterans Affairs Office of Information Technology Product Delivery Service Digital Transformation Center (DTC).

  • Advertising Agency Owner at POV Media, LLC
    Jul 2015 - Oct 2021 · 6 yrs 4 mos

    · Negotiated, conceptualized, developed, and deployed successful multi-stage advertising campaigns in a State- and Federally-regulated industry, consistently resulting in 25%-50% increases in sales, as well as establishing persistent brand recognition.

  • State of Washington - Centralia College IT Technician II at Centralia College
    Jan 2019 - Dec 2019 · 1 yr

    · Provided in-depth Tier 1 and Tier 2 technical support of all types to students, staff, and faculty. · Deployed a unified asset management solution for 2,500+ devices across 11 campus buildings.

  • Senior Cybersecurity Advisor II at Apple
    Jan 2013 - Jul 2016 · 3 yrs 7 mos

    · Global Technical SME, provided guidance to technical support agents for all request types, maintaining stringent knowledge of scope limitations across various service types and contractor providers. · Served on the Executive Escalations team, collaborating with Engineering teams to resolve prioritized issues submitted by Government entities, high-profile customers, and priority enterprise deployments.