Andre Spivey

USAF Cyber Defense Ops Vet|MSc| Certified Ai Manager | GRC Analyst | Webapp Exploitation Expert |Forward Deploying Engineer (FDE) |TedX Speaker | IBM Certified Security Analyst | Sophos Certified Engineer| PhD Student

Greater Tampa Bay Area

About

IT Security Engineer with 10+ years of military and private sector communications experienced in the programming, infrastructure, server and network design. Heavy experience in security and compliance. Proficient in cloud engineering, experienced in AWS, Rackspace, Azure and other services. Proficient in security tools and methods, Nessus-Tenable, CrowdStrike, MS Defender and others. Hands on experience in set-up and maintenance of monitoring tools such as Ninja, Kaseya, ConnectWise and others. Experience coding in HTML/CSS, PhP, Java and Python for scripting, full stack development and security experience. Experienced in set-up, hardening and maintaining Linux and Windows servers. Proficient in supervision, installation, management and security of Cisco, Fortinet, Avaya, SonicWall and others firewalls via cloud and on-premise. Managed and implemented VMware, VSphere environments, and migrated these environments to the Azure cloud.

Experience

  • Manager Cyber Incident Response at Mosaic Health
    Aug 2025 - Present · 1 yr

    As the Manager of Incident Response at Mosaic Health, I lead the cybersecurity function responsible for safeguarding clinical operations, patient data, and enterprise technology across a rapidly growing healthcare organization. My role centers on building a resilient incident response program, strengthening cross-team coordination, and ensuring rapid containment and recovery during cybersecurity events. Key Responsibilities Include: • Leading the Incident Response Team through detection, triage, containment, eradication, and recovery of cybersecurity threats—including ransomware, phishing, insider risk, and clinical system disruptions. • Coordinating cross-functional response with Infrastructure, Networking, Radiology IT, EHR teams, Compliance, Legal, and Executive Leadership to minimize operational and patient-care impact. • Developing IR playbooks, SOC workflows, and escalation paths for clinical environments, including PACS, EHR integrations, and critical care systems. • Driving continuous improvement across monitoring tools (Sentinel, Defender, ReliaQuest, Proofpoint, SolarWinds), automation, alerting, and threat-hunting capabilities. • Establishing communication structure during incidents—assigning Incident Leads, maintaining timelines, documenting decisions, and coordinating with Service Desk as frontline operators. • Leading post-incident analysis and reporting to enhance readiness, reduce risk, and support organizational learning. • Strengthening partnerships with external vendors and third-party cybersecurity providers to accelerate containment and recovery. • Training staff and maturing cybersecurity processes as Mosaic Health scales across multiple clinical sites and integrated care partners. My mission is to ensure Mosaic Health remains secure, resilient, and prepared—protecting both the organization and the patients we serve.

  • Cyber SecOps Engineer/Change Management at Nortek Global HVAC
    Aug 2023 - Jul 2025 · 2 yrs

    Managed access control for Azure AD and on-premise environments Administered DNS and SSL certificates to ensure site reliability Leveraged Microsoft Purview for data governance and Microsoft Defender for threat protection Led AI Governance Board, integrating Microsoft Co-pilot into Azure 365 and establishing AI usage standards Implemented AI automation within FreshService ticketing to improve workflows Enhanced security tools with AI in Sophos and CrowdStrike Facilitated AI Governance Board duties, including change approvals, control schedules, and AI risk assessments Managed Data Loss Prevention (DLP) solutions Administered Tenable for vulnerability management Led Veeam backup and disaster recovery implementations Oversaw patching and updates via Automox Managed Intune, AutoPilot, and Co-pilot for device management Monitored security operations with Arctic Wolf Deployed Semperis to protect Active Directory environments Managed ADManager for streamlined identity management Maintained network security using Cisco and Fortinet solutions Administered Cisco HyperFlex and VMware for virtualization Managed MDM and enforced mobile security policies Configured and responded to Azure security alerts Conducted incident response and security investigations Performed access reviews and investigated anomalous activities Managed ACLs and firewall configurations Oversaw AWS environments, implementing cloud security best practices Managed email security solutions (Avanan and Check Point) Conducted penetration testing to identify and remediate vulnerabilities Authored and maintained security policies and procedures

  • TedX Speaker at Tedx USFSM
    Mar 2025 - Apr 2025 · 2 mos

    April 4th 2025, will be speaking at University of South Florida Sarasota-Manatee Campus (Tedx_USFSM

  • Security Incident Response/Operations Analyst at Rooms To Go
    Oct 2019 - Oct 2023 · 4 yrs 1 mo

    • Managed Access, Changes, Incidents, Knowledge, Problem Management functions within a DevSecOps framework, with zero-trust security models. • Proactively monitored cloud/on-premises infrastructure, using SIEM solutions, automated (SOAR) for real-time threat detection/response. • Developed and utilized automated runbooks and playbooks for streamlined incident response and security remediation within CI/CD pipelines. (Azure) • Led major incident resolution (CSIRT events) by troubleshooting security incidents, automating root cause analysis, escalating appropriately, and maintaining a comprehensive incident timeline. (Microsoft Sentinel/Defender) • Served as Tier 2/3 escalation point for network security and DevSecOps incidents, enabling rapid identification and mitigation of vulnerabilities. • Conducted cloud security health checks and compliance assessments to ensure high availability and resilience of critical business services. • Authored and maintained Knowledge Base articles and security best practices to enhance operational efficiency and team knowledge-sharing. • Provided Request Management by logging, tracking, and resolving security-related service requests, ensuring adherence to RMF compliance and access controls. • Delivered exceptional customer support by ensuring IT and security services aligned with evolving business needs. • Troubleshot and hardened cloud infrastructure (AWS, Azure, GCP), ensuring secure config • Automated infrastructure troubleshooting using Terraform, Ansible, and Python scripting, reducing resolution times and increasing operational efficiency. • Provided training to Level 1/2 Analysts, promoting a DevSecOps culture with a focus on automation and security-first methodologies. • Analyzed security trends and threat intelligence, proactively adjusting defenses and security postures based on real-time data. • Assisted in project-based tasks, contributing to security automation initiatives and infrastructure as code (IaC) deployments.

  • Investor at RYSE Connected
    Dec 2015 - Sep 2022 · 6 yrs 10 mos

    • Maintain the hosting infrastructure, troubleshoot space issues, memory and resource issues, coordinate with hosting companies for elasticity • Create and maintain back-up timing, for regular back-ups and prior to upgrades • Maintain site reliability and uptime, troubleshooting any html/css issues along with back-end server issues • Plan and assist in the upgrading of features, to ensure minimal downtime or quality loss • Manage code improvements and releases, cloud engineering for increased streaming quality, implement and manage CDN • Assist in mobile app development and RYSE Tv/Ryse Creative Village creation and integration ensuring for proper integration and security • Set-up proper infrastructure security protections