Top Talent like Larry are on Pangea

Pangea, a YC company, connects companies with fractional talent. Fractional hiring allows companies to move faster and work with more specialized talent, while giving talent more flexibility and independence. If you are talent open to fractional work, apply here. If you’re a company looking for high-quality fractional talent, learn more here.

Larry Hughes

Policy Analysis
Compliance
Cybersecurity
Cybersecurity frameworks
Available for hire fromNegotiable
Contracts
Full-Time Roles
GRC | Governance, Risk and Compliance | Cybersecurity | CMMC | FedRAMP | NIST
With a wealth of experience in cybersecurity and compliance, I have a proven track record of leading and managing complex programs. My expertise includes FedRAMP, DFARS / CMMC, HITRUST, PCI DSS, and more. As the Owner and Director of LJH Cybersecurity LLC, I assist companies in complying with security standards and compliance frameworks. During my tenure as the Director of GRC at Equinix, I founded and led the organization's GRC program. Additionally, as FedRAMP Director / Program Manager, I successfully orchestrated an 8-figure multi-year security compliance initiative. My ability to drive strategic compliance initiatives has been instrumental in my career.

Projects

CMMC Readiness Analysis

Performed a CMMC Readiness Analysis for an international, publicly-traded satellite company. Deliverables included gap analysis, SSP, POAM, remediation roadmap.See More

Work History

L

Owner and Principal

LJH Cybersecurity LLCI helped companies comply with complicated security standards while imparting hard-earned knowledge and wisdom along the way. My specialties included: Cybersecurity Maturity Model Compliance (CMMC), Federal Risk and Authorization Management Program (FedRAMP), NIST System Security Plans (SSP), DoD Confidential Unclassified Information (CUI), Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012, NIST 800-53, 800-171, 800-160, Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) and Consensus Assessment Initiative Questionnaire (CAIQ), Payment Card Industry Data Security Standard (PCI DSS), HITRUST.
E

Director of Governance, Risk and Compliance (GRC)

EquinixJan 2019 - Jan 2020 • 1 yr 1 moI was the company's first cybersecurity Governance, Risk and Compliance (GRC) leader. I organized my team to deliver a rock solid four-pillar remit: Compliance Consulting, Policies and Common Control Framework (CCF), Vendor Risk Management (VRM), and Continuous Compliance GRC platform with automation. Selected Accomplishments: Combined disparate control frameworks into one for 20 companywide compliance programs, by narrowing more than 10K controls in Unified Control Framework (UCF) to 350. Guided gap analysis and remediation to comply with the US government's NIST 800-171 based Controlled Unclassified Information (CUI) program and preparing for Cyber Security Maturity Model Certification (CMMC), to promote federal sales channels. Interfaced with largest customers, explaining the company's security posture, in support of customer VRM programs.
E

FedRAMP Director / Program manager

EquinixJan 2015 - Jan 2019 • 4 yrs 1 moThis was my first foray into heading a business-critical, multi-year security compliance initiative. It was a highly visible role with C-level accountability. My mission was to orchestrate a symphony of stakeholders from ten business units in technical and business harmony. I passionately championed the case to extend the security benefits to all customers, not just federal agencies, which had a profound impact on the company's overall security posture. The initiative involved ensuring that 300 logical security controls from NIST 800-53 were properly applied to 20 subsystems, in 25 overlapping work streams. Selected Accomplishments: Provided monthly status reports and SSP updates to authorizing officials from US General Services Administration, the agency sponsor, and government-authorized auditors. Yielded monetary savings by proving to auditors that 10% of controls were inapplicable despite appearance. Minimized testing required by third party assessment organization (3PAO) by designing and implementing a highly efficient architecture for inside the system boundary.

How Pangea Works

Effortlessly discover top talent

We've distilled the candidate search from endless hours down to just a few minutes. Using Pangea's AI-powered search tools, you can find top fractional talent able to take on your next project. Our system looks at your company's niche and your needs to find the perfect match faster than any traditional hiring platform.

Start working with talent today

The top talent on Pangea is ready to get started with you right now. You can message or hire a candidate right from their profile page and start assigning work as soon as they respond. And the best part? Pangea's fractional contract structure lets you start small and ramp up as your needs change, keeping your costs manageable and your team's capabliities flexible.

Track work and invoices in one place

Assign tasks, track progress, and complete invoices all on Pangea. We've combined every part of the hiring process into one platform to eliminate the miscommunication that's unavoidable on other freelance platforms. We even send out 1099s to your contractors at the end of the year!

Talk with a Talent Expert

Members of our team are available to help you speed through the hiring process.
Available Now
Book a Call
GRC | Governance, Risk and Compliance | Cybersecurity | CMMC | FedRAMP | NIST
With a wealth of experience in cybersecurity and compliance, I have a proven track record of leading and managing complex programs. My expertise includes FedRAMP, DFARS / CMMC, HITRUST, PCI DSS, and more. As the Owner and Director of LJH Cybersecurity LLC, I assist companies in complying with security standards and compliance frameworks. During my tenure as the Director of GRC at Equinix, I founded and led the organization's GRC program. Additionally, as FedRAMP Director / Program Manager, I successfully orchestrated an 8-figure multi-year security compliance initiative. My ability to drive strategic compliance initiatives has been instrumental in my career.

Talk with a Talent Expert

Members of our team are available to help you speed through the hiring process.
Available Now
Book a Call

Top Talent like Larry are on Pangea

Pangea, a YC company, connects companies with fractional talent. Fractional hiring allows companies to move faster and work with more specialized talent, while giving talent more flexibility and independence. If you are talent open to fractional work, apply here. If you’re a company looking for high-quality fractional talent, learn more here.

Larry Hughes

Policy Analysis
Compliance
Cybersecurity
Cybersecurity frameworks
Available for hire fromNegotiable
Contracts
Full-Time Roles

Projects

CMMC Readiness Analysis

Performed a CMMC Readiness Analysis for an international, publicly-traded satellite company. Deliverables included gap analysis, SSP, POAM, remediation roadmap.

Work History

L

Owner and Principal

LJH Cybersecurity LLCI helped companies comply with complicated security standards while imparting hard-earned knowledge and wisdom along the way. My specialties included: Cybersecurity Maturity Model Compliance (CMMC), Federal Risk and Authorization Management Program (FedRAMP), NIST System Security Plans (SSP), DoD Confidential Unclassified Information (CUI), Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012, NIST 800-53, 800-171, 800-160, Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) and Consensus Assessment Initiative Questionnaire (CAIQ), Payment Card Industry Data Security Standard (PCI DSS), HITRUST.
E

Director of Governance, Risk and Compliance (GRC)

EquinixJan 2019 - Jan 2020 • 1 yr 1 moI was the company's first cybersecurity Governance, Risk and Compliance (GRC) leader. I organized my team to deliver a rock solid four-pillar remit: Compliance Consulting, Policies and Common Control Framework (CCF), Vendor Risk Management (VRM), and Continuous Compliance GRC platform with automation. Selected Accomplishments: Combined disparate control frameworks into one for 20 companywide compliance programs, by narrowing more than 10K controls in Unified Control Framework (UCF) to 350. Guided gap analysis and remediation to comply with the US government's NIST 800-171 based Controlled Unclassified Information (CUI) program and preparing for Cyber Security Maturity Model Certification (CMMC), to promote federal sales channels. Interfaced with largest customers, explaining the company's security posture, in support of customer VRM programs.
E

FedRAMP Director / Program manager

EquinixJan 2015 - Jan 2019 • 4 yrs 1 moThis was my first foray into heading a business-critical, multi-year security compliance initiative. It was a highly visible role with C-level accountability. My mission was to orchestrate a symphony of stakeholders from ten business units in technical and business harmony. I passionately championed the case to extend the security benefits to all customers, not just federal agencies, which had a profound impact on the company's overall security posture. The initiative involved ensuring that 300 logical security controls from NIST 800-53 were properly applied to 20 subsystems, in 25 overlapping work streams. Selected Accomplishments: Provided monthly status reports and SSP updates to authorizing officials from US General Services Administration, the agency sponsor, and government-authorized auditors. Yielded monetary savings by proving to auditors that 10% of controls were inapplicable despite appearance. Minimized testing required by third party assessment organization (3PAO) by designing and implementing a highly efficient architecture for inside the system boundary.

How Pangea Works

Effortlessly discover top talent

We've distilled the candidate search from endless hours down to just a few minutes. Using Pangea's AI-powered search tools, you can find top fractional talent able to take on your next project. Our system looks at your company's niche and your needs to find the perfect match faster than any traditional hiring platform.

Start working with talent today

The top talent on Pangea is ready to get started with you right now. You can message or hire a candidate right from their profile page and start assigning work as soon as they respond. And the best part? Pangea's fractional contract structure lets you start small and ramp up as your needs change, keeping your costs manageable and your team's capabliities flexible.

Track work and invoices in one place

Assign tasks, track progress, and complete invoices all on Pangea. We've combined every part of the hiring process into one platform to eliminate the miscommunication that's unavoidable on other freelance platforms. We even send out 1099s to your contractors at the end of the year!

Talk with a Talent Expert

Members of our team are available to help you speed through the hiring process.
Available Now
Book a Call
Pangea empowers fractional work across the world for marketing and design roles.