The federal government is playing a game of cyber-attack-a-mole with bad actors, constantly adapting to their threats but ultimately driving them to other areas, such as targeting endpoints or applications to find a weak point not being monitored.
This week on Feds At the Edge, we are focusing on sophisticated attacks on federal applications and APIs.
Jerry Cochran, Deputy Chief Information Officer and Director of the Cybersecurity & DigitalOps Division from Pacific Northwest National Laboratory, shares how the once popular Software Bill of Materials has weakened over the years thanks to the constant change of code.
AI can help detect vulnerabilities in dynamic code, but attackers also use AI to find weaknesses. Instead of signature-based approaches, Nate Fountain Deputy CISO from ICE, suggests using behavior analytics to prevent compromised code from exfiltrating data.
Tune in on your favorite podcasting platform as our experts discuss the ongoing battle.
To view this webinar: How to Fight Threats to the Software Supply Chain.
Featured Speakers:

Nate Fontaine

Deputy Chief Information Security Officer
Nate Fontaine started his professional career as an F-16 and F-22 Crew Chief in the United States Air Force, simultaneously graduating from Christopher Newport University and Colorado Technical University. He currently serves as the President of the Christopher Newport University Alumni Society Board of Directors, with the responsibility of leading and guiding the board in its efforts to support and advance the interests of the alumni community and the educational institution.
Following his honorable discharge, Nate embarked on a remarkable career with the United States Government, rising through the ranks from a contractor with multiple departments to his current position as the Deputy Chief Information Security Officer (DCISO) for U.S. Immigration and Customs Enforcement. As DCISO, Nate assists in the development, implementation, and oversight of comprehensive information security strategies, risk management, agency incident response plans, and programs.
In addition to his professional achievements, Nate has dedicated substantial time to public service within his town, serving on the Planning Commission, Town Council, and even elected Mayor twice. Nate was the founding American Legion Post Commander and has recently worked with other leaders to organize a new all-girls’ BSA troop. Nate Fontaine’s exceptional contributions to education, local and federal government, and community service embody the values of leadership, service, and honor.
Deputy CISO,
ICE

Shawn Kingsberry

Vice President, Cybersecurity
Shawn Kingsberry is a vice president in the Digital Innovation Factory at SAIC. He leads teams focused on developing cyber solutions that protect our nation’s interests by enabling situational awareness, active cyber defense, and threat detection and remediation.
Kingsberry has more than 30 years of experience in information technology and has a diverse background in federal and state government as well as corporate technology leadership. He has extensive experience leading large-scale secure digital transformation and fostering productive partnerships with internal teams and external technology partners.
Prior to joining SAIC, Kingsberry led Global Advisory Services for Unisys and directed the development and deployment of secure cloud solutions for Engility.
Before moving to private industry, Kingsberry served as chief information officer for the federal Recovery Accountability and Transparency Board. In that role, he led successful efforts to provide transparency on stimulus spending and oversight of fraud, waste and abuse. He also oversaw the agency’s migration to the public cloud, the first federal-wide system to achieve that milestone. He is a recipient of the prestigious Fed 100 Award, recognizing his leadership at that agency.
He also held executive positions with the U.S. Department of Agriculture.
Kingsberry is frequent speaker and panelist who is recognized by senior industry and government leaders, peers and subordinates for his strategic mindset and leadership in the modernization of IT infrastructure to meet increasing security, data and citizen-services requirements.
Vice President of Cyber,
SAIC

Jerry Cochran

Deputy CIO & Director, Cybersecurity & DigitalOps
Jerry Cochran serves as Pacific Northwest National Laboratory’s deputy chief information officer and director of the Cybersecurity & DigitalOps Division in the Computing and Information Technology Directorate. In this role, Cochran oversees cybersecurity and the office of the chief information security officer, as well as enterprise IT engineering and operations. He also leads PNNL’s five-year Resilience Through Data-Driven, Intelligently Designed Control (RD2C) Initiative, a cybersecurity laboratory directed research and development initiative stewarded by the National Security Directorate.
Cochran’s management, technical, strategy, and operational experiences span both government and private sector over his 30+ year technology and 25+ year cybersecurity career, working in startups and for industry leaders like Compaq/HP, Microsoft, and the U.S. Department of Defense. His multidisciplinary expertise and background in network and systems engineering, software engineering, security architecture, compliance, strategy, security operations, and military cyber operations are directly relevant and impactful to PNNL’s cyber research, operations, and mission focus areas.
Prior to joining PNNL in 2017 as the chief information security officer, Cochran was with Microsoft in the Cloud & Enterprise Azure Security Division as well as prior roles leading Office 365 cloud security operations. He served as a cybersecurity architect, helping to build a cybersecurity practice in Microsoft Services and was with the Trustworthy Computing Group, where he directed the Global Security Strategy Team. Cochran also served as the Microsoft board member and officer with the Information Technology-Information Sharing and Analysis Center (IT-ISAC) and was a founding member and executive committee member of the IT Sector Coordinating Council (IT-SCC).
Culminating a 27-year United States Air Force (USAF) career in 2011, Cochran retired as a Chief Master Sergeant (E9), senior enlisted manager of the 262nd NWS where he also served as a network warfare technical lead, conducting cyber operations around the world. Deployed to locations worldwide throughout his service career, he was initially a radar systems technician, until cross training in the 1990s to become an early thought leader in military network warfare doctrine and mission capabilities. He was part of an eight-member team that established the first network warfare squadron in the USAF, where he led the development of key mission capabilities in network security assessments/red teaming and industrial control systems security.
Cochran has also authored various technical works, including over 200 electronic and print articles and two books for publication. He is a US patent holder for invention in cybersecurity. He holds a BS in engineering and technology management, an AS in electronics technology, and an AS in information systems technology. Cochran also currently holds the Certified Information Systems Security Professional (CISSP) and Certified Information Security Manager (CISM) certifications.
Deputy CIO & Director Cybersecurity & DigitalOps Division, Pacific Northwest National Laboratory

JR Willamson

Senior Vice President& Chief Information Security Officer
JR Williamson is the Senior Vice President and Chief Information Security Officer of Leidos. In that role, he is accountable for all aspects of information security strategy, governance, risk, and full lifecycle cybersecurity operations for the corporation. Specific duties include the governance and defense of the corporation’s computing environments: protection of unclassified and classified intellectual and digital assets against existing and emerging cybersecurity threats; developing and implementing effective risk-based security policies, procedures, and operating practices; executing cyber risk assessments and designing appropriate remediation plans; development and retention of our global cybersecurity workforce, and the evolution of our global information security technology and innovation processes.
Mr. Williamson is a Certified Information Systems Security Professional and a Six Sigma Black Belt. He chairs the Leidos Security Council, is a member of the Executive Security Action Forum, the Microsoft Chief Security Officer Council, the Security 50, the Gartner Advisory Board, the Defense Industrial Base Sector Coordinating Council, a member of the NSA Enduring Security Framework team, WashingtonExec, the Palo Alto Customer Advisory Board, the Zscaler Customer Advisory Board, the F5 Customer Advisory Board, and is the Chairman of the Board of Directors for the Internet Security Alliance.
Mr. Williamson is blessed with a wonderful family of five and spends his free time with them and engaging in all things soccer (he is a professional soccer coach with a US Soccer National C license, a senior certified referee instructor and mentor, and serves on the Herndon Youth Soccer Board of Directors).
Sr. Vice President & CISO,
Corporate IS, Leidos

Peter Chestna

Chief Information Security Officer of North America
Pete Chestna serves as the CISO of North America at Checkmarx, where he provides customers and prospects with practical advice for building successful application security programs. Bringing more than 15 years of direct AppSec practitioner experience, Pete has held roles ranging from developer and development leader to his most recent position as the Global Head of AppSec for the Bank of Montreal where he was responsible for the security of thousands of applications.
Over his years as a software engineer and engineering leader, Pete has led organizational transformations from Waterfall to Agile to DevOps and from monolith to microservice architectures. He is certified as both a scrum master and product owner. Stemming from his experience as both an avid practitioner and consultant, Pete has spoken internationally at numerous prominent security and developer conferences including DevOpsDays, All Day DevOps, OWASP AppSec, and DevSecCon.
Pete has been granted 3 patents. He enjoys whiskey tourism, astronomy, model rocketry and listening to Rush in his spare time.
CISO of North America,
Checkmarx

Jane Norris

Contributing Editor
Jane Norris a contributing editor to FedInsider, is committed to advancing government communications and putting people first in every regard.
Jane brings a lifetime career in media and government to her role. She has held senior roles at the U.S. Department of Labor (DOL) and the U.S. Department of Health and Human Services (HHS). As a consultant and public relations lead, she worked to execute priority issues for two powerhouse government contracting firms creating successful communications strategies for issues like, technology modernization, AI, data analytics, cybersecurity, customer experience, human centered design, health and economic policy, the government workforce and employee engagement.
Jane’s private sector career also includes on-air work with multiple radio and television stations, most recently as a daily drive-time host on Federal News Radio/WTOP in Washington DC.
Moderator & Contributing Editor,
FedInsider
