CMMC • GOVERNANCE • RISK • COMPLIANCE

Eliza Ochoa
Cybersecurity Compliance Portfolio

Professional portfolio focused on cybersecurity compliance, governance, risk assessment, documentation quality, and framework-aligned readiness analysis. This site highlights work aligned with CMMC 2.0, NIST-based security requirements, and structured reporting for regulated environments.

CMMC 2.0
NIST SP 800-171
GRC
Risk Assessment
Control Validation
Compliance Reporting
AI/ML Analysis

Professional Snapshot

Leadership Experience
15 Years
Primary Focus
Security & Compliance
Current Program
Cybersecurity, CMMC Certified Professional (CCP)
Certification Path
CMMC Certified Assessor, compTIA Security+
15+

Years of leadership and structured operational oversight

3.93

Current academic performance in cybersecurity studies

2026

Expected completion of BS in Cybersecurity | Minor: Data Science

1

Primary portfolio direction: Cybersecurity + CMMC

Framework and Compliance Focus

Core areas aligned with compliance readiness, governance, and security documentation.

CMMC 2.0 Readiness
NIST SP 800-171 Alignment
NIST SP 800-53 Familiarity
NIST Risk Management Framework
NIST Cybersecurity Framework
Governance, Risk, and Compliance

Professional Capabilities

Experience areas reflected in professional reporting, technical support, and structured oversight.

Security Control Validation
Risk Assessment
Compliance Documentation
Executive Reporting
Remediation Planning
Research and Publications
AI/ML and Big Data Analysis

Professional Experience

U.S. Navy — Leadership and Compliance-Focused Operations

2008–2023
  • Led structured inspections, documentation, and risk-aware operational oversight across mission-focused environments.
  • Supported compliance-oriented reporting and leadership communication aligned with procedural accountability.
  • Worked across teams, processes, and technical environments requiring disciplined execution and documentation quality.

Advanced Information Security & Privacy (AISP) Research Lab — Research Assistant

2023–2026
  • Collected and validated 500+ research data points across multiple domains, ensuring dataset accuracy and reproducibility for analytical studies.
  • Organized and prepared structured datasets for 3+ research projects, enabling efficient statistical analysis and documentation of research methodologies.

SUNY Research Foundation (RF) — Research Assistant

2023–2024
  • Organized and maintained documentation and datasets for 5+ faculty-led research initiatives, ensuring accuracy, accessibility, and compliance with academic research governance practices.
  • Supported research data management and reporting by preparing multiple datasets and project records, improving documentation consistency and analytical readiness.

SUNY Canton IT Department — Systems IT Assistant

2024–2025
  • Developed 10+ technical training materials and user guides to support system administration and networking tasks for campus users and IT staff.
  • Assisted with 2 network topology and system configuration projects, building sandbox environments and developing Powershell scripts to support testing, troubleshooting, and automation.

Featured Work

Public-facing portfolio demonstrations based on projects developed locally first and later prepared as separate GitHub demo versions. Featured projects highlight responsible AI, cybersecurity analysis, and compliance-aligned tool design.

CMMC Control Mapping and Gap Analysis Tool

A compliance-focused demonstration project for reviewing selected controls, assigning implementation status, and identifying readiness gaps in a structured reporting format.

CMMCNIST 800-171Gap Analysis
Demo Repository Coming Soon

IP Intelligence Analyst Workspace

An interactive cybersecurity analyst workspace that supports single-IP and batch-IP investigation, lightweight risk scoring, analyst tagging, and persistent case history. Designed to simulate real-world SOC and GRC workflows with data visualization and export capabilities.

CybersecurityThreat IntelligenceData AnalysisRisk AssessmentStreamlit+Python
🚀 Live Demo 💻 GitHub Repo

TrustLens

A deterministic responsible-AI review app that helps students evaluate whether an AI-generated answer is trustworthy enough to submit, cite, or revise. TrustLens emphasizes transparent scoring, explainability, validation boundaries, and structured auditability.

Responsible AI Trust Scoring Explainability Auditability Streamlit+Python
🚀 Live Demo 💻 GitHub Repo 🎥 Demo Video

Publications

Professional research outputs, white papers, and technical publications through GitHub, Zenodo, DOI references, and ORCID.

Mental Health Data Analysis in R: A Comprehensive Guide to Insights in the Tech Industry

Presents an in-depth analysis of mental health trends within the tech industry using R programming language. The study involves data cleaning, exploratory data analysis (EDA), and predictive modeling to uncover actionable insights. Findings emphasize the role of factors like age, gender, and family history in shaping treatment-seeking behaviors, providing foundation for data-driven policy recommendations.

ZenodoDOIWhitepaper
R Analysis: Mental Health in Tech

A Comprehensive Study of DoD Training Applications and Needs in the Cyberspace Field

Analyzes existing cyber training programs within the Department of Defense (DoD), highlights critical shortcomings, and proposes innovative training methodologies utilizing Artificial Intelligence (AI), digital twins, and extended reality (XR).

ZenodoDOIWhitepaper
DoD Cyberspace Field

Professional Contact

Email: ochoa104cy@outlook.com

LinkedIn: linkedin.com/in/elizaochoa

GitHub: github.com/eliza-ochoa

Orcid: orcid.org/0009-0006-8845-5692

Merit: meritpages.com/ochoa104

Credly: credly.com/users/eliza-ochoa

Inquiry