TOKEN  LLC

Security engineering · Governance, risk & compliance

Olanrewaju David Kehinde

Thirteen years spent walking toward the same question. Not whether the system is up, but who touched this record, when, from where, and whether you can prove it. I build the controls that produce the proof, and the evidence that survives the assessor.

SUBJECT TOKEN active
subject

Olanrewaju David Kehinde

entity

Token LLC

clearance

Tier 3 (T3), active. Eligible for VA Public Trust.

posture

CMMC · RMF · detection engineering · cloud security

head

Career ledger

Five records.
Each one hashed into the next.

A tamper-evident log is a chain. Every entry carries the digest of the entry before it, so you cannot quietly rewrite history without breaking every link that follows. My career reads the same way: each role is the input to the next one.

The digests below are recomputed in your browser with SHA-256 over the text you can actually see. Open devtools, change a word, run it again.

idle

Where this goes next

The rest of it, in governance risk and compliance.

CMMC readiness

Taking a contractor from a scoping conversation to an assessment they can pass, without pretending the gap analysis is the hard part. The evidence trail is the hard part.

  • CMMC Level 2
  • NIST SP 800-171
  • SSP
  • POA&M
  • C3PAO prep

Authorization and RMF

Moving federal systems through the assessment cycle without losing the ATO. Control selection, Security Impact Analysis, and continuous monitoring that actually monitors something.

  • NIST RMF
  • SP 800-53
  • SIA
  • ConMon
  • ATO sustainment

Detection that survives contact

Detections analysts keep, because I have owned the platform underneath them and know what a bad one costs the queue on a Monday morning.

  • Splunk ES
  • Risk-based alerting
  • CIM
  • Index-time masking

Dispatch

Notes from inside the boundary.

Occasional writing on CMMC scoping, detection engineering, and getting federal systems authorized without grinding delivery to a halt.

Attestation

ODK
T3active

Let's talk about where the bottleneck sits.

I am open to security engineering and GRC work, federal or defense industrial base, on staff or through Token LLC. If you have a provisioning pipeline that security keeps getting routed around, that is the conversation I want to have.