Skip to content
Bull BearDefense SolutionsCapability Statement(opens in a new tab)

Services

Cradle-to-grave IT & cybersecurity

Four practice areas, run end to end — from the first RMF artifact to the cloud the system lands on, and the assessment that keeps it authorised.

What we do

Practice areas

Governance, Risk & Compliance

  • Full RMF lifecycle management & cybersecurity artifact generation
  • NIST 800-53 RMF, NIST 800 series, USAF 17 series, DoD 8500 expertise
  • DISA Cloud SRG & CCPG knowledge; STIG engineering and compliance
  • eMASS & Xacta expertise
  • Source-code bug & vulnerability management and mitigation

IT & Cybersecurity

  • Cloud systems administration & DevSecOps CI/CD pipelines
  • Legacy IT support and legacy-to-cloud upgrade projects
  • New cloud engineering and deployments (IaaS, PaaS, SaaS, IaC)
  • AWS, Azure Gov Cloud, DoD PA-authorized, and FedRAMP-approved clouds
  • USAF system compliance

Data & AI Engineering

  • Data pipelines (ETL / ELT)
  • AI/ML automation (OCR, workflows)
  • Data platforms (lakes, analytics)
  • Data governance & quality
  • Analytics & visualization (Power BI)

Risk Assessments

  • NIST 800-171 gap analysis & assessments
  • DFARS 252.204-7012 assessments
  • DoD Provisional Authorization (DoD PA) & CSP expertise
  • FedRAMP and Cloud Security Requirements (SRG) expertise
  • Cloud Connection Process Guide (CCPG) understanding

Personnel certifications

  • ISC2 CISSP
  • CompTIA Security+
  • CompTIA Network+
  • CompTIA A+
  • Microsoft Certified Professionals

Whitepapers

For the full picture of our competencies, past performance, and contract vehicles, see the capability statement.

Need this scoped against your requirement?

Request a capability briefingCapability statement