CYSE 368 / INTERNSHIP
Final Internship Paper
ITA International
Student: Michael Blanchard
Instructor: [ Teresa Duvall & Jade Hines]
Internship Class: CYSE 368 / Internship
Term: Summer 2026
Date: August 9, 2026
Table of Contents

  1. Introduction ………………………………………………. 1
  2. Management Environment ……………………………………… 3
  3. Major Work Duties, Assignments, and Projects ………………….. 4
  4. Use of Cybersecurity Skills and Knowledge …………………….. 6
  5. How the ODU Curriculum Prepared Me …………………………… 7
  6. Internship Outcomes and Objectives …………………………… 8
  7. Most Motivating or Exciting Aspects ………………………….. 9
  8. Most Discouraging Aspects …………………………………… 9
  9. Most Challenging Aspects ……………………………………. 10
  10. Recommendations for Future Interns ………………………….. 10
  11. Conclusion ……………………………………………….. 11
    References …………………………………………………… 12
  12. Introduction
    My internship at ITA International has been one of the most valuable experiences I
    have had during my time at Old Dominion University. I decided to pursue this
    internship because I wanted to experience cybersecurity outside of a classroom and
    understand what the field actually looks like in a professional environment. I found
    the ITA International internship on LinkedIn only a few hours after it was posted. I
    applied because the position looked like an opportunity to combine cybersecurity,
    quality, compliance, technology, and professional development. Looking back,
    applying so quickly ended up being one of the best decisions I made during college
    because the internship gave me the chance to work with experienced professionals and
    see how cybersecurity connects to many different parts of an organization.
    I completed my internship with ITA International in Newport News, Virginia,
    working primarily with Glenn Mallo and Jim Stewart. My role allowed me to work on
    projects involving CMMC, quality initiatives, databases, documentation, and the
    company’s underwater data center work. Although the position was connected to
    cybersecurity, it was not limited to the technical tasks that I originally associated with
    cybersecurity. I learned that cybersecurity can involve compliance, quality assurance,
    risk management, documentation, communication, process improvement, and making
    sure that an organization can demonstrate that it is meeting required standards. This
    broader understanding became one of the biggest takeaways from my internship.
    ITA International is a technology-enabled professional services company
    headquartered in Newport News, Virginia. The company describes itself as a global
    service provider that combines subject matter expertise, data analytics, and technology
    to support mission success. Its capabilities include operations, training, engineering,
    cyber support, intelligence, data analytics, statistics, machine learning, software
    engineering, and sustainability-related services. ITA has long-standing relationships
    with government customers, including organizations within the Department of
    Defense and Department of Homeland Security. The company also supports
    customers through technology-enabled professional services rather than relying on a
    single product or service. This makes the company a good environment for an intern
    because the work can involve many different disciplines at the same time (ITA
    International, 2026a).
    ITA International was founded in the early 2000s and developed from a
    marine-focused business into a broader provider of integrated professional and
    technical services. Public company information identifies ITA as a Newport
    News-based organization with a global presence. The company’s history also shows a
    progression toward data analytics and technology-enabled services. For example, ITA
    has supported federal customers through large data analytics and engineering efforts
    and has continued expanding its technology and mission-support capabilities. In 2025,
    ITA International was also recognized for its CMMI Development Maturity Level 3
    appraisal, which reflects the organization’s emphasis on established processes and
    continuous improvement (ITA International, 2025).
    The customers served by ITA are different from the customers of a typical
    commercial technology company. A significant part of ITA’s work supports
    government and national-security missions. Its public materials identify relationships
    with the Department of Defense and Department of Homeland Security, while its
    recent contract announcements show continued involvement in major federal
    programs. In January 2026, ITA announced that it had been awarded a position on the
    Missile Defense Agency’s SHIELD IDIQ contract, which has a ceiling of $151
    billion. The announcement described the contract as supporting rapid delivery of
    innovative capabilities for homeland defense and warfighter missions (ITA
    International, 2026b). This environment helped me understand that cybersecurity and
    quality are especially important when an organization works with sensitive
    information and government requirements.
    When I first arrived at ITA International, one of my biggest impressions was that
    the workplace felt much more professional and collaborative than what I was used to
    in a classroom. I was introduced to the people I would be working with, learned about
    expectations, and began becoming familiar with the organization’s work and
    processes. My initial training included learning how work was organized,
    understanding the projects I would be supporting, reviewing information related to
    quality and cybersecurity, and learning how to communicate professionally. I also had
    to become comfortable with asking questions and taking notes because there were
    many terms and processes that were new to me.
    My initial impression was also that there was much more to cybersecurity than I
    had previously understood. Before the internship, when I heard the word
    cybersecurity, I mainly thought about protecting computers, networks, accounts, and
    data from attacks. Those areas are still important, but ITA showed me the business
    side of cybersecurity. A secure organization needs policies, procedures, evidence,
    documentation, quality controls, trained employees, risk management, and continuous
    improvement. Cybersecurity has to be integrated into the way an organization
    operates rather than treated as a separate task.
    There were several learning outcomes and objectives that I wanted to achieve
    during the internship. First, I wanted to develop a better understanding of how
    cybersecurity knowledge is applied in a real organization, especially through
    compliance and CMMC-related work. Second, I wanted to improve my professional
    communication, teamwork, and ability to work with experienced professionals. Third,
    I wanted to strengthen my ability to apply quality assurance, documentation, database,
    and process-improvement skills to cybersecurity-related work. These objectives gave
    me a direction for the internship, but the experience ultimately taught me more than I
    expected.
    This paper explains my internship experience from beginning to end. It discusses
    the management environment, my major duties and projects, my use of cybersecurity
    skills, connections to the Old Dominion University curriculum, and the extent to
    which my learning objectives were fulfilled. It also discusses what motivated me,
    what discouraged me, what challenged me, and what I would recommend to another
    student preparing for the same type of internship. Most importantly, the paper explains
    how this experience changed the way I understand cybersecurity and how it has
    influenced the professional direction I want to take after college.
  13. Management Environment
    The management environment at ITA International was one of the strongest parts
    of my internship. I worked closely with Glenn Mallo and Jim Stewart, and their
    supervision gave me a balance between guidance and independence. I was not
    expected to know everything when I arrived. Instead, I was given opportunities to
    learn, ask questions, complete assignments, and gradually take more ownership of my
    work. This was important because one of my goals was to become more confident in a
    professional setting.
    The organization operates across several areas of expertise, so management
    naturally involves coordination between different groups. ITA’s public description of
    its organizational structure and services shows that the company brings together
    operations, engineering, training, cyber, intelligence, data analytics, and
    software-related capabilities. The company’s 2023 organizational changes were
    specifically intended to improve customer focus, collaboration, and shared success.
    That structure matched what I experienced because many assignments required
    communication between people with different responsibilities (ITA International,
    2023).
    Glenn and Jim were effective supervisors because they were available when I
    needed direction while also allowing me to learn through the work itself. When I did
    not understand a task, I could ask questions and receive clarification rather than being
    expected to guess. At the same time, I was encouraged to think through problems and
    become more independent. This approach helped me realize that good supervision is
    not simply telling an employee what to do. It is also about developing the employee’s
    ability to solve problems, communicate, and make decisions.
    Another important part of the management environment was communication. I saw
    how meetings, emails, documentation, and informal conversations were all part of
    keeping projects moving. I learned that a project can be technically correct and still
    have problems if people are not communicating clearly. In cybersecurity, this is
    especially important because a security issue may involve technical staff,
    management, quality personnel, compliance personnel, and other departments.
    Everyone needs to understand their responsibilities.
    Overall, I believe the management environment was effective for an internship
    because it gave me access to experienced professionals without making me feel like I
    was expected to already be an expert. I was able to learn from the people around me
    and gradually become more comfortable contributing. This environment also showed
    me what I should look for in a future workplace: strong communication,
    accountability, mentorship, teamwork, and managers who are willing to teach.
  14. Major Work Duties, Assignments, and Projects
    My internship duties covered several different areas. The major categories of work
    included CMMC projects, quality initiatives, database-related work, documentation,
    and support for ITA International’s underwater data center project. Having multiple
    types of assignments was valuable because it prevented me from thinking of
    cybersecurity as one specific job function. Each project required a different way of
    thinking, but they all connected to the larger goal of helping an organization operate
    securely, consistently, and effectively.
    One of my main areas of work was supporting CMMC-related projects. CMMC, or
    the Cybersecurity Maturity Model Certification program, is important to organizations
    in the defense industrial base because it establishes cybersecurity requirements
    associated with protecting certain federal information. During the internship, I learned
    more about the importance of organizing evidence, understanding requirements,
    documenting processes, and checking whether an organization can demonstrate that
    its practices meet expectations. This was different from studying cybersecurity
    standards in class because I was seeing the administrative and operational work
    required to prepare for compliance.
    CMMC work is necessary to a company such as ITA because compliance is
    connected to its ability to support government customers and protect sensitive
    information. It is not enough for an organization to say that it is secure. It needs
    repeatable processes and evidence showing how security requirements are addressed.
    My work helped me see why documentation matters. A missing document, outdated
    procedure, or incomplete piece of evidence can create additional work and potentially
    create risk. This made me more careful with details in every other assignment.
    I also worked on quality initiatives. Before this internship, I did not naturally
    connect quality assurance with cybersecurity. I now understand that the two areas
    overlap significantly. Quality management involves making sure processes are
    defined, followed, measured, documented, and improved. Cybersecurity also depends
    on reliable processes. If a company has a security procedure but employees do not
    follow it consistently, the procedure does not provide much protection. Quality
    therefore supports cybersecurity by helping organizations create repeatable and
    dependable processes.
    Database work was another valuable part of my internship. Working with
    information in databases helped me understand that data management is not simply
    about storing information. Organizations need accurate information, consistent
    formats, appropriate access, and processes for maintaining that information. From a
    cybersecurity perspective, data should also be protected against unauthorized access,
    alteration, or loss. Even when a database assignment did not look like a traditional
    cybersecurity task, it still required me to think about accuracy, organization, access,
    and the importance of information.
    I also supported work related to ITA International’s underwater data center project.
    The project was particularly interesting because it combined technology, engineering,
    quality, environmental conditions, data, and cybersecurity. An underwater data center
    has unique challenges because equipment operates in a remote and physically
    demanding environment. Maintenance, monitoring, reliability, network performance,
    physical protection, and cybersecurity all have to be considered together. My work on
    this project helped me understand how cybersecurity can become part of a larger
    engineering and quality problem rather than existing separately.
    The underwater data center project also gave me the opportunity to think about
    predictive maintenance and monitoring. Sensors and data could potentially be used to
    monitor conditions such as temperature, pressure, power consumption, cooling
    performance, vibration, water intrusion, and network performance. If unusual activity
    is detected, personnel could investigate before a larger failure occurs. From a
    cybersecurity perspective, connected sensors and remote systems also create security
    considerations. Devices must be protected, communications need to be secure,
    software updates need to be controlled, and access needs to be managed.
    Another area of work involved documentation and written communication. I
    contributed to materials that required information to be organized clearly for other
    people to understand and use. This taught me that professional writing is different
    from writing an assignment for a class. A workplace document needs to be accurate,
    concise, useful, and understandable to its intended audience. It may become part of a
    process, training material, evidence package, or communication between departments.
    Because of that, I learned to pay more attention to wording and details.
    Each of these duties was necessary to the organization for a different reason.
    CMMC work supported compliance and cybersecurity requirements. Quality
    initiatives supported reliable processes and continuous improvement. Database work
    supported information management. Documentation supported communication and
    organizational knowledge. The underwater data center work supported research and
    development of innovative technology. Even though the assignments were different,
    they all showed me that a successful organization depends on many connected pieces
    working correctly.
    One of the biggest lessons from these assignments was that cybersecurity is a team
    effort. I saw people with different areas of expertise working toward the same goal.
    Someone might understand a technical issue better, while someone else understands
    quality, compliance, operations, or a customer’s requirements. The best outcome
    comes from combining those perspectives. This experience changed the way I think
    about cybersecurity careers because I no longer see the field as only technical work
    performed by someone sitting at a computer.
  15. Specific Use of Cybersecurity Skills and Knowledge
    I entered the internship with a foundation in cybersecurity from my coursework at
    Old Dominion University. I already understood basic concepts such as confidentiality,
    integrity, availability, access control, risk, network security, security policies,
    vulnerabilities, and the purpose of cybersecurity frameworks. I also had experience
    researching cybersecurity topics, writing technical assignments, working with
    computers, and learning how security controls are designed to reduce risk. These
    skills gave me a starting point, but the internship showed me how different it can be to
    apply those concepts in a real organization.
    The most direct cybersecurity connection was my work with CMMC-related
    projects. I had learned about cybersecurity frameworks and compliance in school, but
    the internship showed me the amount of work required to translate requirements into
    real organizational practices. I learned that cybersecurity compliance involves more
    than knowing what a requirement says. People have to understand the requirement,
    identify the organization’s current practices, create or maintain documentation, collect
    evidence, identify gaps, communicate findings, and make improvements. That process
    helped turn an abstract concept from class into something I could understand
    practically.
    I also used skills involving risk awareness and attention to detail. When reviewing
    information or working with documentation, I learned to think about what could go
    wrong if information was incomplete or inaccurate. I became more aware of the
    importance of version control, consistency, and making sure that information could be
    understood by someone else. These habits are important in cybersecurity because
    security decisions often depend on accurate information.
    The internship also required skills that I had not fully developed before starting.
    One of those skills was professional communication. I had communicated with
    classmates and professors, but communicating with coworkers in a professional
    environment is different. I had to listen carefully, take useful notes, ask appropriate
    questions, write professional messages, and understand when I needed clarification. I
    also had to become comfortable speaking about work even when I was still learning
    the subject.
    Another skill I developed was the ability to research unfamiliar concepts
    independently. There were many terms and processes that I had not encountered
    before. Instead of expecting someone else to explain everything, I learned to take
    notes, search for reliable information, review documentation, and then return with
    specific questions. This helped me become more independent. I realized that a
    cybersecurity professional will never know everything because the technology and
    threats continue to change.
    My understanding of cybersecurity changed significantly because of the internship.
    Before ITA, I viewed cybersecurity primarily as technical protection. Now I see
    cybersecurity as a combination of people, processes, technology, compliance, risk
    management, and continuous improvement. A firewall or security tool can be useful,
    but it cannot replace good procedures, trained employees, accurate documentation,
    and responsible management. The internship made cybersecurity feel more like an
    organizational discipline instead of only a technical discipline.
    The quality work especially changed my understanding. I learned that a quality
    program can support cybersecurity by creating consistency. When processes are
    documented and employees follow them, an organization has a better chance of
    knowing what is happening and identifying problems. Continuous improvement also
    applies to cybersecurity because controls cannot simply be created once and forgotten.
    Organizations have to review their processes, respond to changes, and improve over
    time.
    The underwater data center project also expanded my view of cybersecurity into
    operational technology and emerging technology. A system that combines computers,
    sensors, networking, engineering equipment, and remote monitoring has both physical
    and digital risks. Cybersecurity has to account for the entire environment. This made
    me more interested in areas where cybersecurity overlaps with engineering, critical
    infrastructure, data analytics, and emerging technologies.
  16. How the ODU Curriculum Prepared Me
    The Old Dominion University cybersecurity curriculum prepared me for the
    internship by giving me a foundation in security concepts and by requiring me to think
    about problems from different perspectives. My classes taught me vocabulary and
    concepts that became easier to recognize once I encountered them at ITA
    International. Topics involving cybersecurity principles, risk, ethics, networks,
    security controls, and information systems gave me a framework for understanding
    the work I was seeing.
    One of the strongest connections was between coursework involving cybersecurity
    frameworks and the CMMC work I supported. In school, frameworks can sometimes
    feel like lists of requirements that need to be memorized. At ITA, I saw why
    frameworks exist and how they influence an organization’s processes. The internship
    helped me understand that frameworks are useful because they give organizations a
    structured way to identify and manage security risks.
    My coursework also prepared me to research and learn independently. College
    assignments often require finding sources, comparing information, and explaining a
    topic in writing. Those same skills were useful at ITA when I encountered unfamiliar
    subjects. I was able to take a question, research it, organize what I found, and
    communicate the information in a useful way. This was especially important because I
    was exposed to topics that were outside my normal classroom experience.
    At the same time, the internship revealed areas that classroom learning cannot fully
    reproduce. School assignments generally have clear instructions, deadlines, and
    expected outcomes. A workplace project may change as new information becomes
    available. A manager may ask for something different from what you originally
    expected. A document may need to be revised several times. You also have to work
    with other people whose priorities and schedules may be different from yours. These
    realities taught me skills that are difficult to learn only through coursework.
    The internship reinforced the importance of communication and teamwork. In
    school, group projects provide some experience with teamwork, but the professional
    environment has different expectations. At ITA, communication was directly
    connected to getting work completed and supporting organizational goals. I learned
    that being technically capable is not enough if I cannot explain what I am doing, ask
    for help, or work with people from other areas.
    The internship also introduced me to concepts that I had not fully encountered in
    school, particularly the connection between quality management, cybersecurity
    compliance, and emerging technologies. I had learned about security controls and
    frameworks, but I had not previously thought deeply about how quality systems
    support security. I also had limited exposure to underwater data center technology.
    Seeing those areas together helped me understand that a cybersecurity career can
    involve much more than the topics that are normally associated with entry-level
    security jobs.
    Overall, ODU gave me the foundation I needed, but ITA gave me the context.
    School helped me understand the language and basic concepts of cybersecurity. The
    internship helped me understand how those concepts affect real people, projects,
    organizations, and customers. I believe both experiences are necessary. Without
    school, I would have had less background knowledge. Without the internship, I would
    have had a much weaker understanding of how cybersecurity operates in the
    workplace.
  17. Internship Outcomes and Objectives
    The first objective I identified at the beginning of the internship was to develop a
    stronger understanding of how cybersecurity is applied in a real organization. I believe
    this objective was fully achieved. My work with CMMC, documentation, quality
    initiatives, databases, and the underwater data center project showed me that
    cybersecurity is integrated into many business processes. I learned that security is not
    only about responding to attacks. It is also about preventing problems, managing risk,
    meeting requirements, protecting information, and creating reliable processes.
    The second objective was to improve my professional communication, teamwork,
    and confidence. This objective was also fulfilled. When I first started, I was
    sometimes nervous about asking questions or speaking up because I did not want to
    seem like I did not know enough. As the internship continued, I realized that asking
    questions is part of learning. I became more comfortable communicating with
    coworkers and supervisors. I also became better at taking notes, following up on
    assignments, and explaining what I understood.
    The third objective was to strengthen my ability to apply quality, documentation,
    database, and process-improvement skills to cybersecurity-related work. This
    objective was fulfilled and went beyond what I expected. The quality side of the
    internship showed me how process improvement can support security. Database work
    taught me the importance of accurate and organized information. Documentation
    taught me the importance of creating clear evidence and instructions. CMMC work
    connected these skills directly to cybersecurity and compliance.
    A fourth outcome that developed naturally during the internship was increased
    professional independence. I learned to look for answers before immediately asking
    someone else, while still recognizing when a question needed to be escalated. I
    became better at researching unfamiliar topics and organizing my work. This was
    important because cybersecurity professionals have to be able to learn continuously.
    Technology changes too quickly for someone to depend only on what they learned in
    college.
    The internship also fulfilled an outcome that I did not fully anticipate: learning
    more about the different career paths within cybersecurity. Before ITA, I knew I
    wanted a cybersecurity career, but I was less certain about what type of work I wanted
    to pursue. After seeing compliance, quality, data, emerging technology, and technical
    work together, I have a better understanding of the options available to me. I am now
    more interested in roles that allow me to combine cybersecurity knowledge with
    analysis, compliance, technology, and problem solving.
  18. Most Motivating or Exciting Aspects
    The most motivating part of the internship was being trusted to contribute to real
    work. There is a major difference between completing an assignment for a grade and
    knowing that the information you are working on is connected to an actual
    organization and its projects. That responsibility motivated me to take my work
    seriously and pay closer attention to details.
    I was also excited by the variety of projects. Working on CMMC, quality
    initiatives, databases, documentation, and underwater data center research meant that I
    was constantly learning something new. The underwater data center project was
    especially interesting because it connected cybersecurity with technology,
    engineering, data, and environmental challenges. It made me realize that cybersecurity
    can be involved in innovative projects that I would not have expected when I first
    chose the major.
    Another motivating aspect was seeing experienced professionals work. Glenn and
    Jim helped me understand how professionals approach problems, communicate, and
    make decisions. Watching them gave me a better idea of the type of professional I
    want to become. It also made me appreciate the value of mentorship. I learned that
    sometimes the best way to understand a subject is to watch someone who has been
    working with it for years and then ask questions about why they do things a certain
    way.
    Finally, seeing my own growth was motivating. At the beginning, I was more
    hesitant and unsure. By the end, I was more comfortable asking questions, completing
    tasks, and discussing what I had learned. Knowing that I had developed during the
    internship gave me more confidence in my ability to succeed after graduation.
  19. Most Discouraging Aspects
    The most discouraging part of the internship was realizing how much I still did not
    know. There were times when I was exposed to a new term, process, or project and
    initially felt behind. It can be difficult to compare yourself with experienced
    professionals who have years of knowledge when you are still a college student. I
    sometimes questioned whether I was learning fast enough.
    Another discouraging aspect was that some work was less exciting than the
    projects I was most interested in. Documentation, reviewing information, organizing
    data, and repetitive quality tasks are not always as exciting as working directly with
    technology. However, I eventually realized that these tasks are necessary.
    Cybersecurity involves a lot of careful work that may not look exciting but has a
    major effect on the organization’s security and reliability.
    I also found it difficult when I could not immediately see the final result of a
    project. Some professional projects take time, involve multiple people, or continue
    after an intern’s assignment is finished. In school, you usually submit an assignment
    and receive a grade. At work, a project may continue through several stages. Learning
    to be patient and understand my role within a larger process was part of my
    professional growth.
    Even though these experiences were discouraging at times, they ultimately helped
    me develop a healthier attitude toward learning. I stopped viewing not knowing
    something as a failure. Instead, I started viewing it as a reason to ask questions,
    research the topic, and improve.
  20. Most Challenging Aspects
    The biggest challenge was keeping up with the amount of information I
    encountered. Cybersecurity has a large vocabulary, and CMMC, quality management,
    databases, and emerging technology each have their own terminology. I had to learn
    how to separate what I needed to understand immediately from information that I
    could research later. Taking notes became one of my most useful habits.
    Another challenge was learning to manage my time and priorities. Multiple
    assignments can require attention at the same time, and not every task has the same
    urgency. I had to become better at organizing what needed to be completed first and
    making sure that I did not lose track of smaller responsibilities. This is a skill I know
    will continue to matter throughout my career.
    The professional standard for accuracy was also challenging. In school, a small
    mistake on an assignment may result in losing a few points. In a professional
    environment, a mistake in documentation or information can create additional work or
    affect a larger process. I learned to slow down, review my work, and make sure that I
    understood what I was submitting before considering the task finished.
    The final challenge was becoming comfortable with uncertainty. Not every
    problem has an immediate answer. Sometimes the right response is to research, ask
    someone, test an idea, or wait for more information. I learned that being a professional
    does not mean always having the answer. It means knowing how to find the answer
    and knowing when to ask for help.
  21. Recommendations for Future Interns
    My first recommendation for future interns is to come prepared to learn rather than
    expecting to already know everything. An internship is designed to provide
    experience, so students should not be embarrassed by the fact that they have
    questions. At the same time, interns should make an effort to research topics
    independently before asking for help when appropriate. This shows initiative and
    helps the student learn faster.
    Second, future interns should take notes. There is too much information in a
    professional environment to remember everything after one meeting or conversation.
    Writing down terms, instructions, questions, and follow-up items makes it easier to
    stay organized. I would recommend keeping a running list of unfamiliar concepts and
    researching them after work or when there is time.
    Third, students should strengthen their professional communication before
    beginning. This includes learning how to write professional emails, communicate
    respectfully, ask clear questions, participate in meetings, and explain what they are
    working on. Technical knowledge is important, but communication determines how
    effectively that knowledge can be used with a team.
    Fourth, future interns should review cybersecurity frameworks and basic
    compliance concepts before starting. Students do not need to be experts, but
    understanding concepts such as risk management, access control, policies, procedures,
    evidence, and security controls will make CMMC-related work easier to understand.
    Reviewing the NIST Cybersecurity Framework and learning the basic purpose of
    CMMC would also provide useful background.
    Fifth, future interns should become comfortable with Microsoft Office and general
    data organization. Excel, Word, PowerPoint, databases, spreadsheets, and
    documentation are common parts of professional work. An intern who can organize
    information clearly and produce professional documents will be more useful to a
    team.
    Sixth, future interns should be dependable. Showing up on time, meeting deadlines,
    responding to communication, and following through on assignments may seem basic,
    but these behaviors build trust. Once supervisors know they can depend on an intern,
    they are more likely to give that intern additional responsibilities and opportunities to
    learn.
    Finally, I would recommend that future interns take advantage of the people around
    them. Experienced coworkers are one of the most valuable resources available during
    an internship. Ask questions, listen to their experiences, and learn how they approach
    problems. An intern should leave with more than completed assignments; they should
    leave with a better understanding of how professionals think and work.
  22. Conclusion
    My internship at ITA International has been one of the most important experiences
    of my college career. I entered the internship wanting to learn what cybersecurity
    looked like in a real workplace, and I left with a much broader understanding of the
    field. I learned that cybersecurity is not only about networks, computers, and attacks.
    It also includes compliance, quality assurance, documentation, risk management, data,
    communication, teamwork, and continuous improvement.
    Working with Glenn Mallo and Jim Stewart gave me the opportunity to learn from
    professionals while developing confidence in my own abilities. I became more
    comfortable asking questions, researching unfamiliar topics, communicating with
    coworkers, and taking responsibility for my assignments. I also learned that being a
    professional does not mean knowing everything. It means being willing to learn, being
    dependable, and taking the initiative to find answers.
    The CMMC projects were especially important because they changed how I
    understand cybersecurity compliance. I learned that meeting cybersecurity
    requirements involves much more than knowing what the requirements say.
    Organizations have to build processes, maintain documentation, collect evidence,
    identify weaknesses, and continuously improve. The quality work reinforced this
    lesson because it showed me how consistency and process improvement support
    security.
    The underwater data center project also had a major impact on me. It showed me
    that cybersecurity can be part of emerging technology and engineering projects. When
    systems combine sensors, networks, data, physical equipment, and remote operations,
    security has to be considered from multiple angles. This experience made me more
    interested in cybersecurity roles that connect technology with analysis, compliance,
    engineering, and problem solving.
    The internship will influence the remainder of my time at Old Dominion University
    because I now have a clearer reason for learning the material in my classes. Topics
    that once seemed like requirements for a degree now have real examples behind them.
    When I study cybersecurity frameworks, risk, networks, databases, or security
    controls, I can connect those subjects to things I have actually seen in a professional
    environment. This will help me approach the rest of my college work with more
    purpose.
    The experience will also influence my professional path after graduation. Before
    the internship, I knew I wanted a career in cybersecurity, but I was less certain about
    the direction. Now I understand that there are many opportunities beyond traditional
    technical security positions. Compliance, governance, risk management, quality, data
    analytics, security assessment, and technology-focused roles are all areas that interest
    me more because of what I experienced at ITA.
    Most importantly, this internship gave me confidence. I started the experience
    wondering whether I knew enough to contribute. By the end, I understood that I have
    a strong foundation and the ability to continue learning. I still have a lot to learn, but I
    no longer see that as a weakness. Cybersecurity is a field where learning never really
    stops. My goal is to continue building my technical skills while also developing the
    communication, professional judgment, and problem-solving abilities that I gained at
    ITA International.
    I am genuinely thankful to ITA International for giving me this opportunity. I
    appreciate Glenn Mallo and Jim Stewart for their guidance and for allowing me to
    experience professional work instead of only learning about it in a classroom. I am
    also thankful to everyone at ITA who made the internship a welcoming learning
    environment. This experience has helped me become more professional, more
    confident, and more aware of what I want from my future career. I will carry the
    lessons from this internship with me through the rest of my time at ODU and into my
    professional life.
    References
    ITA International. (2023, September 12). ITA International announces new
    organizational changes to enhance customer focus. ITA International.
    https://ita-intl.com/ita-international-announces-customer-focus-org-changes/
    ITA International. (2025, July 28). ITA International appraised at CMMI
    Development Maturity Level 3 for the second time. ITA International.
    https://ita-intl.com/
    ITA International. (2026a). ITA International: Operationalizing data to improve the
    world. https://ita-intl.com/
    ITA International. (2026b, January 20). ITA International awarded position on
    Missile Defense Agency SHIELD IDIQ contract. ITA International.
    https://ita-intl.com/ita-international-awarded-position-on-missile-defense-agenc
    y-shield-idiq-contract/
    ITA International. (2026c). ITA Careers. https://ita-intl.com/ita-careers/
    Virginia Business. (2020, August 25). Newport News-based ITA awarded $50M
    contract.
    https://virginiabusiness.com/newport-news-based-ita-awarded-50m-contract/
    Virginia Business. (2025, March 26). Virginia Chamber’s DuVal to lead new ITA
    venture.
    https://virginiabusiness.com/virginia-chambers-duval-to-lead-new-ita-venture/