CYSE 368: Cybersecurity Internship Portfolio
Intern: David Seliquini | Host Organization: Wise Technical Innovations LLC (WTI)
Internship Overview During the Summer of 2026, I completed a 150-hour cybersecurity internship at Wise Technical Innovations LLC (WTI), a Certified Third-Party Assessment Organization (C3PAO) located in Virginia Beach. WTI specializes in helping defense contractors secure their networks to meet the Department of Defense’s strict cybersecurity standards. As a transitioning Navy veteran with 14 years of operational experience, I sought an internship that would bridge the gap between physical risk management and digital compliance.
My primary role was to operate as a Cybersecurity Intern focused on the Cybersecurity Maturity Model Certification (CMMC) framework. During this internship, I successfully completed 90 hours of formal, sponsored training to earn my certificates of completion for both the Certified CMMC Professional (CCP) and Certified CMMC Assessor (CCA) courses. I spent the remainder of my hours in the WTI office assisting the senior assessment team in conducting practical compliance audits. This involved reviewing complex network diagrams, analyzing System Security Plans (SSPs), and verifying objective quality evidence against the 110 security controls mandated by NIST SP 800-171. My work directly supported WTI’s mission of securing the Defense Industrial Base (DIB) against advanced digital threats.
Internship Reflection
Applying Course Knowledge
The foundational technical knowledge I acquired in my ODU coursework proved essential during this internship. Courses like CYSE 250 (Basic Cybersecurity Programming and Networking) allowed me to immediately understand the underlying technology when reviewing complex client network diagrams. I did not have to stop and ask how a subnet or a VPN functioned; I could focus entirely on whether those systems were compliant with federal rules.
While ODU taught me the theoretical application of these tools, the internship showed me how those concepts are strictly enforced in practice. For instance, my coursework covered the principle of “least privilege” in access control. At WTI, I saw this applied practically by auditing active directory group policies to legally prove to the DoD that a contractor was restricting unauthorized administrative access. Moving forward in my career, the governance, risk, and compliance (GRC) methodologies I learned here will be vital. Technical defenses alone are insufficient without the rigorous documentation, policy enforcement, and continuous monitoring concepts required by frameworks like CMMC.
Skill Development
The most significant new skill I developed was mastering the CMMC Assessment Process (CAP) and scoping methodologies. I learned how to analyze a corporate network to identify Contractor Risk Managed Assets (CRMAs) versus Security Protection Assets (SPAs). This requires high-level analytical skills to determine where a secure boundary begins and ends. Furthermore, I developed the ability to read and untangle Shared Responsibility Matrices, which dictate the specific security obligations between a defense contractor and their external cloud service providers (like Microsoft Azure).
In addition to technical auditing skills, my professional communication abilities improved drastically. Because defense contractors are often overwhelmed by the strict rules of NIST SP 800-171, I learned how to communicate highly technical risk assessments to non-technical business owners. I had to learn how to explain why a piece of evidence was insufficient without being adversarial.
Personal Development
Personally, this internship was incredibly validating. I initially worried that my non-traditional background and lack of deep IT experience would hinder my transition out of the military. However, I discovered that the strict procedural compliance and risk management discipline I honed over 14 years in the Navy Submarine Force and the Norfolk Naval Shipyard translates perfectly into digital auditing.
Observing my supervisor, Koren M. Wise, provided an excellent example of leadership under pressure. When the DoD abruptly announced a 60-day suspension of the CMMC Phase Two rollout, Koren maintained a calm, transparent environment. She openly discussed the operational impacts with the team rather than hiding the uncertainty, teaching me how a strong leader manages ambiguity and client expectations during a crisis. Ultimately, this internship solidified my career path. I am now confident in my ability to pursue a role as a federal compliance auditor upon my graduation in 2027.