JONATHAN RAMSEY
Information Security Risk Management Security Governance Program Development Executive Advisory
Fort Worth, TX ***************@*****.*** 210-***-**** U.S. Citizen
CISM SSCP CySA+ Security+ PenTest+ Network+ A+ ITIL Foundations M.S. Cybersecurity & Information Assurance
PROFESSIONAL SUMMARY
Information security risk management leader with 9 years of progressive experience building, maturing, and governing cybersecurity programs across mission-critical and multi-client environments. Proven ability to assess program maturity, develop risk-based security frameworks anchored to the NIST Cybersecurity Framework, establish governance structures, and lead teams through prioritized, phased capability buildouts. Experienced partnering with executive leadership, legal, and business units to define acceptable risk levels, embed security into decision-making, and report on risk posture to senior stakeholders. Deep expertise across NIST CSF, NIST 800-53, ISO 27001, COBIT, ITIL, and HIPAA. U.S. Navy veteran with hands-on team leadership. Actively pursuing CISSP with CISM and SSCP already achieved.
CORE COMPETENCIES
Information Security Program Development Security Governance & Policy Risk Management & Assessment NIST Cybersecurity Framework Security Framework & Control Design Third-Party Risk Management Security Awareness Programs Incident Response & Disaster Recovery Team Leadership & Development Vendor & Contract Oversight Executive & Board Reporting Security Metrics & Maturity Measurement HIPAA & Data Privacy ISO 27001 / NIST 800-53 / COBIT / ITIL Security by Design Risk-Based Prioritization Influence Without Authority
PROFESSIONAL EXPERIENCE
CISO Advisory Analyst Apollo Information Systems March 2025 - Present Fort Worth, TX
•Assess the maturity of client information security programs and lead prioritized, phased capability buildouts, developing risk-based security frameworks, policies, standards, and guidelines anchored to the NIST Cybersecurity Framework for programs not yet established.
•Develop and deliver security governance structures, policy frameworks, and executive reporting mechanisms, presenting program status and risk posture to senior leadership and board-level stakeholders across client organizations.
•Facilitate risk assessment and risk management processes with business units, empowering leaders to own risk decisions within their appetite, identifying shadow IT, and establishing controls with clear ownership.
•Develop unified control frameworks integrating laws, standards, and regulations including NIST CSF, NIST 800-53, ISO 27001, SOC 2, HIPAA, and CIS Controls, establishing metrics and reporting frameworks to measure maturity and effectiveness.
•Lead risk-based third-party risk management activities, evaluating vendor security posture, embedding security requirements into engagements, and ensuring data is processed and stored in compliance with applicable laws and regulations.
•Advise clients on incident response plans, disaster recovery, and business continuity, ensuring plans are in place and executable, and providing guidance on containing and managing information security incidents.
•Design and recommend security awareness training programs, establishing metrics to measure effectiveness and ensuring consistent application of policies and standards across technology projects and services.
•Partner with client architecture and technology teams to integrate security requirements into reference architectures and system designs, advancing security by design principles.
•Monitor the external threat environment and emerging regulatory developments, advising client leadership on emerging risks and appropriate courses of action.
IT Supervisor / Lead Petty Officer U.S. Navy May 2017 - March 2025 Various
•Led the information security function for 1,800 information systems supporting 4,500 sailors and marines, owning security governance, risk management, compliance, and operations across a 24x7 mission-critical environment.
•Managed and developed a 9-person team, with accountability for hiring input, onboarding, performance evaluations, professional development, and establishing consistent security processes across the organization.
•Developed and maintained security policies, standards, governance documentation, and control frameworks, ensuring confidentiality, integrity, availability, and recoverability of information assets.
•Established and enforced security awareness training and culture change initiatives, embedding cyber judgment across decision-making beyond the IT team.
•Managed vendor relationships, technology dependencies, and procurement, ensuring security requirements were reflected in tool deployments and third-party engagements.
•Ensured incident response plans and disaster recovery policies were in place and executable, managing and containing information security incidents to protect IT assets and regulated data.
•Prepared 1,800 information systems for a pre-deployment command inspection achieving 100% compliance across all systems under oversight.
CERTIFICATIONS
ISACA CISM ISC2 SSCP CompTIA CySA+ CompTIA Security+ CompTIA PenTest+ CompTIA Network+ CompTIA A+ ITIL Foundations CISSP (Expected 2026)
EDUCATION
M.S. Cybersecurity & Information Assurance Western Governors University
B.S. Cybersecurity & Information Assurance Western Governors University
TECHNICAL ENVIRONMENT
NIST Cybersecurity Framework NIST 800-53 ISO 27001 COBIT ITIL SOC 2 HIPAA CIS Controls NIST 800-171 Security Governance & Policy Risk Management Frameworks Third-Party Risk Management Security Metrics & Maturity Models Incident Response & DR Security Awareness Programs Azure Microsoft 365 Entra ID / Azure AD Tenable Nessus PingCastle Security Onion (SIEM) Huntress MDR/EDR ServiceNow Excel Risk Reporting & Dashboards GenAI Tools (Claude / ChatGPT)