Salem, OregonOpen to Director of IT & technology leadership roles

Jared Gross

Director of IT | Enterprise Systems, Cloud Infrastructure, Security & Regulated Operations

IT leader helping organizations modernize enterprise systems, stabilize infrastructure, strengthen security, and align technology roadmaps with business outcomes.

Available for Director of IT, Director of Technology, Head of IT, and security-focused technology leadership roles.

Portrait of Jared Gross
N 44.94°W 123.04°

Stabilizing technology operations where business systems, cloud infrastructure, security, and executive decision-making cannot drift.

Years in IT & cyber
10+
Programs delivered
Enterprise scale
Portfolio led
$3M+
Focus areas
IT strategy · Cloud · Security · AI governance

Target roles

  • 01

    Director of IT

    Enterprise systems, infrastructure, service delivery, security, vendor management, and technology roadmaps.

  • 02

    Director of Technology / Head of IT

    Cloud, business applications, IT operations, executive reporting, and regulated technology environments.

  • 03

    Director of Security / Security Program Leader

    Cyber resilience, identity, cloud security, AI governance, audit readiness, and operational risk reduction.

If your organization needs technology leadership that can connect infrastructure, business systems, security, vendors, and executive priorities, let's talk.

If an audit, recovery initiative, contract review, or operationally critical program is already under pressure, let's talk before the situation becomes harder to unwind.

Discuss a role or engagement

Experience across

  • Fortune 500
  • Healthcare
  • Public Sector
  • Manufacturing
  • SaaS
  • Gaming Infrastructure

01 — Summary

Executive summary

I am an IT and enterprise technology leader with 10+ years across infrastructure, cloud, cybersecurity, automation, AI governance, and technical program leadership.

My work focuses on helping organizations stabilize and scale technology operations across enterprise systems, cloud infrastructure, security, service delivery, vendor management, and operational resilience — across Fortune 500, healthcare, public sector, gaming, SaaS, and regulated environments, including Nike, Bungie, Salesforce, Rockwell Automation, Resource Data, Oregon Health Authority, and healthcare advisory work in Oregon.

I am typically brought into environments where technology ownership is fragmented, systems are scaling quickly, risk is unclear, vendors need tighter accountability, or executives need a clearer picture of roadmap, spend, uptime, security, and operational impact. My strength is translating technical complexity into practical business decisions — aligning executives, Finance, Operations, People, Legal, Compliance, engineering, security, infrastructure, and vendors around clear priorities and sustainable operating models.

Recent emphasis

  • 01

    IT Strategy & Enterprise Systems

    Technology roadmaps, business systems governance, ERP-adjacent platforms, HRIS, CRM, finance systems, integrations, and data integrity.

  • 02

    Cloud Infrastructure & IT Operations

    Cloud modernization, infrastructure reliability, service delivery, uptime, operational support, ITSM/ITAM, and user lifecycle governance.

  • 03

    Security, Identity & Resilience

    IAM/PAM, Zero Trust, ransomware readiness, disaster recovery, business continuity, executive tabletops, and recovery governance.

  • 04

    AI Governance & Emerging Technology Risk

    NIST AI RMF, acceptable use policy, LLM oversight, vendor accountability, privacy boundaries, and responsible AI adoption.

02 — Where I work

Technology environments under pressure

The conditions where I am typically brought in — and the role I play once I'm there.

When I'm brought in

I am typically brought into technology environments where:

  • 01

    Business systems are growing faster than the operating model supporting them

  • 02

    Cloud, infrastructure, security, and enterprise applications need clearer ownership

  • 03

    Executives need better visibility into roadmap, spend, risk, and delivery status

  • 04

    Vendors, internal teams, and business stakeholders are misaligned

  • 05

    Service delivery, user lifecycle, licensing, or access governance needs structure

  • 06

    Audit, compliance, recovery, or business continuity expectations are increasing

The role I play

Establish operational clarity. Stabilize execution.

Create a technology roadmap leadership can manage from — aligning executives, Finance, Operations, People, Legal, Compliance, engineering, infrastructure, security, and vendors around the same operating picture.

Operational clarity

Turn fragmented systems, ownership, and risk into a clear picture leaders can make decisions from.

Reliable execution

Restore cadence, accountability, escalation paths, and delivery confidence across IT, security, infrastructure, and vendors.

Business-aligned technology

Connect technology decisions to uptime, cost control, user experience, compliance, resilience, and growth.

03 — What I deliver

Selected achievements & focus

Programs delivered under audit, compliance, and operational pressure — and the domains where I lead day-to-day.

  • A

    AI Governance & Cloud Security

    Built and led enterprise cloud security and AI governance programs aligned to NIST CSF, NIST AI RMF, CMMC, and SOC 2 — enabling responsible adoption of generative AI within regulated environments.

  • B

    Generative AI Policy & Platform Governance

    Developed AI acceptable use policies and governance frameworks supporting healthcare, small, and mid-market organizations adopting Microsoft Copilot, ChatGPT, Claude, and Perplexity.

  • C

    Cyber Resiliency & Recovery Modernization

    Led enterprise cyber resiliency and recovery modernization initiatives focused on ransomware recovery readiness, isolated recovery environments, operational resilience governance, and executive tabletop exercises.

  • D

    Global WAF Migration & PMO Governance

    Directed Nike's global WAF migration to Akamai across 200+ domains — reducing critical vulnerabilities by 40% — and built the PMO governance framework standardizing cadence, reporting, and delivery across the global cloud/security portfolio.

Where I operate

Focus areas

Domains where I lead, advise, and deliver across enterprise and regulated environments.

  • 01AI Governance
  • 02Identity & Access Governance
  • 03Operational Resilience
  • 04Cybersecurity Program Leadership
  • 05Cloud Security
  • 06Generative AI Risk Management
  • 07Recovery Readiness
  • 08Executive Reporting

04 — Experience

Experience

10+ years across IT, infrastructure, cloud, cybersecurity, and AI governance — Fortune 500, healthcare, gaming, public sector, and military environments.

  1. 01

    Frontier IT Security

    Founder | Embedded IT, Security & Governance Leadership

    Jul 2025 — PresentSalem, OR · Remote

    Founded and lead an independent practice providing embedded IT, security, AI governance, and operational resilience leadership for healthcare and regulated organizations. Serve as vCIO/vCISO advisor to the CFO of one of Oregon's largest home health agencies — supporting technology roadmapping, governance, risk prioritization, vendor accountability, and executive decision-making across IT, security, and compliance. Deliver Fortune 500 operating discipline sized for organizations without Big-Four overhead.

  2. 02

    Rockwell Automation

    Senior Technical PM — Cybersecurity (via Experis)

    Sep 2025 — PresentRemote

    Lead enterprise cyber resiliency, ransomware recovery readiness, isolated recovery environments, executive tabletops, privileged access modernization, and data protection governance — coordinating security, infrastructure, engineering, and vendor stakeholders around enterprise risk priorities.

  3. 03

    Resource Data

    Senior Technical Program Manager & Cloud / AI Security Lead

    Aug 2023 — Aug 2025Portland, OR

    Served as acting Director of IT / director-level technology lead, overseeing IT operations, roadmap planning, and delivery coordination across 15 systems engineers, architects, and technical project managers. Directed a $3M+ portfolio across cloud security, application modernization, and enterprise technology governance, and led the migration of critical applications to AWS with zero downtime. As AI Security Lead, drove enterprise AI adoption and platform evaluation (Microsoft Copilot, ChatGPT, Claude, Perplexity) aligned to NIST AI RMF, partnering with Finance, Operations, and IT leadership on risk, spend, compliance, and vendor accountability.

  4. 04

    Bungie

    Automation & AI Engineering Lead

    Mar 2022 — Jun 2023Bellevue, WA

    Led automation and AI-driven security programs supporting global threat detection, infrastructure reliability, and scalable operations. Partnered with executives and technical leaders on automation strategy, investment priorities, and risk reduction. Built Python, Perl, and PowerShell tooling that eliminated 500+ hours of manual work annually, and founded and scaled the Veteran Vanguard ERG to 40+ members.

  5. 05

    Nike

    PM / Engineering Lead — Cloud & Infrastructure Automation

    Jun 2019 — Sep 2021Beaverton, OR

    Led global infrastructure automation and security projects impacting $1M+ in operations. Oversaw a multi-region enterprise WAF rollout across 200+ domains and coordinated a global CDN migration — improving security posture, standardization, resilience, and audit readiness. Delivered automated certificate lifecycle processes and executive KPI dashboards for compliance visibility, risk tracking, and milestone management.

  6. 06

    Nike

    PMO Lead — Strategic IT Projects

    Jul 2018 — Jun 2019Beaverton, OR

    Built and operationalized a PMO governance framework supporting multi-cloud security and infrastructure programs across AWS, Azure, GCP, and Alibaba Cloud — establishing governance standards, delivery cadence, and runbooks supporting audit stability and predictable execution.

  7. 07

    Salesforce

    Technical Project Lead — Automation & Security

    Aug 2017 — Jul 2018Indianapolis, IN

    Automated LDAP, CRL, and network security monitoring, reducing manual workload by 200+ hours annually. Directed KPI dashboard development and cross-team delivery supporting NIST and SOC 2 audit readiness, operational tracking, and leadership visibility.

  8. 08

    Oregon Health Authority

    Information Systems Analyst — SecOps

    Dec 2015 — Aug 2017Portland, OR

    Led penetration testing, vulnerability assessments, remediation coordination, incident response, and security training in a regulated healthcare environment — supporting HIPAA, NIST, and Oregon state compliance mandates across technology and operations stakeholders.

  9. 09

    Army National Guard

    Squad Leader — Combat Engineer

    May 2013 — Apr 2017Dallas, OR

    Led a combat engineer squad executing high-risk missions — discipline, coordination, and operational risk management under pressure.

05 — Representative initiatives

Representative operational initiatives

Sanitized examples of the operational environments and initiatives I lead inside. Detail and additional context available on request.

  • Enterprise Cyber Resiliency & Recovery Modernization

    Led enterprise resiliency initiatives across ransomware recovery readiness, isolated recovery environments, executive tabletop coordination, and operational recovery governance.

    Aligned infrastructure, identity, security, vendors, and leadership around measurable recovery objectives and continuity planning.

    Focus areas

    • Operational Resilience
    • Recovery Governance
    • Executive Coordination
    • Cyber Recovery

    Why it mattered

    Reduced operational uncertainty during recovery planning across infrastructure and security stakeholders.

  • Global WAF & Infrastructure Security Modernization

    Directed enterprise web application firewall modernization across 200+ domains, improving security posture and reducing critical vulnerabilities at global scale.

    Coordinated infrastructure, security, engineering, and vendor stakeholders while protecting service continuity across enterprise-facing platforms.

    Focus areas

    • Cloud Security
    • Infrastructure Governance
    • Risk Reduction
    • Operational Delivery

    Why it mattered

    Standardized security governance across global infrastructure without disrupting enterprise-facing services.

  • Enterprise Security PMO Governance Framework

    Built and operationalized governance structures supporting multi-cloud security and infrastructure initiatives across AWS, Azure, GCP, and Alibaba Cloud.

    Established executive reporting cadence, dependency management, and delivery governance supporting audit stability and predictable execution.

    Focus areas

    • PMO Governance
    • Executive Reporting
    • Multi-Cloud Coordination
    • Portfolio Governance

    Why it mattered

    Improved governance visibility and delivery coordination across large-scale modernization efforts.

  • AI Governance & Operational Oversight Program

    Led oversight initiatives supporting enterprise AI adoption within regulated and operationally sensitive environments.

    Focused on intake processes, acceptable use guidance, vendor accountability, and alignment to NIST CSF, HIPAA, and enterprise governance expectations. Designed intake and evaluation criteria for LLM-based tools — including output quality review, bias considerations, and operational monitoring requirements — enabling teams to adopt generative AI with defensible release criteria.

    Focus areas

    • AI Governance
    • LLM Evaluation
    • Operational Monitoring
    • Vendor Accountability

    Why it mattered

    Established defensible AI oversight where adoption pressure was already outrunning policy.

  • Privileged Access & Identity Modernization

    Oversaw privileged access modernization across least-privilege enforcement, endpoint privilege management, and service account governance.

    Aligned engineering, infrastructure, and security operations to Zero Trust principles and operational accountability standards.

    Focus areas

    • IAM / PAM
    • Zero Trust
    • Identity Governance
    • Risk Reduction

    Why it mattered

    Reduced identity risk exposure while strengthening operational accountability across regulated environments.

  • Healthcare Governance & Audit Readiness Program

    Supported healthcare organizations navigating audit readiness, AI oversight, vendor accountability, and continuity risk across distributed care environments.

    Work spanned governance assessments, BAA review, policy alignment, and operational ownership mapping tied to real staffing and care delivery constraints. Developed AI oversight frameworks for healthcare organizations evaluating Microsoft Copilot, ChatGPT, and similar platforms — including acceptable use policy, vendor accountability, and PHI boundary controls.

    Focus areas

    • Healthcare Governance
    • HIPAA / HITECH
    • HITRUST
    • PHI Boundary Controls

    Why it mattered

    Established operational accountability structures for audit-sensitive healthcare environments.

  • Enterprise Data Protection & DLP Governance

    Coordinated data protection initiatives across DLP governance, sensitive data classification, insider-risk visibility, and M365 information protection.

    Improved operational visibility into sensitive data handling while supporting compliance and operational risk reduction.

    Focus areas

    • DLP Governance
    • Data Protection
    • Insider Risk
    • Information Governance

    Why it mattered

    Brought operational visibility to sensitive data flows previously governed by assumption.

  • Operational Scale

    Programs and environments spanning:

    • Fortune 500 enterprise environments
    • Healthcare and public sector organizations
    • Multi-million-dollar security and infrastructure initiatives
    • Global infrastructure modernization efforts
    • Enterprise recovery and operational resiliency programs
    • Multi-cloud governance across AWS, Azure, GCP, and Alibaba Cloud
    • Cross-functional coordination across executives, engineering, security, operations, and vendors
    • Audit-sensitive and operationally critical delivery environments

These are representative operational environments and initiatives — not a complete portfolio. Specifics are sanitized to respect the confidentiality of the organizations involved.

06 — Operating environment

Environments I lead inside.

Technical and operational environments I work across while leading enterprise cybersecurity, resiliency, governance, and transformation initiatives under operational and delivery pressure.

  • AI Governance & Risk

    • AI Governance
    • Generative AI Risk
    • AI Acceptable Use
    • LLM Evaluation
    • Vendor Risk Review
    • NIST AI RMF
    • Responsible AI Enablement

    AI oversight, acceptable use policy, and operational governance enabling responsible generative AI adoption across healthcare, mid-market, and regulated environments. Platforms evaluated and governed: Microsoft Copilot, ChatGPT, Claude, Perplexity, and Azure OpenAI.

  • Security, Identity & Resilience

    • NIST CSF
    • CMMC
    • SOC 2
    • HIPAA / HITECH
    • HITRUST
    • IAM / PAM
    • Zero Trust
    • Operational Resilience
    • Data Protection
    • DLP Governance

    Program leadership across security modernization, access governance, cyber recovery, and audit-sensitive initiatives where exposure cannot drift.

  • Cloud & Infrastructure

    • AWS
    • Azure
    • GCP
    • Alibaba Cloud
    • Infrastructure Modernization
    • Cloud Security

    Cloud governance, resiliency planning, and infrastructure modernization across hybrid and multi-cloud environments under enterprise constraints.

  • Automation & Engineering

    • Python
    • PowerShell
    • Terraform
    • Jenkins
    • GitHub
    • Splunk
    • Datadog

    Automation, tooling, and operational telemetry supporting governance enforcement, risk visibility, and delivery acceleration across enterprise programs.

  • Program Delivery & Governance

    • Jira
    • ServiceNow
    • MS Project
    • Smartsheet

    Executive reporting, dependency sequencing, governance cadence, and the operational accountability structures that hold complex programs together.

  • Operating Model

    Programs fail when ownership, sequencing, and operational reality drift apart. My role is to stabilize execution across leadership, engineering, vendors, and operational teams while keeping governance aligned to real delivery constraints.

    Focused on

    • Clarity over noise
    • Measurable progress over theater
    • Sustainable operational cadence
    • Defensible outcomes under pressure

Leadership thesis

A senior PM should have gravity.

Engineers bring risks early. Leaders come for the true program picture. Teams trust you when the work gets messy.

That is the work that has shaped how I lead: earning trust, reading the room under pressure, owning the work, following through, and keeping the signal clear.

07 — How I operate

The operating posture

A few principles that shape how I lead programs and work with teams.

“Operational resilience is built before it is tested. Everything I lead is shaped by that one idea.”
JGOperating principle
Jared with his daughter outside on a snowy evening
Why this workPacific Northwest

The systems I help protect carry real consequences for real people — patients, families, and communities depending on organizations that have to keep operating, no matter what.

  1. 01

    Calm under pressure.

    Stabilize the room before stabilizing the program. Decisions improve when the operating tempo does.

  2. 02

    Clarity over theater.

    Status reports should describe reality. Reporting that survives audit also survives operations.

  3. 03

    Alignment before acceleration.

    Executives, engineers, vendors, and security all need the same picture before speed creates value.

  4. 04

    Governance built for real conditions.

    Cadence, ownership, and escalation paths designed for outages, audits, and quarter-end — not just kickoff decks.

  5. 05

    Measurable resilience over checkbox activity.

    Recovery readiness, control efficacy, and operational risk reduction — the metrics that hold up when something actually happens.

08 — Advisory practice

The same operating layer, applied independently.

Alongside enterprise program leadership, Jared founded Frontier IT Security — a focused advisory practice helping healthcare organizations stabilize cybersecurity governance, audit readiness, AI oversight, and continuity risk under operational pressure.

Fortune 500 operating discipline, sized for organizations that need executive clarity and resilient delivery without the overhead of a Big-Four engagement.

Advisory focus

  • 01Healthcare cybersecurity governance
  • 02Audit readiness & continuity risk
  • 03AI oversight & vendor accountability
  • 04Generative AI oversight & LLM acceptable use
  • 05Operational resilience for mid-market
Visit Frontier IT Security

09 — Contact

Get in touch

For enterprise roles, contract engagements, advisory, or speaking inquiries.

Credentials

Certifications & clearances

Active and prior credentials supporting governance, delivery, and trusted operational work.

  • CISM

    In progress

    Certified Information Security Manager

  • CSM

    Active · Exp. 2027

    Certified ScrumMaster · Scrum Alliance

  • U.S. Army

    Inactive

    Former Secret Security Clearance

Reviewing me for a role or engagement?

Download the current resume for full background and references.

Download Resume