Salem, OregonAvailable for advisory engagements

Jared Gross

Cybersecurity & Technology Governance Leader

I help organizations stabilize and lead complex cybersecurity and technology initiatives where execution, governance, and accountability cannot fail.

Professional portrait of Jared Gross
N 44.94°W 123.04°

Led enterprise-scale security, infrastructure, identity, and governance initiatives across Fortune 100, healthcare, and regulated environments — where audit exposure, recovery readiness, and executive visibility cannot drift.

Years leading
15+
Programs delivered
Fortune 100 scale
Frameworks aligned
NIST · CMMC · SOC 2
Portfolio led
$3M+

If an audit, recovery initiative, contract review, or operationally critical program is already under pressure, let's talk before the situation becomes harder to unwind.

Schedule a working session

Experience across

  • Fortune 100
  • Healthcare
  • Public Sector
  • Manufacturing
  • SaaS
  • Gaming Infrastructure

01 — Summary

Executive summary

I lead high-visibility cybersecurity, infrastructure, and governance programs where execution, accountability, and operational resilience matter.

My work sits between executives, engineering teams, operational stakeholders, vendors, and security leadership — translating ambiguity into measurable execution, operational clarity, and resilient delivery.

Recent emphasis

  • 01

    Cyber Resiliency

    Recovery readiness, IRE, tabletops.

  • 02

    AI Governance

    Intake, oversight, NIST CSF alignment.

  • 03

    Cloud Security

    Multi-cloud, control efficacy, audit.

  • 04

    PMO Governance

    Cadence, reporting, portfolio delivery.

02 — Where I work

Programs under pressure

The conditions where I am typically brought in — and the role I play once I'm there.

When I'm brought in

I am typically brought into initiatives where:

  • 01

    Audit or regulatory deadlines are approaching

  • 02

    Operational ownership is fragmented

  • 03

    Executive confidence is low

  • 04

    Delivery has slowed or drifted

  • 05

    Vendors and internal teams are misaligned

  • 06

    Recovery, governance, or resiliency capabilities need operationalization

The role I play

Establish operational clarity. Stabilize execution.

Align stakeholders and create measurable forward movement across leadership, engineering, infrastructure, vendors, and security teams.

Operational clarity

Cut through ambiguity into a working picture leadership can decide from.

Stabilized execution

Restore tempo, accountability, and signal under audit and delivery pressure.

Measurable movement

Tangible progress against the metrics executives and auditors actually care about.

03 — What I deliver

Selected achievements & focus

Programs delivered under audit, compliance, and operational pressure — and the domains where I lead day-to-day.

  • A

    Cyber Resiliency & Recovery

    Led enterprise cyber resiliency and recovery modernization initiatives focused on ransomware recovery readiness, isolated recovery environments, operational resilience governance, and executive tabletop exercises.

  • B

    AI Governance & Cloud Security

    Built and led multimillion-dollar enterprise cloud security and AI governance programs aligned to NIST CSF, CMMC, and SOC 2 — enabling generative AI adoption within governed security and compliance boundaries.

  • C

    PMO Governance Framework

    Built and operationalized a PMO governance framework for Nike's global cloud and security portfolio, standardizing cadence, reporting, and delivery across multi-cloud initiatives.

  • D

    Global WAF Migration

    Directed Nike's global WAF migration to Akamai across 200+ domains, reducing critical vulnerabilities by 40%.

Where I operate

Focus areas

Domains where I lead, advise, and deliver across enterprise and regulated environments.

  • 01Cybersecurity Program Leadership
  • 02Operational Resilience
  • 03Cyber Recovery Governance
  • 04AI Governance & Oversight
  • 05Cloud & Infrastructure Security
  • 06Identity & Access Governance
  • 07Data Protection & DLP
  • 08Cross-Functional Delivery
  • 09Executive Reporting
  • 10Vendor & Third-Party Coordination

04 — Experience

Experience

Selected roles across Fortune 100, healthcare, gaming, and public sector environments.

  1. 01

    Rockwell Automation

    Senior Technical PM — Cybersecurity

    Aug 2025 — PresentRemote

    Lead enterprise cyber resiliency, ransomware recovery readiness, isolated recovery environments, executive tabletops, privileged access modernization, and data protection governance across security, infrastructure, and engineering.

  2. 02

    Resource Data

    Senior Technical Program Manager & Cloud / AI Security Lead

    Aug 2023 — Aug 2025Portland, OR

    Directed a $3M+ cloud security, AI governance, and infrastructure modernization portfolio across enterprise and regulated environments — improving KPI, risk, and roadmap visibility for the C-suite.

  3. 03

    Bungie

    Automation Engineer / Technical PM

    Mar 2022 — Jun 2023Bellevue, WA

    Led security automation and infrastructure modernization for global threat detection. Built and maintained automation in Python, Perl, and PowerShell — saving 500+ engineering hours annually.

  4. 04

    Nike

    PM / Senior Automation Engineer · Cloud & Infrastructure

    Jun 2019 — Sep 2021Beaverton, OR

    Led global automation and security programs impacting $1M+ in operations. Drove enterprise WAF migration to Akamai across 200+ domains, automated certificate lifecycle for compliance readiness, and delivered executive dashboards for delivery, risk, and milestones.

  5. 05

    Nike

    PMO Lead — Strategic IT Projects

    Jul 2018 — Jun 2019Beaverton, OR

    Built and operationalized a PMO governance framework supporting multi-cloud security and infrastructure programs across AWS, Azure, GCP, and Alibaba Cloud — establishing cadence, runbooks, and audit-stable execution.

  6. 06

    Salesforce

    Technical Project Lead — Automation & Security

    Aug 2017 — Jul 2018Indianapolis, IN

    Led security automation projects to reduce manual effort and tighten enterprise controls.

  7. 07

    Oregon Health Authority

    Information Systems Analyst — SecOps

    Dec 2015 — Aug 2017Portland, OR

    Drove SecOps testing, remediation, and response readiness for state-level healthcare systems.

  8. 08

    Army National Guard

    Squad Leader — Combat Engineer

    May 2013 — Apr 2017Dallas, OR

    Led a combat engineer squad executing high-risk missions — discipline, coordination, and operational risk management under pressure.

05 — Representative initiatives

Representative operational initiatives

Sanitized examples of the operational environments and initiatives I lead inside. Detail and additional context available on request.

  • Enterprise Cyber Resiliency & Recovery Modernization

    Led enterprise cyber resiliency and recovery initiatives focused on ransomware recovery readiness, isolated recovery environments, executive tabletop coordination, and operational recovery governance across infrastructure, identity, and security teams.

    The work centered on operationalizing recovery readiness before incidents occurred — aligning leadership, engineering, vendors, and recovery stakeholders around measurable recovery objectives, dependency visibility, and continuity planning.

    Focus areas

    • Operational Resilience
    • Recovery Governance
    • Executive Coordination
    • Incident Readiness
    • Cyber Recovery
  • Global WAF & Infrastructure Security Modernization

    Directed enterprise web application firewall modernization across 200+ domains, improving security posture, reducing critical vulnerabilities, and standardizing operational governance across global infrastructure environments.

    The initiative required coordination across infrastructure, security, engineering, vendors, and operational stakeholders while maintaining service continuity across enterprise-facing platforms.

    Focus areas

    • Cloud Security
    • Infrastructure Governance
    • Risk Reduction
    • Enterprise Coordination
    • Operational Delivery
  • Enterprise Security PMO Governance Framework

    Built and operationalized governance structures supporting multi-cloud security and infrastructure initiatives across AWS, Azure, GCP, and Alibaba Cloud environments.

    Established executive reporting cadence, operational review structures, dependency management workflows, roadmap visibility, and delivery governance supporting audit stability and predictable execution.

    Focus areas

    • PMO Governance
    • Executive Reporting
    • Multi-Cloud Coordination
    • Delivery Stabilization
    • Portfolio Governance
  • AI Governance & Operational Oversight Program

    Led governance and oversight initiatives supporting enterprise AI adoption within regulated and operationally sensitive environments.

    The work focused on governance intake processes, acceptable use guidance, operational oversight, vendor accountability, risk visibility, and alignment to NIST CSF, HIPAA, and enterprise governance expectations.

    Focus areas

    • AI Governance
    • Operational Oversight
    • Vendor Accountability
    • Policy Governance
    • Risk Management
  • Privileged Access & Identity Modernization

    Oversaw privileged access modernization initiatives focused on least-privilege enforcement, endpoint privilege management, service account governance, and operational alignment to Zero Trust principles.

    The initiative improved operational accountability, reduced identity risk exposure, and strengthened governance across engineering, infrastructure, and security operations.

    Focus areas

    • IAM / PAM
    • Zero Trust
    • Identity Governance
    • Operational Security
    • Risk Reduction
  • Healthcare Governance & Audit Readiness Program

    Supported healthcare organizations navigating audit readiness, AI oversight, vendor accountability, operational continuity, and governance alignment across distributed care environments.

    Work included governance assessments, operational risk visibility, AI acceptable use guidance, vendor and BAA accountability review, policy alignment, continuity planning, and operational ownership mapping tied to real-world staffing and care delivery constraints.

    Focus areas

    • Healthcare Governance
    • HIPAA Readiness
    • Vendor Governance
    • Operational Continuity
    • AI Oversight
  • Enterprise Data Protection & DLP Governance

    Coordinated enterprise data protection initiatives focused on DLP governance, sensitive data classification, insider-risk visibility, encryption strategy, and M365 information protection capabilities.

    The work improved operational visibility into sensitive data handling while supporting governance, compliance, and operational risk reduction efforts.

    Focus areas

    • DLP Governance
    • Data Protection
    • Insider Risk
    • Information Governance
    • M365 Security

These are representative operational environments and initiatives — not a complete portfolio. Specifics are sanitized to respect the confidentiality of the organizations involved.

06 — Operating environment

Environments I lead inside.

Technical and operational environments I work across while leading enterprise cybersecurity, resiliency, governance, and transformation initiatives under operational and delivery pressure.

  • Cloud & Infrastructure

    • AWS
    • Azure
    • GCP
    • Alibaba Cloud

    Cloud governance, resiliency planning, and infrastructure modernization across hybrid and multi-cloud environments under enterprise constraints.

  • Security, Identity & Resilience

    • IAM / PAM
    • Zero Trust
    • Operational Resilience
    • Incident Coordination
    • Recovery Readiness
    • Data Protection & Governance

    Program leadership across security modernization, access governance, cyber recovery, and audit-sensitive initiatives where exposure cannot drift.

  • Automation & Engineering

    • Python
    • PowerShell
    • Terraform
    • Jenkins
    • GitHub

    Automation and infrastructure tooling supporting operational scale, governance enforcement, and delivery acceleration across enterprise programs.

  • Observability & Operational Visibility

    • Splunk
    • Datadog

    Operational telemetry, risk visibility, and executive reporting that turn signal into accountable action across distributed environments.

  • Program Delivery & Governance

    • Jira
    • ServiceNow
    • MS Project
    • Smartsheet

    Executive reporting, dependency sequencing, governance cadence, and the operational accountability structures that hold complex programs together.

  • Operating Model

    Programs fail when ownership, sequencing, and operational reality drift apart. My role is to stabilize execution across leadership, engineering, vendors, and operational teams while keeping governance aligned to real delivery constraints.

    Focused on

    • Clarity over noise
    • Measurable progress over theater
    • Sustainable operational cadence
    • Defensible outcomes under pressure

07 — How I operate

The operating posture

A few principles that shape how I lead programs and work with teams.

“Operational resilience is built before it is tested. Everything I lead is shaped by that one idea.”
JGOperating principle
Jared with his daughter outside on a snowy evening
Why this workPacific Northwest

The systems I help protect carry real consequences for real people — patients, families, and communities depending on organizations that have to keep operating, no matter what.

  1. 01

    Calm under pressure.

    Stabilize the room before stabilizing the program. Decisions improve when the operating tempo does.

  2. 02

    Clarity over theater.

    Status reports should describe reality. Reporting that survives audit also survives operations.

  3. 03

    Alignment before acceleration.

    Executives, engineers, vendors, and security all need the same picture before speed creates value.

  4. 04

    Governance built for real conditions.

    Cadence, ownership, and escalation paths designed for outages, audits, and quarter-end — not just kickoff decks.

  5. 05

    Measurable resilience over checkbox activity.

    Recovery readiness, control efficacy, and operational risk reduction — the metrics that hold up when something actually happens.

08 — Advisory practice

The same operating layer, applied independently.

Alongside enterprise program leadership, Jared founded Frontier IT Security — a focused advisory practice helping healthcare organizations stabilize cybersecurity governance, audit readiness, AI oversight, and continuity risk under operational pressure.

Fortune 100 operating discipline, sized for organizations that need executive clarity and resilient delivery without the overhead of a Big-Four engagement.

Advisory focus

  • 01Healthcare cybersecurity governance
  • 02Audit readiness & continuity risk
  • 03AI oversight & vendor accountability
  • 04Operational resilience for mid-market
Visit Frontier IT Security

09 — Contact

Get in touch

For enterprise roles, contract engagements, advisory, or speaking inquiries.

Credentials

Certifications & clearances

Active and prior credentials supporting governance, delivery, and trusted operational work.

  • CISM

    In progress

    Certified Information Security Manager

  • CSM

    Active · Exp. 2027

    Certified ScrumMaster · Scrum Alliance

  • U.S. Army

    Inactive

    Former Secret Security Clearance

Reviewing me for a role or engagement?

Download the current resume for full background and references.

Download Resume