years in information technology
Enterprise security governance
Jason R.
Hall
Security Governance & Compliance Engineer
Bridging business objectives and technology with security, governance, and risk strategies that build trust, strengthen resilience, and drive results.

Governance engineered for outcomes
Security · Risk · ComplianceEnterprise impact
Operational rigor.
Measurable outcomes.
Truist Financial • Capital One • Northrop Grumman
years in cybersecurity
enterprise security baselines governed
automated compliance policies
enterprise configuration compliance
Representative outcomes from enterprise security configuration governance work; values are approximate where indicated.
What I bring
Security controls should create confidence—not friction.
I work at the intersection of engineering, governance, risk, and operations. My focus is turning complex requirements into practical systems: clear standards, automated validation, accountable remediation, useful evidence, and trusted reporting.
The result is security that teams can operate, leaders can understand, and auditors can verify.
Core expertise
From requirements
to repeatable outcomes.
Connecting control intent with engineering reality across complex enterprise environments.
Security governance
Translate policy, regulatory obligations, and risk objectives into controls teams can implement, measure, and sustain.
Compliance automation
Replace manual point-in-time checks with repeatable validation, continuous monitoring, and decision-ready reporting.
Remediation enablement
Connect findings to accountable owners, practical guidance, risk-based priorities, and measurable closure paths.
Audit readiness
Build evidence and governance routines that make control effectiveness visible before an examination begins.
Cloud security
Apply secure configuration and compliance governance across AWS, Azure, hybrid, and on-premises environments.
Technical-to-business translation
Turn complex security realities into clear choices, aligned stakeholders, and outcomes leaders can act on.
Career progression
Built from operations.
Scaled through governance.
Two decades of progressively broader responsibility across infrastructure, security engineering, compliance automation, and enterprise governance.
Independent Security Engineering Research
Research · Professional Development · Framework Design
Developing practical approaches for security governance, compliance operationalization, AI risk management, and AI-assisted security workflows.
- Security Governance Framework
- Enterprise Cybersecurity Reference Model
- NIST AI RMF
Truist Financial
Cloud Security Engineer → Manager, SCM → Senior Cybersecurity Engineer
Led and operationalized enterprise security configuration governance across cloud, hybrid, and on-premises environments in a highly regulated financial institution.
- 120+ governed baselines
- 80+ automated policies
- FFIEC and NYDFS support
Capital One
Cyber Security Engineer
Built secure configuration standards, compliance validation, reporting, automation, and emerging-technology governance for enterprise platforms and cloud services.
- Database and big-data security
- AWS governance
- Custom reporting and automation
Northrop Grumman Information Systems
Windows Systems Administrator · GCSS-Army
Supported mission-critical Department of Defense systems through secure configuration, DISA STIG compliance, vulnerability remediation, and audit readiness.
- Secure configuration
- DISA STIGs
- Mission readiness
Technical foundation: systems administration, endpoint engineering, networking, identity and access administration, and enterprise support.
Current research
Designing the next generation of operational security governance.
Security Governance Framework
A practical model for connecting strategy, controls, ownership, evidence, remediation, and continuous improvement.
Enterprise Cybersecurity Reference Model
A systems-level view of the capabilities and relationships required to operationalize cybersecurity at enterprise scale.
AI Governance & Risk
Applying NIST AI RMF concepts and AI-assisted workflows to strengthen accountable, risk-aware security operations.
Education
ECPI University
Bachelor's Degree · Information Technology · 2007
Professional connections
Let's make security
work better.
Open to conversations with recruiters, hiring managers, security leaders, and peers working on complex governance, compliance, remediation, and security engineering challenges.