Enterprise security governance

Jason R.
Hall

Security Governance & Compliance Engineer

Bridging business objectives and technology with security, governance, and risk strategies that build trust, strengthen resilience, and drive results.

Jason R. Hall
Lewisburg, WV · Remote-ready

Governance engineered for outcomes

Security · Risk · Compliance

Enterprise impact

Operational rigor.
Measurable outcomes.

Truist Financial Capital One Northrop Grumman

20+

years in information technology

15+

years in cybersecurity

120+

enterprise security baselines governed

80+

automated compliance policies

~73% → ~92%

enterprise configuration compliance

Representative outcomes from enterprise security configuration governance work; values are approximate where indicated.

What I bring

Security controls should create confidence—not friction.

I work at the intersection of engineering, governance, risk, and operations. My focus is turning complex requirements into practical systems: clear standards, automated validation, accountable remediation, useful evidence, and trusted reporting.

The result is security that teams can operate, leaders can understand, and auditors can verify.

Core expertise

From requirements
to repeatable outcomes.

Connecting control intent with engineering reality across complex enterprise environments.

01

Security governance

Translate policy, regulatory obligations, and risk objectives into controls teams can implement, measure, and sustain.

02

Compliance automation

Replace manual point-in-time checks with repeatable validation, continuous monitoring, and decision-ready reporting.

03

Remediation enablement

Connect findings to accountable owners, practical guidance, risk-based priorities, and measurable closure paths.

04

Audit readiness

Build evidence and governance routines that make control effectiveness visible before an examination begins.

05

Cloud security

Apply secure configuration and compliance governance across AWS, Azure, hybrid, and on-premises environments.

06

Technical-to-business translation

Turn complex security realities into clear choices, aligned stakeholders, and outcomes leaders can act on.

Career progression

Built from operations.
Scaled through governance.

Two decades of progressively broader responsibility across infrastructure, security engineering, compliance automation, and enterprise governance.

2025 — Present

Independent Security Engineering Research

Research · Professional Development · Framework Design

Developing practical approaches for security governance, compliance operationalization, AI risk management, and AI-assisted security workflows.

  • Security Governance Framework
  • Enterprise Cybersecurity Reference Model
  • NIST AI RMF
2020 — 2025

Truist Financial

Cloud Security Engineer → Manager, SCM → Senior Cybersecurity Engineer

Led and operationalized enterprise security configuration governance across cloud, hybrid, and on-premises environments in a highly regulated financial institution.

  • 120+ governed baselines
  • 80+ automated policies
  • FFIEC and NYDFS support
2012 — 2020

Capital One

Cyber Security Engineer

Built secure configuration standards, compliance validation, reporting, automation, and emerging-technology governance for enterprise platforms and cloud services.

  • Database and big-data security
  • AWS governance
  • Custom reporting and automation
2008 — 2012

Northrop Grumman Information Systems

Windows Systems Administrator · GCSS-Army

Supported mission-critical Department of Defense systems through secure configuration, DISA STIG compliance, vulnerability remediation, and audit readiness.

  • Secure configuration
  • DISA STIGs
  • Mission readiness
2004 — 2008

Technical foundation: systems administration, endpoint engineering, networking, identity and access administration, and enterprise support.

Current research

Designing the next generation of operational security governance.

SGF

Security Governance Framework

A practical model for connecting strategy, controls, ownership, evidence, remediation, and continuous improvement.

ECSRM

Enterprise Cybersecurity Reference Model

A systems-level view of the capabilities and relationships required to operationalize cybersecurity at enterprise scale.

AI RMF

AI Governance & Risk

Applying NIST AI RMF concepts and AI-assisted workflows to strengthen accountable, risk-aware security operations.

Education

ECPI University

Bachelor's Degree · Information Technology · 2007

Professional connections

Let's make security
work better.

Open to conversations with recruiters, hiring managers, security leaders, and peers working on complex governance, compliance, remediation, and security engineering challenges.

Lewisburg, West VirginiaRemote-readyUnited States