Jorden Britto

Security Compliance & Risk Leader

CISSP · CCSP · NIST 800-171 & CMMC · AI Governance

10+ years securing regulated environments and building resilient security architectures

Open to new rolesSecurity Compliance / GRC Manager & AI Governance. Remote or Providence/Groton/Boston.
Book a Call

About Me

Cybersecurity leadership across enterprise, regulated, and defense-adjacent environments

Jorden Britto

Securing the Digital Frontier

As Founder of Cyber Security Tech Solutions, I lead a cybersecurity consulting practice focused on practical risk reduction, security assessments, compliance advisory, incident response planning, and AI-enabled security solutions for small and mid-sized organizations.

As a Cybersecurity Compliance Manager at Unisys Corporation, I led enterprise security and compliance initiatives for complex, regulated environments. Supporting the General Dynamics Electric Boat account through Unisys, I focused on risk reduction, vulnerability security governance, and resilient operations.

Earlier, through DXC Technology, I delivered cybersecurity engineering support for the General Dynamics Electric Boat account in a defense-industry setting. This experience strengthened my approach to secure infrastructure, access control, and operational security at scale.

I hold a B.S. in Cybersecurity from Western Governors University and am currently pursuing my Master's degree. My commitment to the security community extends to contributing to the Cloud Security Alliance, where I participate in the TAISE and CCSK v5 working groups.

Beyond compliance, I'm passionate about building security tools and infrastructure. My home lab serves as a testing ground for new technologies, from MISP threat intelligence platforms to honeypot deployments and containerized security solutions. You can explore the full build logs and architecture on my dedicated technical site, jordenbritto.tech.

Download Standard Resume

CISSP Certified

Elite security professional certification

CSA Contributor

TAISE & CCSK v5 working groups

10+ Years

Enterprise security experience

Cloud Expert

AWS, Azure, GCP security

Certifications

Professional certifications demonstrating expertise and commitment to excellence

CISSP

Certified Information Systems Security Professional

ISC2

Nov 2023

CCSP

Certified Cloud Security Professional

ISC2

May 2026

CCSK v5

Certificate of Cloud Security Knowledge (v5)

Cloud Security Alliance

Oct 2024

CCZT

Certificate of Competence in Zero Trust

Cloud Security Alliance

Jun 2024

AWS SAA

AWS Certified Solutions Architect - Associate

Amazon Web Services Training and Certification

Sep 2023

TAISE

Trusted AI Safety Expert (TAISE)

Cloud Security Alliance

Oct 2025

A/AISF

AKYLADE AI Security Foundation (A/AISF)

AKYLADE

Nov 2024

SecurityX

CompTIA SecurityX

CompTIA

Apr 2024

PenTest+

CompTIA PenTest+

CompTIA

May 2025

CySA+

CompTIA Cybersecurity Analyst (CySA+)

CompTIA

Jan 2024

Security+

CompTIA Security+

CompTIA

Jul 2023

eJPT

Junior Penetration Tester (eJPT)

INE

Jan 2025

BTL1

Blue Team Level 1

Security Blue Team

Dec 2024

A/CRMF

AKYLADE Cyber Risk Management Foundation (A/CRMF)

AKYLADE

Oct 2024

A/CCRF

AKYLADE Certified Cyber Resilience Fundamentals (A/CCRF)

AKYLADE

Jan 2026

ITIL 4

ITIL 4 Foundation

PeopleCert

Nov 2023

Industry Contributions

Recognized participation in Cloud Security Alliance research and professional community initiatives

Cloud Security Alliance

Trusted AI Safety Expert

TAISE Contributors

Listed contributor to CSA's TAISE initiative focused on trusted AI, safety, security, and governance.

View Contribution
Cloud Security Alliance

Cloud Security Knowledge

CCSK v5 Contributors

Listed contributor to CSA's CCSK v5 body of knowledge supporting cloud security education and standards.

View Contribution

Projects

Security tools and infrastructure I've built to solve real-world challenges

SecBaseline Suite

Compliance engineering suite for explaining STIG and CIS findings, crosswalking controls, validating OSCAL, and drafting RMF-ready System Security Plans.

DISA STIGCIS BenchmarksNIST 800-53OSCAL+4

AIBOM Studio

AI governance workspace for building audit-ready AI Bills of Materials aligned to major security, risk, and compliance frameworks.

AI GovernanceAI Bill of MaterialsNIST AI RMFISO/IEC 42001+4

Phishing Sonar

AI-powered phishing email analyzer that produces forensic-style verdicts, threat indicators, and exportable IOCs from suspicious email content.

ReactTailwind CSSSupabaseAnthropic Claude API+4

POA&M Tracker

Federal RMF-focused POA&M management platform for tracking findings, milestones, remediation status, and continuous monitoring outputs.

POA&M ManagementRMFNIST 800-53Continuous Monitoring+4

AttackBranch

AI-assisted threat modeling platform that generates STRIDE models, attack trees, and prioritized mitigations from architecture descriptions.

Threat ModelingSTRIDEAttack TreesMITRE ATT&CK+4

Mark My Words

AI-powered web application that analyzes Terms of Service (ToS) and Privacy Policies for privacy and security concerns.

React 19Node.jsOpenAI APIVercel+2

BumpInTheLog

AI-assisted log investigation tool that turns raw security logs into chronological incident narratives, anomaly findings, and prioritized analyst pivots.

Log AnalysisSOC InvestigationIncident ResponseMITRE ATT&CK+4

CyberBrief HQ

Cybersecurity briefing platform delivering concise threat intelligence, vulnerability watch, and compliance-aware risk updates for security teams and executives.

Threat IntelligenceCVE AnalysisCompliance ResearchSecurity News+2

Home Lab & Technical Work

Self-hosted security lab and infrastructure — SIEM/EDR, threat intel feeds, honeypots, firewalls, and containerized services. Full build logs and architecture live on the dedicated technical site.

Wazuh SIEMMISPpfSenseHoneypots+2

Skills & Expertise

Technical competencies developed over a decade of security work

Security & Compliance

Core

SIEM/SOAR
EDR/XDR
Threat Intelligence
Vulnerability Management
Incident Response
Risk Assessment
Security Auditing
Compliance (HIPAA, SOC2)

Cloud & Infrastructure

Core

AWS
Azure
Docker
VMware
Linux Administration

Working knowledge

Google Cloud
Kubernetes
Terraform

Security Tools

Core

Tenable / Tenable SC
Nessus
IBM QRadar
Splunk
CrowdStrike
Carbon Black
Wazuh

Working knowledge

Burp Suite

Networking

Core

pfSense
Wireshark
Firewalls
VPN
IDS/IPS
Network Segmentation
Load Balancing
DNS/DHCP

Development & Scripting

Core

Python
Bash/Shell
PowerShell
REST APIs
Git
Automation

Working knowledge

SQL
CI/CD

AI Engineering

Core

Prompt Engineering
LLM Application Design
AI Security & Governance
API Integration
AI Risk Assessment

Working knowledge

RAG Systems
AI Agent Workflows
Model Evaluation

Frameworks & Standards

Core

NIST 800-53
NIST 800-171
CMMC
FedRAMP
DFARS
SOX
GDPR
GLBA
ISO 27001
CIS Controls/Benchmarks
STIGs
Core
Working knowledge

Experience

A decade of progressive responsibility in IT and cybersecurity

Founder & Principal Consultant

Cyber Security Tech Solutions

Self-Employed | Cyber Security Industry

Current
Jan 2025 - Present
Pawtucket, RI

Founded and lead a cybersecurity consulting firm delivering security strategy, technical risk reduction, and compliance-aligned advisory services for small and mid-sized organizations.

  • Lead security assessments and vulnerability testing to identify, prioritize, and remediate high-impact risk
  • Advise clients on network security architecture, control hardening, and secure configuration baselines
  • Develop incident response plans, playbooks, and tabletop exercises to improve operational readiness

Cybersecurity Compliance Manager

Unisys Corporation

Client Environment: General Dynamics Electric Boat (DoD supplier account)

Nov 2020 - Feb 2026
Remote

Supported the General Dynamics Electric Boat account in a defense-industry environment through Unisys, leading cybersecurity compliance, risk, and enterprise security operations.

  • Led enterprise vulnerability management and endpoint defense operations using Tenable (Nessus/Tenable SC), SEP, and Carbon Black, maintaining 95% scan coverage and 98% update compliance
  • Drove compliance alignment to NIST 800-53/171, DFARS, SOX, and CMMC through recurring audits, risk assessments, control validation, and remediation governance
  • Delivered biweekly vulnerability and risk presentations to CIO, CISO, and audit stakeholders, accelerating remediation prioritization and executive decision-making

Cybersecurity Engineer

DXC Technology

Client Environment: General Dynamics Electric Boat (Defense-Industry Account Support)

Jun 2018 - Nov 2020
Rhode Island

Delivered cybersecurity engineering and infrastructure support for the General Dynamics Electric Boat account through DXC Technology in a regulated defense-industry environment.

  • Executed patch management, vulnerability scanning, and remediation coordination for enterprise endpoints
  • Implemented PowerShell automation, VPN security controls, and NAC support for secure access
  • Supported endpoint protection, mobile device management, and security auditing activities

Cyber Security Analyst

CharterCare Health Partners
Mar 2016 - Jun 2018
Rhode Island

Supported cybersecurity analysis, secure access operations, and endpoint controls for a healthcare organization.

  • Supported endpoint, server, and clinical application security in HIPAA-regulated healthcare environment
  • Managed Active Directory, Group Policy, and user access controls to enforce secure access practices
  • Reviewed security events, access issues, and EMR application risks, coordinating remediation with IT and clinical stakeholders

System Administrator

Med Tech Ambulance Services
Sep 2013 - Mar 2016
Rhode Island

Managed IT infrastructure and systems for emergency medical services provider.

  • Administered Windows servers and workstations fleet-wide
  • Maintained CAD and dispatch systems critical to operations
  • Implemented backup and disaster recovery solutions

IT Administrator

Northeast Direct Marketing
Nov 2006 - Sep 2013
Rhode Island

Responsible for all IT operations and infrastructure management.

  • Built and maintained IT infrastructure from ground up
  • Managed Windows domain, Exchange, and file servers
  • Implemented network security and access controls

Get in Touch

Interested in collaborating or have questions? I'd love to hear from you.

Prefer email? jorden.britto@linux.com

Still have security questions? Ask our Security Advisor