💡 Jerod Brennen

💡 Jerod Brennen 💡 Jerod Brennen is an influencer

Cybersecurity Executive | AI Governance & Enterprise Risk | Board Advisory | CISSP | 25 Years Translating Risk into Business Strategy

Columbus, Ohio Metropolitan Area
31K followers 500+ connections

About

Security executives who influence revenue sit at a different table than those who manage compliance checklists. I've spent 25 years earning a seat at both.

I've built and led security programs for organizations ranging from 10 employees to 50,000 employees across healthcare, financial services, manufacturing, retail, higher education, technology, and private equity. I architected the first PCI compliance program for Abercrombie and Fitch, protecting $4 billion in annual revenue. At The Ohio State University, I directed a third-party risk program covering over 100 vendors.

Today I advise boards and executive teams on cybersecurity program maturity, risk quantification, and AI governance. My clients operate in multiple industries, manage over $4.5 billion in combined revenue, and earn customer trust via NIST CSF, ISO/IEC 27001, and SOC 2 Type 2 audits while meeting regulatory requirements from CCPA, COPPA, FERPA, GDPR, and HIPAA/HITECH.

Core areas of expertise: Strategic Risk Management, AI Governance and Shadow AI Auditing, GRC Program Development, Board-Level Risk Communication, Security Program Optimization, Identity and Access Management, Application Security (DevSecOps)

#Cybersecurity #InformationSecurity #AI #Leadership #CISO

Services

Courses by 💡 Jerod

See all courses

Articles by 💡 Jerod

Activity

Experience

  • SideChannel

    SideChannel

    4 years 3 months

    • SideChannel Graphic

      VP, Cybersecurity Advisor

      SideChannel

      - Present 7 months

      Delivering executive advisory services for mid-market and enterprise clients. Responsible for translating 25 years of operational data into strategic 'Business Alignment' frameworks. Driving internal product development to create scalable, revenue-generating security solutions.

    • SideChannel Graphic

      vCISO

      SideChannel

      - Present 3 years 7 months

      Columbus, Ohio Metropolitan Area

      Serving as the fractional Chief Information Security Officer for multiple organizations. Directing capital allocation for security budgets, overseeing GRC roadmaps, and presenting 'State of Risk' reports to client Boards of Directors. Focus areas include Security Program Optimization, Incident Response Planning and Compliance/Regulatory Defensibility.

      In my time at SideChannel, I've provided (and continue to provide) vCISO services for clients in the following industries:

      ->…

      Serving as the fractional Chief Information Security Officer for multiple organizations. Directing capital allocation for security budgets, overseeing GRC roadmaps, and presenting 'State of Risk' reports to client Boards of Directors. Focus areas include Security Program Optimization, Incident Response Planning and Compliance/Regulatory Defensibility.

      In my time at SideChannel, I've provided (and continue to provide) vCISO services for clients in the following industries:

      -> Biotechnology
      -> Business/Productivity Software
      -> Data Analytics
      -> Educational Technology
      -> Healthcare Technology
      -> Higher Education
      -> Industrial Manufacturing
      -> Philanthropy & Social Impact (Nonprofit)
      -> Private Equity

    • SideChannel Graphic

      VP, Cybersecurity Services

      SideChannel

      - 1 year 3 months

      Remote

      While I'm still serving as a vCISO for multiple clients, I'm taking on the additional responsibility of supporting the executive leadership team in expanding our service offerings, helping to grow SideChannel's business while providing even more business value to our clients.

    • SideChannel Graphic

      vCISO

      SideChannel

      - 9 months

      At SideChannel, I serve as the virtual Chief Information Security Officer (vCISO) for multiple clients across a variety of industries.

      So who is SideChannel?

      SideChannel protects mid-market to enterprise organizations with cutting-edge cybersecurity technology and services. Our Enclave patented microsegmentation technology isolates critical systems by creating secure, software-defined networks that reduce attack surfaces without requiring complex infrastructure changes. With rapid…

      At SideChannel, I serve as the virtual Chief Information Security Officer (vCISO) for multiple clients across a variety of industries.

      So who is SideChannel?

      SideChannel protects mid-market to enterprise organizations with cutting-edge cybersecurity technology and services. Our Enclave patented microsegmentation technology isolates critical systems by creating secure, software-defined networks that reduce attack surfaces without requiring complex infrastructure changes. With rapid deployment and granular access controls, Enclave strengthens security and limits lateral movement.

      Our vCISO services provide hands-on leadership expertise, offering tailored risk assessments, compliance guidance, incident response planning, and security program development. By combining advanced technology with real world expertise, SideChannel defends organizations against evolving cyber threats with scalable, more cost-effective solutions than our competitors.

      You can learn more about how SideChannel can help your organization at https://sidechannel.com/

  • LinkedIn Graphic

    LinkedIn Learning - Online Instructor

    LinkedIn

    - Present 7 years 8 months

    Columbus, Ohio Area

    LinkedIn has provided me with an amazing opportunity to develop and deliver cybersecurity courses for learners all around the globe.

    You can visit my instructor profile for courses on cybersecurity fundamentals, application security, ethics, soft skills, and even prepare for certs like the CRISC and the CSSLP.

    And if you want to take one of my courses for free, all you need to do is ask! 😉

    ➡️ Author and instruct multiple courses for the LinkedIn Learning platform…

    LinkedIn has provided me with an amazing opportunity to develop and deliver cybersecurity courses for learners all around the globe.

    You can visit my instructor profile for courses on cybersecurity fundamentals, application security, ethics, soft skills, and even prepare for certs like the CRISC and the CSSLP.

    And if you want to take one of my courses for free, all you need to do is ask! 😉

    ➡️ Author and instruct multiple courses for the LinkedIn Learning platform, educating hundreds of thousands of global learners on critical cybersecurity topics.

    ➡️ Develop expert curricula on cybersecurity fundamentals, application security, ethics, and certification prep for the CRISC and CSSLP.

  • Brennen Consulting Graphic

    Founder & Principal Consultant

    Brennen Consulting

    - Present 7 years 4 months

    Columbus, Ohio Area

  • SafeGuard Cyber Graphic

    Cybersecurity Strategy & Solutions Advisor

    SafeGuard Cyber

    - 8 months

    Columbus, Ohio Metropolitan Area

    Turns out that clients really appreciate the advisory work I do, and moving to SafeGuard Cyber allowed me to continue serving in that advisor role by helping organizations understand how to embrace collaboration technologies while getting ahead of security and compliance risks that might disrupt their business.

    At SafeGuard Cyber, I provided clients with insights into these risks, and I offered both business and technical advice regarding how their organizations might best manage these…

    Turns out that clients really appreciate the advisory work I do, and moving to SafeGuard Cyber allowed me to continue serving in that advisor role by helping organizations understand how to embrace collaboration technologies while getting ahead of security and compliance risks that might disrupt their business.

    At SafeGuard Cyber, I provided clients with insights into these risks, and I offered both business and technical advice regarding how their organizations might best manage these risks.

    The best part is that I was still able to bring my deep business and technical knowledge to bear by having those conversations with everyone from entry level security analysts to C-level executives.

  • SailPoint Graphic

    Identity Strategy & Solutions Advisor

    SailPoint

    - 2 years 2 months

    Columbus, Ohio Area

    As I continued to move forward in my cybersecurity career, it became clear that working with SailPoint would be a win-win situation.

    At SailPoint, I was able to develop and deliver Identity Governance and Administration (IGA) program maturity assessments, helping organizations understand how to organize and implement an IGA program.

    I was also able to consult with clients on IGA architecture by conducting client-facing meetings, and I was actively engaged in a variety of marketing…

    As I continued to move forward in my cybersecurity career, it became clear that working with SailPoint would be a win-win situation.

    At SailPoint, I was able to develop and deliver Identity Governance and Administration (IGA) program maturity assessments, helping organizations understand how to organize and implement an IGA program.

    I was also able to consult with clients on IGA architecture by conducting client-facing meetings, and I was actively engaged in a variety of marketing and business development activities.

    ➡️ Orchestrated and delivered comprehensive Identity Governance & Administration (IGA) program maturity assessments for enterprise clients.

    ➡️ Served as a subject matter expert on IGA architecture, consulting with clients to design and implement robust, scalable identity programs.

  • The Ohio State University

    The Ohio State University

    5 years

    • The Ohio State University Graphic

      Guest Lecturer

      The Ohio State University

      - 3 years 7 months

      Columbus, Ohio Area

      OSU provided me with multiple opportunities to share what I've learned in my career with students, faculty, and employees alike.

      I delivered a lecture on cybersecurity, risk management, and privacy topics in October 2016 and a lecture on security awareness training in April 2019 and April 2020.

      I have a hunch they appreciate my insights, because they keep inviting me back to participate in their Herding Cybercats course for aspiring cybersecurity professionals

    • The Ohio State University Graphic

      Associate Director

      The Ohio State University

      - 1 year 10 months

      Columbus, Ohio Area

      At OSU, I managed a team of information security analysts and senior security analysts. We performed IT risk assessments of third party technology service providers, provided security consulting services for internal projects, and drove university-wide security initiatives.

      ➡️ Directed a team of security analysts and engineers responsible for the university's third-party vendor risk management program.

      ➡️ Instituted a formal risk assessment process for dozens of technology service…

      At OSU, I managed a team of information security analysts and senior security analysts. We performed IT risk assessments of third party technology service providers, provided security consulting services for internal projects, and drove university-wide security initiatives.

      ➡️ Directed a team of security analysts and engineers responsible for the university's third-party vendor risk management program.

      ➡️ Instituted a formal risk assessment process for dozens of technology service providers, significantly reducing the university's third-party risk exposure.

      ➡️ Facilitated interdepartmental risk management meetings, aligning security initiatives between the central IT team and university departments.

  • One Identity Graphic

    Security Solutions Architect

    One Identity

    - 1 year 5 months

    Columbus, Ohio Area

    Having spent years in both enterprise and consulting roles, I wanted to apply that knowledge and experience at a technology company.

    At One Identity, I developed and delivered Identity and Access Management (IAM) program maturity assessments, helping organizations understand how to organize an IAM program.

    I consulted with clients on IAM architecture (governance, access management, privilege management), conducted client-facing meetings, and actively engaged in a variety of…

    Having spent years in both enterprise and consulting roles, I wanted to apply that knowledge and experience at a technology company.

    At One Identity, I developed and delivered Identity and Access Management (IAM) program maturity assessments, helping organizations understand how to organize an IAM program.

    I consulted with clients on IAM architecture (governance, access management, privilege management), conducted client-facing meetings, and actively engaged in a variety of marketing and business development activities. I provided similar consulting to our service delivery partners as well.

  • Information Security Instructor

    MIS Training Institute

    - 6 years

    All over the world

    MISTI (now ACI Learning) provided me with the opportunity to teach hundreds of cybersecurity and IT audit learners all over the world. I continue to develop course material and deliver training on a wide variety of topics, including:

    -> Mobile Computing Security
    -> Mobile Banking Security
    -> Vulnerability Management
    -> Penetration Testing
    -> Wireless Networking Security
    -> Web Application Security
    -> Security Incident Response
    -> In-Depth…

    MISTI (now ACI Learning) provided me with the opportunity to teach hundreds of cybersecurity and IT audit learners all over the world. I continue to develop course material and deliver training on a wide variety of topics, including:

    -> Mobile Computing Security
    -> Mobile Banking Security
    -> Vulnerability Management
    -> Penetration Testing
    -> Wireless Networking Security
    -> Web Application Security
    -> Security Incident Response
    -> In-Depth Technical Auditing
    -> Information Security Program Management
    -> Third Party Security Risk Management
    -> Open Source Intelligence Gathering

  • GBQ Partners Graphic

    Security Architect

    GBQ Partners

    - 1 year 1 month

    Columbus, Ohio Area

    Jacadis was acquired by GBQ Partners, which gave me an opportunity to return to consulting for a more expansive group of clients.

    At GBQ, I designed and delivered a variety of professional service engagements. I conducted risk/security/compliance assessments, workshops, & penetration tests, and I both drafted & delivered client-facing reports once those engagements were complete.

    I conducted numerous client-facing meetings, everything from pre-sales to engagement kick-off to…

    Jacadis was acquired by GBQ Partners, which gave me an opportunity to return to consulting for a more expansive group of clients.

    At GBQ, I designed and delivered a variety of professional service engagements. I conducted risk/security/compliance assessments, workshops, & penetration tests, and I both drafted & delivered client-facing reports once those engagements were complete.

    I conducted numerous client-facing meetings, everything from pre-sales to engagement kick-off to report delivery, while also conducting marketing and business development activities.

  • Harrison College Graphic

    Adjunct Instructor for Dual Enrollment

    Harrison College

    - 4 months

    Columbus, Ohio Area

    I had the opportunity to teach the course "Ethics in IT" to a class of dual enrollment high school seniors. It was an absolutely fantastic experience, and it laid the foundation for the ethics courses I've contributed to the LinkedIn Learning library.

  • Chief Technical Officer & Principal Security Consultant

    Jacadis

    - 4 years 4 months

    Columbus, Ohio Area

    With roughly a decade of enterprise experience under my belt, I made a move into consulting.

    At Jacadis, I designed and delivered a variety of professional service engagements. I conducted risk/security/compliance assessments, workshops, & penetration tests, and I both drafted & delivered client-facing reports once those engagements were complete.

    I conducted numerous client-facing meetings, everything from pre-sales to engagement kick-off to report delivery, while also conducting…

    With roughly a decade of enterprise experience under my belt, I made a move into consulting.

    At Jacadis, I designed and delivered a variety of professional service engagements. I conducted risk/security/compliance assessments, workshops, & penetration tests, and I both drafted & delivered client-facing reports once those engagements were complete.

    I conducted numerous client-facing meetings, everything from pre-sales to engagement kick-off to report delivery, while also conducting marketing and business development activities.

  • Abercrombie & Fitch Graphic

    Manager, Information Security

    Abercrombie & Fitch

    - 4 years 3 months

    Columbus, Ohio Area

    Founded the enterprise GRC function for a global retailer. Delivered multiple successful Reports on Compliance (ROC) for PCI DSS, effectively securing revenue streams against regulatory penalties. Managed the P&L for a cross-functional security team.

  • American Electric Power Graphic

    Information Security Specialist

    American Electric Power

    - 5 years 2 months

    Columbus, Ohio Area

    At AEP, I made the transition from IT (EDI administration) to a full-on infosec role.

    I researched security technologies to support our SOX and NERC/FERC compliance efforts. I ultimately deployed and managed a few of those solutions. In addition to the hands-on technical work, I contributed to AEP's information security policy development activities, and I conducted internal security training sessions.

  • Sterling Commerce Graphic

    Solutions Support Specialist

    Sterling Commerce

    - 1 year 5 months

    Columbus, Ohio Area

    This is where I cut my teeth in IT. I perform phone support for Gentran, Sterling's EDI software solution. In this role, I helped customers troubleshoot issues so they could get back up and running, and I documented our internal support procedures to help improve efficiency, effectiveness, and customer satisfaction.

Education

Licenses & Certifications

Volunteer Experience

  • Central Ohio ISSA Graphic

    Director Of Education

    Central Ohio ISSA

    - 1 year 7 months

    Science and Technology

Skills

Publications

  • 30 Day Career Sprint - Becoming a Cybersecurity Analyst

    Independent

    Bridging the Cybersecurity Skills Gap, 30 Days at a Time.

    The hardest part of starting a cybersecurity career isn't the technology. It's knowing what to study and how to prove your skills in an interview. Many entry-level books give you the "what," but few give you the experience and confidence required to land the job.

    With the 30 Day Career Sprint: Becoming a Cybersecurity Analyst, security graybeard Jerod Brennen cuts through the noise, delivering the essential, job-focused…

    Bridging the Cybersecurity Skills Gap, 30 Days at a Time.

    The hardest part of starting a cybersecurity career isn't the technology. It's knowing what to study and how to prove your skills in an interview. Many entry-level books give you the "what," but few give you the experience and confidence required to land the job.

    With the 30 Day Career Sprint: Becoming a Cybersecurity Analyst, security graybeard Jerod Brennen cuts through the noise, delivering the essential, job-focused curriculum you need to turn your ambition into a career. Leveraging his decades of experience as a vCISO and his passion for mentoring, Jerod provides the ultimate daily workout for your future in cybersecurity:

    -> Practical Mastery: Go from zero to fluent in core analyst responsibilities, including Log Analysis, Vulnerability Scanning, and Incident Response.
    -> The Right Tools: Get foundational familiarity with high-demand tools like Nmap and Splunk, plus Python for automation basics.
    -> Career Readiness: Dedicated lessons on Resume Building, Technical Interview Prep, and Professional Networking ensure you can communicate your value.

    Join Jerod on his mission to simplify cybersecurity and empower the next generation of cybersecurity professionals. If you're ready to leave the confusion behind and embark on an efficient, effective path to becoming a Cybersecurity Analyst, the time to start is now.

    Secure your future. Secure your career.

    This is the first release in the Simplifying Cybersecurity series.

    See publication
  • It’s time for a common sense security framework

    Help Net Security

    Privacy Rights Clearinghouse maintains a database of every data breach made public since 2005, and as the total number of records rapidly approaches one billion, board members, infosec leaders, and consumers are all asking the same question: Why does this keep happening?

    This article provides insight into a framework designed to help organizations get back to the information security fundamentals.

    See publication

Honors & Awards

  • Identity Champion

    Identity Defined Security Alliance

    Identity Management Day day is supported by companies and business leaders across a range of industries. Led by the Identity Defined Security Alliance, in partnership with the National Cyber Security Alliance, the IDSA spotlights individuals and organizations who are prioritizing identity management and security. More info at: https://www.idsalliance.org/identity-management-day-champions/

  • Award - Sales Engineering Impact Player of the Year

    SailPoint

  • Article - People to Know in Cybersecurity

    Business First

    https://www.bizjournals.com/columbus/news/2017/12/20/people-to-know-jerod-brennen.html

  • Article - What it takes to be a security architect

    CSO Online

    Featured in an article published on CSO Online. http://www.csoonline.com/article/3194783/it-careers/what-it-takes-to-be-a-security-architect.html

Organizations

  • Electronic Frontier Foundation (EFF)

    -

    - Present
  • (ISC)2

    Member

    - Present
  • Central Ohio ISSA

    Senior Member

    - Present

Recommendations received

View 💡 Jerod’s full profile

  • See who you know in common
  • Get introduced
  • Contact 💡 Jerod directly
Join to view full profile

Other similar profiles

Explore top content on LinkedIn

Find curated posts and insights for relevant topics all in one place.

View top content

Add new skills with these courses