Group Purchasing
Group Purchasing

Brian Ventura

Principal InstructorPartner at Cyverity

Specialities

Cybersecurity Leadership

Connect with Brian

Brian Ventura

About Brian Ventura

Brian Ventura stands as a respected authority in cybersecurity leadership, serving as Partner at Cyverity and as course author and principal instructor at the SANS Institute. As the author of SEC566: Implementing and Auditing CIS Controls, and an instructor for LDR512: Security Leadership Essentials for Managers, he brings both strategic oversight and practical execution to the classroom.

Brian’s journey began in systems administration installing his first Unix/Linux system while pursuing an undergraduate degree in physics before transitioning to information technology and security. during in the early part of Brian’s career, he worked in information technology and security architecture and audit roles in global, complex environments. Starting in 2001, He worked at a fortune-100 company where he consolidated over 350 DNS and e-mail sub-domains, then pivoted into audit and compliance as Sarbanes-Oxley regulations came online. These formative roles gave him a foundational view of how technology, risk, and governance intersect and this experience shaped the labs and real-world scenarios he designs for the course.

Brian holds key credentials including Certified Information Systems Security Professional (CISSP), 8 GIAC certifications, and serve as a member of GIAC Advisory Board. He is also a faculty member of the SANS Technology Institute (SANS.edu). SANS.edu is designated as an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition. His course contributions span the CIS Controls suite, and his community work includes contributing to the CIS Controls, volunteering with the Oregon Cybersecurity Advisory Council, and publishing a free-to-use GRC management tool based on the NIST Cybersecurity Framework.

What distinguishes Brian in the classroom is his “real-world conversation” style: his labs do not only teach “what” but explore “why” and “how”, helping students translate theory into defensible security programs that speak to senior management. He loves the moment when students say, “that’s the way my organization should be doing this” and walk away confident. Off duty he’s likely pedaling around Portland’s bike paths, cheering on the Portland Thorns and Portland Timbers, or crawling through the wilderness in his Toyota truck, proof that his commitment to continuous movement spans both his career and his hobbies.

Qualifications Summary
  • Partner at Cyverity, an information-security consulting firm specializing in governance, risk and compliance
  • Professional Certifications: Certified Information Systems Security Professional (CISSP)
  • GIAC Certifications:
    • GIAC Defensible Security Architecture (GDSA)
    • GIAC Strategic Planning, Policy, and Leadership (GSTRT)
    • GIAC Security Leadership Certification (GSLC)
    • GIAC Certified Intrusion Analyst (GCIA)
    • GIAC Certified Incident Handler (GCIH)
    • GIAC Security Essentials Certification (GSEC)
    • GIAC Certified Forensic Analyst (GCFA)
    • GIAC Critical Security Controls Certified (GCCC)
  • Key Achievements: Over 30 years of industry experience across systems administration, enterprise architecture, audit/compliance, and security; author of SEC566; contributor to the CIS Controls and volunteer with Oregon State & Local Government cybersecurity programs.
  • Publications and Tools: Volunteer contributor to the CIS Controls; published a GRC management tool aligned with the NIST Cybersecurity Framework; frequent speaker and instructor in cybersecurity leadership and risk programs.
  • Courses
  • Community Contributions: Faculty member at SANS Technology Institute; GIAC Advisory Board member; volunteer on the Oregon Cybersecurity Advisory Council; board member for Portland Community College CIS advisory board; member of local ISSA/OWASP chapters.

Press & Media