Jon Zeolla
Certified InstructorFounder and CEO at Zenable
Specialities
Cloud Security

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsCloud Security

Jon Zeolla is a SANS Certified Instructor and Founder and CEO of Zenable. He teaches SEC545: GenAI and LLM Application Security and SEC540: Cloud Native Security and DevSecOps Automation, bringing real-world experience in AI safety, cloud-native security, automation, policy as code, and compliance into the classroom. His work helps students connect modern security practices to the developer workflows where security decisions increasingly happen.
Jon’s path into security started early, driven by a competitive streak in video games and a habit of looking for unintended consequences in systems. That curiosity eventually led to vulnerability disclosure work, then to security automation, DevOps, and large-scale analysis of security data across complex environments. He previously worked at Carnegie Mellon University, American Eagle Outfitters, and PNC Bank, where his work spanned cybersecurity-focused data science, automated threat detection and mitigation, governance-aligned controls, and security in regulated environments. He draws on that experience while teaching the labs, helping students connect topics such as AI Governance and Guardrails, CI/CD security, Kubernetes, Infrastructure as Code, policy as code, and automated compliance to the decisions teams face at work.
Jon holds three undergraduate degrees, including a bachelor’s degree in cyber forensics and information security, and certifications including certified information systems security professional, AWS Security Specialty, and multiple GIAC certifications across cloud security automation, Windows security, penetration testing, UNIX system administration, and perimeter protection. Beyond teaching, he builds and shares open-source projects such as AI Native Python, cookiecutter-python, easy_infra, zeek-kafka, goat, and easy_sast, bringing the same guardrails-over-gates mindset to community tools.
Jon teaches by pushing students past labels and into how tools work, where they break down, and how they can be adapted. Students describe him as clear, respectful, thorough with questions, and deeply knowledgeable. Students leave Jon’s class with the knowledge and tools to evaluate AI and cloud-native risks, apply security guardrails in developer workflows, reason through tradeoffs, and build lower-friction paths to secure delivery. Outside work, Jon mountain bikes through the Appalachian hills, lifts weights, and plays chess with his son, which feels about right for someone who likes difficult problems with consequences.
Jon was clear and to the point, happy to answer questions and respectful.
Jon has taken significant time to thoroughly answer questions myself and other classmates have had that have really helped in our understanding. He reminds me a lot of John Strand from back in the day.
Instructor is fantastic. Extremely knowledgeable in the subject matter and has easily answered many complicated questions.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
This session focuses on AI coding guardrails: practical, developer-friendly controls that help teams adopt coding assistants with confidence while maintaining strong security, governance, and assurance.

Manual reviews simply can’t keep pace with AI-generated code. In Part 3, see how agentic AI integrates with GitHub and GitLab to analyze pull requests, deliver structured findings, and provide scalable, consistent code review before and after commit.

AI is transforming DevSecOps. In Part 1 of this series, learn how AI coding agents and MCP extend cloud-native security tooling, configuring DevSecOps tools, policies, and integrations through prompts with live demos of LLM-powered workflows.

Join SANS Instructors AJ Yawn and Zenable Founder/CEO Jon Zeolla as they introduce the core concepts of GRC Engineering and explore how Policy as Code can bridge the gap between regulatory demands and the flexibility required in cloud-native environments.

Traditional compliance and risk management techniques don’t scale in cloud-native environments—manual processes are now an anti-pattern for good security.

Part 3: Continuing the Cloud Security Flight Simulator series, join SEC540: Cloud Native Security and DevSecOps Automation instructor Jon Zeolla for a webcast on software supply chain security.

The Cloud is enabling businesses to quickly adopt and use technology in ways that we've never imagined before. Security teams need to find ways to keep up; automation is the solution.By using Policy as Code tools we can define and enforce security guardrails. This allows developers and cloud engineers to continue shipping features while bringing the confidence to everybody that security requirements are being met.

This is a 2 hour hands-on workshop. Is your company adopting containers but you haven’t had a chance to figure out the best way to secure them yet?

Review relevant educational resources made with contribution from this instructor.