Group Purchasing
Group Purchasing

Jon Zeolla

Certified InstructorFounder and CEO at Zenable

Specialities

Cloud Security

Connect with Jon

Jon Zeolla

About Jon Zeolla

Jon Zeolla is a SANS Certified Instructor and Founder and CEO of Zenable. He teaches SEC545: GenAI and LLM Application Security and SEC540: Cloud Native Security and DevSecOps Automation, bringing real-world experience in AI safety, cloud-native security, automation, policy as code, and compliance into the classroom. His work helps students connect modern security practices to the developer workflows where security decisions increasingly happen.

Jon’s path into security started early, driven by a competitive streak in video games and a habit of looking for unintended consequences in systems. That curiosity eventually led to vulnerability disclosure work, then to security automation, DevOps, and large-scale analysis of security data across complex environments. He previously worked at Carnegie Mellon University, American Eagle Outfitters, and PNC Bank, where his work spanned cybersecurity-focused data science, automated threat detection and mitigation, governance-aligned controls, and security in regulated environments. He draws on that experience while teaching the labs, helping students connect topics such as AI Governance and Guardrails, CI/CD security, Kubernetes, Infrastructure as Code, policy as code, and automated compliance to the decisions teams face at work.

Jon holds three undergraduate degrees, including a bachelor’s degree in cyber forensics and information security, and certifications including certified information systems security professional, AWS Security Specialty, and multiple GIAC certifications across cloud security automation, Windows security, penetration testing, UNIX system administration, and perimeter protection. Beyond teaching, he builds and shares open-source projects such as AI Native Python, cookiecutter-python, easy_infra, zeek-kafka, goat, and easy_sast, bringing the same guardrails-over-gates mindset to community tools.

Jon teaches by pushing students past labels and into how tools work, where they break down, and how they can be adapted. Students describe him as clear, respectful, thorough with questions, and deeply knowledgeable. Students leave Jon’s class with the knowledge and tools to evaluate AI and cloud-native risks, apply security guardrails in developer workflows, reason through tradeoffs, and build lower-friction paths to secure delivery. Outside work, Jon mountain bikes through the Appalachian hills, lifts weights, and plays chess with his son, which feels about right for someone who likes difficult problems with consequences.

Qualifications Summary
  • Bachelor of Science in Cyber Forensics and Information Security; two associate degrees in information technology
  • Key Achievements: Founder and CEO of Zenable; Co-Founder and CTO of Seiso; previously held security engineering roles at Carnegie Mellon University, American Eagle Outfitters, and PNC; recipient of the 2021 Start-Up Innovator of the Year Award for work at Seiso
  • GIAC Certifications: GIAC Cloud Security Automation (GCSA); GIAC Certified Windows Security Administrator (GCWN); GIAC Certified Penetration Tester (GPEN); GIAC Certified UNIX System Administrator (GCUX); GIAC Certified Perimeter Protection Analyst (GPPA)
  • Other Professional Credentials: Certified Information Systems Security Professional (CISSP); AWS Security Specialty; CNCF Ambassador
  • Courses: Instructor for SEC545: GenAI and LLM Application Security and SEC540: Cloud Native Security and DevSecOps Automation
  • Community Contributions: CNCF Ambassador; CNCF TAG-Security member; OpenSSF working group participant; Apache Software Foundation Committer; IANS Faculty member; AWS Community Builder; BSides Pittsburgh organizer; founder of Steel City InfoSec and PittSec

Press & Media

More From Jon

  • AI Native PythonThe AI-Native paved road for Python projects.
  • Cookiecutter-PythonAn example of a secure-by-default paved road project generator.
  • Easy_InfraA docker container to simplify and secure the use of Infrastructure as Code (IaC).
  • Zeek-KafkaA popular plugin for Zeek to send logs to Kafka.
  • Release_monitorA simple Lambda to identify if a specific commit is included in a GitHub release or tag.
  • GoatThis is a GitHub Action that applies Seiso’s policy as code.
  • Easy_sastA product-agnostic docker container to automate the integration with static analysis tools.
  • GitHubVarious hands-on labs covering topics such as password cracking, software defined radios, block cipher cryptography, automotive security, 802.11 security, and security data analysis at scale with open source tools.