Group Purchasing
Group Purchasing

Jonathan Risto

Principal InstructorTechnical Director, Cyber Posture Management Program at Government of Canada

Specialities

Cybersecurity Leadership

Connect with Jonathan

Jonathan Risto

About Jonathan Risto

Jonathan brings 25 years of experience across network design, IP telephony, service development, security, and project management. He is currently the Technical Director for the Cyber Posture Management Program at the Government of Canada, where he conducts cybersecurity research focused on vulnerability management and automated remediation. He is also the Founder and Principal Consultant of ZenzizenSec Inc., advising organizations on scalable security programs, and the author and instructor for LDR516: Strategic Vulnerability and Threat Management. The course focuses on helping leaders build exposure-driven programs that align cyber risk with business priorities.

Jonathan’s career spans more than two decades of engineering, network architecture, and cybersecurity leadership across government and industry. He began his career at Bell Canada, building a foundation in large-scale enterprise environments before moving into government work. He spent three years at the Canadian International Development Agency (CIDA), where he led cybersecurity projects and served as the cyber operations prime. During this time, he conducted forensic investigations and led incident response efforts, working directly on real-world security events across diverse environments. He later joined Defence Research and Development Canada as a Cyber Security Research Engineer, contributing to the development and evaluation of security capabilities in support of national defense.

He holds a master’s degree in information security management from the SANS Technology Institute and a bachelor’s degree in electrical engineering from Queen’s University and is a Licensed Professional Engineer (P.Eng.). He is also a faculty member at the SANS Technology Institute and serves on the Research Committee, where he mentors graduate students in vulnerability management and risk leadership as they complete their degrees and final papers. Beyond teaching, he developed the Vulnerability Management Maturity Model (VMMM) and Continuous Threat Exposure Management Maturity Model (CTEMMM), open-source frameworks that help organizations assess and improve their security posture.

Jonathan’s teaching philosophy centers on practical, achievable progress: he reminds students that “strategic” doesn’t mean “complex”, it means consistent and defensible. His workshops emphasize storytelling with data and building trust through metrics. Students often describe his sessions as “transformative, equal parts technical and executive.” Outside of SANS, Jonathan pursues photography and astronomy, passions that mirror his professional focus: capturing clarity from complexity and seeing risk from new perspectives.

Qualifications Summary
  • Roles and affiliations: Principal Instructor, SANS Institute; Technical Director, Cyber Posture Management Program, Government of Canada, founder and Founder and Principal Consultant of ZenzizenSec Inc.
  • Credentials: Master’s degree in information security management (SANS Technology Institute); bachelor’s degree in electrical engineering (Queen’s University); Licensed Professional Engineer (P.Eng.). 11 GAIC certifications including: GIAC Systems and Network Auditor Certification (GSNA), GIAC Critical Controls Certification (GCCC), GIAC Web Application Penetration Tester (GWAPT), GIAC Law of Data Security & Investigations (GLEG), GIAC Certified Project Manager (GCPM), GIAC Security Essentials (GSEC), GIAC Penetration Tester Certification (GPEN), GIAC Security Leadership (GSLC), GIAC Certified Incident Handler (GCIH), GIAC Assessing and Auditing Wireless Networks (GAWN), and GIAC Certified Forensic Analyst (GCFA)
  • Key achievements: 25+ years of cross-disciplinary experience spanning networks, security operations, research and leadership; Author of LDR516; creator of the VMMM and CTEMMM frameworks.
  • Publications and tools: VMMM Self-Assessment Tool and CTEMMM framework on GitHub; white papers and research through SANS and STI.
  • Courses taught/authored: LDR516: Strategic Vulnerability and Threat Management.
  • Community roles: Faculty member, SANS Technology Institute; conference speaker (SiberX, Blue Team Summit); mentor to cyber leaders and students worldwide.

Press & Media