Tony Rossi
Security and GRC leader. Retired Navy Senior Chief. 21 years running cyber operations on nuclear submarines.
I build security and compliance programs from zero, then make them run without me.
CISSP · CISM · CEH · Active TS/SCI · Ph.D. candidate, Cyber Leadership
Leadership Proof
- 21 yrsleading cyber operations in the U.S. Navy submarine force
- 7programs built from zero across the Navy, UW, Nutanix, and my own firm
- 350 → 11STIG review hours after a tool I designed and shipped
- 4frameworks unified under one SOC 2 program
- CMMC L2and FOCI remediation delivered for a federal business unit
- 2companies founded, 1 nonprofit, 1 federal contractor registration
- AIES '26paper under review, and serving on the program committee
- A-listrecovered a hijacked X account for a Hollywood actor
Timeline
-
Jul 2026 – present
Member · Seattle GRC Engineering Club
Built the reproducible document pipeline behind the club's CGE-P certification. 15 documents, deterministic output, vendored fonts.
-
Oct 2025 – 2028 (expected)
Ph.D. Candidate, Cyber Leadership · Capitol Technology University
Doctoral research on how security leaders build programs that outlast them.
-
Mar 2025 – Jun 2026
Federal Compliance Program Manager · Nutanix
Owned the federal compliance program for a public company's government business.
Led CMMC Level 2 readiness. Ran FOCI remediation. Delivered SOC 2 across four frameworks on Drata. Designed and shipped Security Scan Mapper, cutting STIG review from 350+ hours to 11.
-
Jul 2024 – Jun 2026
Co-Founder · leveld
Co-built a candidate-first hiring platform from idea to production.
Accepted into NVIDIA Inception. Shipped a 15-agent CI/CD pipeline with privacy and accessibility agents holding veto. Designed the ACIE framework: 28 vectors across 4 domains. Research paper under review at AIES 2026.
-
2026
Program Committee Member · AIES 2026 (AAAI/ACM Conference on AI, Ethics, and Society)
Reviewing for the field's leading AI ethics venue while a paper of my own is under review there.
Serving on the program committee. Separate paper under review as lead author.
-
Jan 2024 – Jun 2024
SMX (classified)
Supply chain hardware security and nation-state threat investigation.
Cleared work. Details on request with appropriate authority.
-
Apr 2023 – Jan 2024
Security Lead · University of Washington, Office of Research
Stood up the office's first security risk function.
Built the first departmental risk assessment and the first third-party risk management program. Established the baseline the office still runs on.
-
Summer 2023
Founder · The sIQurity Foundation (501(c)(3))
K-12 cybersecurity education, run as a nonprofit.
Founded as CyberSmrt. Teaching kids to defend themselves online before someone else teaches them the hard way.
-
2023 – present
Principal · Tony Rossi Consulting LLC
Built a GRC, cybersecurity, and privacy practice from a blank page.
Serves wealth management firms, high net worth individuals, and the defense industrial base. Recovered a hijacked X account for an A-list Hollywood actor. Subcontracts NIST 800-53 assessments through A-LIGN. SAM.gov registered with CAGE code. Pursuing SDVOSB. Engineered the entire delivery stack in-house: encrypted client vault, reporting pipeline, client portal.
-
Jul 2002 – Aug 2023
U.S. Navy Submarine Force · Retired as Senior Chief, Senior Cyber Operations Chief
21 years. Led cyber operations where failure is not a ticket, it's a casualty.
Rose from enlisted sailor to the senior cyber chief on the boat. Wrote the submarine force's first cybersecurity policy. Led teams, trained sailors, owned mission systems at depth with no outside help available. Retired August 31, 2023.
Bio
I lead security the way I learned it on submarines: own the outcome, train the people, build the system so it holds when you're asleep.
I grew up in the inner city with no direction. My father dropped out of high school. My mother graduated, and that was as far as anyone in the house got. I fought. I skipped school. I got suspended for both. I repeated 10th grade because I barely showed up for the first one. The only reason I didn't drop out was the rule at home: you drop out, you move out.
In study hall I saw a man in uniform and had no idea what he did. He was a Navy recruiter. My friends had graduated a year ahead of me, and I watched them sink their money and their time into college with no clue what they actually wanted. That wasn't for me. I joined the Navy with a loose understanding of what that even meant.
I spent 21 years in the submarine force and retired as a Senior Chief, the senior cyber operations chief on the boat. I wrote the force's first cybersecurity policy. Then I went into industry and found the same problem everywhere. Compliance programs built from spreadsheets and hope, run by people who were never given the authority to fix them.
So I fixed them. At the University of Washington I stood up a risk function from nothing. At SMX I did cleared work on supply chain hardware and nation-state threats. At Nutanix I owned federal compliance for a public company: CMMC Level 2, FOCI, SOC 2 across four frameworks. When STIG review was eating 350 hours a cycle, I built the tool that brought it to 11.
Now I run my own practice and I'm looking for the room where the security program is either broken or doesn't exist yet. That's where I'm useful. I build the program, hire and train the team, put the controls in code, and hand leadership a function that reports on itself.
I hold an active TS/SCI and CISSP, CISM, and CEH. I'm a Ph.D. candidate in Cyber Leadership. I co-founded a hiring platform and a nonprofit that teaches kids cybersecurity. I have a paper under review at AIES 2026 and I sit on its program committee. I live in Poulsbo, Washington.
Straight edge. Tattooed. DIY. I'd rather build it than buy it, and I'd rather tell you the truth than tell you what you want to hear.
Built
- Security Scan Mapper. STIG review: 350 hours to 11. Shipped inside a public company.
- Federal compliance program, Nutanix. CMMC L2, FOCI, SOC 2 x4 frameworks.
- UW Office of Research risk function. First risk assessment, first TPRM.
- Tony Rossi Consulting delivery stack. LUKS2 + YubiKey client vault, WeasyPrint report pipeline, Cloudflare Workers/Pages/D1/R2 client portal.
- evd. Compliance evidence engine. In development.
- leveld. Candidate-first hiring. 15-agent CI/CD, ACIE framework, AI coaching.
- CGE-P document pipeline. Reproducible builds for the GRC Engineering Club's certification.
- indee.music. DIY venue discovery. Early stage.
Credentials
CISSP · CISM · CEH · Active TS/SCI · Ph.D. candidate, Capitol Technology University · AIES 2026 Program Committee · SAM.gov registered (NAICS 541512) · Seattle GRC Engineering Club
Contact
Ready to talk about a Director or VP role, or a program that needs rebuilding.
me [at] tonyrossi [dot] devlinkedin.com/in/tonyrossi-grc Poulsbo, WA