Tony Rossi

Security and GRC leader. Retired Navy Senior Chief. 21 years running cyber operations on nuclear submarines.

I build security and compliance programs from zero, then make them run without me.

CISSP · CISM · CEH · Active TS/SCI · Ph.D. candidate, Cyber Leadership

Leadership Proof

  • 21 yrsleading cyber operations in the U.S. Navy submarine force
  • 4programs built from zero across the Navy, UW, Nutanix, and my own firm
  • 350 → 11STIG review hours after a tool I designed and shipped
  • 4frameworks unified under one SOC 2 program
  • CMMC L2and FOCI remediation delivered for a federal business unit
  • 2companies founded, 1 nonprofit, 1 force-wide policy authored
  • AIES '26paper under review, and serving on the program committee
  • A-listrecovered a hijacked X account for a Hollywood actor

Timeline

  1. Jul 2026 – present

    Member · Seattle GRC Engineering Club

    Built the reproducible document pipeline behind the club's CGE-P certification. 15 documents, deterministic output, vendored fonts.

  2. Jun 2026 – present

    Program Committee Member · AIES 2026 (AAAI/ACM Conference on AI, Ethics, and Society)

    Reviewing for the field's leading AI ethics venue.

  3. Oct 2025 – 2028 (expected)

    Ph.D. Candidate, Cyber Leadership · Capitol Technology University

    Doctoral research on cybersecurity leadership in nonprofits that serve schools, workforce pipelines, and underserved communities.

  4. Mar 2025 – Jun 2026

    Federal Compliance Program Manager · Nutanix

    Owned the federal compliance program for a public company's government business.

    Led CMMC Level 2 readiness. Ran FOCI remediation. Delivered SOC 2 across four frameworks on Drata. Designed and shipped Security Scan Mapper, cutting STIG review from 350+ hours to 11.

  5. Jul 2024 – Jun 2026

    Co-Founder · leveld

    Co-built a candidate-first hiring platform from idea to production.

    Accepted into NVIDIA Inception. Shipped a 15-agent CI/CD pipeline with privacy and accessibility agents holding veto. Designed the ACIE framework: 28 vectors across 4 domains. Lead author on the research paper under review at AIES 2026.

  6. Jan 2024 – Jun 2024

    SMX (classified)

    Supply chain hardware security and nation-state threat investigation.

    Cleared work. Details on request with appropriate authority.

  7. Summer 2023

    Founder · The sIQurity Foundation (501(c)(3))

    K-12 cybersecurity education, run as a nonprofit.

    Founded as CyberSmrt. Teaching kids to defend themselves online before someone else teaches them the hard way.

  8. Apr 2023 – Jan 2024

    Security Lead · University of Washington, Office of Research

    Stood up the office's first security risk function.

    Built the first departmental risk assessment and the first third-party risk management program. Established the baseline the office still runs on.

  9. 2023 – present

    Principal · Tony Rossi Consulting LLC

    Built a GRC, cybersecurity, and privacy practice from a blank page.

    Serves wealth management firms, high net worth individuals, and the defense industrial base. Subcontracts NIST 800-53 assessments through A-LIGN. SAM.gov registered with CAGE code. Engineered the entire delivery stack in-house: encrypted client vault, reporting pipeline, client portal.

  10. Jul 2002 – Aug 2023

    U.S. Navy Submarine Force · Retired as Senior Chief, Senior Cyber Operations Chief

    21 years. Led cyber operations where failure is not a ticket, it's a casualty.

    Rose from enlisted sailor to the senior cyber chief on the boat. Wrote the submarine force's first cybersecurity policy. Led teams, trained sailors, owned mission systems at depth with no outside help available. Retired August 31, 2023.

Bio

I lead security the way I learned it on submarines: own the outcome, train the people, build the system so it holds when you're asleep.

I grew up in the inner city with no direction. My father dropped out of high school. My mother graduated, and that was as far as anyone in the house got. I fought. I skipped school. I got suspended for both. I repeated 10th grade because I barely showed up for the first one. The only reason I didn't drop out was the rule at home: you drop out, you move out.

In study hall I saw a man in uniform and had no idea what he did. He was a Navy recruiter. My friends had graduated a year ahead of me, and I watched them sink their money and their time into college with no clue what they actually wanted. That wasn't for me. I joined the Navy with a loose understanding of what that even meant.

I spent 21 years in the submarine force and retired as a Senior Chief, the senior cyber operations chief on the boat. I wrote the force's first cybersecurity policy. Then I went into industry and found the same problem everywhere. Compliance programs built from spreadsheets and hope, run by people who were never given the authority to fix them.

So I fixed them. At the University of Washington I stood up a risk function from nothing. At SMX I did cleared work on supply chain hardware and nation-state threats. At Nutanix I owned federal compliance for a public company: CMMC Level 2, FOCI, SOC 2 across four frameworks. When STIG review was eating 350 hours a cycle, I built the tool that brought it to 11.

Now I run my own practice and I'm looking for the room where the security program is either broken or doesn't exist yet. That's where I'm useful. I build the program, hire and train the team, put the controls in code, and hand leadership a function that reports on itself.

I hold an active TS/SCI and CISSP, CISM, and CEH. I'm a Ph.D. candidate in Cyber Leadership. I co-founded a hiring platform and a nonprofit that teaches kids cybersecurity. I have a paper under review at AIES 2026 and I sit on its program committee. I live in Poulsbo, Washington.

Straight edge. Tattooed. DIY. I'd rather build it than buy it, and I'd rather tell you the truth than tell you what you want to hear.

Built

  • Security Scan Mapper. STIG review: 350 hours to 11. Shipped inside a public company.
  • Federal compliance program, Nutanix. CMMC L2, FOCI, SOC 2 x4 frameworks.
  • UW Office of Research risk function. First risk assessment, first TPRM.
  • Tony Rossi Consulting delivery stack. LUKS2 + YubiKey client vault, WeasyPrint report pipeline, Cloudflare Workers/Pages/D1/R2 client portal.
  • evd. Compliance evidence engine. In development.
  • leveld. Candidate-first hiring. 15-agent CI/CD, ACIE framework, AI coaching.
  • CGE-P document pipeline. Reproducible builds for the GRC Engineering Club's certification.
  • indee.music. DIY venue discovery. Early stage.

Credentials

CISSP · CISM · CEH · Active TS/SCI · Ph.D. candidate, Capitol Technology University · AIES 2026 Program Committee · SAM.gov registered (NAICS 541512) · Seattle GRC Engineering Club

Contact

Ready to talk about a Director or VP role, or a program that needs rebuilding.

me [at] tonyrossi [dot] dev

linkedin.com/in/tonyrossi-grc Poulsbo, WA