Benjamin Hobbs
Goodyear, AZ, USA
About Me
I started in cybersecurity (officially) by having a conversation with a classmate that I hadn't seen in almost three decades one summer. Over lunch, he spoke about his networking systems background, working from the command line, and learning to code in Python. I told him that I used to be interested in that stuff a long time ago, but the tech had long since advanced and passed me by...everything was so complex now. He disagreed and encouraged me to check it out, and if I was serious, he had some resources that he could share. I downloaded an app to begin learning Python and took some Udemy classes in Linux. By the end of the year, I had passed a few certification exams and really began to get interested in transitioning to cybersecurity. To my mind, it was something that everyone needed, but not everyone really understands or even knows about it. I felt I could really contribute to the "greater good" and be a part of something bigger than myself (like my military service). I also thought that I was doing good work teaching people about real estate, but this was different...yet, also life-changing, but people NEEDED this; they don't NEED to buy a home. This felt better. More purposeful. I leveraged my GI Bill Benefits to attend a cyber graduate course called Code Fellows where I took their Cybersecurity Engineer program. I learned to code, I learned some common tools, I worked with both AWS and GCP (Google Cloud Platform) services. I learned about working in help desk support (writing tickets, posting evidence, root cause analysis, etc.), blue team operations (Security Operations Centers, Incident Response, Forensics, etc.), and some red team operations (network enumeration and scanning, social engineering, some Kali Linux tooling, etc.). Here at Code Fellows is where I first learned of Governance, Risk, and Compliance (GRC). To be honest, it felt like a bunch of policy drafting/writing, cat herding, and inspections. I didn't think it was in my lane as I really had my fill of policies, "bureaucracies", inspections and broken processes from military service. I went to work for my first company as a Junior Cybersecurity Engineer in an opportunity to stand up an information security program for an organization. What I learned was a lot of what goes into starting an information security program is GRC (analyzing risk, creating structure via policies, and beginning to clarify processes). I was excited to be a part of the process, and I learned a lot. I mapped controls, I drafted over 50 policies for review and approval from leadership. I identified and gathered the screenshot evidence to arrange in our tool (Vanta), and I conducted access review for systems that the org had identified as 'privileged.' I began to maintain and update the company's risk register, be more vocal during audit meetings (both internal and external audits), and even draft additional controls for review and approval by leadership. Understanding that GRC is a process of continual improvement, I studied for, took and passed the CISM exam to better understand the relationship to business goals that an Information Security Program should have. I continued to read articles and trends pointing toward a shift in GRC becoming more technical. So I committed to learning skills to be able to better engineer GRC system solutions in the future. The final thing that I have learned about GRC in my experience is two-fold: First, believe GRC is the conversation that drives information security. Second, though I'm not entirely sure of the reasoning, I observe that there continues to be a disconnect between organizational leadership's valuation of investing in their information security program and the potential differentiation that an appropriately robust information program could provide.
Experience Highlights
- Drafted, implemented, and maintained 7 custom controls for AI security in support of ISO 42001 internal and external audits, resulting in certification in 5 months.
- Performed annual risk assessments and risk treatment plans for the company, leading to the first AI impact assessment for the organization.
- Conducted company’s first self-assessment for cloud security resulting in inclusion to CSA STAR’s Level 1 registry, also leading a process resulting in certification as CSA STAR Level 2 registrant.
- Coordinated the company’s internal audit efforts, to include an external surveillance audit for ISO 27001.
- Served as a subject matter expert on GRC matters to leadership, and lead Vanta administrator.
- Implemented and gathered audit evidence for 81 security controls for SOC 2 Type 2 and ISO 27001 security audits, concurrently resulting in certification in both frameworks in 7 months.
- Documented 35 points in company cloud infrastructure where the monitoring of logs would significantly improve visibility and reduce incident response time.
- Performed and managed periodic security reviews for third-party vendors for due diligence of TPRM.
- Planned and conducted the company's initial tabletop exercise for Disaster Recovery and Incident Response to improve organizational resilience.
- Researched and presented a business case leading to acquisition of Fulcrum’s first SIEM platform.
Get in Touch
DM me on LinkedIn or schedule a meeting with me on Calendly (https://calendly.com/benjamin-s-hobbs/60-min-meeting)
Specializations
Languages & Tools
Frameworks
Certifications
Projects
Built a secure CI/CD pipeline to automate real-time audit-grade evidence gathering, reducing audit prep time by up to 85%. Created secure Cloud IaC using Terraform. Configured artifact signing using Cosign. Automated Security Gates via GitHub Actions (grc-gate workflow) utilizing OPA, Rego, and Conftest. Configured machine-readable documentation via OSCAL.