John Edward Norton

About Me

Building solutions that scale โ€” and last.

Cybersecurity Engineer, IC, PM

20+ years of cloud security leadership with 10+ focused on cybersecurity product management. Reduced organizational risk, prevented millions in potential costs, and enhanced compliance through IaC guardrails and policy-as-code.

I've led infrastructure migrations, built zero-downtime deployment pipelines, and architected serverless platforms processing millions of events daily.

"Is Smart. Gets things done."

Work With Me โ†’
๐Ÿšฃ

Rowing

Concept2 RowErg โ€” the ultimate honest machine. No coasting

๐Ÿ“–

Favorite Book

Brave New World by Aldous Huxley โ€” still relevant, still unsettling

๐Ÿช“

Chopping Wood

Wood warms you twice โ€” once when you chop it, and once when you burn it

Career

Current

Owner | Principal Cybersecurity Engineer

As an owner at Integrated Specialty Coverages, LLC (ISC), I bridge the gap between Engineering/IT and Business Leadership.

My focus here is, aligning every security measure with our core mission to protect both our people and our progress.

In this role, I am responsible for building robust enterprise defenses and optimizing operational workflows that accelerate scalable business growth.

2025

Distinguished Cloud Platform Security Engineer

Strategy & Leadership

  • Orchestrated multi-year security roadmaps across SaaS, multi-cloud, and on-prem environments
  • Advised executive leadership on risk decisions that strengthened platform security posture

Scale & Impact

  • Secured 15K+ users and 1.2K+ applications across hybrid cloud environments
  • Architected Zero Trust frameworks with continuous verification across IAM, network, endpoint, and logging

Measurable Results

  • Reduced lateral-movement risk by ~70% across three hybrid environments
  • Improved deployment time by 95% through IaC CI/CD automation
  • Cut audit evidence collection efforts by 70%

Platform & Governance

  • Owned enterprise vulnerability management with 99%+ coverage across all workloads
  • Institutionalized blameless root cause elimination (RCE) across 20+ teams and 400+ members
  • Achieved 40% improvement in remediation consistency and eliminated recurring platform failures

Enablement & Mentorship

  • Built scalable security capabilities replacing ad hoc solutions with repeatable, platform-level controls
  • Produced architecture standards used by 400+ engineers, architects, and auditors
  • Cut security misconfigurations by 40% through standardized controls and onboarding
  • Mentored 8 senior engineers, elevating design quality and technical proficiency
2017

Lead Security Engineer

Program Leadership

  • Led cross-functional security programs across IT, Engineering, Legal, and Compliance
  • Protected 20K+ users, 1.2K+ applications, and 25K+ endpoints globally

Compliance & Hardening

  • Reduced vulnerability exposure by 45% through policy enforcement and system hardening
  • Achieved 99% patch compliance; maintained 100% audit readiness for SOC 2 and ISO 27001

Operations Optimization

  • Improved detection coverage by 35% and MTTR by 40% through incident response optimization
  • Standardized architectural guardrails across six teams, reducing configuration errors by 40%

Visibility & Infrastructure

  • Delivered executive dashboards demonstrating a 30% decrease in critical security incidents
  • Reduced IaC configuration errors by 25% for 1.2K+ applications and services
2016

Senior Security Engineer

  • Managed enterprise endpoint security across 100+ district courts with policy enforcement at scale
  • Built custom IaC pipelines that eliminated manual provisioning and accelerated deployment
  • Led threat hunting and vulnerability management, reducing incident response time by 25%
2011

Security Platform Engineer

  • Modernized endpoint security across 80+ global missions protecting 10K+ users
  • Automated remediation workflows generating ~$100K in annual savings
  • Directed enterprise firewall and NIDS evaluations with adopted recommendations for perimeter controls
2010

Network Systems Engineer | Server Administrator

  • Enforced USCYBERCOM / FedRAMP compliance across thousands of DoD users to secure ATO
  • Integrated SCCM, ePO, NAC, VPN, and patching to secure enterprise platforms
  • Led STIG-based hardening, vulnerability scanning, threat hunting, and network mapping initiatives
2010

George Mason University

Volgenau School of Engineering

B.S. Applied Information Technology

Concentration in Database & Programming

Skills & Proficiency

Cloud & Infrastructure

AWS95%
Terraform / IaC92%
Docker / Kubernetes88%
CI/CD Pipelines90%

Development

Python90%
JavaScript / TypeScript85%
Bash / Shell88%
SQL / DynamoDB82%

Impact by the Numbers

Compliance & Deployment Risk & Effort Reduction
Metric Achievement
Users / Applications Secured 150K+ users  ยท  1.2K+ applications
Deployment Time Improvement
95%
Lateral Movement Risk Reduction
~70%
Audit Effort Reduction
70%
Security Misconfigurations Cut
40%
Patch Compliance
99%
Incident Response MTTR Improvement
40%