AeroLeads people directory · profile

Brian Ruf, Cissp, Ccsp, Pmp Email & Phone Number

Cybersecurity Automation Strategist and Solution Architect at Ruf Risk
Location: Mclean, Virginia, United States 15 work roles 2 schools
1 work email found @easydynamics.com 3 phones found area 703 LinkedIn matched
✓ Verified July 2026 4 data sources Profile completeness 100%

Contact Signals · 1 work email · 3 phones

Work email b****@easydynamics.com
Direct phone (703) ***-****
LinkedIn Profile matched
3 free lookups remaining · No credit card
Current company
Role
Cybersecurity Automation Strategist and Solution Architect
Location
Mclean, Virginia, United States
Company size

Who is Brian Ruf, Cissp, Ccsp, Pmp? Overview

A concise factual answer block for searchers comparing this professional profile.

Quick answer

Brian Ruf, Cissp, Ccsp, Pmp is listed as Cybersecurity Automation Strategist and Solution Architect at Ruf Risk, a with 1 employees, based in Mclean, Virginia, United States. AeroLeads shows a work email signal at easydynamics.com, phone signal with area code 703, and a matched LinkedIn profile for Brian Ruf, Cissp, Ccsp, Pmp.

Brian Ruf, Cissp, Ccsp, Pmp previously worked as Owner / Consultant at Ruf Risk and Director Of Cybersecurity at Easy Dynamics Corp. Brian Ruf, Cissp, Ccsp, Pmp holds Bs, Information Science from Stockton University.

Company email context

Email format at Ruf Risk

This section adds company-level context without repeating Brian Ruf, Cissp, Ccsp, Pmp's masked contact details.

*@easydynamics.com
68% confidence

AeroLeads found 1 current-domain work email signal for Brian Ruf, Cissp, Ccsp, Pmp. Compare company email patterns before reaching out.

Profile bio

About Brian Ruf, Cissp, Ccsp, Pmp

Co-Creator of the NIST OSCAL Specification and the OSCAL REST OpenAPI Specification.An excellent balance of leadership qualities, strategic vision, realistic execution, strong interpersonal skills, collaboration, information sharing, sound fiscal-based and mission-based decision-making. Possesses a broad expert-level understanding of IT, cyber security, compliance, quality management, and process improvement. Proven ability to enable business/mission success and reduce risk.Successful IT and cybersecurity projects for federal, pharmaceutical, medical, telecommunication and financial industries. Projects include modernization and security of our nation's air traffic control systems, IT Security Architect for Customs and Border Protection, Booz Allen Hamilton, and the Nuclear Regulatory Commission (NRC), and process improvement activities for the FedRAMP PMO. Federal customers include DOL, EPA, FBI, USPS, DOC, USDA, ED, DOD, DHS, and inter-agency PMOs.Specialties include: FedRAMP Compliance, Assessments, Adjudication, and Continuous MonitoringOpen Security Controls Assessment Language (OSCAL)Holistic IT ManagementCompliance FrameworksSecurity FrameworksEnterprise IT/Security ArchitectureCloud/Virtualization StrategiesISO-9001, SE-CMM, Process ImprovementRisk Management and ComplianceSystem Development Life Cycle (SDLC) Methodologies, including AgileRecords and Information ManagementInformation Life Cycle Management

Listed skills include Security, Enterprise Architecture, Information Assurance, Integration, and 46 others.

Current workplace

Brian Ruf, Cissp, Ccsp, Pmp's current company

Company context helps verify the profile and gives searchers a useful next step.

Ruf Risk
Ruf Risk
Cybersecurity Automation Strategist and Solution Architect
Aldie, VA, US
Website
Employees
1
AeroLeads page
15 roles

Brian Ruf, Cissp, Ccsp, Pmp work experience

A career timeline built from the work history available for this profile.

Cybersecurity Automation Strategist And Solution Architect

Aldie, Va, Us

Owner / Consultant

Current

Founder. Providing independent consulting, proposal support and training for organizations seeking to know more or adopt OSCAL as a basis for cybersecurity automation, continuous authorization to operate (cATO) and continuous monitoring.Clients include the FedRAMP PMO, government contractors and OSCAL tool developers.

Sep 2024 - Present

Director Of Cybersecurity

Mclean, Virginia, Us

Leading efforts to create cyber-automation and continuous authorization (cATO) capabilities based on the Open Security Controls Assessment Language (OSCAL). Led and co-created the OSCAL REST OpenAPI specification. Coordinate and co-host Mid-Atlantic OSCAL Community Meetup events.Co-chair Multi-Cloud Security Public Working Group (MCSPWG), enabling best practices for securing complex cloud solutions involving multiple service providers and multiple clouds.

Jul 2022 - Sep 2024

Sbg Trust & Compliance / Public Sector Manager

San Jose, Ca, Us

Managed a team of experts to achieve and maintain compliance with US public sector frameworks, including FedRAMP, FISMA, StateRAMP, CMMC, and NIST SP 800-171. The team provides subject matter expertise, thought leadership, continuous monitoring leadership, and assessment facilitation to the portfolio of systems operated by Cisco's Security Business Group (SBG), including Umbrella, CloudLock, and Duo.

Dec 2021 - Jun 2022

Umbrella Fedramp Lead

San Jose, Ca, Us

Planned and coordinated the execution of Cisco's efforts to achieve FedRAMP authorization for Cisco Umbrella services.

Mar 2021 - Dec 2021

Fedramp Automation Lead / Nist Oscal Architect

Reston, Va, Us

Led efforts on behalf of the FedRAMP PMO to enhance the FedRAMP experience for CSPs, 3PAOs, and Agencies, as well as for the PMO and JAB through process improvements, and refinement of documents and standards. Also lead efforts to enhance existing tools and implement new tools that reduce effort for stakeholders while simultaneously increasing effectiveness of FedRAMP outcomes. Simultaneously supported NIST's efforts on behalf of FedRAMP to develop the Open Security Controls Assessment Language (OSCAL). Designed and led the development of OSCAL-based FedRAMP automation capabilities, which will simultaneously expedite and increase the accuracy of FedRAMP authorization activities. Authored the SSP, SAP, SAR, and POA&M OSCAL Syntax, as well as the FedRAMP Guides to OSCAL adoption.

May 2017 - Feb 2021

Fedramp Authorization Lead

Reston, Va, Us

Returned to Noblis and the FedRAMP PMO after a brief stint with Blackboard. Facilitate and ensure the integrity of the process cloud service providers must follow to achieve a FedRAMP JAB P-ATO. Improve the experience for CSPs and 3PAOs through continuous process improvements. Lead an effort to better automate the information gathering and validation throughout the FedRAMP life-cycle.

Aug 2015 - May 2017

Cyber Security Architect/Program Manager

Reston, Virginia, Us

Provided winning proposal support to cyber-security RFP responses in the FedCiv, DoD and financial markets. Provided Enterprise Risk Management thought leadership to NRC, including an ERM Blueprint for the agency based on the NIST Risk Management Framework (RMF). Managed cyber security projects for a million-member credit union, including efforts that ensured compliance with PCI, GLBA and similar requirements. Managed and mentored staff supporting DHS US CERT.Successfully led a five-business group project to develop a portfolio of cyber solutions that provided CACI with a competitive suite of capabilities related to VMware-based cloud deployment, security, virtualization, and the enablement of mobile devices for Federal clients. This resulted in an immediate return on investment in the form of new business.

Aug 2010 - Jul 2015

Records & Info. Mgt. (Rim) Manager

Mclean, Va, Us

Led firm-wide RIM policy, processes and guidance activities enabling more efficient and complete compliance. Defined and executed strategic plan. Managed staff and contractors. Achieved success where several previous managers could not. Formed Information Management Committee, bringing together stove-piped information management across the firm’s Global Operations (GO) Team.

Feb 2008 - Aug 2010

Application Portfolio Manager

Mclean, Va, Us

Managed the firm’s IT project portfolio. Lead internal offices in the definition, prioritization and planning of IT requirements as part of annual strategy, budget development, and project execution cycle, including an effort to support the Business Assurance Office in the development of their three-year IT strategy in alignment with their business strategy.

Mar 2007 - Feb 2008

It Security Architect

Mclean, Va, Us

Defined, established and communicated strategies and standards based on regulatory and business drivers, market analysis, and stakeholder interaction. Managed firm’s IT & IS policies. Standardized policy management, including template development and process for policy modification. Shaped the firm’s Stage Gate Review Board (SGRB).Developed Concept of Operations for IT Standards Board. Assessed & reported on firm-wide information sharing responsibilities and risks, which formed the foundation for a firm-wide multi-million dollar remediation initiative.

Jan 2005 - Mar 2007

Program Manager/Security Architect

Reston, Virginia, Us

Commercial Information Assurance (IA) Program Manager (6/2003 – 1/2005): Led and managed all commercial IA customers, including a Fortune 50 company. Full fiscal and managerial responsibilities. Final internal approving authority for all technical efforts and customer deliverables. Emphasis on development and implementation of enterprise security programs, policies, and processes, as well as security assessment activities.IT Security Architect for the Bureau of Customs and Border Protection (8/2001 – 11/2003): Developed CBP IT security strategies and architectural process, linked to enterprise security requirements with emphasis on standards and reuse. Designed a tool to enforce same, and supervised development.Assisted in the Systems Engineering Capability Maturity Model (SE-CMM) 2+ Certification of the CBP Infrastructure Services Division (ISD).ISO-9001 Certification Oversight (9/2003 – 1/2005, Collateral Duty): Led and managed the CACI Information Assurance Division (IAD) to achieve initial ISO-9001 certification for two key processes (Achieved 6/2004). Managed ongoing efforts to maintain process compliance and develop additional processes for semi-annual certification activities.

Aug 2001 - Jan 2005

Information Assurance Lead/Deputy Technical Lead

Falls Church, Va, Us

Provided thought leadership, strategy, and project leadership for a congressionally funded program to modernize the US export licensing process. Developed fully compliant Security Program Plan for the Pension and Welfare Benefits Administration (PWBA). The plan later served as the example and template for similar efforts in the Department of Labor (DoL).Designed and coordinated implementation of SRA's first Information Assurance Lab. Managed and coordinated vulnerability assessment activities for several customers, often involving both sub-contractors and internal staff.

Jul 2000 - Aug 2001

Infrastructure And Security Lead

Faa

Washington, Dc, Us

Coordinated policy and procedure development, security training and awareness, risk assessment and mitigation activities, and various technical projects involving heterogeneous platforms for a new generation of air traffic control systems. Lead critical aspects of the first FAA-wide computer security incident response capability. Included internal coordination, vendor and contractor management, and financial management.Planned, implemented and supported infrastructure conversion, IT standards, end-user support mechanisms, and interconnectivity projects as a Network Engineer and Administrator. Designed and implemented enhancements to air traffic control systems, involving cross platform development and data conversion, interconnectivity, and remote support.

Jan 1990 - Jul 2000

Independent Consultant

Self

Supported the IT needs of small businesses in Southern NJ. Most active customers included a multi-location medical practice, a concrete supply company, a commercial collection agency, and a law office.Developed point-of-sale software in 1988 that was still in use over 25 years later. Developed collection management software. Installed networks and servers. Provided on-site and remote support. Provided guidance on strategic vision, managed vendors, and ensured successful migration from legacy systems. As the Internet became popular, expanded to Internet marketing, web site development, and web-to-office integration.

Jun 1988 - Jul 2000
2 education records

Brian Ruf, Cissp, Ccsp, Pmp education

Bs, Information Science

Stockton University

Electrical Engineering

Virginia Tech
FAQ

Frequently asked questions about Brian Ruf, Cissp, Ccsp, Pmp

Quick answers generated from the profile data available on this page.

What company does Brian Ruf, Cissp, Ccsp, Pmp work for?

Brian Ruf, Cissp, Ccsp, Pmp works for Ruf Risk.

What is Brian Ruf, Cissp, Ccsp, Pmp's role at Ruf Risk?

Brian Ruf, Cissp, Ccsp, Pmp is listed as Cybersecurity Automation Strategist and Solution Architect at Ruf Risk.

What is Brian Ruf, Cissp, Ccsp, Pmp's email address?

AeroLeads has found 1 work email signal at @easydynamics.com for Brian Ruf, Cissp, Ccsp, Pmp at Ruf Risk.

What is Brian Ruf, Cissp, Ccsp, Pmp's phone number?

AeroLeads has found 3 phone signal(s) with area code 703 for Brian Ruf, Cissp, Ccsp, Pmp at Ruf Risk.

Where is Brian Ruf, Cissp, Ccsp, Pmp based?

Brian Ruf, Cissp, Ccsp, Pmp is based in Mclean, Virginia, United States while working with Ruf Risk.

What companies has Brian Ruf, Cissp, Ccsp, Pmp worked for?

Brian Ruf, Cissp, Ccsp, Pmp has worked for Ruf Risk, Easy Dynamics Corp, Cisco, Noblis, and Caci Inc. - Federal.

How can I contact Brian Ruf, Cissp, Ccsp, Pmp?

You can use AeroLeads to view verified contact signals for Brian Ruf, Cissp, Ccsp, Pmp at Ruf Risk, including work email, phone, and LinkedIn data when available.

What schools did Brian Ruf, Cissp, Ccsp, Pmp attend?

Brian Ruf, Cissp, Ccsp, Pmp holds Bs, Information Science from Stockton University.

What skills is Brian Ruf, Cissp, Ccsp, Pmp known for?

Brian Ruf, Cissp, Ccsp, Pmp is listed with skills including Security, Enterprise Architecture, Information Assurance, Integration, Program Management, Information Technology, Information Security, and Sdlc.

Find 750M verified contacts

Search by job title, company, industry, location, and seniority. Export verified B2B contact data when you need it.