About

Tristan Jones

Senior IT Auditor specializing in AI risk assessment, threat-informed controls, and governance frameworks for financial services. 15+ years spanning infrastructure, audit, and risk advisory.

Career Arc

From building systems to auditing them to governing AI that augments the work.

2010 — 2016

IT Management

Built and managed enterprise IT infrastructure — servers, databases, networks, and end-user systems. Hands-on with the full technology stack before moving to the audit side.

2016 — 2022

IT Audit

Transitioned to IT audit under ISACA COBIT methodology. Designed and executed audits for enterprise systems, access controls, change management, and data integrity.

2022 — Present

IT Risk & AI Governance

Specialized in threat-informed risk assessment, AI governance, and CRI Profile implementation for financial services. Building a governed AI workforce for audit automation.

What Sets This Apart

01

Technical Depth

I built servers and databases before I audited them. When I assess a control, I understand the system underneath it — not just the policy document.

02

Threat-Informed

Every assessment starts with the threat landscape, not the compliance checklist. Controls exist to mitigate specific adversary behaviors — MITRE ATT&CK is the map.

03

AI-Augmented

A governed AI workforce handles repetitive analysis while I focus on judgment. Same rigor I apply to client controls, I apply to my own AI agents.

Certifications

Active and in-progress credentials.

CISA

Active

Certified Information Systems Auditor

ISACA

AAIA

Active

Advanced in AI Audit

ISACA

AWS AIF

Active

AWS Certified AI Practitioner

AWS

CRISC

In Progress

Certified in Risk & IS Control

ISACA

AAIR

In Progress

Advanced in AI Risk

ISACA