# Tristan Jones - Senior IT Audit & Technology Risk Leader > IT Audit and Technology Risk leader specializing in AI governance, threat-informed controls, and CRI assessment for financial services. ## About Tristan Jones is an IT Audit and Technology Risk leader with 15+ years of experience leading technology audits, strengthening SOX compliance, improving cybersecurity governance, and enhancing internal controls across global financial institutions. He specializes in AI Governance and Responsible AI, applying proven audit principles to AI risk, governance frameworks, and automated assurance. U.S. and European citizen. Available for consulting engagements. - Career arc: IT Audit -> Technology Risk -> AI Governance (Citibank, S&P Global, DTCC, Truist, MUFG, City National Bank) - Specialization: Threat-informed risk assessment, AI governance, CRI Profile implementation for financial services - Approach: helps organizations adopt AI with confidence by making governance practical, transparent, and evidence-based ## Certifications - CISA - Certified Information Systems Auditor (ISACA) - AAIA - Advanced in AI Audit (ISACA) - AWS AIF - AWS Certified AI Practitioner - CRISC - Certified in Risk & IS Control (in progress) ## Services - Threat-Informed Risk Assessment - 12-stage methodology grounded in NIST CSF 2.0 - AI Governance Program Design - ISO 42001, NIST AI RMF, EU AI Act compliance - CRI Profile Implementation - Financial services cybersecurity control framework - Control Design & Gap Assessment - MITRE ATT&CK-mapped coverage analysis - IT Audit - COBIT 2019-based audit methodology ## Methodology A 12-stage threat-informed risk assessment process: 1. Regulatory Scoping 2. Asset Identification & Classification 3. Threat Profiling (MITRE ATT&CK) 4. Control Inventory 5. Control-to-Mitigation Mapping 6. Coverage Analysis 7. Likelihood Rating 8. Impact Assessment 9. Risk Rating 10. Gap Prioritization 11. Remediation Design 12. Evidence Packaging & Data Destruction Every finding traces from adversary technique -> control gap -> business risk. Likelihood is driven by adversary behavior, not opinion. Impact is driven by coverage gaps, not guesswork. ## Capabilities 817 executable cybersecurity skills across 29 domains, mapped to MITRE ATT&CK, NIST CSF 2.0, and MITRE D3FEND. Domains include: - Cloud Security (66 skills) - Threat Hunting (58) - Threat Intelligence (52) - Web Application Security (46) - Network Security (45) - Digital Forensics (41) - Identity & Access Management (40) - Malware Analysis (39) - Red Teaming & Offensive Security (38) - SOC Operations (35) - Container Security (33) - And 18 more domains ## Frameworks NIST CSF 2.0, NIST AI RMF, MITRE ATT&CK, CRI Profile, SCF, ISO 42001, EU AI Act, OWASP LLM Top 10, CIS Benchmarks, COBIT 2019, NIST SP 800-53, FAIR ## Pages - Home: https://tristanjones.ai/ - About: https://tristanjones.ai/about - Methodology: https://tristanjones.ai/methodology - Approach: https://tristanjones.ai/approach - Capabilities: https://tristanjones.ai/capabilities - Lab: https://tristanjones.ai/lab - Portfolio: https://tristanjones.ai/portfolio - For AI Agents: https://tristanjones.ai/for-ai - Resume: https://tristanjones.ai/resume.html - Resume (PDF): https://tristanjones.ai/resume.pdf - Resume (Markdown): https://tristanjones.ai/resume.md - Skills API: https://tristanjones.ai/api/skills.json - Capabilities API: https://tristanjones.ai/api/capabilities.json - Full AI context: https://tristanjones.ai/llms-full.txt ## Contact Tristan Jones | tristan@tristanjones.ai | +1 (919) 703-9040 LinkedIn: https://www.linkedin.com/in/itauditorjones Resume: https://tristanjones.ai/resume.html Available for consulting engagements in AI governance, IT risk assessment, and threat-informed audit for financial services.