Tristan Jones
AI governance, technology risk, and audit professional with 15+ years of experience assessing technology controls and designing evidence-based risk methodologies for financial institutions. Develops traceable AI and cybersecurity governance assessments aligned with NIST AI RMF, CRI, NIST 800-53, ISO/IEC 42001, and ISO 27001.
View ResumeCareer Arc
From building systems to auditing them to governing AI that augments the work.
IT Management
Built and managed enterprise IT infrastructure — servers, databases, networks, and end-user systems. Hands-on with the full technology stack before moving to the audit side.
IT Audit
Transitioned to IT audit under ISACA COBIT methodology. Designed and executed audits for enterprise systems, access controls, change management, and data integrity.
IT Risk & AI Governance
Specialized in threat-informed risk assessment, AI governance, and CRI Profile implementation for financial services. Building a governed AI workforce for audit automation.
During a major banking engagement, I recognized that expert advisory work was being crowded out by manual assessment effort. I designed a methodology and supporting platform that compresses the assessment phase so senior practitioners can spend more time interpreting verified gaps, challenging assumptions, and advising leadership on threat-informed risk.
What Sets This Apart
Technical Depth
I built servers and databases before I audited them. When I assess a control, I understand the system underneath it — not just the policy document.
Threat-Informed
Every assessment starts with the threat landscape, not the compliance checklist. Controls exist to mitigate specific adversary behaviors — MITRE ATT&CK is the map.
AI-Augmented
A governed AI workforce handles repetitive analysis while I focus on judgment. Same rigor I apply to client controls, I apply to my own AI agents.
Certifications
Active and in-progress credentials. Click a card to see what it covers.
CISA
Certified Information Systems Auditor
ISACA
AAIA
Advanced in AI Audit
ISACA
AWS AIF
AWS Certified AI Practitioner
AWS
CRISC
Certified in Risk & IS Control
ISACA
Mentors
I owe my level of expertise to these three professionals. Each shaped a different dimension of how I approach risk, audit, and governance work.
Neil Lindholm
View on LinkedIn
Recruited me from IT management and trained me in ISACA COBIT-based audit methodology — the foundation of everything I do.
Satya Vithala
View on LinkedIn
Trained me in MITRE ATT&CK, CRI Profile, and threat-informed risk assessment to meet regulatory requirements.
Vince Werling
View on LinkedIn
Shaped my ability to turn technical analysis into corporate audit deliverables with enterprise impact at S&P Global.