Practitioner. Executive. Speaker.

Jim Nitterauer is a strategic information security executive with over 30 years of experience building and leading enterprise security, IT, and compliance programs. He combines rare technical depth with executive-level communication — the same person who spoke at DEF CON main track is the one who reported quarterly to the board.

At Graylog, Jim delivered four consecutive SOC 2 Type II audits with zero exceptions, reduced corporate tooling spend by 30%, and built an AI security governance framework before regulators required one. He has managed simultaneous SOC 2, ISO 27001, PCI DSS, HIPAA, and SOX audit programs — not sequentially, but concurrently.

He founded and grew one of the first web hosting companies in the Southeast, which gives him a perspective on security from the business owner's side of the table that most security executives don't have.

CISSP#547941 · Since 2016
CISM#1192800 · Since 2019
CredlyVerified Badges
See Jim's Latest Articles & Portfolio

30 years of building things that work.

2025–2026
Sr. Director, Information Security
Graylog, Inc.
  • Led 2025 SOC 2 Type II audit — zero findings
  • Built AI security governance framework for entire organization
  • Deployed Cloudflare Zero Trust + EntraID SSO globally
  • Sustained Microsoft Security Score above 98%
  • Reduced tooling expenditure 30% through vendor consolidation
2022–2024
Director, Information Security
Graylog, Inc.
  • Reported directly to Board of Directors on risk and compliance
  • Three consecutive SOC 2 Type II audits with zero exceptions
  • Reduced IT onboarding from hours to under 10 minutes via automation
  • Deployed CrowdStrike Falcon EDR + 24/7 SOC monitoring
2019–2022
Senior Security Engineer / Acting CISO
Zix | AppRiver
  • Elevated to Acting CISO for 500+ employee organization during OpenText acquisition
  • Managed simultaneous PCI DSS, SOC 2, SOC 2+HITRUST, SOX, ISO 27001 audits
  • Led Enterprise Risk Management program formalization
  • Built Pandemic Preparedness program with board-level briefings
2017–2019
Senior Security Specialist
AppRiver, LLC
  • Managed SecureSurf DNS security platform across 7 global data centers
  • Spoke at DEF CON main track, BSides Las Vegas, DerbyCon, and 10+ conferences
  • Led GDPR compliance effort with 6-person team

15+ conference stages.

DEF CON
2017
DNS Dark Matter & Threat Detection — Main Track
RSA Conference
2023
Corporate Reputation Attacks: Dissecting Job Offer Scams
FBIIC-FSSCC
2023
Corporate Reputation Attack Response
HouSecCon
2023, 2025
Security Tool Sprawl & NIST CSF Alignment
Hackfest CA
2024
Hacker Mindset vs. Business Leadership Mindset
BSides Las Vegas
2016
DNS Security as a Service Provider
BSides Charm
2022
Vendor Risk Management & Third-Party Rating
Graylog GO
2021, 2022
AD DNS Logging; SOAR and Security Ecosystems

Tier-one security media.

RT InsightsJune 2025
Corporate AI Governance Best Practices
Infosecurity MagazineJune 2023
Balancing Cybersecurity Budgets and Risk
CPO MagazineMay 2023
Rebooting Your Cybersecurity Hygiene
Cyber Defense MagazineAug 2022
Everyone Is Part of Security
Security MagazineJune 2022
The Importance of the Human Element of Security
Brilliance Security MagazineJune 2022
Moving Cybersecurity from Cost Center to Revenue Enabler