James Blocho
NDT/QA Assesor @ MISTRAS Group
About
Open to employment, partnering, or contractual (including fractional) consideration: Cybersecurity professional with over 9 years of experience in IT risk, controls assessment, and compliance across cloud and hybrid environments. Proven expertise in applying PCI-DSS, SOC2, NIST SP800-53, SOX, ISO 27001, and FedRAMP frameworks. Adept at control testing, evidence evaluation, audit coordination, and remediation planning. Holds active Secret Clearance and multiple certifications. In addition, as a consulting generalist with a proven track record driving results across go-to-market strategy, product development/marketing, finance, business development, operations, and strategic planning. My career has spanned diverse sectors and functions—deliberately so. I thrive on solving problems that don’t fit neatly into one box. By drawing from a broader lens, I bring a systems-level understanding of how markets, processes, people, and technologies interact. This versatility enables me to lead cross-functional initiatives, connect strategic dots others miss, and adapt quickly in fast-changing environments— I’ve led initiatives that range from segmenting new markets and building scalable operations to aligning financial planning with GTM strategies and unlocking new revenue opportunities. Whether it’s helping an early-stage company find product-market fit or optimizing enterprise processes, I bring clarity, momentum, and results. My value lies not in knowing one thing deeply—but in knowing how everything fits together. An individual with a penchant for many philosophies, a few of which are summed up best by the quotes below: “Measurement is the first step that leads to control and, eventually, improvement. If you can’t measure something, you can’t understand it. If you can’t understand it, you can’t control it. If you can’t control it, you can’t improve it.” “If you don’t ask the right questions, you don’t get the right answers. A question asked the right way often point to its own answer. Asking questions is the ABC of diagnosis.” I have proven I can be thrown into any situation so far and get on top of it. Whether by industry or role I have worked in Financial Services, Banking, Retail, Ecommerce, SaaS, Chemical Engineering, Emergency Response, Architecture, Construction, Property Management as an individual contributor and/or direct or indirect leader I bring passion and perspective to every team and project I join. Remember, "The skills to get the job are not the same to do the job." And as Paw Patrol says, “no job is too big or small!”
United States
San Francisco
Chemicals
Business Continuity, Security Compliance, Cyber Security Risk, GRC, IT Operations, Information Security Management, Critical Thinking, Problem Solving, Strategic Planning, Agile Methodologies, Microsoft Azure, Amazon Web Services (AWS), Google Cloud Platform (GCP), SharePoint, Strategy, Leadership, Continuous Improvement, Risk Management, Microsoft Excel, Analysis
Experience

NDT/QA Assessor
Benicia, California, United States
Continuous testing/measuring through a series of assessment techniques (PT, UT, MT, RT etc )in order to find vulnerabilities on critical infrastructure Sharing findings, priorities, & remediation options through reports to reduce risks to people, materials, & processes

Operations & Support Section Chief
Oakland, California, United States
State Duty Backfill Role: Responsible for all management functions including: operations, planning, logistics, finance and administration The Operations Section Chief is responsible for developing and implementing strategy and tactics to accomplish the mission objectives. Organizing, assigning, and supervising all the tactical and/or response resources assigned to the institution

Security Compliance Project Manager
San Francisco, California, United States
Facilitated the completion of a previously delayed external audit by identifying & streamlining outstanding tasks that could be while coordinating with key stakeholders to ensure timely closure of other open items. Resolved delays by implementing effective remediation strategies and driving cross-functional collaboration to achieve closure.

Senior Technical Risk Analyst/Delivery Management
Austin, Texas Metropolitan Area
Led planning and migration of over 6000 servers to a multi-cloud environment. Worked with a cross functional team of Resource managers, ITSEC, App Owners, and Executive members to coordinate, discover, communicate, and remediate risks/issues before this transition ie) Corp2Cloud/Data Center Exit initiative Supported the planning & implementation of key security functions (SSO/2FA, DR, IAM, Splunk, etc) & tools related to company security policy, vendor security assessments, and overseeing PenTesting & remediation Personal contributions: Helped drive a 36 month program delay within 3 months of joining team, identified overlap in resource planning (lease extension) that eased perceived time constraints, while also finding $13 million under utilized assets for repurpose within Data Center Exit (DCX) and Corp to Cloud (C2C) programs

GRC Senior Analyst
Walnut Creek, California, United States
"Local payments for global businesses" Yapstone is the payments platform that powers how the world pays Owned the BCPDR function of the organization and sat on the IR team with SOC constituents Lead the development & implementation of the system-wide risk management function of the information security program to ensure information security risks are identified and monitored Executed strategy for dealing with increasing number of audits, compliance checks and external assessment processes for internal/external auditors, PCI DSS, SOC2, NIST 800, GDPR, NYFDS State exam, etc Personal Contribution: Helped save $900K in resource budget by leveraging features of current tool sets by making adjustments to organizational policy, Reduced redundancy of compliance efforts by unifying IT, Engineering, Security, Legal & HR team while centralizing documentation

Director & Founder
San Francisco Bay Area
This started out as a Best Practices Consulting Service for SaaS based Startups, then turned Hacker Home & Incubator > Micro Portfolio, and then back to freelance consulting when real estate went wild. As a general practitioner, I am open to hearing any current operational issues your organization is having to see how I can help. I used to go by the title of a Strategic Resource Consultant for all SMB and Startup needs. When it comes to cyber security, secure code is the safest code, and best practices keep networks secure. We can help build secure code into your SDLC with our preferred vulnerability management package. These tool sets and processes can save countless hours, dollars, and headaches (engineering retention!!) to traditional security review and fix practices still in use. For security compliance concerns, we do internal audits and prep work for PCI, SOC2, GDPR, ISO 27001 mostly as well as reorganizational work to help work compliance into normal workflows and processes. See more in Project Section below:

Security Operations Specialist
Remote
Solutions-orientated IT Security Operations Specialist with success directing a broad range of network & application security initiatives to include Vulnerability Assessments, Intrusion Detection & Prevention, Dynamic Application Scanning, Security Engineering, and Business Integration Support This franchise was owed and operated by FOB Miami LLC

Security Program Manager & Product Manager
Mountain View, California, United States
(Formerly Tinfoil Security) Eliminating exploitable vulnerabilities makes it more difficult for attackers to gain access to applications and systems exposed. Founded in 2011, the company’s signature web scanning tool identifies vulnerabilities on web applications and is tightly integrated with DevOps workflows. With its DAST [dynamic application security testing] and API security testing capabilities, they are in a stronger position to help developers and IT security professionals build secure solutions for their organizations.

Technical Risk & Vulnerability Consultant
San Francisco, California, United States
HubHaus is a provider of a shared community platform to solve housing issues in the modern age Oversaw the planning, implementation, and overall delivery of core security policies and technologies within core applications such as: SSO/2FA, Splunk, Vulnerability Mgt, & PenTesting Provided awareness to key concerns of operational model while making formal and informal adjustments to organizational policies to access risks through threat modeling
Education
James Blocho's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.









