About Jonathan Major
25 years in engineering, security, and compliance — why that background is what closes your audit gaps.

Jonathan Major
Founder — Fractional CISO
San Francisco, CA
LinkedInJonathan Major is a highly experienced technology and security leader with a 25-year career in engineering, information security, and compliance. As the founder of Risk and Response, Jonathan helps businesses build and protect their digital assets through compliance readiness and strategic security programs.
With career-spanning roles at BlackRock, Barclays Global Investors, and IBM, Jonathan has deep expertise in cloud engineering, cybersecurity, and compliance. He co-founded Proga Digital, a low/no-code application development company, and served as the founding VP of Engineering and Chief Security Officer at Crux Informatics.
At Risk and Response, Jonathan delivers compliance readiness services for SOC 2, ISO 27001, and HIPAA — leveraging hands-on expertise with platforms like Drata and Vanta alongside deep knowledge of cloud platforms, infrastructure as code, and cybersecurity best practices.
What this means for your audit
Two decades of engineering and security roles inside regulated financial institutions like BlackRock, Barclays Global Investors, and IBM mean Jonathan understands the operational reality auditors expect from a control, not just the paperwork that describes it.
As the founding VP of Engineering and Chief Security Officer at Crux Informatics, he built a security and compliance program from zero — the same starting point most clients are in before their first SOC 2, ISO 27001, or HIPAA audit.
He configures Drata and Vanta himself, so evidence collection gets set up correctly the first time instead of being handed off to a generalist.
Internal Audit Service — independent ISO 27001 & ISO 9001 internal audits from the same team.
Want a plain read on where your program stands against SOC 2, ISO 27001, or HIPAA requirements? Start with a scoping call.
Schedule a Call