Jon Zeolla
Founder, Zenable
Pittsburgh, Pennsylvania, United States
Actions
Jon Zeolla builds governance-first software factories. As the founder of Zenable, he leads the team in developing self-improving verifiers that maintain alignment between coding agents and evolving company requirements.
Jon got his start with AI and machine learning in 2015 at Carnegie Mellon, applying large-scale data analysis to improve security automations. That work led him to contribute to dozens of open source projects and initiatives, and he's particularly interested in using data and feedback to improve systems and automate repetitive work.
He now serves as an Agentic AI Foundation (AAIF) Ambassador, helping engineers understand and adopt open protocols for agentic systems, including MCP and A2A, via anything from talks and hands-on workshops to running strategy sessions to help navigate tradeoffs.
Links
Area of Expertise
Topics
Simplifying IaC Security
Let's talk through the ups, downs, and lessons learned of using open source security tools to secure IaC pipelines, as well as a new open source tool I developed to simplify the management and deployment of these tools. Teams should be able to easily manage and configure their tools independently and in a distributed manner, while still having centralized visibility and the ability to quickly deploy new IaC-specific security policies.
We will also discuss a reasonable onramping process to ensure that teams don’t have their sprints uprooted by triaging piles of findings only to discover that most of them are false positives or low-priority noise. This will include a discussion of a real world roll-out, and a method that was developed to add passive security scans into existing IaC pipelines with no changes other than running the existing commands (terraform, ansible, etc.) inside of a new docker container.
Cloud Native GRC
Policy-as-Code is a pivotal tool for security across various domains, particularly in its role as an enabler of admission control. By managing access and evaluation, it fortifies the security posture by facilitating scrutiny and decisive actions.
Expanding beyond its role in admission control, Policy-as-Code extends its reach to compliance and security auditing functions. Through automation, it streamlines traditionally cumbersome tasks, benefiting system owners and ensuring continuous reporting on compliance status against established thresholds.
This presentation delves into the versatile application of both governance and policy for conducting seamless, ongoing audits across diverse environments. From infrastructure to applications, it underscores the potential of policy-driven approaches in achieving comprehensive compliance.
Furthermore, it advocates for collaborative efforts in shaping reference architectures that support automated Governance, Risk, and Compliance frameworks.
Empowering the Deaf and Hard of Hearing in Cloud Native and Open Source
During this session, Jon and Catherine will present a new CNCF initiative that aims to create a pathway into cloud native for the deaf and hard of hearing (DHH).
Diversity and inclusion foster vibrant communities where everyone contributes their unique perspectives and talents. The result: innovation that is more inclusive, higher quality, and a broader set of contributors. But when it comes to cloud native, we have yet to see universal representation of communities with disabilities. And visibility is key because, if you don't see individuals "like you" thriving in a particular field, it can be difficult to envision your own journey. This initiative aims at creating and supporting patterns and a pathway for Deaf or Hard of Hearing individuals to become active open source community members who can serve as role models, motivating a new generation of engineers to join them on this journey. Join this session to learn why these initiatives are important and what you can do to help.
BSides Cleveland 2025 Sessionize Event
2025 BSIDES Columbus Sessionize Event
DevOpsDays DC 2025 Sessionize Event
BSidesPGH 2025 Sessionize Event
CloudNativeSecurityCon North America 2024 Sessionize Event
KubeCon + CloudNativeCon North America 2023 Sessionize Event
Jon Zeolla
Founder, Zenable
Pittsburgh, Pennsylvania, United States
Links
Actions
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top