Client Trust Center Contract vehicles Contact Traverge

Home / About / Leadership

The people in the pitch are the people on the work.

Large firms send principals to win the engagement and staff it with whoever is available. Traverge has three practitioners, and all three deliver. Between them: more than sixty systems currently in the FedRAMP Marketplace assessed as lead assessors, and a certification history reaching back to the program's first authorization in 2011.

Leadership

Three practitioners. No bench to hide behind.

Experience earned in the U.S. Military, federal civilian agencies, the intelligence community, 3PAO assessment firms and hyperscaler security leadership. The same three people scope the work and deliver it.

Jon Riddle, Chief Executive Officer and Founder of Traverge

Jon Riddle

Chief Executive Officer and Founder

Twenty five years in technology, seventeen in cybersecurity compliance and fifteen dedicated to federal cloud, spent deliberately on both sides of the authorization boundary. He has run compliance as a cloud service provider program manager, and he has assessed it as a FedRAMP certified independent lead assessor, which is a combination almost nobody in this market actually holds.

He has led more than forty independent FedRAMP and FISMA assessments, advised over twenty cloud service providers through the certification lifecycle, and helped build what became the largest FedRAMP 3PAO in the industry. At a global zero trust cloud provider he owned the full FedRAMP and DoD CC SRG program at IL-5 and IL-6, including the Revision 4 to Revision 5 transition and a collaborative ConMon charter built to meet FedRAMP PMO guidelines. He is an 82nd Airborne Division veteran and a disabled American veteran, and Traverge is an SBA certified SDVOSB because of it.

CISSP / FedRAMP Certified Lead Assessor / CCSK / PCIP
FedRAMP Rev5 and 20x / DoD CC SRG IL-2 to IL-6 / OSCAL and KSI / Continuous ATO
LT

Lucas Truax

Director of Engineering and Offensive Security

Fifteen years across the environments most firms never touch: space domain systems, 5G and 6G deployments, industrial control networks and federal cloud. He has designed Zero Trust architectures for space systems down to policy enforcement inside a MIL-STD-1553 bus, and built continuous ATO capability for 5G deployments on Kubernetes and service mesh.

He contributed to the inaugural DoD DevSecOps working groups when container security in defense was still an open question, and he is the sole author of a forty page Space Domain Cyber Assurance Report defining risk-based approaches for space systems under the NIST CSF. He has briefed the Space Force, the Space Development Agency and the intelligence community, spoken at ICSJWG, AFPM and BSides on industrial control supply chain attacks and 5G network security, and serves as a SANS Institute subject matter expert, writing the assessment questions behind certifications other testers hold.

CISSP / GPEN / AWS / Azure / M.S. Software Engineering
Zero Trust architecture / DevSecOps and IaC / Penetration testing / AI red teaming
MR

Mushad Rahman

Director of Compliance

A certified information systems auditor who has spent his career on the evidence itself, where compliance programs are actually won or lost. As GRC information security audit lead at a global technology company he directed collaboration with the FedRAMP Program Management Office and third party assessment organizations, and ran FedRAMP, SOC 2, ISO 27001, PCI DSS and CMMC audit activity across internal stakeholders, agency authorizing officials and external auditors at once.

Before that he performed independent assessments submitted directly to the FedRAMP PMO and agency AOs, and briefed the FedRAMP ISSO and Joint Authorization Board technical reviewers across DoD, DHS and GSA. He has architected cloud security for a national healthcare enterprise under FISMA, HIPAA, HITRUST and PCI simultaneously, and he holds a current Public Trust clearance. He owns control implementation and evidence depth at Traverge, and keeps client programs defensible in the long stretch between assessment cycles.

CISA / CCSK / AWS Solutions Architect / FITSP-O / ISO 27001 Lead Internal Auditor
NIST SP 800-53 Rev 5 / RMF assessment and authorization / CMMC 2.0 / ConMon operations