About
Yonathan Rivas

Yonathan Rivas

Senior GRC and information security consultant. FTC Safeguards Rule, HIPAA, NIST CSF and AI governance.

Twenty years turning complex technology problems into solutions that hold up under scrutiny.

I help organizations manage technology risk, strengthen information security, and turn regulatory obligations into controls, ownership and verifiable evidence. The work is practical: policies people follow, controls that run, documentation an auditor or regulator can read.

Two decades designing infrastructure, automating processes and solving technology problems across Venezuela, the Dominican Republic, Colombia and Spain. That background means I understand your systems before I write a control for them.

For Florida clients, two things tend to matter: you work directly with the consultant doing the work, and I cover AI governance, a gap most security consultants have not filled yet. I work in English and Spanish, across both U.S. and European frameworks.

Contact LinkedIn

How engagements run

Remote-first, on site when it counts
Most work is done remotely. Workshops, walkthroughs and audit support can be in person in Florida.
One consultant, start to finish
No handoff between the person who scoped the work and the person who delivers it.
Fixed scope, defined deliverables
You know what you are getting and when before the engagement starts.

Academic background

Master’s in Cybersecurity and Privacy
Universitat Oberta de Catalunya (UOC) · In progress
Computer Engineering (academic equivalence to Bachelor’s degree level)
Universidad Alejandro de Humboldt · Caracas, Venezuela
Advanced Data Protection Officer Program
CAS-Training (CMICE Fuencarral) · In progress

Certifications

ISO 27001:2022 Internal Auditor Bureau Veritas