Sign in to view Ronald’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Ronald’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Washington DC-Baltimore Area
Sign in to view Ronald’s full profile
Ronald can introduce you to 10+ people at Google
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
3K followers
500+ connections
Sign in to view Ronald’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Ronald
Ronald can introduce you to 10+ people at Google
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Ronald
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Ronald’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
About
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
Activity
3K followers
-
Ronald Bushar shared thisIn the public sector, compliance deadlines are accelerating—and so are the threats. ⏱️ Mandates like CISA BOD 26-04 are a strong reminder that federal security policies are rapidly evolving to match the speed of modern cyber adversaries. Keeping pace demands a fundamental shift. We must move past static, reactive security models and embrace automated, risk-based operations that scale to machine speed. At Google Public Sector, we are partnering with agencies to enable this transition. By combining Mandiant’s frontline threat intelligence and multi-cloud insights—including Wiz solutions—with AI-driven security tools like Gemini in SecOps, we are helping public sector teams: 🔎 Anticipate threats and automate investigation workflows. 📊 Prioritize risks dynamically based on real-world threat behavior. ⚙️ Accelerate response while keeping human analysts firmly in control. On October 20th at the Google Public Sector Summit in Washington, D.C., we will dive deep into the future of security operations and how Agentic Defense is transforming federal resilience. Register today: https://lnkd.in/eptKfCAk
-
Ronald Bushar shared thisExcited to be chatting with Kevin as he accepts his Cyber Luminary Award. Join us in what is sure to be an exiting and insightful conversation! https://lnkd.in/e9YRmux3Ronald Bushar shared thisBuilding Mandiant into a $5.4B acquisition took grit, conviction, and a willingness to go where others wouldn't. Kevin Mandia did it once. Now he's doing it again: Armadin emerged from stealth in March 2026 with a record-breaking $189.9M raise, the largest in cybersecurity history. On June 10, NVTC is honoring him as our 2026 Cyber Icon. He'll sit down with Ronald Bushar, CISO at Google Public Sector, for a candid conversation on: ✅ The decisions behind building and scaling Mandiant ✅ Why he came back to found Armadin, and what problem he's solving ✅ How AI has rewritten the rules of cyber offense and defense ✅ What the future cyber workforce needs to be ready for No recording. No replay. Just a rare, unfiltered conversation with one of the most consequential figures in cybersecurity history. 🔗 Register now: https://lnkd.in/eyrQe27S James Leach | Brad Medairy | CISOnow | Cloud Security Partners | LMI #NVTC #WhereTechThrives #NVTCCOI #Cybersecurity
-
Ronald Bushar shared thisI had a fantastic discussion at #GooglePSSummit with Patrick Moorhead on the Six Five Media podcast. We focused on the crucial role of AI-powered security for public sector agencies as they confront the evolving landscape of cybersecurity threats. In today's environment, traditional security models are inadequate against sophisticated, AI-driven threats. We discussed how [TAG: @GooglePublicSector] helps agencies proactively employ an intelligence-led approach, modernize security operations and counter the most advanced adversaries. Watch the full conversation below.Ronald Bushar shared thisHow is the integration of AI and cloud technologies transforming cybersecurity for federal agencies as they face a rapid evolution of cyber threats? Host Patrick Moorhead is joined by Google Public Sector's Ronald Bushar, Chief Security Officer & Managing Director, at Google Public Sector Summit, for a conversation on AI-powered security. They explore how Google’s full-stack AI is reshaping cybersecurity strategies for national security and critical government missions. Key Takeaways Include: 🔹Full-stack AI integration: Google’s end-to-end AI platform, including custom silicon and Gemini models, is engineered to deliver improved threat detection and accelerated response for federal agencies. 🔹Modern security for government data: By leveraging “FedRAMP High” as a security baseline, applying zero-trust principles, Mandiant expertise, and Google Distributed Cloud (GDC), Google enables more robust security postures versus traditional GovCloud solutions. 🔹Multi-cloud security tools: How agencies benefit from posture management, virtual red teaming, and lifecycle AI protection, securing sensitive workloads not only on Google Cloud but also in other clouds and at the tactical edge. 🔹Roadmap to proactive defense: Google is working towards autonomous SecOps, combining AI-driven agents, Mandiant incident response, and continuous threat intelligence to shift agencies from reactive to proactive cybersecurity. #GooglePSSummit
-
Ronald Bushar posted thisThrilled to have moderated the Mission Track Security session at @ Google Public Sector Summit. Our discussion, "Unlocking the power of AI to secure critical infrastructure and ensure mission success", underscored a vital strategic shift: moving from a fragmented, reactive defense to a unified, intelligent security model. As adversaries leverage AI to scale their attacks, we discussed how Google Unified Security operationalizes threat intelligence and infuses AI—like the Big Sleep agent —to shift the advantage back to cyber defenders. A massive thank you to our expert panelists for their actionable insights and real-world experience: David Nguyen, Founder & CEO, US AI (on behalf of Carahsoft) Rezaur Rahman, Chief AI Officer, Advisory Council on Historic Preservation Katie Arrington, PTDO CIO, Department of War Google Public Sector is committed to being your mission partner, bringing the best of our integrated, secure, full stack AI innovation to government #GeminiForGovernment #GooglePSSummit
-
Ronald Bushar shared thisGoogle Cloud Next is happening this week, April 9-11 in Las Vegas. If you're unable to attend in person you can register to watch the Opening Keynote via livestream. I look forward to hearing our product updates, meeting with partners and seeing some of you there!Ronald Bushar shared thisLive from Las Vegas, it's #GoogleCloudNext! Tune into the Opening Keynote right now to learn about all our new announcements, strategies, and tools to help you build the next big thing ↓
-
Ronald Bushar shared thisAI is a national security priority. I recently spoke at the Google Public Sector Summit about how Google is helping government agencies leverage AI for cybersecurity and mission success. Want to learn more? Check out my latest blog post and register for the Google Public Sector Summit On-Demand to hear more of my insights. https://lnkd.in/eA4KuWQ3 #AI #Cybersecurity #NationalSecurity #GooglePublicSector #GPSSummitEmpowering Public Sector with Secure AI | Google Cloud | Google Cloud BlogEmpowering Public Sector with Secure AI | Google Cloud | Google Cloud Blog
-
Ronald Bushar shared thisRonald Bushar shared thisMandiant (now part of Google Cloud) just published threat research on a cascading software supply chain attack involving malware-laced products by 3CX and Trading Technologies. While investigating the 3CX software supply chain attack, we discovered the source of their compromise was a different software supply chain attack involving another vendor’s product – the X_TRADER application made by Trading Technologies. We assess these cascading supply chain attacks to be attributed to a North Korean-nexus threat actor who we are tracking as UNC4736. This is the first time that Mandiant’s observed a software supply chain attack lead to another software supply chain attack. Here are some of the highlights: - Last year, the X_TRADER software was laced with the VEILEDSIGNAL backdoor. The software installer was digitally signed with a valid Trading Technologies code signing certificate, available for download on their website, and used their website for command and control. - Trading Technologies retired the X_TRADER platform in 2020, but made the software available for download until 2022. While this is not an immediate threat to organizations today, we suspect other organizations had downloaded the malware-laced version of the software when it was available on the Trading Technology website. - North Korean nexus threat actors continue to demonstrate increased offensive cyber capabilities. We also saw this group exploit a 0-day vulnerability in Google Chrome last year (CVE-2022-0609). Huge shout out to the incredible team behind the discovery, analysis, documentation, and coordination with the known impacted parties - Marius F., Jennifer Starling Burnside, Jeff Johnson, Fred Plan, Renato Fontana, Jake Nicastro, Adrian Sanchez Hernandez, Lucas Kossack, Manfred Erjak, Phil Pearce, Mitchell Clarke, Matias Bevilacqua, and many more. And thanks to the 3CX team for their intense focus on investigating and remediating the attack over the last several weeks.3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspected North Korean Actor Responsible | Mandiant3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspected North Korean Actor Responsible | Mandiant
-
Ronald Bushar shared thisRonald Bushar shared thisThank you Edward Boute and Pieter De Schryver for hosting me and Ronald Bushar at your annual Cyber Defense Live event in Brussels, jointly held for the first time this year with Google Cloud. Enjoyed sharing highlights from Mandiant (now part of Google Cloud)’s latest M-trends report and discussing major shifts in cybersecurity policy areas. Bad news is public sector targeting is on the rise and adversary TTPs are accelerating. Good news is detection is improving and partnerships are paying off. Read more here: https://lnkd.in/gCU68UKaTop Trends in Cyber Security | Cyber Attacks Trends | M-TrendsTop Trends in Cyber Security | Cyber Attacks Trends | M-Trends
-
Ronald Bushar shared thisRonald Bushar shared thisHello hive! I'm hiring a consultant to support the development and execution of U.S. government strategies, policies, and partnerships for Mandiant (now part of Google Cloud) Cybersecurity Consulting, Google Public Sector. Please take a look below! 👇 https://lnkd.in/eXuxKjT8
-
Ronald Bushar liked thisRonald Bushar liked thisThis week I had the honor of participating in the National Emergency Management Association mid-year conference alongside my incredible colleagues Emily Reinstein Katie Harris sharing some of the incredible ways Google Public Sector can support the emergency management mission with Gemini. Thank you to Christopher Hein Terence O'Leary and David Orr for the timely insights on utilizing AI during our panel discussion. It was great to hang out with the TerraFort team and see the amazing things they're building with Google. Finally, a heartfelt thanks to Chad Gorman for all the things big and small he's supported over the past several months.
-
Ronald Bushar liked thisRonald Bushar liked thisI took a breath today to look back at the last month... phew our Government Affairs team has covered a lot of ground--both policy-wise and geographically. At a time when visions for the future of the internet, AI and cloud are becoming more fragmented, Wiz has become a truly global company in every sense. Matching that reality, our team is meeting with government leaders at every level -- local government, U.S. State Governors and their teams, Federal Partners and International Cyber Leads. We're working around the world (and pretty much around the clock) to help build the right policies to secure this technological shift--and the fun continues this week at RSAC. From meeting Chief Innovation Officers in Miami, to working internally with our colleagues at Wiz SKO, to diving in with our new partners Google, to conferences domestic and international, to meetings with Governors' policy leads, the goal remains the same: support policies that make the world's digital infrastructure more secure. Thanks to all our partners who have helped make many of these interactions happen.
-
Ronald Bushar liked thisRonald Bushar liked thisToday Armadin comes out of stealth. I have spent my entire career helping organizations secure their networks, applications, and overall security architecture. One thing I saw repeatedly is that even the best red teams do not have enough time or expertise to identify every meaningful attack path across complex environments before an attacker does. The shift to AI changes that. For the first time we can leverage systems that can think, act, and reason creatively in ways that resemble a human operator, allowing offensive expertise to scale far beyond what humans alone can achieve. That is why we built Armadin. Our platform trains agentic AI on the instincts and workflows of elite red teamers to uncover real paths to compromise across an organization’s environment, helping defenders answer the question that matters most: Are we secure? Now that expertise runs continuously, at scale, without sleep. https://lnkd.in/gzsbiMgg
-
Ronald Bushar liked thisRonald Bushar liked thisSandra Joyce, Vice President of Google Threat Intelligence Group, gave IWP's annual Pearl Harbor Day lecture this year on the topic of “The AI Threat Landscape.” IWP commemorates Pearl Harbor Day each year as a reminder of the need for defense preparedness. During the discussion, Ms. Joyce examined how threat actors are leveraging AI in today's national and economic security environment. The event was hosted by Michelle Watson, IWP Executive Director for Corporate Relations. #IWP #PearlHarborDay #DefensePreparedness #NationalSecurity #CyberSecurity #AIThreats #ArtificialIntelligence #ThreatIntelligence #EconomicSecurity #SecurityStudies #CyberDefense #AIinSecurity #HomelandSecurity
-
Ronald Bushar liked thisRonald Bushar liked thisAn honor to talk to Rob Joyce today at CDS. I was especially interested in his new perspective on threats associated with AI. The adversary is going to find bugs at scale and move faster than ever before.
Experience & Education
-
Google
***** *********** ******** ******* * ******** ******** * ****** ****** ******
-
*** ****** **********
** *** undefined
-
-
******** *********** ********* *** ***** **********
******** ** ******* ********** ***********
-
View Ronald’s full experience
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
Licenses & Certifications
-
Project Management Professional
Project Management Institute
IssuedCredential ID 912828 -
Information Systems Security Architecture Professional
ISC2
Issued -
Certified Information Systems Security Professional
ISC2
IssuedCredential ID 27626
Languages
-
English
-
Organizations
-
PMI
PMP
- Present -
ISC2
-
- Present
View Ronald’s full profile
-
See who you know in common
-
Get introduced
-
Contact Ronald directly
Other similar profiles
-
Chris Stolley
Chris Stolley
20+ years of Cybersecurity Sales and Channel leadership experience. Experience with small to large organizations. Proven success with high growth companies. Extensive experience building and scaling sales teams. I have held executive leadership roles but also enjoy working with sales teams to grow business and solve security challenges for clients.
4K followersDenver, CO
Explore more posts
-
Michael Smith, MSCIA, CISSP-ISSEP, CISM
Open to opportunities • 5K followers
I was in AFCEA's Signal talking about the Cyber Security Risk Management Construct (CSRMC), which is the DoW's new replacement for the Risk Management Framework. Change is good, and some of the streamlining is excellent. However, you're always dealing with the checklist nature of the compliance beast, and like most things, it comes down to intelligent execution. https://lnkd.in/e3nQ6_J5
21
-
Vishal Masih
Zephon LLC • 5K followers
Conditional access fails when ICAM is fragmented. Civilian agencies can deploy MFA, PAM, and identity tools and still miss the intent of OMB M-22-09 if those controls are not tied to an enterprise ICAM platform. CISA ZTMM is clear: Advanced maturity requires dynamic, risk-based access decisions using current identity attributes, privileged access controls, and continuous policy enforcement. The common failure pattern: - Multiple IdPs with different rules - PAM outside the ICAM workflow - Static application roles replacing real attribute-based decisions What we look for first: - Is there an enterprise-wide ICAM control point? - Is PAM integrated for provisioning and deprovisioning? - Are permissions adjusted from trusted enterprise attributes? AISE gives civilian agencies one assessment and produces separate scores for CISA ZTMM and DoD ZTA CoA. The CISA ZTMM score maps to OMB M-22-09, while the DoD ZTA CoA score provides additional context. That gives CISOs, IT directors, and procurement teams a clean baseline before buying another point solution. Comment ZTMM or visit zephon.tech/zt #ZeroTrust #CISA #FedRAMP
1
-
ISACA Greater Cincinnati Chapter
463 followers
Hundreds of vulnerabilities in 24 leading GenAI models Explore security profiles of 24 leading GenAI models, revealing hundreds of chatbot vulnerabilities with attack success rates up to 64%. Learn strategies to secure AI systems, meet compliance and close the prevention gap. https://lnkd.in/gn4BvKiQ
1
-
Michael Devine
Agility Development Group • 11K followers
“This directly affects two NIST SP 800-171 practices: 🔒 IR-4 (Incident Handling) — Assessors will expect integrated CUI classification workflows in incident response procedures 🔒 IR-6 (Incident Reporting) — Assessors will review tabletop exercises, playbooks, and historical incident documentation for evidence of this integrated approach” #CMMC #DefenseContracting #Cybersecurity Boyd Williams Jared Chambliss Keith Nicoletti
3
-
Anna Ribeiro
IndustrialCyber • 27K followers
The Cybersecurity and Infrastructure Security Agency's Infrastructure Security Division is seeking public comment on an extension of its information collection for voluntary vulnerability assessments of critical infrastructure organizations. In a Federal Register notice published last week, the agency requests an additional 60 days for comments on the CISA Vulnerability Assessments program, with submissions due by Sept. 10. The assessments collect high-level information on an organization’s security posture and dependencies and use the data to generate Protective Measures and Resilience Measure indexes that organizations can use for risk identification, mitigation, planning, and security-related decisions. Under the proposed extension, CISA would continue collecting information electronically through assessments conducted by Protective Security Advisors and Cybersecurity Advisors, or through organizational self-assessments. The agency said changes since its previous Office of Management and Budget approval include moving three cyber-focused questionnaires to a separate system and decommissioning the Stakeholder Risk Assessment and Mitigation, reducing estimated annual respondent burden costs from US$1.91 million to $640,685. The collection covers an estimated 1,100 respondents and 7,150.5 burden hours annually, with information also shared with the Federal Emergency Management Agency for public assistance grant determinations. Winfield P. Werntz, acting chief information officer at DHS’ CISA, said that the Office of Management and Budget is particularly interested in comments assessing whether the proposed information collection is necessary for the agency to perform its functions effectively and whether the information would have practical utility. More at: https://lnkd.in/d56Q6HPZ
17
1 Comment -
Hussar Systems LLC | Palo Alto Networks
49 followers
Is your federal agency's security operations center struggling to keep pace with state-sponsored threats while burdened by fragmented tools, manual processes, and a growing workforce gap? Federal SOCs require a transformational approach to outpace modern adversaries. Palo Alto Networks Cortex delivers an AI-driven, unified platform designed to meet stringent federal mandates—including FedRAMP High Authorization—while dramatically improving threat response times. • Consolidate over 50+ disparate tools into a single AI-driven platform, reducing alert fatigue and eliminating the need to pivot between multiple dashboards. • Leverage machine learning and Unit 42 Threat Intelligence to drastically reduce mean time to detect (MTTD) and mean time to respond (MTTR) from weeks to hours. • Automate labor-intensive compliance checks for mandates like FedRAMP, FIPS 140-2, and CISA directives, freeing your team for higher-value mission tasks. Empower your existing workforce to operate at an advanced level and achieve operational superiority against evolving threats. Explore Palo Alto Networks Quick Start Service: https://lnkd.in/gcDg3rrf Explore Palo Alto Networks Firewall Managed Service: https://lnkd.in/gTt-RcTB #PaloAltoNetworks #ResourceLibrary #PaloAltoNetworksResourceLibrary #Cortex #FedRAMP #FederalCyberSecurity #SOC #ZeroTrust #DoD
-
Jeff Baldwin, DSc
12K followers
DFARS 7012 requires contractors to implement NIST SP 800-171 to protect Covered Defense Information (CDI). DFARS 7019/7020 requires contractors to perform a basic assurance self-assessment and submit a score to SPRS that is within 3 years of contract award. DFARS 7021 specifies the CMMC level required to be awarded a DoD contract. CMMC levels require either self-assessment or third-party assessment. When making the determination of the level required for a contract, there is a memo that outlines the process that must be followed by the DoD program manager to obtain a waiver to "CMMC assessment requirements" for that contract. "Program Managers and requiring activities should identify information security requirements for the types of information most likely to be associated with the planned contract effort. When market research indicates that including a CMMC assessment requirement may impede ability to generate robust competition or delay delivery of mission critical capabilities, the SAE, CAE, or DAE may approve requests to waive inclusion of CMMC assessment requirements. SAEs and CAEs must carefully weigh the risk of potential loss of CUI associated with mission critical capabilities before granting a waiver." Level 1 - "There are no circumstances likely to warrant approval of requests to waive CMMC Level 1 requirements." Level 2 - "In rare circumstances. such as when seeking competition from non-traditional DoD sources. waivers may be warranted for CMMC Level 2 third-party assessment requirements. Such waivers are not appropriate for contracts requiring performance by a cleared defense contractor. Approved waivers on a class basis must include a planned expiration date and guidance for requiring CMMC certification in subsequent solicitations." Level 3 - "In rare circumstances, waivers may be warranted for CMMC Level 3 third-party assessment requirements: such waivers, however, are not appropriate for contracts or work statements requiring access to both unclassified and classified DoD information." Full memo on the process found here, starting on page 6: https://lnkd.in/eeBCW53n #cmmc #dib #dfars
57
12 Comments -
Riccardo Sirigu
2K followers
If you’re interested in OT cybersecurity, this webinar will walk you through the recently released "Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators". You’ll learn the steps to building and maintaining a robust asset inventory, because if you don’t know what you have, you can’t protect it. #otsecurity #securebydesign #cybersecurity
6
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top content