IT Operations · Security · AIOps

Twenty years building programs that use data, automation, and AI to change how IT teams operate and make decisions.

Currently leading the vCTO practice at Abacus Group as a player/coach — leading a team of 5 senior engineers while owning the assessment and advisory relationship for a portfolio of financial services clients representing $70B+ in combined AUM and $3M+ in client ARR. I built the Python-based reporting engine the practice runs on, deploy it directly with clients, and set the assessment methodology every engineer follows. CISSP · CISM.

"The best IT and security programs start with clear goals and the discipline to work through ambiguity to get there."

Jason Benner
Credentials & Role
CISSP
ISC²
Active
CISM
ISACA
Active
Manager, CTM · vCTO Practice
Abacus Group · Financial Services MSP
Current
VP of IT · Director of IT MS
BlueNovo / Medicus IT · 2014–2025
Former
20+
Years in IT & Security
12+
Director & VP Years
$70B+
Client AUM
$3M+
Client ARR
95%+
Client Satisfaction
5K+
Endpoints Managed
Frameworks & Platforms
NIST CSF 2.0ITILZero TrustCIS ControlsHIPAASOC 2SEC / FINRAM365IntunePower BIPCI-DSSISO 27001AWS / AzureSIEM / MDRServiceNow
02

Selected Work

Assessment Toolchain · Financial Services
M365 Security Posture Assessment

Fully automated PowerShell-based collection and scoring pipeline covering 16 assessment modules across Entra ID, Exchange Online, SharePoint, Defender, and AI Tool Discovery. Produces structured output consumed directly by Power BI for client reporting.

PowerShellMS Graph SDKPower BI
M365 Posture Overview User Status and Auth Sign-In Activity Email and App Security Conditional Access
Assessment Automation · Financial Services
CTM Assessment Reporting Engine

Python-based reporting engine (~8,600 lines, 161 functions) that reconciles data across five independent sources — RMM inventory, on-prem AD, endpoint protection, file-server permissions, and M365/Entra — into a single self-contained HTML report with live filtering and drill-down. Replaced the practice's earlier Power BI and desktop-app tooling.

PythonData ReconciliationSelf-Contained HTML
Screenshots of the rebuilt report coming soon
Access Review · Dashboard
File Server & SharePoint Access Review

Power BI dashboard on Varonis exports providing structured permission visibility across NTFS ACLs and SharePoint sites. Features disconnected slicer patterns for reviewer-driven filtering and exception tracking.

Power BIVaronisNTFS
File Access Summary User Access Review Group Access Review Folder Access Review
AI Governance · Compliance
Claude Enterprise Controlled Deployment Framework

Compliance architecture for a financial services client deploying Claude Enterprise. Maps Web/Desktop, Cowork, and Direct API paths against device management, Conditional Access, and compliance capture — identifying gaps and required controls for each path.

Anthropic APISEC / FINRAEntra ID
Claude Enterprise Compliance Matrix
Network Monitoring · MSP
Multi-Site Network Monitoring & Reporting

Power BI reporting layer on Auvik network monitoring data — surfacing uptime, alert volume, bandwidth, and critical device status across sites and endpoints. Tied directly to MBR/QBR reporting cadence.

AuvikPower BIHealthcare MSP
Auvik Overview Dashboard Alerts by Site Site Uptime Server Uptime
Healthcare IT · Strategic Advisory
Multi-Site FQHC Security & Infrastructure Program

Technology advisory for Federally Qualified Health Centers — covering HIPAA SRAs, full infrastructure modernization (SD-WAN, Meraki, HCI), M365 and Azure migrations, EHR transitions, and multi-year IT budgets in the $500K–$1M+ range.

HIPAA SRAM365 / AzureMeraki
IT Project Timeline IT SWOT Analysis Focus Areas Future Projects
Cybersecurity Responsibilities NIST CSF 2.0 Framework Controls Grid Multi-client Dashboard
Cybersecurity Framework · Practice Ops
NIST CSF 2.0 Cybersecurity Practice Framework

Built and operationalized a cybersecurity practice framework at BlueNovo grounded in NIST CSF 2.0 — covering all six functions and mapping 18 controls. SmartSheet-based Security Assessment Plan deployed across 10+ healthcare clients with a portfolio dashboard.

NIST CSF 2.0HIPAA SRASmartSheet
← scroll to explore →
03

Perspectives & Insights

MSP · Client AdvisoryLinkedIn

Stability Isn't the Finish Line

You put in the work, fixed the obvious issues, tightened controls, and suddenly the environment behaves the way it always could. That's a win — but it's also when your value proposition has to change. On showing value after the chaos is gone.

Compliance · FrameworksLinkedIn

Most Small IT Teams Are Already Doing Compliance Work

NIST, ISO, and CIS aren't out of reach for smaller organizations. Most teams are already patching, backing up, running MFA, and managing EDR — they just don't think of it in control numbers.

AI · Support OperationsLinkedIn

The Real Bottleneck in AI-Powered Support Isn't the AI

AI is great at aggregating and connecting data. End users are notoriously bad at providing it. "It just doesn't work" isn't a ticket — it's a guess. The next improvement in support isn't automation, it's better intake.

Metrics · LeadershipLinkedIn

Without Curiosity, Data Is Just Decoration

Tickets closed, MTTR, CSAT, uptime — the numbers tell you what changed, but connecting the dots takes context and judgment. A drop in ticket volume could mean users are happier, or it could mean they've given up.

Supply Chain · RiskLinkedIn

Tool Diversification Doesn't Always Lower Supply Chain Risk

Diversification reduces single-vendor exposure — but every tool you add creates new pathways for incidents to travel. Before expanding your stack, understand the connections you already have.

Resilience · ArchitectureLinkedIn

The Cloudflare Outage and What It Means for How We Build

When a single provider touches auth, DNS, WAF, and CDN simultaneously, an outage isn't just an inconvenience — it's a design conversation. On concentration risk in modern infrastructure.

04

Areas of Expertise

Automation & Data-Driven Operations

Building pipelines, automated assessments, and reporting infrastructure that surface real intelligence from raw operational data — replacing manual work with repeatable, scalable tooling.

PowerShellPower BIPython

Cybersecurity & Compliance

Security program design from the ground up — risk assessment, control frameworks, policy development, and audit readiness — built to be operational, not just documented.

🔒NIST CSF 2.0HIPAASIEM / MDR

M365 & Endpoint Management

Deep expertise across the M365 stack — Intune, Entra ID, Purview, Defender — including zero-touch provisioning, conditional access design, and device compliance at scale.

🖥IntuneEntra IDMDM / MAM

IT Operations & Service Delivery

NOC/SOC operations, ITSM process maturity, and service delivery across multi-client MSP and enterprise environments — with a focus on SLA discipline and team development.

🏗ITILServiceNowNOC / SOC

Identity & Access Management

IAM strategy across Active Directory, Entra ID, SSO, and PAM — including lifecycle management, MFA rollouts, role-based access, and Zero Trust architecture.

🪪Entra IDPAMZero Trust

Cloud & Infrastructure

Azure and AWS migrations, SaaS and hybrid deployments, DR/BCP design, and infrastructure modernization — including 20+ M365 and Azure migrations across healthcare and financial services clients.

☁️AzureAWSSD-WAN / HCI
05

Career Timeline

2026 – Present
Abacus Group
2014 – 2025
BlueNovo / Medicus IT
2006 – 2014
SOME / AnalySys
2026– Present
Manager, Client Technology Management — vCTO Practice
Abacus Group (Abacus Financial) · Financial Services MSP
$70B+
Client AUM
$3M+
Client ARR
8,600
Lines · Reporting Engine
5
Senior Engineers Led
  • Built a Python-based reporting engine (~8,600 lines, 161 functions) that reconciles data across five independent sources — RMM inventory, on-prem AD, endpoint protection, file-server permissions, and M365/Entra — into a single self-contained HTML report with live filtering and drill-down, replacing separate Power BI and desktop-app tooling
  • Created the CTM Engineer Playbook, a 50-task methodology that keeps client assessments and recurring reviews consistent in quality and scope regardless of which engineer runs them
  • Built an AI governance framework evaluating enterprise AI platforms — M365 Copilot, Claude Enterprise, ChatGPT Enterprise, and Gemini — against SEC/FINRA requirements, giving clients a defensible basis for AI adoption decisions
  • Player/coach role — de facto practice owner for assessment methodology and tooling, directly advising clients while leading a team of 5 senior engineers
2014– 2025
Senior IT Consultant → Director → VP, IT
BlueNovo → Abacus Healthcare (acq. by Medicus IT, 2024) · Healthcare MSP & MSSP
15+
Team Members
95%+
Client Satisfaction
20+
M365 / Azure Migrations
50%
DR/BCP Cost Reduction
  • Rose through four roles over eleven years — Senior IT Consultant, Director of IT Managed Services, Director of Infrastructure, and VP, IT — managing both the internal IT budget and client technology budgets across a $6M+ net revenue book of business
  • Scoped and structured $3M+ in signed technology remediation engagements across 10+ healthcare clients — including one program exceeding $1M — spanning data center migration, virtualization, DR, network security, and endpoint modernization
  • Led service desk and NOC operations across a multi-client MSP environment — 15+ person team including NOC, SOC, and Help Desk managers — maintaining 95%+ client satisfaction with defined SLA targets
  • Built a NIST CSF 2.0 cybersecurity practice framework from scratch, mapping 18 controls across all six functions and deploying a SmartSheet-based Security Assessment Plan across 10+ healthcare clients
  • Built an operational monitoring layer across 87 sites, 338 managed devices, and 5,000+ endpoints — surfacing uptime, SLA, and service health into a live Power BI dashboard
  • Led M365 and Azure migrations for 20+ clients including Intune endpoint management, device compliance policies, conditional access, and zero-touch provisioning
  • Navigated the Medicus IT acquisition of BlueNovo, leading service delivery continuity and integration of people, processes, and tooling across the combined organization
  • Reduced orphaned and over-privileged accounts by 50% through automated identity lifecycle management, rolling out MFA and expanded SSO coverage as part of a multi-year Zero Trust initiative
2006– 2014
IT Consultant → Director of IT
So Others Might Eat (SOME) / AnalySys Ent. · Non-profit / Healthcare
75%
Server Footprint Reduction
8
Years as IT Lead
HIPAA
Compliance Programs
250
Users · 20 Sites
  • Came in through an MSP engagement and transitioned to a full-time role, ultimately leading IT for an organization spanning nearly 20 locations and roughly 250 users
  • Reduced server footprint by 75% through VMware virtualization — significant infrastructure modernization for a growing multi-site nonprofit
  • Led HIPAA and PCI-DSS compliance programs including policy development and technical control implementation
  • Managed Windows Server and Exchange migrations across multiple sites with no major service disruptions
1 / 3
06

About Me

IT and security programs succeed when they're built to scale — not just to pass an audit.

I manage the vCTO practice at Abacus Group, a financial services MSP, as a player/coach leading a team of 5 senior engineers. I own the assessment and advisory relationship for a portfolio of financial services clients with $70B+ in combined assets under management and $3M+ in client ARR. My work sits at the intersection of technical delivery, practice automation, and client-facing security leadership — building the tooling and frameworks that let a team deliver consistent, credible advisory at scale.

Before Abacus, I spent eleven years at BlueNovo / Medicus IT rising through four roles from Senior IT Consultant to VP, IT — running NOC and Help Desk operations with manager-level direct reports, driving M365 and Azure migrations for 20+ clients, and scoping $3M+ in signed technology remediation engagements across a healthcare MSP/MSSP environment. I also led the integration workstream following the Medicus IT acquisition of BlueNovo.

I hold the CISSP and CISM and bring a practitioner's perspective to every engagement. I actively use AI tooling across assessment development, reporting, and client advisory work, and I'm genuinely interested in how automation and AI change what's possible for an IT team — and building toward it.

Open to Director and VP-level conversations in IT leadership, security, and operations — across enterprise, MSP, financial services, and healthcare environments.

Jason Benner
20+
Years in IT
12+
Dir & VP Yrs
CISSP
CISM
Active Certs
MCSE · MCP
CCNA · A+ · Net+
Prior Certs
Recommendations

"Jason was not only technically skilled but also a great communicator who made complex problems understandable and worked collaboratively with teams across the organization. I highly recommend Jason for any organization looking for a capable, dependable, and forward-thinking IT professional."

Carolyn Penn, MBA, PHR, SHRM-CP, CPSP
EVP, Chief HR Officer · Colleague at SOME, Inc.

"Jason is a go-to for technical knowledge and a strong people leader. His ability to distill complex technical information into clear, understandable language makes him an effective communicator with both internal and external stakeholders."

Cameron Joelson
Manager, Professional Services · Abacus Healthcare
Verified Credentials