Gauthier Cyber Advisory

Eric Gauthier

From the boardroom to the build pipeline.

Security leadership built for the AI era.

CISO VP SECURITY RISK & COMPLIANCE AI GOVERNANCE

I build security programs that work — ones that pass audits, enable growth, and actually get adopted by the teams they’re meant to protect. 25+ years spanning network engineering, cloud infrastructure, application security, DevSecOps, compliance, and executive leadership.

Eric Gauthier, Cybersecurity Executive
25+
Years of Experience
5+
Security Programs Built from Scratch
50%
Avg. Control Score Improvement, Year 1
10+
Compliance Frameworks
About

Security as an enabler — not a barrier.

I build security programs that work — ones that pass audits, enable growth, and actually get adopted by the teams they’re meant to protect.

With 25+ years of experience spanning network engineering, cloud infrastructure, application security, DevSecOps, compliance, and executive leadership, I bring a full-stack perspective that lets me engage credibly from the boardroom to the build pipeline. I’m equally comfortable presenting risk posture to a board as I am architecting a cloud security control or building an AI-powered security workflow.

Today I lead SideChannel’s vCISO delivery practice — overseeing a team of consultants delivering fractional CISO services to 40+ clients across a broad range of industries — while also advising clients directly, working hands-on to build and mature security programs across technology, manufacturing, hospitality, and higher education.

A consistent theme across my career: I show up where organizations need to build something. Whether that’s founding a security program at Wayfair, building Scout Exchange’s SOC 2-compliant security practice from scratch, or guiding a national manufacturer to completely remediate repeated failed penetration tests showing full-domain compromise — I build things that last.

I’m now focused on helping organizations navigate the AI era — both governing AI risk responsibly and deploying AI to make security programs smarter and more efficient. I've completed ISO 42001 (AI Management Systems) and ISO 31000 (Risk Management) training and actively build AI-powered tooling to enhance security delivery. I also contribute to the ISC² CISSP exam development process and co-authored “The Six Pillars of DevSecOps” for the Cloud Security Alliance.

“The brakes on a car are what allow it to go fast — without them, you drive fast but recklessly, endangering yourself and everyone around you. The right security program works like the brake pedal: invisible in daily use, instinctual for the people who rely on it, yet hiding vast complexity behind something deceptively simple.”
— Eric Gauthier

Security Program Design

End-to-end builds grounded in NIST CSF and ISO 27001 that pass audits and get adopted.

DevSecOps Integration

Embedding security throughout the SDLC with DAST/SAST/SCA scanning and CI/CD hardening.

AI Governance

ISO 42001-based programs and frameworks for responsible, secure AI adoption.

Risk & Compliance

SOC 1/2, PCI-DSS, GDPR, ISO 27001 — audit-ready programs that drive revenue.

Cloud Security (AWS)

Infrastructure-as-code, container and serverless hardening, AWS cost governance.

Incident Response

Led major IR efforts — reduced median resolution from 1 week to 1 day at Lightcast.

Featured Writing

Published thinking on security practice.

A couple of pieces worth a read — one on rethinking phishing defense, one a foundational contribution to DevSecOps practice.

Expertise

Security that gets adopted — not worked around.

That means embedding it into the culture, the pipeline, and the default — not bolting it on at the end and hoping it sticks.

01

Security Program Design & Execution

Building programs from the ground up or maturing existing ones — policy, governance, and operations that pass audits and actually get adopted by the teams they protect.

02

Risk & Compliance Leadership

NIST CSF/SSDF, ISO 27001, SOC 1/2, PCI-DSS, GDPR. Translating audit requirements into prioritized, business-aligned roadmaps rather than checkbox exercises.

03

AI Governance & Strategy

ISO 42001-based governance frameworks for organizations adopting AI — balancing responsible risk management with practical, secure deployment.

04

Cloud Security & Zero Trust Architecture (AWS)

Infrastructure-as-code, container and serverless hardening, and Zero Trust design for cloud-native environments with no legacy perimeter to fall back on.

05

DevSecOps & Application Security

Embedding security throughout the SDLC — automated DAST/SAST/SCA scanning, secure design checklists, and CI/CD pipeline integration that engineering teams actually use.

06

Incident Response & Board Communication

Leading response efforts across endpoint compromise, BEC, and targeted attacks — then translating risk posture clearly for boards and executive leadership.

Expertise

Frameworks & Technologies

Equally at home in a board meeting, a risk assessment workshop, and a CI/CD pipeline review.

Certifications & Credentials
CISSP
ISO 42001 — AI Management Systems
ISO 31000 — Risk Management
ITILv3
ISC² CISSP Exam Development Contributor
InfraGard Member
CSA DevSecOps Working Group
Compliance & Standards
NIST CSFNIST SSDFNIST 800-53ISO 27001ISO 42001ISO 31000SOC 2PCI-DSSGDPRCCPACSA CCMCIS Controls
Security Governance
Security Program DesignRisk AssessmentThird-Party Risk MgmtVendor ManagementSecurity PolicySecurity Awareness TrainingBoard & Executive ReportingAudit ReadinessBusiness ContinuityDisaster RecoverySecurity Committee Leadership
Security Operations & AppSec
SIEMDAST / SAST / SCAEDR / XDRCASB / DLPVulnerability MgmtThreat ModelingPenetration TestingWAF / DDoSIncident ResponseVanta GRC
Cloud, Infrastructure & DevSecOps
AWSDockerServerlessInfrastructure as CodeCI/CDKubernetesDevSecOpsGoogle Workspace
Experience

25 years across security, infrastructure & engineering leadership.

A track record built at some of the web’s largest platforms and SaaS companies. Scroll to explore.

“The best conversations I’ve had with other practitioners weren’t about finding a job or filling a role — they were just two people comparing notes.”

I’m always happy to connect with other security and technology leaders — whether that’s a question about AI governance, navigating compliance in a SaaS or technology environment, or just talking through where the field is headed. No agenda required.

I’m also open to board and advisory roles, and to mentorship or volunteer opportunities where 25+ years of program-building experience is useful.

Book Time →