Chell Mendiola

Chell Mendiola

Cybersecurity & Risk in San Francisco, She/Her

About

I'm a believer.

I believe a secure enterprise starts with its people. My goal is to foster secure habits through hacking the human bean to develop good security habits.

I believe good design changes lives and good education saves lives. To that end, I do security and awareness with a dash of visual design.

Work Experience

2022 — Now
San Francisco

Cribl is the data engine for Security and IT. For Cribl, I am one part historian, one part custodian, and one part contriver - translation: I write a lot docs, create a lot of content, which I then cajole, bribe, and threaten people into consuming - all in the hopes of brokering some kind of understanding and creating a stratagem for vanquishing my foes. I'm kidding. It's stratagem for the next fiscal year. Always the upcoming year.

2021 — 2022
San Francisco

Metrics, metrics, and more metrics, usually to do with security training. Policy redrafts and content creation for internal wiki and SCORM training modules.

Responsible for creation and upkeep of Security's front door for the end user.

Create, publish, & maintain security policies, runbooks, education. Cross functionally work with Engineering, Legal, Technical Program Management, Compliance & Risk to create, maintain, track & socialize, training content & metrics for security awareness, infrastructure engineering, mobile developers SDLC, data privacy.

Draft comms, work with brand and marketing for visualization of security metrics. Socialize security initiatives through blog, Show & Tell, #slack, and email. Drafted Risk Governance runbooks and created the Risk Governance Intern Program.

2016 — 2021
San Francisco

2017 - 2021

  • Sat on the Cyber Security Assurance team; ran SOC 2 annual certification. Built Risk Register prototype in Jira, drafted enterprise risk, SOC 2 & COSO kbase in Confluence for end users and auditors. Contributed to FedRAMP documentation.

  • Wrote related security documentation and runbooks. Ran risk and SOC 2 education.

2016 - 2017

  • Operationalized and documented IT processes for automation.

  • Admined Atlassian stack of tools: Jira, Confluence, Fisheye, Crucible. Wrote and published end user support kbase articles.