Security is personal to me — and so is how I work with clients.

I started RitchSec because I believe every organization deserves senior-level security leadership, not just the ones large enough to afford a full-time CISO.

Horacio Ritch, founder of RitchSec
My story

20 years. Three countries. One mission.

My path to cybersecurity didn't start in a corporate office — it started in the U.S. Marine Corps.

From 2004 to 2008, I served as a Network Administrator and Data Chief at Camp Lejeune and in the Middle East, managing over $1.75 million in communications equipment and implementing DOD and NSA security standards in some of the most demanding environments imaginable. Four years. Zero major security incidents.

That experience shaped how I think about security — not as a checkbox or a compliance exercise, but as something that genuinely matters. When the stakes are real, you don't cut corners.

After the Marines, I built a career across some of the most security-demanding industries in the world — financial services, healthcare, energy, and federal contracting. I've led security programs at Fortune 10 companies, built ISO 27001 programs for GE's global operations, served as a FedRAMP SME for companies pursuing federal authorization, and managed enterprise security engineering for Fiserv, one of the largest financial technology companies in the world.

Most organizations don't need more tools or more frameworks. They need someone they can trust — someone who will tell them the truth about where they stand, build something that actually works, and be there when things get hard. That's what I built RitchSec to be.

A few things worth knowing

20+

years in enterprise cybersecurity

4

years U.S. Marine Corps, Camp Lejeune & Middle East

0

major security incidents during Marine Corps service

30%

cost reduction delivered at a Fortune 10 company

$1.75M+

communications equipment managed and secured in active operations

Fortune 10

company experience — Fiserv, GE

6

major compliance frameworks mastered

2

languages — English & Spanish

Where I've worked

2019–2024

Senior Advisory Manager, Information Security Engineering

Fiserv

Led enterprise security engineering for one of the world's largest fintech companies. Primary technical lead for Web Application Firewall (WAF) protection across Fiserv's entire online presence. Reduced implementation timelines by 30% through process optimization. Managed a team of 8 security engineers.

2015–2017

Lead IT Security Analyst, SaaS & Software Solutions

GE Grid Solutions

Led ISO 27001 certification and global expansion for GE Grid Solutions' SaaS and Software division. Security lead for GE's transition to AWS. Responsible for ISMS implementation and enforcement worldwide.

2014–2015

Information Security Analyst III

QTS Data Centers

Developed QTS's Information Security Office from the ground up. Served as FedRAMP SME for federal certification process. Led corporate security audit engagements across NIST, FIPS, SOC 1/2/3, HIPAA, and PCI DSS.

2008–2014

Information Security Analyst

Ceridian / FIS

Primary technical resource for WAF implementation, Identity Management migration, and enterprise-wide encryption deployment. Led multinational team covering multiple time zones.

2004–2008

Network Administrator, Data Chief

United States Marine Corps

Camp Lejeune, NC & Middle East. Managed $1.75M+ in computer and telecommunications equipment. Implemented DOD and NSA standards. Zero major security incidents during tenure.

A word on how I work

"I run a small, focused practice by design. When you work with me, you work with me — not a team of analysts managed from a distance. Not a junior consultant who just passed their first certification. Me, directly, with 20+ years behind every recommendation I make.

I also believe in being straight with people. If I think you're heading in the wrong direction, I'll tell you. If I don't think I'm the right fit, I'll say that too. Life's too short for consultants who just tell you what you want to hear.

I'm based in Alpharetta, Georgia. I work remotely and travel as needed. I'm bilingual in English and Spanish — useful for clients with international operations."

Let's get to know each other.

The best way to find out if we're a good fit is to talk. Book a free 30-minute call and let's see what we can build together.

Schedule a Free Call →