Area of Focus
Risk consulting
Connect

Andrew Weidenhamer

Government Services Cyber Leader, Principal, Risk Consulting
Area of Focus
Risk consulting
Connect

About Andrew

Andrew Weidenhamer is a principal in the RSM US LLP technology risk advisory services practice. With close to 20 years of consulting experience within the information security and data governance field, Andrew has a unique combination of technical and business-related skills which allow him to perform in multiple roles. The bulk of his security/privacy experience has been consulting within the public sector field leading myriad engagements including tactical penetration testing and red teaming engagements to large statewide NIST cybersecurity efforts and strategic roadmap development.

As the security and privacy risk public sector lead, Andrew’s responsibilities range from overseeing large government engagements to providing thought leadership, talent development and other business growth activities.

Outside of work, Andrew is the co-lead of the D.C. OWASP chapter and has helped organize large information security conferences such as OWASP’s annual U.S. flagship conference, AppSec USA. Andrew has spoken at national industry conferences such as Maryland Association of Counties (MACo), ISACA, Defcon, OWASP AppSec, and Rochester Security Summit. He has also worked with security researchers on penetration testing tool development and has author credits on a well-known red teaming offensive security book. Finally, he keeps his skills sharp by taking industry leading training.


Experience

Andrew has served as a subject matter expert and strategic advisor to state and local government entities. He has worked directly with state CISOs to oversee the delivery of large statewide security engagements including NIST CSF assessments and penetration testing. He has led strategic program development efforts in the areas of enterprise vulnerability and identity and access management, led the development of information security programs as a virtual CISO for small and medium-sized businesses, and managed a practice that included a team of over 50 security professionals spread across the United States and around the globe. 


Professional affiliations and designations

  • Information Systems Audit and Control Association
  • DC Open Web Application Security Project
  • International Information Systems Security Certification Consortium (ISC)2
  • Certified information systems security professional
  • Certified red team operator
  • Certified information privacy practitioner-US
  • Qualified security assessor
  • Certified information systems auditor
  • ISO 27001 provisional auditor certified
  • Offensive security certified professional
  • Certified information systems security professional

Education

  • Bachelor of Science, computer engineering, Ohio University