CISSP  ·  PMP  ·  MBA  ·  CIO  ·  20+ YEARS ENTERPRISE IT & CYBERSECURITY

Senior-Level Expertise.
Direct Access.

When you work with JRM360, you work directly with Johny — not a junior consultant or account manager. That's the point.

CISSP Certified
PMP Certified
20+ Years Experience
CIO in Healthcare

Johny Metellus

Johny Metellus is the Founder and Principal Consultant of JRM360, bringing over 20 years of hands-on IT and cybersecurity leadership to every client engagement. His career spans helpdesk administration, web and digital project management, enterprise cloud services, and C-suite IT leadership in healthcare.

He has served as IT Manager, Director of IT Infrastructure & Security, and Chief Information Officer — giving him a rare end-to-end perspective that spans both the technical depth of an engineer and the strategic view of an executive.

Outside of client work, Johny is an active security researcher. He runs a homelab SOC with Security Onion, Suricata, and Elastic Stack, publishes open source security tools on GitHub, and documents real-world threat discoveries — including a supply chain malware disclosure involving the Vo1d botnet that was filed with the FBI's IC3.

He founded JRM360 to give Florida businesses direct access to senior-level IT and cybersecurity expertise without the cost structure of a large consultancy or the commitment of a full-time hire.

CIO in Healthcare

Executive IT leadership in regulated environments

CISSP / GRC / Network+

Security-first approach at every engagement

PMP / MBA / Lean Six Sigma

Projects delivered on time and on budget

Microsoft 365 / MCSA

Deep M365 and Azure administration expertise

GRC & Compliance

HIPAA, NIST, and regulatory alignment

Active SOC Researcher

Hands-on threat detection and network forensics

Johny Metellus

Founder  ·  CIO  ·  CISSP  ·  PMP  ·  MBA
CISSP PMP MBA CIO MCSA GRC Network+ 20+ Yrs
Request a Free Consultation
20+
Years Experience
CIO
Healthcare Executive
CISSP
Certified
FL
Statewide

Public Contributions & Research

Security work that has been published, shared with the community, or contributed to the public record.

Vo1d Botnet Disclosure

Discovered and documented pre-installed Vo1d botnet malware on a consumer device — a confirmed supply chain compromise. Filed IC3 complaint, reported to AWS and Tencent, published full technical disclosure to GitHub.

RapidHostBaseline

Open source Windows baseline auditing tool with MITRE ATT&CK mapping. Published to GitHub under MIT license for use by security practitioners performing system hardening assessments.

pcap2story

Network packet analysis tool that converts PCAP files into human-readable threat narratives. Features DNS tunneling detection, C2 beacon analysis, VirusTotal enrichment, and a Flask-based whitelist management UI.

Purple Team Framework

Original 12-question Purple Team Framework (6 attacker + 6 defender) for structured adversarial simulation. Published via writeups on Medium, LinkedIn, and GitHub with accompanying lab exercises.

Home Lab SOC

Production-grade home lab SOC on Proxmox with Security Onion, OPNsense, Suricata, Zeek, and Elastic Stack. Monitors real production traffic and is used for ongoing security research and tool development.

Security Writing

Publishes practical cybersecurity content on Medium and LinkedIn covering threat detection, network security, lab walkthroughs, and IT leadership aimed at practitioners and business decision-makers.

Let's Talk About Your IT Needs

No sales pitch. No runaround. Just a straight conversation about what your business needs.

Contact Information

Location

Ocala, Florida
Serving all of Florida