Senior-Level Expertise.
Direct Access.
When you work with JRM360, you work directly with Johny — not a junior consultant or account manager. That's the point.
Johny Metellus
Johny Metellus is the Founder and Principal Consultant of JRM360, bringing over 20 years of hands-on IT and cybersecurity leadership to every client engagement. His career spans helpdesk administration, web and digital project management, enterprise cloud services, and C-suite IT leadership in healthcare.
He has served as IT Manager, Director of IT Infrastructure & Security, and Chief Information Officer — giving him a rare end-to-end perspective that spans both the technical depth of an engineer and the strategic view of an executive.
Outside of client work, Johny is an active security researcher. He runs a homelab SOC with Security Onion, Suricata, and Elastic Stack, publishes open source security tools on GitHub, and documents real-world threat discoveries — including a supply chain malware disclosure involving the Vo1d botnet that was filed with the FBI's IC3.
He founded JRM360 to give Florida businesses direct access to senior-level IT and cybersecurity expertise without the cost structure of a large consultancy or the commitment of a full-time hire.
CIO in Healthcare
Executive IT leadership in regulated environments
CISSP / GRC / Network+
Security-first approach at every engagement
PMP / MBA / Lean Six Sigma
Projects delivered on time and on budget
Microsoft 365 / MCSA
Deep M365 and Azure administration expertise
GRC & Compliance
HIPAA, NIST, and regulatory alignment
Active SOC Researcher
Hands-on threat detection and network forensics
Johny Metellus
Public Contributions & Research
Security work that has been published, shared with the community, or contributed to the public record.
Vo1d Botnet Disclosure
Discovered and documented pre-installed Vo1d botnet malware on a consumer device — a confirmed supply chain compromise. Filed IC3 complaint, reported to AWS and Tencent, published full technical disclosure to GitHub.
RapidHostBaseline
Open source Windows baseline auditing tool with MITRE ATT&CK mapping. Published to GitHub under MIT license for use by security practitioners performing system hardening assessments.
pcap2story
Network packet analysis tool that converts PCAP files into human-readable threat narratives. Features DNS tunneling detection, C2 beacon analysis, VirusTotal enrichment, and a Flask-based whitelist management UI.
Purple Team Framework
Original 12-question Purple Team Framework (6 attacker + 6 defender) for structured adversarial simulation. Published via writeups on Medium, LinkedIn, and GitHub with accompanying lab exercises.
Home Lab SOC
Production-grade home lab SOC on Proxmox with Security Onion, OPNsense, Suricata, Zeek, and Elastic Stack. Monitors real production traffic and is used for ongoing security research and tool development.
Security Writing
Publishes practical cybersecurity content on Medium and LinkedIn covering threat detection, network security, lab walkthroughs, and IT leadership aimed at practitioners and business decision-makers.
Let's Talk About Your IT Needs
No sales pitch. No runaround. Just a straight conversation about what your business needs.
Contact Information
Ocala, Florida
Serving all of Florida