Home / About / Jonathan Pollet
Founder · Red Tiger Security · The Woodlands, Texas
Jonathan Pollet
Jonathan Pollet founded Red Tiger Security in 2008. He started as an electrical and automation engineer on oil field SCADA and PLC systems, and he has worked on the security of industrial control systems since 2001. He still goes to the plant with the assessment team, and he still presents the findings to the board.

Jonathan Pollet, CISSP, CAP, PCIP
Founder and Sr. Security Consultant, Red Tiger Security
Co-founder and Chief Learning Officer, CambiOS Academy
Background
Jonathan began in electrical engineering. As a technician with the U.S. Army Corps of Engineers in New Orleans, he worked on three-phase power and transformers for Mississippi River shore power. He earned a B.S. in Electrical Engineering, with honors, from the University of New Orleans.
Chevron hired him into its SCADA and automation team for upstream production in California's San Joaquin Valley. He designed and installed PLC and SCADA systems for onshore and offshore facilities and set the SCADA, PLC, and IT standards for the field. He then ran professional services at PLCs Plus International, a systems integrator, where his team programmed PLCs, DCS, and HMIs and tied plant data into business systems.
In the late 1990s the industry was moving control systems to TCP/IP and connecting SCADA to the business network. Jonathan saw what that meant for security. In 2001 he founded PlantData Technologies to research SCADA vulnerabilities and assess critical infrastructure. Industrial Defender acquired PlantData in 2006, and Jonathan led professional services and sales there as the company grew. In 2008 he founded Red Tiger Security in The Woodlands, Texas.
Work at Red Tiger
Jonathan leads Red Tiger's plant-safe assessments of live OT in water and wastewater, electric power, oil and gas, transportation, manufacturing, and maritime. The team walks the plant with operations, from the perimeter down to the field devices, then presents the findings and the remediation options to the board. Red Tiger has completed more than 500 assessments with no plant interruptions.
Standards work
- ISA99 and ISA/IEC 62443: early contributor to the committee work and the standards.
- NERC: contributor to Urgent Action 1200 and 1300 and to the CIP standards.
- DHS CFATS: contributor and reviewer for the chemical-sector standards.
- NIST SP 800-82 and SP 800-53: reviewer.
- UK CPNI good practice guide on moving SCADA and PLC networks to IP: contributor.
- GIAC Global Industrial Cyber Security Professional (GICSP): Red Tiger helped develop the certification.
Teaching and talks
- Black Hat USA 2010 briefing: "Electricity for Free? The Dirty Underbelly of SCADA and Smart Meters."
- Black Hat training, "Building, Attacking and Defending SCADA Systems," co-taught with Tom Parker: Black Hat USA 2011, 2012, and 2013, and Black Hat Europe 2014.
- Co-developer of the 5-day SCADA Security Advanced course, first offered in February 2009, and the SCADA Security bootcamp.
- Instruction and collaboration with national-lab and agency programs: INL, Sandia, PNNL, and the NSTB, plus training for DHS, the FBI, and DoD.
- His training library moved to CambiOS Academy, where it continues as on-demand OT cybersecurity courses with virtual labs.
Selected papers
- "Electricity for Free? The Dirty Underbelly of SCADA and Smart Meters" (with Joe Cummins, 2010)
- "Innovative Defense Strategies for Securing SCADA and Process Control Systems"
- "SCADA Security Threats and Vulnerabilities"
- "Safety Considerations for SCADA/DCS Security"
- "Is Your SCADA Network Insecure By Design?"
- "Cyber Vulnerability Testing Techniques for SCADA Consoles and Embedded Devices"
- EPRI best-practices guide to securing SCADA and DCS networks
Certifications and education
- CISSP (ISC2), CAP (ISA), PCIP
- B.S. Electrical Engineering, University of New Orleans