Named ownership
Every engagement has a clear technical owner, approval path, and escalation route.
Every engagement has a clear technical owner, approval path, and escalation route.
Automation handles consistent transformations; engineers review exceptions and document decisions.
Runbooks, monitoring, access, maintenance, failure behavior, and rollback are part of the design.
Perimeter One is a wholly US owned and operated company focused on security and network segmentation, led by practitioners who have run security programs from all three sides of the industry: as the provider, as the channel, and as the enterprise buyer. The two of us have worked together since 2019, which is why the engagements here are scoped like operations work rather than slideware.
Jason has spent 25 years in enterprise security, infrastructure engineering, and managed service delivery. He founded and ran Type-X Networks and SecNoc for thirteen years, building a multi-tenant detection and response platform that secured healthcare, government, financial services, and commercial clients under one program. He then led the solutions research and development organization at Cloud Harmonics, an Ingram Micro company, where he built an authorized support center and a professional services practice from the ground up for the Palo Alto Networks and Check Point partner ecosystem. His first hire into that support center was Mason Freeman.
Most recently he has served as a vice president of network security engineering at a global financial institution, owning firewall, proxy, cloud edge, and email security for an estate under continuous regulatory scrutiny. There he led the move from legacy perimeter security to a cloud delivered SASE and SSE model and re-architected flat networks into segmented, policy driven zero trust environments. The same playbook, the same runbooks, and the same insistence on rollback paths are what Perimeter One brings to a conversion.
He is a certified instructor for Palo Alto Networks, Check Point, and Google Cloud, has sustained clean SOX and PCI DSS audit outcomes as the primary liaison to internal audit, and has built compliant programs against SOC 2, ISO 27001, NIST 800-53, FedRAMP, HIPAA, and HITRUST. His current work also covers AI security governance, including data boundary controls and alignment to the NIST AI Risk Management Framework and the EU AI Act.
Mason is a principal cybersecurity engineer at a global financial institution, where he owns the unglamorous work that decides whether a firewall estate is actually defensible. He rebuilt the firewall policy attestation and cleanup process there, which raised both the accuracy of who owns each rule and the share of the rulebase that can be shown to be compliant. He also wrote the enterprise decryption policy and put it into production, which is what turns a firewall's advanced inspection features from licensed to useful: traffic nobody decrypts is traffic nobody inspects.
He leads new feature rollouts across the internal firewall estate, and the development of an internal application for attestation and compliance reporting. Before that he deployed Palo Alto infrastructure for customers at Cloudnomics, on premises and in the cloud, covering architecture, planning and execution for organizations of very different sizes, and taking greenfield builds and policy migrations through to the point where the customer's own team could run them.
The two of them go back to the start of all this. Jason built the Palo Alto Networks authorized support center at Cloud Harmonics after Ingram Micro acquired the company, one of only three such centers in North America at the time, and Mason was his first hire into it: a young engineer with more appetite than résumé, taken on because he was plainly willing to do the work and learn it properly. He worked up to tier three, handling the center's hardest cases, and that grounding still shows. He has seen how these platforms fail in the field, not only how they behave in a design document.
He is a certified Palo Alto Networks instructor and has taught the Strata and Prisma curriculum at every level, which is the skill a conversion actually needs on the day the customer's own engineers take the keys.
He also runs a five node Proxmox cluster at home, segmented behind a Palo Alto VM firewall with security profiles, decryption, zone protection, inbound NAT, User-ID and GlobalProtect all in play. It is the same architecture Perimeter One builds for customers, at a scale where he can break it on purpose.
Tell us what you run, what needs to change, and which constraints cannot move. We will help define a practical next step.