Drew Ellis
Drew Ellis is a Compliance Program Strategist at Fortra, helping organizations build secure, governable technology environments in highly regulated markets. His work focuses on the intersection of data security, system architecture, governance, and compliance, ensuring regulatory requirements can be operationalized in complex technology environments.
Over the course of his career, Drew has led six FedRAMP authorization programs, including new program builds and the recovery of failing initiatives. He has served as a primary interface to assessors, regulators, government stakeholders, and executive leadership, helping align technical and business teams around defensible security, compliance, and authorization outcomes.
At the center of Drew's approach is the belief that effective compliance begins with understanding the data itself—its sensitivity, ownership, authorized use, location, and mission context. He works closely with leaders across product, engineering, security, operations, and executive management to understand how regulatory requirements, data governance, and system design intersect in real-world environments.
Drew's perspective focuses on translating regulatory obligations into practical operating models that support secure technology delivery at scale. He regularly advises organizations on governance structures, accountability frameworks, evidence strategies, and authorization approaches that enable both security and business objectives.
At Fortra, Drew helps shape federal authorization strategy, regulated-market expansion, and the governance structures required to deliver secure technology platforms in high-assurance environments.
With more than 25 years of experience spanning public-sector operations, federal contracting, cybersecurity, regulated technology, and compliance, Drew brings a practical understanding of how organizations turn complex regulatory requirements into sustainable, defensible business and technology practices.