Who you actually work with.
FedRAMP tells buyers to check an advisor's experience and past performance before engaging them. Reasonable asks. Here are the answers.

Rob Gil
Principal
Sr. Director, Federal Architecture at Okta, working on federal and Department of Defense programs.
Rob Gil has spent over 20 years in security, leading initiatives at cloud service providers including Okta, Elastic, and Salesforce. Through REM5 he advises cloud service providers on the architecture and security work needed to meet the most stringent requirements of the U.S. public sector.
He also contributes to the standards themselves, working on current and emerging guidance from NIST and FedRAMP, and was instrumental in writing the first Okta STIG.
Most advisory stops at control mapping and gap assessment. That tells you which controls you are missing; it does not tell you how to meet them. REM5 helps organizations implement solutions that meet and exceed those controls, for real security and business outcomes rather than a passing score.
Experience and qualifications
- Over 20 years in technology, more than 10 of them working with FedRAMP and DoD Impact Levels.
- Contracted to DISA’s Cloud Computing Program Office on the JEDI program, a $10 billion Department of Defense cloud modernization effort. His first IL4 authorization came out of that work.
- Previously at Elastic, working on its FedRAMP program and leading the Cloud SecOps team. Elastic is now an advisory client.
- Previously at Salesforce, leading one of the engineering TechOps teams responsible for service delivery, availability, and security.
- FedRAMP certification under the 2026 Consolidated Rules, including Certification Classes A through D and Key Security Indicators.
- DoD Impact Level 4 and Impact Level 5 authorization under the DoD Cloud Computing SRG.
- Supply chain security engineering: SBOM, provenance, attestation, and artifact signing.
- FIPS-validated cryptography, DNSSEC, patch automation, and System Security Plan automation.
- Authoring CIS Benchmarks and DISA STIGs, in addition to applying them.
Past performance
- Led Okta’s side of the DISA partnership that produced the Okta Identity as a Service (IDaaS) STIG, published by DISA in May 2025.
- Department of Defense Impact Level 5 authorization work supporting Okta for US Military, which earned its IL5 Provisional Authorization to Operate in July 2026.
- Ongoing advisory engagements across identity, search and observability, human capital management, and supply chain security companies.
- Participated through CISA’s Joint Cyber Defense Collaborative in the development of NIST IR 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse.
- Member of the Chainguard OS Fully User Directed (FUD) Committee.
Interviews and press
- Rob Gil, OktaChainguard Assemble 2026 (opens on YouTube)
- FedRAMP Vulnerability Management Special EventFedRAMP panel with Amazon, Google, Cisco and Wiz (opens on YouTube)
- Announcing Chainguard Libraries for JavaScriptChainguard, September 2025 (opens on YouTube)