by CSO staff | Apr 7, 2023 | Cybersecurity
Looking for a qualified candidate or new job? CSO’s security recruiter directory is your one-stop shop.
The recruiters listed below can help you find your next chief information security officer (CISO) or VP of security and fill hard-to-hire positions in risk management, security operations, security engineering, compliance, application security, penetration testers, and computer forensics, among many others.
If you’re a security recruiting firm, we want your information! Our goal is to provide the most complete recruiter resource available, but to do that we need your assistance. Please send the name, contact info and a few sentences about your company and its specialties to Michael Nadeau.
Ready to get started? Browse the table below.
We welcome your submissions.
by CSO staff | Jul 21, 2022 | Cybersecurity
The upper ranks of corporate security are seeing a high rate of change as companies try to adapt to the evolving threat landscape. Many companies are hiring a chief security officer (CSO) or chief information security officer (CISO) for the first time to support a deeper commitment to information security.
Follow this column to keep up with new appointments to senior-level security roles and perhaps gain a little insight into hiring trends. If you have an announcement of your own that you would like us to include here, contact Amy Bennett, executive editor.
New CISO appointments, July 2022
Anne Marie Zettlemoyer joins CyCognito as CSO
Ms. Zettlemoyer has over 20 years of experience in technical leadership and has served as a trusted advisor for Fortune 500 companies, government agencies, law enforcement, security vendors, and think tanks. She was most recently the Business Security Officer and VP of Security Engineering at Mastercard. She is also a Fellow at the National Security Institute, and has held a number of strategic and technical security leadership roles, including the Head of Security Architecture, Engineering, and Solutions at Freddie Mac, Director of the Cyber Think Tank at Capital One, Director of Business Analytics at Mandiant, and Special Advisor for the Director of the US Secret Service. She has served on the board of directors and advisors for several security companies and nonprofits, is a founding board member of Security Tinkerers, and advocated for security policies on Capitol Hill. (H/t Security Magazine)
Andrew Hollister promoted to CISO at LogRhythm
As CISO, Mr. Hollister will expand his role to develop and maintain the company’s security governance model and risk strategies, as well as lead the strategy for the protection, confidentiality, integrity and availability of information assets. Hollister will also lead LogRhythm Labs, directing the mission and strategic vision for the LogRhythm Labs threat research, compliance research, and strategic integrations teams. Hollister has held a number of technology and security roles at LogRhythm since he joined the company in 2012. (H/t PRweb.com)
Tony Faria joins Point32Health as CISO
Mr. Faria has been successful in creating and maturing information security functions at a number of Fortune 500 financial services organizations. He is the co-inventor of patented, award-winning cyber assessment methodology leveraged by FM Global, where he was global CISO. Prior to that he was CISO and Security Strategist at Consortium Networks. He is a recognized industry leader and volunteers his time, expertise and resources to help the security industry and his local community. (H/t LinkedIn)
New CISO appointments, June 2022
Nada Noaman joins The Estée Lauder Companies Inc. as CISO
Ms. Noaman brings over two decades of strategic cybersecurity and management consulting experience in the private and public sectors to her new role. She has led security programs for clients ranging from those in technology, entertainment, media, communications, hospitality, aerospace and defense, retail and consumer, and financial services industries. She brings much of her cybersecurity expertise from over a decade of experience in the Intelligence Community (IC), Department of Defense (DoD), and international NGOs. (H/t LinkedIn)
Kenneth Townsend joins Ingredion Incorporated as CISO
Mr. Townsend is a proven IT and cybersecurity leader with a successful track record spanning over 20 years. He has been successful in a variety of industries and is a highly respected specialist in financial services, retail and healthcare. As an IT and infosec leader, Townsend has led global teams with a focus on establishing infosec programs that align to the business strategy and collaboratively executing IT and security projects. (H/t LinkedIn)
Meredith R. Harper joins Synchrony as SVP, CISO
Prior to joining Synchrony, Ms. Harper held VP, CISO positions at Eli Lilly and Company and Henry Ford Health Systems. Her success has been attributed to her ability to manage large-scale complex programs while advancing the skill sets and careers of her most important assets, her team members. Harper is an active member of the Health Care Compliance Association and holds dual certifications in healthcare compliance and privacy. She is certified as a HealthCare Information Security & Privacy Practitioner through the International Information System Security Certification Consortium, Inc. and a Certified Information Security Manager through the Information Systems Audit and Control Association. Harper is passionate about empowering women and minorities to embark upon careers in technology. She’s committed to transforming the industry by driving engaging and provocative discussions around diversity, equity and inclusion and the value it brings. Harper is an alumna of the University of Detroit Mercy where she received her Master’s in Health Services Administration and her Bachelor of Science in Computer Information Systems. (H/t LinkedIn)
New CISO appointments, May 2022
Eric Galis steps into CISO role at Cengage
Prior to being named CISO, Mr. Galis he had been VP of Compliance and Security for over 4 years. He has over 17 years of experience in information security and risk & compliance. Galis has spent time at two other education software and publishing companies, also within the security function. He got his start in InfoSec at PricewaterhouseCoopers, focusing on the financial services industry. Becoming CISO has been his career goal for some time, he credits the passion and work of his team with helping him rise to the level of this role at Cengage. (H/t LinkedIn)
Angela C. Williams joins UL as VP, Global CISO
Prior to joining UL, Ms. Williams held a number of lead security positions at Hillrom, Blue Cross Blue Shield and Wayne County Michigan, among others. She is a results-oriented CISO with extensive experience leveraging technology to integrate best practice cybersecurity solutions. Williams is a people-oriented leader with a focus to attract, develop and retain the right talent to support a culture of belonging where people thrive. In her spare time, she serves on the Board of the Girls Scouts of Southeast Michigan and as an Advisor for the Henry Ford Community College Computer Information Assurance [CIA] program and University of Detroit Mercy Center for Cyber Security and Intelligence Studies. (H/t LinkedIn)
Ron Sanderson promoted to CISO at Redpoint Global
The appointment is part of Redpoint’s continued commitment to ensuring customer data remains private and secure. Mr. Sanderson is one of Redpoint’s earliest employees. He has taken a leadership role in Redpoint’s security and privacy initiatives, including spearheading SOC 2 compliance and HIPAA certification. He most recently served as Director of Information Security, overseeing the company’s InfoSec awareness training and leading initiatives to build out Redpoint’s Information Security capabilities from the ground up. In his role as CISO, Sanderson will further strengthen Redpoint’s security and privacy approach as the company offers further cloud native offerings to some of the world’s leading retailers, healthcare organizations and financial institutions. (H/t Redpoint Global)
Michael Mestrovich joins Rubrik as CISO
In his new role, Mr. Mestrovich will lead Rubrik’s internal data security efforts and provide cybersecurity and cyber policy expertise to support the company’s mission to secure the world’s data. Mestrovich joins Rubrik with more than 20 years of distinguished IT and security leadership, most recently serving as CISO for the CIA, leading the Agency’s cyberdefense operations, developing and implementing cybersecurity regulations and standards, and directing the evaluation and engineering of cyber technologies. While at the CIA, Mestrovich served on a rotational detail as the Principal Deputy Chief Information Officer for the US Department of State. Before Mestrovich’s career in the public sector, he was a systems engineer at Cisco Systems and served in the US Air Force. (H/t GlobeNewswire)
Roger Hale joins Agora as CSO
Prior to joining Agora, Mr. Hale was CSO at BigD. In his new role, Hale will work with executive management to navigate compliance and security, and determine risk management and security best practices for the organization. He will also serve as the process owner of all assurance activities related to the availability, integrity and confidentiality of customer, business partner, employee and business information in compliance with Agora’s information security and business compliance policies. (H/t PR Newswire)
Rich Baich joins the CIA as CISO and Director of the Office of Cybersecurity
In this role,Mr. Baich will be responsible for leading the strategy and implementation of the Agency’s cybersecurity capabilities throughout CIA’s information technology ecosystem. He comes to the CIA from the American Insurance Group (AIG), where he most recently served as the Global CISO. Previously, Rich was the CISO for Wells Fargo and a principal at Deloitte. He is a retired US Navy Information Warfare Officer and was once assigned as the Special Assistant to the Deputy Director for the National Infrastructure Protection Center at the Federal Bureau of Investigation (FBI). (H/t The Record)
Alex Attumalil promoted to CISO at Under Armour
Mr. Attumalil has been named CISO at Under Armour, where he has been Deputy CISO since 2018. Mr. Attumalil is a transformational leader who has over 18 years of experience in developing, managing, and maintaining information security programs in both the public and private sectors. Previously, he held positions with Vencore, US Government Intelligence Agency, Raytheon, and Lockheed Martin. In his professional career, Mr. Attumalil has taught as an adjunct professor, presented at various cyber conferences, and continues to serve as a technical consultant on various customer advisory boards. (H/t LinkedIn)
Stacy Hughes joins Voya as CISO
Ms. Hughes has more than 20 years of experience leading complex IT initiatives within Fortune 500 financial technology organizations. Most recently, she was the CISO at Global Payments Inc., after holding senior-level positions across governance, compliance and audit functions within the company. In addition, Hughes has been an active industry leader in payment security, serving on the Payment Card Industry (PCI) Security Standards Council Board of Advisors and being recognized by PaymentsSource in 2020 as one of the most Influential Women in Payments. Hughes holds a bachelor’s degree in business administration from Wayne State College and an MBA from DeVry University-Keller Graduate School of Management, Atlanta, GA. (H/t Bakersfield.com)
Keith Dempsey joins ArisGlobal as CISO
Prior to joining ArisGlobal Dempsey, Mr. Dempsey served as CIO/CISO at Xybion Corporation, VP of IT at AIG, and VP of IT at Lehman Brothers. In his new role, he will lead the work to enhance ArisGlobal’s focus on security earlier in the development cycle and represent client-facing functions. He will lead the current advanced electronic guided interceptor system (AEGIS) team and continue to strategically enhance ArisGlobal’s security systems. (H/t PR Newswire)
Nicola McCoy joins RSM as CISO
In her new role, Ms. McCoy will lead the implementation of RSM’s global information security strategy. Joining from Planview, McCoy held the role of Practice Director within the company’s professional services division for over 10 years. There, she acquired a wealth of experience working with FTSE 100 companies, international banks, insurers and defence organizations to enhance key technology governance, architecture, risk and resilience activities, as well as regulatory reporting and enterprise risk management. Prior to this, McCoy spent over 12 years at PwC where she was a key member of the Global IT Security and Global IT functions. (H/t Accountancy Today)
Samuel John Cure joins AMI as CISO
Mr. Cure previously served as CISO of Planview, Inc., and AXIS Capital. Along with his two successful tenures as CISO, he brings a spirit of innovation and expertise in building international cybersecurity programs to the AMI team. He has extensive experience crafting business-aligned cybersecurity programs, providing executive oversight of risk management, including identifying and mitigating security risks in all corporate functions and external-facing products and solutions. With 25 years of experience in the cybersecurity industry, Cure has developed and managed multiple programs and security consulting services with a global focus, spanning North and South America, Bermuda, Europe, and Asia-Pacific. He is known in the field for his trademarked cybersecurity platform, Mr. CISO, developing the IBM X-Force database, and creating several ethical hacking programs for global Fortune 500 companies. (H/t PR Newswire)
by CSO staff | Jun 3, 2022 | Cybersecurity
The upper ranks of corporate security are seeing a high rate of change as companies try to adapt to the evolving threat landscape. Many companies are hiring a chief security officer (CSO) or chief information security officer (CISO) for the first time to support a deeper commitment to information security.
Follow this column to keep up with new appointments to senior-level security roles and perhaps gain a little insight into hiring trends. If you have an announcement of your own that you would like us to include here, contact Amy Bennett, executive editor.
New CISO appointments, May 2022
Eric Galis steps into CISO role at Cengage
Prior to being named CISO, Mr. Galis he had been VP of Compliance and Security for over 4 years. He has over 17 years of experience in information security and risk & compliance. Galis has spent time at two other education software and publishing companies, also within the security function. He got his start in InfoSec at PricewaterhouseCoopers, focusing on the financial services industry. Becoming CISO has been his career goal for some time, he credits the passion and work of his team with helping him rise to the level of this role at Cengage. (H/t LinkedIn)
Angela C. Williams joins UL as VP, Global CISO
Prior to joining UL, Ms. Williams held a number of lead security positions at Hillrom, Blue Cross Blue Shield and Wayne County Michigan, among others. She is a results-oriented CISO with extensive experience leveraging technology to integrate best practice cybersecurity solutions. Williams is a people-oriented leader with a focus to attract, develop and retain the right talent to support a culture of belonging where people thrive. In her spare time, she serves on the Board of the Girls Scouts of Southeast Michigan and as an Advisor for the Henry Ford Community College Computer Information Assurance [CIA] program and University of Detroit Mercy Center for Cyber Security and Intelligence Studies. (H/t LinkedIn)
Ron Sanderson promoted to CISO at Redpoint Global
The appointment is part of Redpoint’s continued commitment to ensuring customer data remains private and secure. Mr. Sanderson is one of Redpoint’s earliest employees. He has taken a leadership role in Redpoint’s security and privacy initiatives, including spearheading SOC 2 compliance and HIPAA certification. He most recently served as Director of Information Security, overseeing the company’s InfoSec awareness training and leading initiatives to build out Redpoint’s Information Security capabilities from the ground up. In his role as CISO, Sanderson will further strengthen Redpoint’s security and privacy approach as the company offers further cloud native offerings to some of the world’s leading retailers, healthcare organizations and financial institutions. (H/t Redpoint Global)
Michael Mestrovich joins Rubrik as CISO
In his new role, Mr. Mestrovich will lead Rubrik’s internal data security efforts and provide cybersecurity and cyber policy expertise to support the company’s mission to secure the world’s data. Mestrovich joins Rubrik with more than 20 years of distinguished IT and security leadership, most recently serving as CISO for the CIA, leading the Agency’s cyberdefense operations, developing and implementing cybersecurity regulations and standards, and directing the evaluation and engineering of cyber technologies. While at the CIA, Mestrovich served on a rotational detail as the Principal Deputy Chief Information Officer for the US Department of State. Before Mestrovich’s career in the public sector, he was a systems engineer at Cisco Systems and served in the US Air Force. (H/t GlobeNewswire)
Roger Hale joins Agora as CSO
Prior to joining Agora, Mr. Hale was CSO at BigD. In his new role, Hale will work with executive management to navigate compliance and security, and determine risk management and security best practices for the organization. He will also serve as the process owner of all assurance activities related to the availability, integrity and confidentiality of customer, business partner, employee and business information in compliance with Agora’s information security and business compliance policies. (H/t PR Newswire)
Rich Baich joins the CIA as CISO and Director of the Office of Cybersecurity
In this role,Mr. Baich will be responsible for leading the strategy and implementation of the Agency’s cybersecurity capabilities throughout CIA’s information technology ecosystem. He comes to the CIA from the American Insurance Group (AIG), where he most recently served as the Global CISO. Previously, Rich was the CISO for Wells Fargo and a principal at Deloitte. He is a retired US Navy Information Warfare Officer and was once assigned as the Special Assistant to the Deputy Director for the National Infrastructure Protection Center at the Federal Bureau of Investigation (FBI). (H/t The Record)
Alex Attumalil promoted to CISO at Under Armour
Mr. Attumalil has been named CISO at Under Armour, where he has been Deputy CISO since 2018. Mr. Attumalil is a transformational leader who has over 18 years of experience in developing, managing, and maintaining information security programs in both the public and private sectors. Previously, he held positions with Vencore, US Government Intelligence Agency, Raytheon, and Lockheed Martin. In his professional career, Mr. Attumalil has taught as an adjunct professor, presented at various cyber conferences, and continues to serve as a technical consultant on various customer advisory boards. (H/t LinkedIn)
Stacy Hughes joins Voya as CISO
Ms. Hughes has more than 20 years of experience leading complex IT initiatives within Fortune 500 financial technology organizations. Most recently, she was the CISO at Global Payments Inc., after holding senior-level positions across governance, compliance and audit functions within the company. In addition, Hughes has been an active industry leader in payment security, serving on the Payment Card Industry (PCI) Security Standards Council Board of Advisors and being recognized by PaymentsSource in 2020 as one of the most Influential Women in Payments. Hughes holds a bachelor’s degree in business administration from Wayne State College and an MBA from DeVry University-Keller Graduate School of Management, Atlanta, GA. (H/t Bakersfield.com)
Keith Dempsey joins ArisGlobal as CISO
Prior to joining ArisGlobal Dempsey, Mr. Dempsey served as CIO/CISO at Xybion Corporation, VP of IT at AIG, and VP of IT at Lehman Brothers. In his new role, he will lead the work to enhance ArisGlobal’s focus on security earlier in the development cycle and represent client-facing functions. He will lead the current advanced electronic guided interceptor system (AEGIS) team and continue to strategically enhance ArisGlobal’s security systems. (H/t PR Newswire)
Nicola McCoy joins RSM as CISO
In her new role, Ms. McCoy will lead the implementation of RSM’s global information security strategy. Joining from Planview, McCoy held the role of Practice Director within the company’s professional services division for over 10 years. There, she acquired a wealth of experience working with FTSE 100 companies, international banks, insurers and defence organizations to enhance key technology governance, architecture, risk and resilience activities, as well as regulatory reporting and enterprise risk management. Prior to this, McCoy spent over 12 years at PwC where she was a key member of the Global IT Security and Global IT functions. (H/t Accountancy Today)
Samuel John Cure joins AMI as CISO
Mr. Cure previously served as CISO of Planview, Inc., and AXIS Capital. Along with his two successful tenures as CISO, he brings a spirit of innovation and expertise in building international cybersecurity programs to the AMI team. He has extensive experience crafting business-aligned cybersecurity programs, providing executive oversight of risk management, including identifying and mitigating security risks in all corporate functions and external-facing products and solutions. With 25 years of experience in the cybersecurity industry, Cure has developed and managed multiple programs and security consulting services with a global focus, spanning North and South America, Bermuda, Europe, and Asia-Pacific. He is known in the field for his trademarked cybersecurity platform, Mr. CISO, developing the IBM X-Force database, and creating several ethical hacking programs for global Fortune 500 companies. (H/t PR Newswire)
Keith Brautigam named Penn State University CISO
Before stepping into the CISO role, Mr. Brautigam served as director of identity and access management (IAM) at the University and was a member of the CISO leadership team. He came to Penn State after departing his IAM role at the University of Iowa. Brautigam is a certified information systems security professional with two decades of experience in IT and cybersecurity. He has been in leadership positions within Penn State for the past eight years, during which he established the University’s IAM program. Brautigam is currently pursuing his MBA and master’s certificate in strategic leadership through Penn State’s World Campus and the Smeal College of Business, which he expects to complete later this year. Brautigam received his bachelor of arts degree in communications and media studies from the University of Iowa. (H/t Penn State University)
Charles Miller joins Blackbaud as CISO
Mr. Miller is active in the cybersecurity community and a sought-after expert. With a background in the financial services industry, Miller has been instrumental in successful mergers, public cloud adoption, digital transformation and driving best-in-class cybersecurity. He has experience in security operations, data configuration management, application security and data protection. Miller most recently served as SVP of Cybersecurity at Truist. Prior to that, he was SVP of Cybersecurity for SunTrust and supported cybersecurity efforts at Capital One and Verizon. (H/t Security Magazine)
by CSO staff | Feb 6, 2022 | Cybersecurity
The problems cybersecurity startups attempt to solve are often a bit ahead of the mainstream. They can move faster than most established companies to fill gaps or emerging needs. Startups can often innovative faster because they are unfettered by an installed base.
The downside, of course, is that startups often lack resources and maturity. It’s a risk for a company to commit to a startup’s product or platform, and it requires a different kind of customer/vendor relationship. The rewards, however, can be huge if it gives that company a competitive advantage or reduces stress on security resources.
The vendors below represent some of the most interesting startups (defined here as a company founded or emerging from stealth mode in the past two years).
Grip Security
As organizations use more software-as-a-service (SaaS) platforms, security teams can find it hard to monitor and guard against the risks they present. Grip Security’s product promises to provide greater visibility across all SaaS platforms used in an organization. According to the company, this allows for better enforce security policies and identify security blindspots. The Grip platform can work standalone or with a cloud access security broker (CASB).
JupiterOne
The cloud-native JupiterOne cyber asset attack surface management platform promises to bring more context to a range of security processes including vulnerability management, compliance, and identity and access management (IAM). The company also claims that its platform can better enable organizations to comply with security regulations. Enabling this are JupiterOne’s integration capabilities, which allow it to work within the existing security environment.
Lightspin
Lightspin offers a cloud-native application protection platform (CNAPP) that the company claims can identify, prioritize and remediate attack paths within the cloud stack. The platform will work in any cloud hosting environment including Amazon Web Services (AWS), Azure and Google Cloud Platform (GCP). The Lightspin platform works across all phases of DevOps. For example, it can perform IaC and API scanning during build, identify misconfigurations and exposed secrets during production, and provide malware and runtime protection during runtime.
Noetic Cyber
Noetic Cyber sells what it calls a “continuous cyber asset management and controls platform.” The company claims that this platform can provide greater visibility into the network, improved controls monitoring, and a better understanding of the relationship network entities. On the last point, Noetic’s platform can map relationships among assets to help identify security gaps. Noetic also offers integration with orchestration and automation workflows.
Polar Security
Tracking what Polar Security calls “shadow data” across the cloud can be a challenge. The company attempts to meet that challenge with its data security posture management (DSPM) solution, which it claims is the first automated data security and compliance platform. According to Polar Security, its platform will automatically map and follow data and data workflows of cloud-native data to better prevent vulnerabilities and meet regulatory compliance. Once the platform identifies data, an automated labeling feature allows for classifying sensitive data.
Revelstoke
Revelstoke offers what it claims is the first low-code security orchestration, automation and response (SOAR) platform. The company’s aim is to simplify the implementation and management of SOAR. It does so by offering low-code playbooks to automate security processes, pre-built integrations built on a unified data layer, case management though what it calls “guided investigations”, and a dashboard-based user interface.