Cybersecurity Leadership · Risk · Resilience · Transformation

Miguel A. Perez

Chief Information Security Officer / Cybersecurity Executive
CISSPCISMCCSPPMPCompTIA SecAI+

Cybersecurity executive with 25+ years across enterprise, federal, regulated, and classified environments, including 11 years leading an enterprise security function with CISO-equivalent scope. Focused on cyber risk, Zero Trust, cloud and SaaS security, AI governance, incident readiness, data protection, resilience, and turning security strategy into accountable operating practice.

Executive Profile

I operate at the intersection of security strategy, business risk, architecture, resilience, and execution. My work has included building security governance, strengthening identity and access controls, improving audit readiness, leading incident preparedness, modernizing physical and technical security, and translating complex cyber risk into decisions senior leaders can act on.

Strategy

Security as an operating model

Security programs should create accountable ownership, visible risk treatment, and repeatable decision-making—not just policy binders.

Execution

From control intent to implementation

Experienced across IAM, Microsoft security, vulnerability management, SIEM, endpoint protection, vendor risk, incident response, and resilience.

Leadership

Executive-ready risk communication

Translate technical findings into business priorities, remediation ownership, accepted-risk decisions, and clear leadership action.

Selected Impact

A representative set of security leadership outcomes. These will become deeper case studies as the evidence portfolio is developed.

Enterprise Security

Built and matured an enterprise security program

Owned security strategy, governance, operational security, policy, risk management, resilience, and executive reporting.

  • Established risk-register and POA&M-style remediation discipline
  • Embedded security reviews and accountability into daily IT operations
  • Supported audit readiness and evidence-driven control assurance
Zero Trust & IAM

Advanced identity-first security

Strengthened identity controls and reduced reliance on weak access patterns.

  • Microsoft Entra ID / Azure AD
  • Okta, Duo, MFA, access reviews, Windows Hello
  • Secure remote access and endpoint governance
Risk & Resilience

Improved organizational readiness

Strengthened resilience through incident-response planning, tabletop exercises, business continuity, and recovery discipline.

  • Executive tabletop exercises
  • Incident escalation and corrective action
  • Business continuity and disaster recovery alignment
Fraud Prevention

Reduced human and process risk

Combined security awareness and process improvements to address real-world fraud risk.

  • KnowBe4 awareness and phishing-prevention work
  • Process changes to reduce financial exposure
  • Security culture strengthened through practical controls
Physical Security

Modernized access and surveillance controls

Supported modernization of physical-security capabilities and operational readiness.

  • Badge and access-control modernization
  • CCTV / Verkada deployment support
  • Security drills and inspection readiness
AI Governance

Translated AI risk into practical controls

Advised professional and leadership audiences on secure AI adoption, model/vendor risk, data protection, access control, and responsible use.

  • AI security policy and governance concepts
  • Vendor-review criteria and risk assessment
  • Secure adoption guidance for technical and executive stakeholders

Security Philosophy

Effective security leadership is not about maximizing the number of controls. It is about building organizations that can continue operating when controls fail, suppliers fail, systems fail, or attackers succeed.

Resilience

Design for disruption

Efficiency matters. Resilience matters more when the environment is uncertain. Security should test assumptions before adversaries do.

Identity

Move beyond passwords

Identity should increasingly rely on stronger combinations of what a person is and what they possess, reducing dependence on reusable secrets.

Governance

Controls must change behavior

Policies are useful only when they lead to ownership, measurable action, evidence, escalation, and better decisions.

Leadership & Security Capabilities

A CISO-level capability map spanning governance, technical risk, operating resilience, and executive leadership.

Cybersecurity StrategyExecutive Risk CommunicationGRC / Audit ReadinessNIST / FISMA / RMFZero Trust / IAMCloud & SaaS SecurityMicrosoft Entra / M365 / IntuneIncident ResponseBusiness Continuity / DRThird-Party RiskVulnerability ManagementSIEM / MonitoringData Protection / DLP / EncryptionAI Security & GovernanceProgram / Project LeadershipSecurity Culture & Training

Selected Projects & Evidence

Public summaries of deeper evidence-backed work. Over time, each can become a dedicated case-study page.

Enterprise Security Program Buildout

Security governance, risk register, remediation accountability, audit readiness, incident preparedness, vendor risk, and executive reporting.

Case study planned

Enterprise Identity & Zero Trust Modernization

Led a 493-user MFA, SSO, identity-governance, and access-lifecycle transformation using Okta and Duo, with phased deployment, user training, role-based application access, privileged-account separation, quarterly reviews, and NIST 800-53 evidence.

Small-Business Security & Resilience — SteveBenson.com

Designed a right-sized security and business-continuity approach for a small music studio, expanding cloud protection from temporary file sharing measured in tens of megabytes to automated backup of nearly the full dataset—just under 1 TB—while strengthening identity, network segmentation, recovery readiness, and protection of customer data.

Operational Resilience & Incident Readiness

Executive tabletop exercises, incident-response planning, continuity, recovery, escalation, lessons learned, and corrective action.

Case study planned

Credentials

Completed professional certifications supporting cybersecurity leadership, cloud security, governance, AI security, and execution.

Security Leadership

CISSP

Certified Information Systems Security Professional

Governance

CISM

Certified Information Security Manager

Cloud Security

CCSP

Certified Cloud Security Professional

Program Leadership

PMP

Project Management Professional

AI Security

CompTIA SecAI+

Security certification focused on AI-era cybersecurity risks and controls

Education

B.A., Chemistry & Physics

St. Mary’s College of Maryland

Background

A career spanning national-security environments, enterprise cybersecurity leadership, advisory work, and emerging AI-security governance.

2014–2025

Information Security Manager / Enterprise Security Lead — AFGE

Led enterprise security strategy, governance, operations, incident readiness, risk management, resilience, and executive reporting.

2002–2014

Program Security / National Security Support — TASC / NRO

Supported classified mission environments and security programs across national-security contexts.

2026

AI Security Curriculum Advisor / Instructor — Intellectual Point

Advised professional and leadership audiences on secure AI adoption, model/vendor risk, data protection, access controls, and governance.

Let’s connect.

Open to conversations around CISO, vCISO, cybersecurity leadership, enterprise risk, cloud security, AI governance, and resilient security programs.