Cybersecurity Leadership · Risk · Resilience · Transformation

Miguel A. Perez

Chief Information Security Officer / Cybersecurity Executive
CISSPCISMCCSPPMPCompTIA SecAI+

Cybersecurity executive with 25+ years across enterprise, federal, regulated, and classified environments, including 11 years leading an enterprise security function with CISO-equivalent scope. Focused on cyber risk, Zero Trust, cloud and SaaS security, AI governance, incident readiness, data protection, resilience, and turning security strategy into accountable operating practice.

Executive Profile

I operate at the intersection of security strategy, business risk, architecture, resilience, and execution. My work has included building security governance, strengthening identity and access controls, improving audit readiness, leading incident preparedness, modernizing physical and technical security, and translating complex cyber risk into decisions senior leaders can act on.

Strategy

Security as an operating model

Security programs should create accountable ownership, visible risk treatment, and repeatable decision-making—not just policy binders.

Execution

From control intent to implementation

Experienced across IAM, Microsoft security, vulnerability management, SIEM, endpoint protection, vendor risk, incident response, and resilience.

Leadership

Executive-ready risk communication

Translate technical findings into business priorities, remediation ownership, accepted-risk decisions, and clear leadership action.

Selected Impact

A representative set of security leadership outcomes. These will become deeper case studies as the evidence portfolio is developed.

Enterprise Security

Built and matured an enterprise security program

Owned security strategy, governance, operational security, policy, risk management, resilience, and executive reporting.

  • Established risk-register and POA&M-style remediation discipline
  • Embedded security reviews and accountability into daily IT operations
  • Supported audit readiness and evidence-driven control assurance
Zero Trust & IAM

Advanced identity-first security

Strengthened identity controls and reduced reliance on weak access patterns.

  • Microsoft Entra ID / Azure AD
  • Okta, Duo, MFA, access reviews, Windows Hello
  • Secure remote access and endpoint governance
Risk & Resilience

Improved organizational readiness

Strengthened resilience through incident-response planning, tabletop exercises, business continuity, and recovery discipline.

  • Executive tabletop exercises
  • Incident escalation and corrective action
  • Business continuity and disaster recovery alignment
Fraud Prevention

Reduced human and process risk

Combined security awareness and process improvements to address real-world fraud risk.

  • KnowBe4 awareness and phishing-prevention work
  • Process changes to reduce financial exposure
  • Security culture strengthened through practical controls
Physical Security

Modernized access and surveillance controls

Supported modernization of physical-security capabilities and operational readiness.

  • Badge and access-control modernization
  • CCTV / Verkada deployment support
  • Security drills and inspection readiness
AI Governance

Translated AI risk into practical controls

Advised professional and leadership audiences on secure AI adoption, model/vendor risk, data protection, access control, and responsible use.

  • AI security policy and governance concepts
  • Vendor-review criteria and risk assessment
  • Secure adoption guidance for technical and executive stakeholders

Security Philosophy

Effective security leadership is not about maximizing the number of controls. It is about building organizations that can continue operating when controls fail, suppliers fail, systems fail, or attackers succeed.

Resilience

Design for disruption

Efficiency matters. Resilience matters more when the environment is uncertain. Security should test assumptions before adversaries do.

Identity

Move beyond passwords

Identity should increasingly rely on stronger combinations of what a person is and what they possess, reducing dependence on reusable secrets.

Governance

Controls must change behavior

Policies are useful only when they lead to ownership, measurable action, evidence, escalation, and better decisions.

Leadership & Security Capabilities

A CISO-level capability map spanning governance, technical risk, operating resilience, and executive leadership.

Cybersecurity StrategyExecutive Risk CommunicationGRC / Audit ReadinessNIST / FISMA / RMFZero Trust / IAMCloud & SaaS SecurityMicrosoft Entra / M365 / IntuneIncident ResponseBusiness Continuity / DRThird-Party RiskVulnerability ManagementSIEM / MonitoringData Protection / DLP / EncryptionAI Security & GovernanceProgram / Project LeadershipSecurity Culture & Training

Selected Projects & Evidence

Public summaries of deeper evidence-backed work. Over time, each can become a dedicated case-study page.

Enterprise Security Program Buildout

Security governance, risk register, remediation accountability, audit readiness, incident preparedness, vendor risk, and executive reporting.

Case study planned

Identity & Zero Trust Modernization

MFA, Entra ID, Okta, Duo, Windows Hello, access reviews, endpoint governance, and secure remote access.

Case study planned

Small-Business Security Advisory — Steve Benson

Customer-data protection, MFA adoption across critical accounts, access-risk reduction, and practical security improvements.

Evidence in development

Operational Resilience & Incident Readiness

Executive tabletop exercises, incident-response planning, continuity, recovery, escalation, lessons learned, and corrective action.

Case study planned

Credentials

Completed professional certifications supporting cybersecurity leadership, cloud security, governance, AI security, and execution.

Security Leadership

CISSP

Certified Information Systems Security Professional

Governance

CISM

Certified Information Security Manager

Cloud Security

CCSP

Certified Cloud Security Professional

Program Leadership

PMP

Project Management Professional

AI Security

CompTIA SecAI+

Security certification focused on AI-era cybersecurity risks and controls

Education

B.A., Chemistry & Physics

St. Mary’s College of Maryland

Background

A career spanning national-security environments, enterprise cybersecurity leadership, advisory work, and emerging AI-security governance.

2014–2025

Information Security Manager / Enterprise Security Lead — AFGE

Led enterprise security strategy, governance, operations, incident readiness, risk management, resilience, and executive reporting.

2002–2014

Program Security / National Security Support — TASC / NRO

Supported classified mission environments and security programs across national-security contexts.

2026

AI Security Curriculum Advisor / Instructor — Intellectual Point

Advised professional and leadership audiences on secure AI adoption, model/vendor risk, data protection, access controls, and governance.

Let’s connect.

Open to conversations around CISO, vCISO, cybersecurity leadership, enterprise risk, cloud security, AI governance, and resilient security programs.