Carmelo Walsh
Cybersecurity Executive | CISO | Security Leader
I’ve spent more than two decades working in cybersecurity, technology, risk, and operations. My career has taken me from hands-on IT and security roles to leading enterprise cybersecurity organizations in healthcare and other highly regulated environments.
Today, I’m particularly interested in the intersection of security, AI, business risk, resilience, and the people who make security programs work.
A little about my work
I’ve led organizations responsible for cyber defense, threat intelligence, incident response, vulnerability management, application security, GRC, and business information security.
I’ve also had the opportunity to lead through some complicated environments; including mergers and acquisitions, divestitures, organizational change, and the inevitable tension between improving security and managing a budget.
I’ve learned that good security leadership isn’t about having the biggest security program or buying the most technology.
It’s about understanding what matters to the business, understanding the risks, and helping people make good decisions.
What I care about
Building capable teams.
Security technology matters, but people ultimately create the processes that make the program work. I’ve had the pleasure of hiring some of the best people and helping people become the best versions of themselves.
Making risk understandable.
Executives shouldn’t need to be cybersecurity experts to make informed decisions about cyber risk. I help translate complex security issues into clear, business-focused decisions by applying quantitative risk management and data-driven analysis.
Improving how security operates.
I’ve always enjoyed finding a better way to do something, especially when that makes the organization both more secure and more efficient. I live my life through Kaizen (改善) principles and make changes for the better.
Keeping security connected to the business.
The goal isn’t security for security’s sake. The goal is helping the organization accomplish its mission safely with customer confidence.
A few things I’ve been fortunate enough to accomplish
94% reduction in enterprise vulnerabilities
$1M+ annual security savings
95% improvement in MTTR
20+ years in cybersecurity and technology
What I write about
7 Habits of Highly Effective People book summary Building a Metrics Program career advice CISM CISSP CISSP vs CISM Cyber Risk Quantification Cybersecurity Career Cybersecurity Certifications Cybersecurity leadership Cybersecurity roles Dan Inosanto Eskrima FAIR Framework Filipino Martial Arts freeCodeCamp How to get into cybersecurity Incident Response Information Security information security risk IT Help Desk Jack Jones Keyboard shortcuts Leadership Development Manny Jacinto Metrics monte carlo simulation NIST cybersecurity framework OpenFAIR Productivity Tips Risk Management Risk management Strategy Security Governance Self Improvement Star Wars Martial Arts Stephen Covey Study Tips Theory of Constraints Threat Intelligence Time Management touch typing Vulnerability Management YouTube shortcuts YouTube tricks
Explore my cybersecurity thinking →
Beyond cybersecurity
Books, Martial Arts, Life Hacks, Videos, Ukulele; or peruse All blog posts.
