Path study 03
Builders in the chair: the engineers, researchers and product people who became CISOs
Eleven profiled CISOs came up through hands-on technical work: software and security engineering, malware research, breach analysis, product and infrastructure.
Eleven of the 51 security chiefs profiled on this site at launch have a documented stretch of hands-on technical work behind them: writing software, engineering security systems, taking malware apart, analyzing breach data or building cloud infrastructure. The profiles show that this is less one route than four, and in several cases the kind of technical work a person did resembles the business of the company that later hired them to run security.
Engineers who stayed close to code
The plainest version is the software or security engineer who climbed. SecurityWeek noted that Doug Bowers worked as a software engineer early on, before vice president roles at Symantec, Dell and ServiceNow and then the CISO seat at MongoDB in April 2026. At Symantec, according to an older RSA Conference page, his remit combined engineering and product management for endpoint, messaging, web and data center security products.
Mike Marshall took the public-sector version of the same climb. He held titles including security engineer and security architect at California's public employees' retirement system from 2008 to 2017, then ran security at the state's environmental agency, and was named state CISO in August 2026.
Researchers and authors
A second group made its name in research. Michael Sikorski is the author of Practical Malware Analysis and, per RSA Conference, has more than 20 years of incident and research work, including time at the National Security Agency and Mandiant. He was CTO and vice president of engineering at Palo Alto Networks before Coinbase named him CISO in July 2026.
Christopher Porter was a lead analyst and author on Verizon's Data Breach Investigations Report series and co-created the VERIS framework for recording incidents in a standard way, before security leadership at Fannie Mae and the global CISO title at Booz Allen Hamilton. David Raymond has published more than 30 papers on cyber operations, information assurance, wireless protocols and privacy, and co-wrote a book on the operational art of cyber conflict, before becoming Virginia Tech's CISO.
These three share a habit of publishing. Their profiles cite books, reports and papers rather than only job titles, which also makes their careers unusually easy to document from public sources.
Product and platform builders
A third group built products or platforms rather than security tools. Igor Tsyganskiy came to Microsoft's CISO job from seven years running the technology stack at Bridgewater Associates, after senior vice president posts in product management at Salesforce and engineering at WideOrbit. Of the eleven, he is the one whose recorded pre-CISO titles are mostly outside security.
CJ Moses described one of his team's first AWS projects as Amazon Virtual Private Cloud, and by the end of 2011 the whole Amazon.com web fleet ran on it. Paras Malhotra spent nearly a decade at Amazon Web Services, where as principal manager for security assurance he led engineering strategy and the product roadmap, then led information security at Datadog before Starburst. John Walton held a vice president of security engineering title during more than 16 years at Microsoft, then worked at Electronic Arts before Nubank.
Practitioners who built teams
The fourth group moved from doing technical security work to building the teams that do it. Philip Martin built and led incident response and security engineering at Palantir, after working on virtual infrastructure at Amazon's A9, before Coinbase and then Uber. Alan Rosa spent roughly his first decade in general technology work, including at Boeing's defense business, before his first formal security role; he now runs infrastructure and operations alongside security at CVS Health.
Where the builders ended up
In this small set, destinations often echo starting points. The platform and infrastructure builders now run security at MongoDB, Starburst, Microsoft, Amazon, Nubank and Uber, companies whose business rests on large technology platforms. The three researchers landed at Virginia Tech, Coinbase and Booz Allen Hamilton. And Rosa's combined security and infrastructure title at CVS Health is the most literal expression of a technologist's path, since it puts both functions under one executive.
Two cautions apply. First, the tag counts only technical work that a source names; a profile with no engineering tag may simply lack a detailed biography. Second, several of these leaders also fit other paths studied on this site, including military service (Moses, Raymond, Martin, Rosa) and deputy roles (Walton, Moses), so the categories overlap rather than divide the profession.
Sources
The people behind the pattern
Doug Bowers
Chief Information Security Officer
MongoDB
Mike Marshall
State Chief Information Security Officer
California Department of Technology
Michael Sikorski
Chief Information Security Officer
Coinbase
Christopher Porter
Global Chief Information Security Officer
Booz Allen Hamilton
David Raymond
Associate Vice President and Chief Information Security Officer
Virginia Tech
Igor Tsyganskiy
Chief Information Security Officer
Microsoft
CJ Moses
Chief Information Security Officer and VP of Security Engineering
Amazon
Paras Malhotra
Chief Information Security Officer
Starburst
John Walton
Chief Information Security Officer (CISO)
Nubank
Philip Martin
Chief Information Security Officer
Uber