Columbus, Ohio · CISSP · U.S. Army veteran

Security only works
when people understand it.

I'm Samuel J. Davis, Director of Information Security and Head of Cybersecurity. I stood up an enterprise security program from nothing, cut PCI audit scope roughly in half, and spend most of my day turning frightening technical problems into decisions a leadership team can actually make.

tip The terminal below is a real conversation. Type help, hire, or just ask a question in plain English.

Diagram of layered security controls arranged in rings, with an inbound attack path stopped before it reaches the core. Samuel J. Davis, smiling, arms folded, in a white shirt in an open-plan office.

Interactive

Pull up a chair. Ask me anything.

No form, no autoresponder. Type a command or a plain-English question and you'll get the same answer I'd give you over coffee. Recruiters: start with hire.

guest@samueljdavis: ~/chat

About

I translate for a living.

Most security failures I've seen weren't sophisticated. They were ordinary: a process nobody owned, an exception nobody revisited, a warning nobody understood well enough to act on. Technology rarely fails alone; it fails alongside a sentence somebody didn't say out loud.

So that's the work. I take the thing the engineers are worried about and tell it as a story the finance team, the board, and the person in the warehouse can all follow. Then I make sure the story ends with a decision instead of a slide.

In practice that means putting the risk and the tradeoffs on the table together. Executives are not asking me to make the call for them. They are asking me to make the call makeable, which means naming what we accept if we do nothing and what each option actually costs us.

I came to security sideways: programmer, architect, web development manager, then senior manager over network, cloud, and web operations. I earned the CISSP on my own initiative and used it to start a conversation that eventually became a formal enterprise security program. Before all of that, I was a Military Police Sergeant and a communications specialist in the U.S. Army, which is where I learned that a plan nobody has rehearsed isn't a plan.

The programs I'm proud of are the ones still standing after I leave. People follow them without being chased, because they understand them. They report bad news early, because the program earned it. And none of it falls over when priorities shift and the org chart gets redrawn.

“If I can't explain the risk in one breath, I don't understand it yet.”
Diagram showing security jargon such as lateral movement and residual risk passing through a translation layer and emerging as plain-English business decisions.
The whole job, in one diagram.

Your turn

You are the executive. Make the call.

This is the job from your side of the table. I bring the risk and the realistic options, each one labelled with what it costs and what it quietly accepts. There is no trick answer here, because in real rooms there rarely is one. Pick the one you would defend out loud.

Four decisions I have had to put in front of leadership, with the tradeoffs attached. This one needs JavaScript. For the short version of how I think about them, type approach in the terminal above.

How I work

Five convictions I keep proving right.

Every one of these started as an argument I had to win with evidence rather than authority.

Wheel of the NIST Cybersecurity Framework functions (Identify, Protect, Detect, Respond, Recover) around a Govern core.

Govern first, or the rest is theater

I built our first program on the NIST CSF, not because frameworks are magic, but because they give a company a shared vocabulary and an honest scorecard. Governance is the boring function everyone skips and the only one that makes the other five stick.

Program design · Policy · Operating model

Comparison showing a large set of in-scope systems on the left reduced to roughly half as many after segmentation and retirement.

Shrink the problem before you defend it

Leading PCI DSS governance and auditor engagement, we cut cardholder scope by about half over three years. Every system we segmented, retired, or took out of the flow was one we never had to patch, monitor, audit, or explain again.

PCI DSS · Compliance strategy · Audit engagement

Zero trust flow where identity, device health, privilege, location, and data sensitivity feed a policy engine that grants scoped access or steps up authentication.

Trust is a verb, checked per request

Identity is the real perimeter now. MFA, SSO, and privileged access management do more for a mid-sized company's risk profile than any appliance, and they do it without asking employees to become security experts.

Concretely, that meant taking the minimum password length from 8 characters to 15 and cutting MFA session trust from 90 days to 7. That is roughly thirteen times more revalidation, and almost nobody noticed except an attacker holding a stolen session.

Zero Trust · Identity · MFA/SSO · Cloud security

Funnel showing twenty or more vendors per year triaged, security reviewed, and passed through a procurement gate to approval, conditions, or rejection.

Your vendors are your attack surface

I put a third-party and SaaS review in front of procurement, not behind it: 20+ vendors a year, assessed on the data and access they'd actually get. Saying “not like that” before a contract is signed costs nothing. Afterward it costs everything.

Vendor risk · SaaS governance · Procurement

Twelve recorded systems sit inside a shaded band of control coverage. Four more sit outside it as dashed outlines marked with question marks, unmanaged because nothing wrote them down.

If you don't know you have it, you can't protect it

Every framework opens with an inventory, and nearly every organization I've walked into has one that stopped being true years ago. You cannot patch, monitor, retire, or defend a system nobody wrote down, and the ones nobody wrote down are precisely where the trouble starts.

So I treat knowing what you own as a control in its own right, not as paperwork that precedes the real work. Lifecycle tracking that matches reality, procurement and onboarding wired together so a thing is known the day it arrives, and offboarding that genuinely closes the door behind it. It is the least glamorous work in security and the foundation every other control stands on.

Asset visibility · Lifecycle governance · NIST CSF Identify

Incident response

Everyone has a plan until the phone rings at 5:00 p.m. on a Friday.

You learn this the first time it happens to you, and every incident since has re-taught it: calm on the bad day is manufactured in advance, out of rehearsal, clear roles, and permission to speak up early. So we rehearse it. Most recently that was a facilitated tabletop that put the plan under real pressure and handed back a short, unflattering list of things to fix.

Incident severity curve across the four NIST SP 800-61 phases: preparation, detection and analysis, containment, eradication and recovery, and post-incident activity.
  • Roles before rules. Who decides, who talks, who touches the keyboard, all settled while it's quiet.
  • Communicate up early. Executives forgive bad news. They don't forgive late news.
  • Blameless review, real fixes. A postmortem that produces a scapegoat produces nothing else.

PCI DSS

Compliance is an outcome, not a goal.

Sound practice is the goal, and compliance is what falls out of it. Run that backwards, chasing the checklist and hoping security follows, and you end up with a binder that passes an audit and an environment that doesn't survive contact with anyone actually trying. I led PCI DSS governance and auditor engagement, and the number I care about isn't the passing grade. It's that cardholder scope came down by roughly half over three years, and stayed down.

  • Shrink it before you defend it. The cheapest control is the system you no longer have. Every system we segmented, retired, or lifted out of the cardholder flow is one nobody has to patch, monitor, assess, or explain again.
  • The auditor is a partner. Treat them like an engineer working the same problem. Show your work, answer the question that was actually asked, and the relationship ends up worth more than the certificate.
  • A floor, not a ceiling. Passing is the least a regulator will accept, not the standard worth building to. Build for the standard and the certificate takes care of itself.

Experience

Twenty-plus years of building the thing, then securing it.

  1. Apr 2023 – Present

    Director of Information Security / Head of Cybersecurity

    Highlights for Children, Inc. · Columbus, OH

    Established and lead the enterprise Information Security function with full accountability for strategy, governance, risk, and incident response across corporate, cloud, and application environments, as the organization's sole dedicated security resource, delivering through a cross-functional task force and third-party partners rather than headcount. Senior-most authority on cyber risk, reporting posture and recommendations directly to executive leadership.

    • Program strategy: built the organization's first formal cybersecurity program: governance, operating model, and a multi-year strategy aligned to NIST CSF 2.0.
    • Executive advisory: advise leadership on risk acceptance and prioritization, always with the tradeoffs attached. My job is to hand over the risk and the realistic options, not one answer dressed up as the only one.
    • Compliance optimization: led PCI DSS governance and auditor engagement, cutting scope ~50% and reducing audit burden and long-term cost.
    • Identity hardening: raised the enterprise minimum password length from 8 to 15 characters and cut MFA session trust from 90 days to 7, increasing identity revalidation roughly thirteenfold.
    • Distributed ownership: launched a cross-functional Security Task Force with liaisons on every IT team, turning vulnerability remediation from centralized chasing into owned accountability.
    • Audit leadership: led the annual PCI DSS compliance effort and coordinated a finance-sponsored IT audit, working directly with external auditors on control evidence, remediation tracking, and closure.
    • Detection maturity: expanded SIEM visibility with network telemetry feeding a 24/7 managed SOC, and ran a facilitated tabletop to pressure-test incident response.
    • Cloud and data platform security: reviewed security architecture and access governance for Microsoft cloud and data platforms, joining modernization work early enough to shape controls before deployment rather than after it.
    • Governance and reporting: turned the security steering committee into a decision forum, reporting posture, risk, and progress to executive leadership on metrics rather than status updates.
    • Emerging tech governance: formalized a structured software approval process and shaped early policy guidance for AI adoption.
    • Risk integration: stood up a formal third-party/SaaS risk program, embedding security review into procurement.
    • Strategic planning: authored the “Resilience Blueprint” multi-year roadmap aligning progress, constraints, and resourcing to business priorities.
  2. Jun 2017 – Apr 2023

    Senior Manager, Network Services

    Highlights for Children, Inc. · Columbus, OH

    Senior operations leader over enterprise network, cloud (Azure), and web platforms, accountable for uptime, resilience, and team performance across business-critical and customer-facing systems.

    • Directed multidisciplinary network, cloud, and web operations teams.
    • Owned an operating budget in excess of $1M.
    • Partnered with application, product, and business teams to deliver infrastructure for growth.
    • Developed engineers, drove operational consistency, and prioritized ruthlessly.
    • Delivered under both Agile and Waterfall, matching the method to the work and the stakeholders rather than to fashion.
    • Earned the CISSP independently and used it to influence the creation of a formal security program.
  3. Earlier career

    Web Development Manager · Applications & Solutions Architect · Senior Applications Programmer · Programmer / Analyst

    Progressively responsible technology roles spanning application development, systems architecture, physical security, enterprise platforms, vendor coordination, and delivery in complex organizations. I've been the person on the other end of the security requirement, which is precisely why mine are written to be implementable.

Four workstreams staged across three years: foundation, then identity, then resilience, then assurance.
Security programs mature in roughly this order. You can't do assurance on a foundation that isn't there yet. The years are sequence, not schedule.

Security culture

The best control I've ever deployed was psychological safety.

You can buy detection. You cannot buy the four seconds in which an employee decides whether to tell you they clicked the link. That decision is made long before the incident, based on how the last person who admitted a mistake was treated.

So I run awareness like storytelling, not compliance homework: short, specific, human, and occasionally funny. I'd rather someone remember one story about a fake invoice than pass a quiz they'll forget by Thursday.

Last year that meant five sessions, covering HR, Finance, IT, the steering committee, and the whole company. Several were requested by business leaders rather than scheduled by me. That is the only attendance metric I actually trust.

And none of it stays at work. The person who learns to spot a fake invoice on Tuesday is the same person who spots the text about their bank on Saturday. I teach it that way on purpose. Security that only works between nine and five was never really understood.

It shows up in the numbers eventually. It shows up in the hallway first.

Network of people where one person reporting a mistake sends a protective signal outward to everyone connected.

Education

B.S., Computer Information Systems
DeVry University, Columbus, OH

Certification

CISSP · (ISC)², 2019
Verify on Credly ↗

Military service

U.S. Army & Army Reserve
Military Police Sergeant · Communications Specialist

Frameworks

NIST CSF · PCI DSS · Zero Trust · Business continuity & disaster recovery

Professional memberships

(ISC)² Central Ohio Chapter Security MBA, Sep 2019 – Present  ·  Central Ohio ISSA Member, Jun 2015 – Present  ·  InfraGard Member, 2015 – 2024

Contact

Let's talk.

I'm open to security leadership roles across the Columbus metro or fully remote, and to fractional and advisory work. If you're standing up a program and want an outside read on it, or you need someone who can explain risk to a room that doesn't work in security, write to me. I'd rather tell you something useful than something polite.

Two working options: on site or hybrid across the Columbus, Ohio metro, or fully remote anywhere.

Prefer the keyboard? Type contact in the terminal.