Chris Jolley

Director of Information Security | Enterprise Cybersecurity, Risk & GRC | Executive & Board Advisory

United States

About

I’m a cybersecurity executive focused on building security programs that enable the business, scale with growth, and hold up under real-world pressure. My background spans regulated commercial environments and mission-critical federal systems, where reliability, trust, and disciplined risk management matter more than security theater. I currently serve as Director of Information Security, leading enterprise security operations and the continued maturation of the security program within a regulated insurance environment. My scope includes incident response, threat detection, vulnerability and exposure management, governance and risk, and executive-level security reporting, with a strong emphasis on practical execution and continuous improvement. Earlier in my career, I led global cybersecurity operations supporting large healthcare platforms and federal systems, including Veterans Affairs environments through Oracle Cerner and Department of Defense missions through Northrop Grumman. These roles required calm decision-making, clear accountability, and strong coordination across technical, operational, and executive teams during high-impact incidents. Known for leading through influence, building durable cross-functional partnerships, and translating complex security risk into clear, actionable guidance for executives and boards. I’m most effective in environments that value accountability, collaboration, and long-term thinking over short-term fixes. I’ve spent my career building teams and programs that leaders trust when it matters most.

Experience

  • Director of Information Security at The Baldwin Group
    Aug 2023 - Present · 2 yrs 11 mos

    Senior cybersecurity leader responsible for the day-to-day operation and maturity of the enterprise security program within a regulated insurance environment, supporting a distributed enterprise. Lead security execution and incident response while advising executive leadership on cyber risk, prioritization, and regulatory obligations. • Own enterprise security operations across incident response, threat detection, vulnerability management, endpoint protection, and security monitoring • Lead enterprise governance, risk, and compliance (GRC), including risk identification, analysis, prioritization, and treatment • Serve as the primary cybersecurity advisor to executive leadership; partner closely with IT, infrastructure, applications, compliance, privacy, and legal teams • Led an enterprise NIST CSF assessment and built a multi-year, risk-prioritized security roadmap • Implemented SIEM + MDR capabilities to strengthen 24×7 detection and response • Established continuous vulnerability and exposure management with risk-based remediation governance • Developed board-level cybersecurity reporting to communicate risk posture and priorities

  • Senior Manager → Director, Cybersecurity Operations at Cerner Corporation
    Sep 2017 - Aug 2023 · 6 yrs

    Led cybersecurity operations across federal and commercial healthcare environments, including Veterans Affairs systems and large-scale commercial platforms, during and after Oracle’s acquisition of Cerner. • Built and led cybersecurity operations spanning incident response, threat detection, vulnerability management, and security monitoring • Owned a $9M+ security operations budget and led a team of 30+ security professionals • Protected more than 150,000 assets across regulated federal and commercial environments • Designed and implemented an enterprise telemetry and SIEM strategy ingesting multiple terabytes of security data daily • Partnered with GRC teams to align security operations with HIPAA, NIST, HITRUST, SOC 2, and PCI requirements

  • Multiple Progressive Leadership & Technical Roles at Northrop Grumman
    2003 - 2017 · 14 yrs

    Held progressively senior technical and leadership roles supporting U.S. Department of Defense and allied nation missions across domestic and international environments, including long-term leadership assignments in the Middle East. Selected roles held: • Regional Manager — Counter Rocket, Artillery, and Mortars (C-RAM), Afghanistan • Site Manager — Regional Computer Emergency Response Team (RCERT), Kuwait / Southwest Asia • IT Project Lead — Joint Intelligence & Joint Operations Centers, Kuwait Ministry of Defense • Network Engineer / OSP–ISP Supervisor • Project Manager — Enterprise IT & Infrastructure Programs • Led regional cyber defense and incident response operations across multiple countries, supporting sovereign and coalition networks • Directed large, distributed teams delivering secure communications and infrastructure in high-risk, mission-critical environments

  • Army Officer at Army National Guard
    1986 - 1995 · 9 yrs

    Served as an Army National Guard officer with leadership responsibility for personnel, operations, and mission execution.