Michael Simmons

Passionate and Pragmatic Chief Information Security Officer (CISO) | Technology Executive | Board Director | Servant Leader | Casino/Hotel, Restaurant, Airline, and Retail Industry Experience

Dallas-Fort Worth Metroplex

About

Results-driven servant leader with expertise delivering enterprise-wide cybersecurity strategies, enterprise risk management, security engineering, and security operations. Proven record with regulatory compliance (SEC, PCI-DSS, SOX, privacy, and industry specific), mitigating sophisticated adversary attacks with breach remediation experience, and aligning cybersecurity initiatives with business goals. Trusted advisor known for fostering collaboration across C-suite, boardrooms, and external partners. Passionate about building high-performing teams and embedding security within digital transformation strategies to drive business growth and resilience.

Experience

  • Vice President, Information Security at Ulta Beauty
    Jun 2025 - Present · 1 yr 1 mo

  • Cybersecurity Consultant at The Feld Group Institute
    Jan 2025 - Jun 2025 · 6 mos

    Providing cybersecurity advisory and expertise for the development and incorporation of cybersecurity artifacts into The Feld Group Institute’s business and technology transformation, leadership, and dialogue frameworks and associated intellectual capital materials.

  • DICK'S Sporting Goods (Coraopolis, Pennsylvania, United States · Remote)
    • Vice President, Chief Information Security Officer and Technology Operations
      Mar 2023 - Sep 2024 · 1 yr 7 mos

      Oversaw strategic direction and execution of cybersecurity and technology operations to safeguard data and business functions. Domain accountability included enterprise information security governance, risk management, regulatory compliance, privacy technical controls, business/cyber resilience (covering business continuity and disaster recovery), vulnerability management, threat intelligence, security operations, incident response, digital fraud, network and endpoint security engineering, identity and access management, edge security/bot prevention, reliability engineering, test engineering, service desk, computer operations, asset/facilities management, and IT service management. Coached and empowered people, developed team members, and engaged with C-suite executives, the Board of Directors, external partners, law enforcement, and industry groups.

    • Vice President and Chief Information Security Officer
      Nov 2021 - Mar 2023 · 1 yr 5 mos

      Oversaw strategic direction and execution of cybersecurity to safeguard data and business functions. Domain accountability included enterprise information security governance, risk management, regulatory compliance, privacy technical controls, business/cyber resilience (covering business continuity and disaster recovery), vulnerability management, threat intelligence, security operations, incident response, digital fraud, network and endpoint security engineering, identity and access management, and edge security/bot prevention. Coached and empowered people, developed team members, and engaged with C-suite executives, the Board of Directors, external partners, law enforcement, and industry groups.

  • Southwest Airlines (Dallas-Fort Worth Metroplex · On-site)
    • Managing Director and Chief Information Security Officer
      Jan 2019 - Nov 2021 · 2 yrs 11 mos

      Executed company-wide comprehensive security strategies to protect business operations, data, and aircraft. Domain accountability included enterprise information security governance, risk management, regulatory compliance, privacy technical controls, vulnerability management, security software development, threat intelligence, security operations, incident response, network and endpoint security engineering, identity and access management, and edge security/bot prevention. Coached and empowered people, developed team members, and engaged with C-suite executives, the Board of Directors, external partners, law enforcement, and industry groups.

    • Senior Director and Chief Information Security Officer
      Jan 2016 - Jan 2019 · 3 yrs 1 mo

      Executed company-wide comprehensive security strategies to protect business operations, data, and aircraft. Domain accountability included enterprise information security governance, risk management, regulatory compliance, privacy technical controls, vulnerability management, security software development, threat intelligence, security operations, incident response, network and endpoint security engineering, identity and access management, and edge security/bot prevention. Coached and empowered people, developed team members, and engaged with C-suite executives, the Board of Directors, external partners, law enforcement, and industry groups.

  • Brinker International (Dallas-Fort Worth Metroplex · On-site)
    • Senior Director of I.T. Maintenance and Support
      Feb 2015 - Jan 2016 · 1 yr

      Leadership accountability included restaurant and corporate service desks, enterprise applications (inclusive of financials, supply chain, real estate management, and human resources), I.T. quality assurance, restaurant technology deployments, application maintenance/support, and key I.T. service management functions: change management, configuration management, knowledge management, incident management, request fulfillment, problem management, and access management. Coached and empowered people, developed team members, and engaged with C-suite executives, external partners, and industry groups.

    • Director of I.T. Strategy and Enterprise Architecture
      Oct 2012 - Feb 2015 · 2 yrs 5 mos

      Led IT strategy and enterprise architecture initiatives while delivering IT innovation, research, and software development efforts. Responsibilities included building out first-ever organizational enterprise architecture competencies and leading a team of architects and supplier partner resources in defining the enterprise architectural framework, I.T. innovation/research and development, partnering with executive leaders to interpret how business capabilities will impact I.T., defining and maintaining technical standards and a forward looking I.T. strategy/architectural roadmap covering server and network systems, applications, integrations, data/information, and information security, defining and maintaining enterprise architecture governance via the Enterprise Architecture Board, establishing business cases, liaising with and supporting domestic and global franchise partners, and ultimately assuring I.T. is ahead of the business on I.T. solutions. Coached and empowered people, developed team members, and engaged with C-suite executives, external partners, and industry groups.

    • Interim Director of Business Solutions Delivery
      Oct 2013 - Feb 2014 · 5 mos

      In addition to existing I.T. Strategy and Enterprise Architecture responsibilities (October 2012 – February 2015), provided interim leadership over application development, application support, and program management teams covering web systems (internal and external), restaurant online ordering (e-commerce), business intelligence and analytics, integrations, master data management, restaurant technology systems (front of house and back of house covering point of sale, inventory management, kitchen display systems, tabletop tablets, table management/reservations, and team member scheduling), financial systems, human capital systems, real estate management systems, and supply chain systems. Coached and empowered people, developed team members, and engaged with C-suite executives, external partners, and industry groups.