Stephen Di Rito, CPP, CISM

Director of Risk Management

Denver, Colorado, United States

About

Senior Executive with 40 years of private sector and law enforcement experience demonstrating outstanding collaborative leadership in high risk and complex environments. Strategic thinker who forecasts future requirements, maps out strategy, and uses performance metrics combined with appropriate controls to achieve results. Skillfully drive cultural and operational change across the organization through transparency, communication, and collective discussions with key stakeholders. Experienced business continuity planner with exceptional ability to identify and mitigate risks in a global corporate environment. Certified Information Security Manager (CISM) and known for building cross-functional teams that strengthen Cyber partnerships.

Experience

  • Director of Risk Management at Colorado Academy
    Oct 2025 - Present · 10 mos

  • Vice President of Police, Security, and System Emergency Management at Texas Health Resources
    Mar 2024 - Sep 2025 · 1 yr 7 mos

    Hired to integrate police and security capabilities across a 4390-bed healthcare organization with over 30k employees working in 29 hospitals, 325 clinics, 45 corporate buildings, and over 100 leased medical office buildings. Lead staff of nine Directors and one Chief of Police supporting staff of 435 with a $46.1M operating and $25M capital budget. • Revamped seven department budgets by aligning staff and all expenses to accurately track and manage costs. o Police and security expenses now tracked separately with system costs captured and shared across all sites. • Reduced reliance on contract police and security officers and used cost savings to fund sorely needed training. o Hired three full-time trainers and built a training academy with 2 ½ week integrated police & security course. o Added Quartermaster to manage $3.8M of equipment and Quality Manager to track certifications & licenses. • Built separate team to manage and support all security for 325 clinics across 19 North Texas counties. o Implemented $15M in physical security upgrades to meet standards - on track for completion in 2025. o Includes daily mobile patrols at all clinics to address security concerns and proactively reduce violence. • Expanded the Technology team to modernize & all access and video into an integrated system to manage alarms. o Completed analysis on repair costs and established maintenance service agreement that saves $400k annually. • Completed risk assessment and implemented weapon screening at nine hospitals in under 19 months. o Screened 30k people/month preventing 74 guns, 2,234 knives, and 3,147 other items in six months. • Implemented Fusion business continuity (BC) and Everbridge emergency management (EM) software. o Completed three BC/EM tabletop exercises and implemented security best practices to improve.

  • Vice President, Chief Security Officer at HealthPartners
    Jan 2022 - Mar 2024 · 2 yrs 3 mos

    First CSO selected to integrate and align security for over 27k employees with teams representing 18 separate employers, 8 hospitals, 223 clinics, and over 50 support facilities into a single department including budget, staffing, technology, procedures, and more. Managed $24.1M annual operating budget with $5.1M in capital investments over the first 18 months and commitment for additional $14.9M over the next five years. Skillfully navigated relationships needed to facilitate comprehensive change in this complex environment and inspire confidence in the Security team. • Secured $2.4M in capital to expand capability in two Security Operations Centers (SOC) needed to support sites. • Leading overhaul in technology by integrating 13 access control and 9 video systems into a single standard. o Project in year 2 of 5 with 38% of cameras, and 25% of access control readers plus related hardware replaced. • Took business priorities & developed ERM matrix distilling 231 site assessments into 3-page leader summary. o Matrix integrates site vulnerability assessment with upgrades needed to meet Physical Security Standards. o Engaged leaders across organization to review the site list and prioritize where to make capital investments. o Presented methodology used to other Security leaders at ASIS International Global Security Exchange. • Justified and aligned the Emergency Management and Business Continuity functions under the Security team. o Provides single system-wide responsibility for all incidents from routine to emergency to crisis situations. • Implemented AI weapon detection technology in highest risk hospitals (including level-1 trauma center) to prevent entry at Emergency Department of 61 handguns, 713 knives, and 649 contraband items in first 3 months. • Annual Engagement Survey of all colleagues shows improvement in 9 out of 9 areas over last 18 months with “I feel safe again” and “Security has vastly improved” represented as a consistent theme in comments.

  • Director of Security Operations at Capital One
    Jun 2019 - Jan 2022 · 2 yrs 8 mos

    Responsible for security of 3.6M sq ft of corporate facilities in 36 locations across the United States and Canada including the Capital One Headquarters campus in McLean, Virginia. Provide all protective services at these locations for 65k employees, 10k contractors, and 100k annual visitors with an operating budget of $26.2M. • Leading design standards and security engineering for two major construction projects totaling 2.5M sq ft • Assessed data privacy and information security gaps, then mitigated each and implemented governance controls • Implemented premium armed officer standards and robust training curriculum including bi-annual refresher class o Conducted multiple tabletop and live drills which were tested with outstanding results in a full-scale exercise • Developed protocols and use case for integration of cyber, information, and physical security capabilities: o Cyber assists with Wi-Fi login data for employee self-harm cases and bank branch customer assault cases o Physical Security assists with reviewing video cameras and conducting physical surveillance for cyber cases • Identified deficiency in guidance and authored new Standards, Procedures, & Job Aids needed to protect all sites • Wrote and implemented COVID screening protocols to meet CDC guidance and safely return critical workers

  • Discover Financial Services ()
    • Senior Manager, Enterprise Security Operations
      Jul 2018 - Jun 2019 · 1 yr

      Promoted to lead the Security Operations team with a staff of 73 operating in ten U.S. and two overseas locations. • Responsible for contract security staffing and management of all incidents along with risk mitigation measures • Wrote standardized procedures and developed Key Performance Indicators with metrics to gauge success • Developed and executed plan to collapse eight Operations Centers into two (primary and alternate) which saved the company over $1.1M annually and efficiently used technology to gain enterprise awareness of risk o Utilized IP Radios, enhanced software, consolidated staffing, and integrated systems to simultaneously manage officer dispatch and intelligence functions supporting all employees across the enterprise • Commended for superb leadership abilities and A+ satisfaction surveys by empowering and trusting his team • Managed $12.2M annual budget

    • Senior Manager, Enterprise Security Programs
      Jan 2017 - Jul 2018 · 1 yr 7 mos

      Responsible for establishing the Security Center of Excellence which provides integrated travel security, event security, executive protection, security training, data analytics, and oversight of an incident management database. • Integrated all programs into an intelligence-driven model through the Global Security Operations Center • Successfully completed complex incident management software migration from corporate hosted to the Cloud • Developed Workplace Violence Program and trained five investigators to conduct sensitive victim interviews • Developed roadmap for improving the Travel Security program using a risk-based maturity model • Researched IRS Section 132 tax requirements and completed assessment to identify security protections the company could provide executives as a business requirement without incurring personal tax liability • Managed $3.2M annual budget and programmed for expansion of capabilities over the following five years