Thomas A. Giacchetti

Information Security Leader | Building and scaling security programs across regulated industries.

New York City Metropolitan Area

About

I've spent 20+ years keeping critical systems running and secure, starting in places where failure got people killed. I came up in the U.S. Air Force, working in avionics and then network systems, including a combat deployment running network operations under fire. That's where I learned to rebuild complex systems under real pressure, with a sense of urgency and with whatever I had. It's still how I work. Since then, my security career has run through healthcare, medical devices, insurance, and clinical research: building and scaling security operations, risk, and governance programs, and leading teams through acquisitions and transformation. At Worldwide Clinical Trials I was hired to build and lead the information security program as the company scaled for growth. I took a small, operations-focused team and matured it into a structured program across security operations, risk and governance, and awareness. I also extended security oversight into areas I didn't directly own and built the cross-functional relationships that make governance work in a regulated, validated clinical-systems environment. That program has since grown into a multi-tower security organization. The thing I push hardest: security has to move at the speed of the business. The real work is holding the line on critical risk and everyday hygiene while keeping process light enough that the business moves faster, not slower. Done right, security is the reason the business can move, not the reason it can't.

Experience

  • Senior Director, Information Security at Worldwide Clinical Trials
    Aug 2021 - Present · 5 yrs

    Hired to build and lead the information security program for a growing global CRO that needed to scale, mature, and reduce risk. Inherited a two-person team focused on incident response fundamentals and built it into a structured program. • Formalized a hybrid Security Operations Center and incident response program, integrating managed detection and response, standardized playbooks, and regulatory-aligned coordination with QA, Legal, and Privacy. • Stood up the cyber risk and governance function, including a formal enterprise risk register and a recurring risk-assessment program, and drove ISMS and policy development toward ISO 27001. • Built enterprise security awareness from the ground up, cutting phishing click-through by roughly 75%. • Extended security governance into capabilities outside direct ownership by establishing oversight relationships with leaders across the business. • Advanced zero-trust architecture modernization and strengthened reporting frameworks that informed leadership decision-making.

  • Senior Director, Information Security Operations at Magellan Health
    Dec 2020 - Aug 2021 · 9 mos

    Recruited during a period of expanded security investment to rebuild and mature security operations for a national managed-healthcare company. • Designed and stood up a 24/7 Security Operations Center, integrating existing staff and systems into a functioning operation. • Cut a critical vulnerability backlog by roughly 80% through risk-based prioritization with senior business and IT leaders. • Partnered with the Business Information Security Officer team to develop customer-facing security services and deliverables, helping rebuild client trust.

  • BD ()
    • Business Information Security Officer
      Aug 2019 - Dec 2020 · 1 yr 5 mos

      Owned information security strategy for BD's R&D business units and embedded security into how product teams worked. • Built a functional risk profile from NIST requirements, security event history, and threat reporting, and used it to establish a governance model with R&D executive leadership. • Partnered with IT and security leaders to creating transparency into security deliverables across the system lifecycle. • Established a security champions program, embedding security expertise inside agile development teams.

    • Senior Manager, Security Operations
      Aug 2016 - Aug 2019 · 3 yrs 1 mo

      Led BD's security operations function (continuous monitoring, cyber threat intelligence, vulnerability management) through a security transformation. • Aligned and matured capabilities to the NIST Cybersecurity Framework and ISO 27002, exceeding maturity targets in the first year. • Met a strategic partner's third-party security requirements under their supply-chain risk program, leading the remediation that lifted BD's rating to the highest tier within three months and protected the partnership. • Led security integration for mergers, acquisitions, and divestitures, and identified managed services consolidation opportunities that reduced operating expense by roughly 10% without increasing risk.

    • Senior Risk Analyst, Information Security
      Sep 2015 - Aug 2016 · 1 yr

      Ran risk analysis across a portfolio of information-system projects and managed BD's information security program initiatives, including the rollout of its governance, risk, and compliance platform.

  • Cybersecurity Advisory Board Member at Rutgers University
    Aug 2018 - Jul 2019 · 1 yr

    Advised on cybersecurity program direction and industry alignment.

  • United States Air Force (8 yrs 3 mos)
    • Manager, Information Protection
      Jun 2003 - Nov 2007 · 4 yrs 6 mos

      Led information protection and network operations across communications and security roles, including a combat deployment to Iraq. • Served as the designated Information Systems Security Officer for the wing's networks, leading a small team and owning information assurance. • Turned around an under-performing information-protection office, raising vulnerability compliance to 99% from one of the lowest rates in the command. • Deployed to Kirkuk, Iraq, running network operations under sustained fire, including a wartime Active Directory migration and a denial-of-service response that kept joint forces connected.

    • Guidance & Control Systems Specialist
      Sep 1999 - Jun 2003 · 3 yrs 10 mos

      Maintained C-130 flight-control and guidance avionics across home-station and deployed operations, sustaining mission readiness in combat-airlift environments.