FractionalCXO
Brian Nichols

Brian Nichols

Fractional CISO

Director of Infrastructure & Information Security | Fractional CISO

Dallas, United States

About

As Director of Infrastructure & Information Security at Caravel Autism Health, I focus on managing the Information Security Risk Management program and overseeing a robust cloud technology environment. My work emphasizes safeguarding electronic information assets, including ePHI and PII, through comprehensive governance and risk management frameworks.

With over 16 years of experience in IT operations, cybersecurity, and risk management, I specialize in aligning security initiatives with business objectives in regulated environments. My pragmatic approach ensures the implementation of scalable, secure systems that support privacy, safety, and operational excellence.

Experience

Caravel Autism Health

Director, Infrastructure & Information Security

Caravel Autism Health

Jan 2026 – Present(4 mos)

As the Director of Infrastructure & Information Security for Caravel Autism Health, I lead the management of the organization’s Information Security Risk Management program and oversee its cloud technology environment. Safeguarding information, understanding of risk prioritization and remediation, and embedding information security within an overall risk management and governance framework. Responsibilities: • Develop, implement, and maintain a comprehensive Information Security Governance and Risk Management Program to protect electronic information assets, including ePHI, PII, and other sensitive data. • Design, deliver, and support infrastructure and security services for the organization, including cloud systems such as Azure, Microsoft 365, Meraki, ArcticWolf, and related technologies. • Supervise and manage internal teams, vendors, and external partners supporting the IT and information security functions. • Monitor, evaluate, and improve information security controls across the organization. Proactively manage risks to protected data and lead efforts to detect, investigate, and respond to security incidents. • Conduct and document internal and third-party risk assessments regularly, leveraging external partners as necessary. • Develop and implement appropriate policies, procedures, training, and technical controls to mitigate identified risks. • Ensure compliance with HIPAA, PII, and other regulatory or accreditation requirements related to information security.

Select Data

Fractional CISO

Select Data · Dallas, Texas, United States

Dec 2025 – Present(5 mos)

• Provided part-time executive-level cybersecurity leadership and strategy for organizations. • Developed comprehensive security policies and conducted thorough risk assessments. • Ensured compliance with regulations such as NIST CSF, SOC2, HIPAA, and ISO while managing security incidents. • Trained staff and advised leadership on aligning security measures with business objectives.

Select Data

Director of Infrastructure, CISO

Select Data · Dallas, Texas, United States

Jan 2021 – Jan 2026(5 yrs 1 mo)

In my role at Select Data, I spearheaded the organization’s cybersecurity strategy and infrastructure operations, ensuring alignment with compliance and business objectives. I successfully led compliance initiatives across multiple environments and developed key performance indicators to enhance threat visibility. My leadership in migrating workloads to Azure significantly reduced infrastructure costs while improving scalability and security.

Select Data

System Engineer

Select Data · Anaheim, CA

Aug 2019 – Apr 2023(3 yrs 9 mos)

Responsible for designing, implementing, and managing highly available, cost-efficient, fault-tolerant, and scalable distributed systems on Select Data's hybrid Cloud infrastructure. Experience includes: Virtual Infrastructure Administrator: VMware vSphere/ESXi 4.x/5.x/6.x/7.x Windows Server Administrator 2003R2/2008R2/2012R2/2016/2019/2022 (AD DS, DNS, DHCP, TCP/IP.) • Responsible for Cybersecurity Training and Awareness, Network Security, and Risk Management • Responsible for Backup and Disaster Recovery, Standard Care of Data, Shadow IT • Responsible for installing and managing VMware vSphere, ESXi Hosts, SAN, Fiber Channel, Routers, Firewalls, Switches, and VOIP systems • Experience with virtualization and containerization (e.g., VMware, Virtual Box, Docker, and Kubernetes) • Experience with monitoring systems (e.g., SolarWinds/N-able, PRTG, Orion, and Glances.) • Solid scripting skills (e.g., shell scripts, Python) • Solid networking knowledge (OSI network layers, TCP/IP)

Select Data

Network And Systems Administrator

Select Data · Anaheim, CA

Apr 2012 – Aug 2019(7 yrs 5 mos)

Responsible for the day-to-day operation of networks. Organize, install, and support our organization's computer systems, including local area networks (LANs), wide area networks (WANs), network segments, intranets, and other data communication systems. • Virtual Infrastructure: VMware vSphere 4.x/5.x/6.x/7.x & vCenter Server • Cloud and Hybrid solutions architecture • Window Server administration (2016/2019). • Ubuntu Server x64 & LAMP Stack (TLS 18.04.x/20.04.x) • Containers: Docker Engine, CoreOS rkt, Nginx, Docker Swarm, Network Load Balancing (NLB) • Microsoft SQL Server (2016/2019). • Active Directory: AD DS, GPOs, DHCP, DNS, etc. • Firewall security, cybersecurity, network security including the following vendors: Cylance, Palo Alto Networks, Cisco systems, Malwarebytes, Vipre, Dell EMC, Solar Winds, Symantec.Cloud, & more. • Remote Access (WAN/LAN): Administer remote access systems including VPN & site-to-site VPN. • Storage Area Network (SAN): Administer DELL EMC multi-site SAN infrastructure including FC & iSCSI transport layer. • Security & Compliance: Responsible for security assessments, questionnaires, SOC 1 Audits, HIPAA HITECH • SSL/TLS Encryption, creation, monitoring via JAVA keystore, Apache/Tomcat, IIS, OpenSSL • Experience with Atlassian products (JIRA/Confluence/Crowd/Service Desk) Outstanding customer service skills, as well as excellent verbal & written communication skills. Able to act in a quick and decisive manner to mitigate, identify problems, formulate solutions, negotiate on one's behalf or the behalf of others.

Select Data

IT Help Desk/Remote Support Technician

Select Data

Feb 2009 – Apr 2012(3 yrs 3 mos)

Advanced support of personal computing systems either remotely or face-to-face at one of our Service Desks • User-facing support of mobile devices i.e. laptops, tablets and smartphones • Support messaging & calendaring services and content collaboration. • Working knowledge of video collaboration. • Responsible for user support from cradle to grave - whether the support is delivered by myself or through another team. • Troubleshooting of client-side network connectivity issues including digital authentication, remote access, secure WiFi and wired connectivity to the internal network. • Apply critical thinking to complex user requests and ensure you are providing as much context and information as possible to deliver the best solutions as quickly as possible. • Manage your workload and ensure tasks are completed right the first time. • Always look for problem trends and recommend ways to improve support across the team. • Support user requests and perform break/fix or remote installations as needed. • Assist remote users with access problems ranging from password resets to network access failures. • Working knowledge of Windows - ranging from resolving registry conflicts to troubleshooting system crashes and performance issues. • Proven experience resolving secure network access problems involving but not limited to digital certificate authentication and client remote access services - either using Juniper Networks or Cisco solutions. • Complete understanding of Microsoft Outlook™ client (Windows & Mac) and Outlook Web Access with experience resolving complex problems and assisting users with advanced functionality. • Applied experience with Microsoft Exchange™ including a firm understanding of Groups and permissions. • Working knowledge of Active Directory and basic AD administration.

Education

Western Governors University

Western Governors University

Master of Science - MS, Cybersecurity and Information Assurance

Mar 2026

Rochester Institute of Technology

Rochester Institute of Technology

MicroMasters, Cybersecurity

Feb 2021 – Jun 2021

California State University, Fullerton

California State University, Fullerton

Master of Science - MS, Kinesiology

2018 – 2021

California Baptist University

California Baptist University

Bachelor of Science - BS, Kinesiology

2015 – 2017

Santa Ana College

Santa Ana College

Associate of Science - AS, Public Fire Service

2009 – 2011

Orange Coast College

Orange Coast College

Associate of Arts - AA, Liberal Arts

2001 – 2007

Expertise

Specialties

Cloud SecuritySecurity OperationsSecure Network DesignSecure Software DesignComputer ForensicsNetwork SecurityMicrosoft AzureEndpoint SecurityCybersecurity StrategyCloud Infrastructure (Azure & VMware)Risk Management & Compliance (NIST, HITRUST, ISO 27002)Incident Response & Threat ManagementIdentity and Access Management (IAM)Information Security GovernanceGovernance, Risk Management, and Compliance (GRC)Risk Management & CompliancePolicy Development & ImplementationHIPAA-HITECH Security FrameworksManaged Detection and Response (MDR)Managed RiskLinuxCisco TechnologiesVMwareActive DirectoryWindows ServerServersRemote DesktopSQLVMware InfrastructureRoutersCisco Systems ProductsApacheInternet Information Services (IIS)TomcatMySQLCisco IOSTransact-SQL (T-SQL)Operational ExcellenceRoot Cause AnalysisPerformance EngineeringRisk ManagementCorporate GovernanceConfiguration ManagementInformation SecurityHigh Performance Computing (HPC)Ethical HackingCybersecurityPenetration TestingEnterprise Network SecurityIT Infrastructure AnalyticsSQL Server OptimizationCross-Functinoal LeadershipAI/MLLLMsGraphics CardsEnterpriseData Center RelocationData MigrationVPNDell ComputersPrint ServersNetwork AdministrationProject ManagementSANMac OS X ServerIBM ServersLoad BalancingBrocadeRoutingFirewallsNetworkingPuttyCLIDell CompellentTerminalHP Procurve NetworkingMS Reporting ServicesCisco ASADell PowerEdge ServersEnterprise ManagerStorage Area Network (SAN)Brocade Fibre SwitchesCisco Firewall Security

Past companies

Caravel Autism HealthSelect Data

Similar executives