Brian Nichols
Director of Infrastructure & Information Security | Fractional CISO
About
As Director of Infrastructure & Information Security at Caravel Autism Health, I focus on managing the Information Security Risk Management program and overseeing a robust cloud technology environment. My work emphasizes safeguarding electronic information assets, including ePHI and PII, through comprehensive governance and risk management frameworks.
With over 16 years of experience in IT operations, cybersecurity, and risk management, I specialize in aligning security initiatives with business objectives in regulated environments. My pragmatic approach ensures the implementation of scalable, secure systems that support privacy, safety, and operational excellence.
Experience
Director, Infrastructure & Information Security
Caravel Autism Health
Jan 2026 – Present(4 mos)
As the Director of Infrastructure & Information Security for Caravel Autism Health, I lead the management of the organization’s Information Security Risk Management program and oversee its cloud technology environment. Safeguarding information, understanding of risk prioritization and remediation, and embedding information security within an overall risk management and governance framework. Responsibilities: • Develop, implement, and maintain a comprehensive Information Security Governance and Risk Management Program to protect electronic information assets, including ePHI, PII, and other sensitive data. • Design, deliver, and support infrastructure and security services for the organization, including cloud systems such as Azure, Microsoft 365, Meraki, ArcticWolf, and related technologies. • Supervise and manage internal teams, vendors, and external partners supporting the IT and information security functions. • Monitor, evaluate, and improve information security controls across the organization. Proactively manage risks to protected data and lead efforts to detect, investigate, and respond to security incidents. • Conduct and document internal and third-party risk assessments regularly, leveraging external partners as necessary. • Develop and implement appropriate policies, procedures, training, and technical controls to mitigate identified risks. • Ensure compliance with HIPAA, PII, and other regulatory or accreditation requirements related to information security.
Fractional CISO
Select Data · Dallas, Texas, United States
Dec 2025 – Present(5 mos)
• Provided part-time executive-level cybersecurity leadership and strategy for organizations. • Developed comprehensive security policies and conducted thorough risk assessments. • Ensured compliance with regulations such as NIST CSF, SOC2, HIPAA, and ISO while managing security incidents. • Trained staff and advised leadership on aligning security measures with business objectives.
Director of Infrastructure, CISO
Select Data · Dallas, Texas, United States
Jan 2021 – Jan 2026(5 yrs 1 mo)
In my role at Select Data, I spearheaded the organization’s cybersecurity strategy and infrastructure operations, ensuring alignment with compliance and business objectives. I successfully led compliance initiatives across multiple environments and developed key performance indicators to enhance threat visibility. My leadership in migrating workloads to Azure significantly reduced infrastructure costs while improving scalability and security.
System Engineer
Select Data · Anaheim, CA
Aug 2019 – Apr 2023(3 yrs 9 mos)
Responsible for designing, implementing, and managing highly available, cost-efficient, fault-tolerant, and scalable distributed systems on Select Data's hybrid Cloud infrastructure. Experience includes: Virtual Infrastructure Administrator: VMware vSphere/ESXi 4.x/5.x/6.x/7.x Windows Server Administrator 2003R2/2008R2/2012R2/2016/2019/2022 (AD DS, DNS, DHCP, TCP/IP.) • Responsible for Cybersecurity Training and Awareness, Network Security, and Risk Management • Responsible for Backup and Disaster Recovery, Standard Care of Data, Shadow IT • Responsible for installing and managing VMware vSphere, ESXi Hosts, SAN, Fiber Channel, Routers, Firewalls, Switches, and VOIP systems • Experience with virtualization and containerization (e.g., VMware, Virtual Box, Docker, and Kubernetes) • Experience with monitoring systems (e.g., SolarWinds/N-able, PRTG, Orion, and Glances.) • Solid scripting skills (e.g., shell scripts, Python) • Solid networking knowledge (OSI network layers, TCP/IP)
Network And Systems Administrator
Select Data · Anaheim, CA
Apr 2012 – Aug 2019(7 yrs 5 mos)
Responsible for the day-to-day operation of networks. Organize, install, and support our organization's computer systems, including local area networks (LANs), wide area networks (WANs), network segments, intranets, and other data communication systems. • Virtual Infrastructure: VMware vSphere 4.x/5.x/6.x/7.x & vCenter Server • Cloud and Hybrid solutions architecture • Window Server administration (2016/2019). • Ubuntu Server x64 & LAMP Stack (TLS 18.04.x/20.04.x) • Containers: Docker Engine, CoreOS rkt, Nginx, Docker Swarm, Network Load Balancing (NLB) • Microsoft SQL Server (2016/2019). • Active Directory: AD DS, GPOs, DHCP, DNS, etc. • Firewall security, cybersecurity, network security including the following vendors: Cylance, Palo Alto Networks, Cisco systems, Malwarebytes, Vipre, Dell EMC, Solar Winds, Symantec.Cloud, & more. • Remote Access (WAN/LAN): Administer remote access systems including VPN & site-to-site VPN. • Storage Area Network (SAN): Administer DELL EMC multi-site SAN infrastructure including FC & iSCSI transport layer. • Security & Compliance: Responsible for security assessments, questionnaires, SOC 1 Audits, HIPAA HITECH • SSL/TLS Encryption, creation, monitoring via JAVA keystore, Apache/Tomcat, IIS, OpenSSL • Experience with Atlassian products (JIRA/Confluence/Crowd/Service Desk) Outstanding customer service skills, as well as excellent verbal & written communication skills. Able to act in a quick and decisive manner to mitigate, identify problems, formulate solutions, negotiate on one's behalf or the behalf of others.
IT Help Desk/Remote Support Technician
Select Data
Feb 2009 – Apr 2012(3 yrs 3 mos)
Advanced support of personal computing systems either remotely or face-to-face at one of our Service Desks • User-facing support of mobile devices i.e. laptops, tablets and smartphones • Support messaging & calendaring services and content collaboration. • Working knowledge of video collaboration. • Responsible for user support from cradle to grave - whether the support is delivered by myself or through another team. • Troubleshooting of client-side network connectivity issues including digital authentication, remote access, secure WiFi and wired connectivity to the internal network. • Apply critical thinking to complex user requests and ensure you are providing as much context and information as possible to deliver the best solutions as quickly as possible. • Manage your workload and ensure tasks are completed right the first time. • Always look for problem trends and recommend ways to improve support across the team. • Support user requests and perform break/fix or remote installations as needed. • Assist remote users with access problems ranging from password resets to network access failures. • Working knowledge of Windows - ranging from resolving registry conflicts to troubleshooting system crashes and performance issues. • Proven experience resolving secure network access problems involving but not limited to digital certificate authentication and client remote access services - either using Juniper Networks or Cisco solutions. • Complete understanding of Microsoft Outlook™ client (Windows & Mac) and Outlook Web Access with experience resolving complex problems and assisting users with advanced functionality. • Applied experience with Microsoft Exchange™ including a firm understanding of Groups and permissions. • Working knowledge of Active Directory and basic AD administration.
Education
Western Governors University
Master of Science - MS, Cybersecurity and Information Assurance
Mar 2026
Rochester Institute of Technology
MicroMasters, Cybersecurity
Feb 2021 – Jun 2021
California State University, Fullerton
Master of Science - MS, Kinesiology
2018 – 2021
California Baptist University
Bachelor of Science - BS, Kinesiology
2015 – 2017
Santa Ana College
Associate of Science - AS, Public Fire Service
2009 – 2011
Orange Coast College
Associate of Arts - AA, Liberal Arts
2001 – 2007
Expertise
Specialties