FractionalCXO
Kurt S.

Kurt S.

Fractional CISO

Cybersecurity Leader | CISO | Security Architecture | SecOps | GRC | AI Risk Management | Healthcare, SaaS, Compliance | Open to Executive & Advisory Roles - The only story that matters is the one you’re working on.

Portland, United States

About

CISO and cybersecurity executive with 18 years of experience building audit-ready, multi-cloud security programs for regulated industries.

Professional Brief:

• Building security programs from zero to enterprise scale

• Healthcare & regulated environments (HITRUST, SOC 2, NIST, FedRAMP)

• Leading security through M&A and a $400M acquisition

• Multi-cloud security architecture (AWS, Azure, VMware)

• Enabling growth, AI adoption, and compliance

Experience

DigitalCyx

Cybersecurity Consultant | vCISO | Fractional CISO | Security Architecture & GRC

DigitalCyx

Apr 2025 – Present(1 yr 1 mo)

Delivering cybersecurity consulting, vCISO and fractional CISO services for organizations scaling securely in healthcare, SaaS, and regulated industries. Build audit-ready, cloud-first security programs aligned with NIST, SOC 2, HITRUST, and HIPAA. Advise executives and boards on cyber risk, GRC, AI security, and architecture to drive resilience, compliance, and business growth.

Vālenz®

Chief Information Security Officer

Vālenz® · Wayne, PA

Apr 2017 – Apr 2025(8 yrs 1 mo)

Recruited to modernize and scale Valenz’s IT and cybersecurity strategy. Designed and led implementation of a three-tier, defense-in-depth security architecture and established a fully remote production model—foundational for scalable growth, resilience, and risk mitigation. Expanded architecture to hybrid AWS, Azure, and VMware infrastructure, integrating 7 acquisitions and 30 digital platforms. Built and led security, assurance, and compliance teams to HITRUST and SOC 2 Type 2 certification—enabling enterprise growth and client trust. Pioneered NIST AI Risk Management Framework to protect PHI, PII, and proprietary data during AI innovation—balancing compliance, privacy, and business enablement.

HMS

VP of Security and IT Systems | CISO | Director of IT Security

HMS · Las Vegas Metropolitan Area

Sep 2007 – Oct 2016(9 yrs 2 mos)

Recruited to transform startup IT and security at HealthDataInsights. Architected government-grade, multi-zoned, defense-in-depth environments for commercial and CMS contracts (RAC-D, PERM), laying the foundation for secure growth and regulatory compliance. Designed core infrastructure, including $5M disaster recovery site, 24/7 NOC, and compliant DMZ, aligning to NIST SP 800-53 and CMS ARS. Led five CMS SCAs and multiple SOC 2 and ISO 9001 audits. Post-acquisition, managed strategic integration and ongoing modernization for a 900-server enterprise, sustaining federal/commercial growth and continuous compliance.

Education

S

SF Academy of Art University and California College of Arts and Crafts

No degree, made career change into technology.

Jun 1986 – Sep 1989

Expertise

Specialties

Governance, Risk Management, and Compliance (GRC)Security Architecture DesignInformation Security ManagementRisk ManagementOrganizational LeadershipEnterprise Risk ManagementIT Risk ManagementIT Security AssessmentsInformation Security Management System (ISMS)Cybersecurity Incident ManagementCybersecurity Incident ResponseInformation SecurityChange ManagementCISSPGIACNIST 800-53FIPSSOC 2IT Project & Program ManagementBoard PresentationsTeam LeadershipAnalytical SkillsProblem SolvingTeamworkCommunicationGSECLeadershipManagementHITRUSTAI SecurityData Encryption StandardsAI StrategyLinuxCloudflareMicrosoft Entra IDAWS SecurityDarktrace Immune SystemCrowdstrike FalconCyber Threat Hunting (CTH)Internet Information Services (IIS)OS XMicrosoft SQL ServerMCSEActive DirectoryWindows ServerISC2Cyber InsuranceCyber Threat Intelligence (CTI)Role-Based Access Control (RBAC)Data ClassificationEndpoint SecuritySecurity Information and Event Management (SIEM)Cybersecurity ToolsPassword ManagementIT Asset ManagementSecurity Patch ManagementIT Security OperationsCloud SecurityDLPEncryptionShell ScriptingVulnerability ManagementMicrosoft 365 SecurityEmail SecurityData SecurityU.S. Federal Information Security Management Act (FISMA)Standard Operating Procedure (SOP)Security PolicyU.S. Health Insurance Portability and Accountability Act (HIPAA)Security AssuranceVulnerability AssessmentPenetration TestingIdentity and Access Management (IAM)Threat ManagementCybersecurityThreat & Vulnerability ManagementTeam BuildingIT ManagementSubnettingActive Directory ExperienceIT Infrastructure DesignInformation Technology TrainingInformation TechnologyBackup & Recovery SystemsServer AdministrationWindows System AdministrationNetwork AdministrationEmail ManagementNetwork TroubleshootingInformation Security AnalysisProject ManagementSecurity Systems IntegrationMCDBANetwork + CertifiedDisaster RecoveryProcess ImprovementNetwork SecuritySecuritySystem Deployment

Past companies

DigitalCyxVālenz®HMS

Similar executives