Pataskala, Ohio · CISSP · U.S. Army veteran

Security only works
when people understand it.

I'm Samuel J. Davis — Director of Information Security and Head of Cybersecurity. I stood up an enterprise security program from nothing, cut PCI audit scope roughly in half, and spend most of my day turning frightening technical problems into decisions a leadership team can actually make.

tip The terminal below is a real conversation — type help, hire, or just ask a question in plain English.

Diagram of layered security controls arranged in rings, with an inbound attack path stopped before it reaches the core. Samuel J. Davis — smiling, arms folded, in a white shirt in an open-plan office.
  • 0 → 1Built the first formal security program at a company that had none
  • ~50%PCI audit scope removed — the cheapest control is the system you no longer have
  • 20+ yrsBuilding and running the systems before I was asked to secure them

Interactive

Pull up a chair. Ask me anything.

No form, no autoresponder. Type a command or a plain-English question and you'll get the same answer I'd give you over coffee. Recruiters: start with hire.

guest@samueljdavis: ~/chat

About

I translate for a living.

Most security failures I've seen weren't sophisticated. They were ordinary — a process nobody owned, an exception nobody revisited, a warning nobody understood well enough to act on. Technology rarely fails alone; it fails alongside a sentence somebody didn't say out loud.

So that's the work. I take the thing the engineers are worried about and tell it as a story the finance team, the board, and the person in the warehouse can all follow — and then I make sure the story ends with a decision instead of a slide.

I came to security sideways: programmer, architect, web development manager, then senior manager over network, cloud, and web operations. I earned the CISSP on my own initiative and used it to start a conversation that eventually became a formal enterprise security program. Before all of that, I was a Military Police Sergeant and a communications specialist in the U.S. Army — which is where I learned that a plan nobody has rehearsed isn't a plan.

“If I can't explain the risk in one breath, I don't understand it yet.”
Diagram showing security jargon such as lateral movement and residual risk passing through a translation layer and emerging as plain-English business decisions.
The whole job, in one diagram.

How I work

Four convictions I keep proving right.

Every one of these started as an argument I had to win with evidence rather than authority.

Wheel of the NIST Cybersecurity Framework functions — Identify, Protect, Detect, Respond, Recover — around a Govern core.

Govern first, or the rest is theater

I built our first program on the NIST CSF — not because frameworks are magic, but because they give a company a shared vocabulary and an honest scorecard. Governance is the boring function everyone skips and the only one that makes the other five stick.

Program design · Policy · Operating model

Comparison showing a large set of in-scope systems on the left reduced to roughly half as many after segmentation and retirement.

Shrink the problem before you defend it

Leading PCI DSS governance and auditor engagement, we cut cardholder scope by about half over three years. Every system we segmented, retired, or took out of the flow was one we never had to patch, monitor, audit, or explain again.

PCI DSS · Compliance strategy · Audit engagement

Zero trust flow where identity, device health, privilege, location, and data sensitivity feed a policy engine that grants scoped access or steps up authentication.

Trust is a verb, checked per request

Identity is the real perimeter now. MFA, SSO, and privileged access management do more for a mid-sized company's risk profile than any appliance — and they do it without asking employees to become security experts.

Zero Trust · Identity · MFA/SSO · Cloud security

Funnel showing twenty or more vendors per year triaged, security reviewed, and passed through a procurement gate to approval, conditions, or rejection.

Your vendors are your attack surface

I put a third-party and SaaS review in front of procurement, not behind it — 20+ vendors a year, assessed on the data and access they'd actually get. Saying “not like that” before a contract is signed costs nothing. Afterward it costs everything.

Vendor risk · SaaS governance · Procurement

Incident response

Everyone has a plan until the phone rings at 4:40 p.m. on a Friday.

You learn this the first time it happens to you, and every incident since has re-taught it: calm on the bad day is manufactured in advance, out of rehearsal, clear roles, and permission to speak up early.

Incident severity curve across the four NIST SP 800-61 phases: preparation, detection and analysis, containment, eradication and recovery, and post-incident activity.
  • Roles before rules. Who decides, who talks, who touches the keyboard — settled while it's quiet.
  • Communicate up early. Executives forgive bad news. They don't forgive late news.
  • Blameless review, real fixes. A postmortem that produces a scapegoat produces nothing else.

Experience

Twenty-plus years of building the thing, then securing it.

  1. Apr 2023 — Present

    Director of Information Security / Head of Cybersecurity

    Highlights for Children, Inc. · Columbus, OH

    Established and lead the enterprise Information Security function with full accountability for strategy, governance, risk, and incident response across corporate, cloud, and application environments. Senior-most authority on cyber risk, reporting posture and recommendations directly to executive leadership.

    • Program strategy: built the organization's first formal cybersecurity program — governance, operating model, and a multi-year strategy aligned to NIST CSF.
    • Executive advisory: advise leadership on risk acceptance, prioritization, and where the security dollar actually goes.
    • Compliance optimization: led PCI DSS governance and auditor engagement, cutting scope ~50% and reducing audit burden and long-term cost.
    • Risk integration: stood up a formal third-party/SaaS risk program, embedding security review into procurement.
    • Strategic planning: authored the “Resilience Blueprint” multi-year roadmap aligning progress, constraints, and resourcing to business priorities.
  2. Jun 2017 — Apr 2023

    Senior Manager, Network Services

    Highlights for Children, Inc. · Columbus, OH

    Senior operations leader over enterprise network, cloud (Azure), and web platforms — accountable for uptime, resilience, and team performance across business-critical and customer-facing systems.

    • Directed multidisciplinary network, cloud, and web operations teams.
    • Partnered with application, product, and business teams to deliver infrastructure for growth.
    • Developed engineers, drove operational consistency, and prioritized ruthlessly.
    • Earned the CISSP independently and used it to influence the creation of a formal security program.
  3. Earlier career

    Web Development Manager · Applications & Solutions Architect · Senior Applications Programmer · Programmer / Analyst

    Progressively responsible technology roles spanning application development, systems architecture, physical security, enterprise platforms, vendor coordination, and delivery in complex organizations. I've been the person on the other end of the security requirement, which is precisely why mine are written to be implementable.

Four workstreams staged across three years: foundation, then identity, then resilience, then assurance.
Security programs mature in roughly this order — you can't do assurance on a foundation that isn't there yet. The years are sequence, not schedule.

Security culture

The best control I've ever deployed was psychological safety.

You can buy detection. You cannot buy the four seconds in which an employee decides whether to tell you they clicked the link. That decision is made long before the incident, based on how the last person who admitted a mistake was treated.

So I run awareness like storytelling, not compliance homework: short, specific, human, and occasionally funny. I'd rather someone remember one story about a fake invoice than pass a quiz they'll forget by Thursday.

It shows up in the numbers eventually. It shows up in the hallway first.

Network of people where one person reporting a mistake sends a protective signal outward to everyone connected.

Education

B.S., Computer Information Systems
DeVry University — Columbus, OH

Certification

CISSP — (ISC)², 2019
Verify on Credly ↗

Military service

U.S. Army & Army Reserve
Military Police Sergeant · Communications Specialist

Frameworks

NIST CSF · PCI DSS · Zero Trust · Business continuity & disaster recovery

Contact

Let's talk.

I'm open to security leadership roles across the Columbus metro or fully remote, and to fractional and advisory work. If you're standing up a program and want an outside read on it, or you need someone who can explain risk to a room that doesn't work in security, write to me. I'd rather tell you something useful than something polite.

Two working options: on site or hybrid across the Columbus, Ohio metro, or fully remote anywhere.

Prefer the keyboard? Type contact in the terminal.