Cybersecurity Executive · Deputy CISO
Robert J. Hill
I build enterprise security programs that hold up to auditors, budget scrutiny, and real incidents — and I report them in language a board can act on.
CISSP | CISM | CISA | CRISC | CDPSE | CRMA
The short version
Security leadership across four very different risk environments
I currently own enterprise security strategy, governance, risk, architecture direction, vendor strategy, and a $24M annual security budget as Director of Cybersecurity and Deputy CISO at a global food production and manufacturing company — $14B in revenue, more than 50,000 employees worldwide. I report to the CISO and present to the Executive Cybersecurity Committee and the board.
Before that I led information security at a leading global healthcare organization, directing a 100-person organization across security operations, threat management, IAM, GRC, engineering, architecture, and cloud security for a 76,000-employee academic medical center. Earlier I was the first enterprise security leader at a major sporting goods and outdoor retailer, and spent seven years assessing IT, cybersecurity, and compliance for more than 500 banks and credit unions.
The through-line is that I keep landing in places where the security function has to be built, rebuilt, or defended — usually while an audit, an IPO, a regulator, or an incident is already in motion.
Selected impact
Five problems worth reading about
Each of these is written the way I would brief an executive committee: what the situation actually was, what I decided to do, and what changed as a result.
Turning vulnerability counts into $46M of risk removed
Remediation was being prioritized by severity score. Re-sequencing it around business impact took roughly $46M of quantified annual exposure off the books without adding headcount.
Read the case studyAn IPO-ready security program, one year early
Policies, control evidence, audit documentation, and executive reporting accepted by auditors, cyber-insurance underwriters, and regulators — delivered a full year ahead of schedule.
Read the case studyCutting security spend 27% without cutting coverage
Overlapping tools, duplicated effort between IT and security, and renewal-by-default. Rationalizing the portfolio returned 27% of annual spend and simplified the control environment.
Read the case studyA 24x7 SOC that didn't hollow out the team
Outsourcing Tier 1 monitoring is easy. Doing it without losing detection engineering, incident response, and institutional knowledge is the hard part — that was the design constraint.
Read the case studyStanding up security for a $6.5B retailer from zero
No prior enterprise security function, 40,000 employees, card-present and e-commerce payment environments, and a PCI DSS obligation that was not optional.
Read the case studyHow I actually run a security organization
The handful of positions I keep returning to: sequence by business impact, make the risk legible before you make it smaller, and never let the program depend on one person staying.
Read the approachWhere I go deep
Core expertise
The areas I have personally owned, built, or been accountable for — not a list of things I have read about.
- Enterprise security strategy & roadmaps
- Risk quantification & executive reporting
- GRC, ISMS & audit readiness
- Security operations & incident command
- IAM, Zero Trust & cloud security
- Secure SDLC & security architecture
- Third-party & supply-chain risk
- Budget, vendor & portfolio strategy
- AI security & agentic governance
- Board, regulator & customer advisory
- Team building & operating models
- NIST, ISO 27001, HITRUST & PCI DSS
Writing
Recent insights
Practical governance guidance for organizations adopting AI faster than they are governing it.
-
Your vendor just shipped an AI feature. Is it still the same approved tool?
A practical review checklist for third-party AI features — before you approve AI by accident just because it appeared inside a platform you already trust.
-
An AI governance checklist for regulated small and mid-sized organizations
Generative AI is already inside most organizations, whether or not leadership approved it. Ten areas to get in order before broad adoption.
Let’s talk
If you are hiring for senior security leadership, or working through a program build, an audit, or a risk-reporting problem, I’m glad to have the conversation.