Cybersecurity Executive · Deputy CISO

Robert J. Hill

I build enterprise security programs that hold up to auditors, budget scrutiny, and real incidents — and I report them in language a board can act on.

CISSP | CISM | CISA | CRISC | CDPSE | CRMA

15+Years leading enterprise security programs
~$46MAnnual quantified cyber risk exposure removed
27%Year-over-year reduction in security spend
100Person security organization led in global healthcare

The short version

Security leadership across four very different risk environments

I currently own enterprise security strategy, governance, risk, architecture direction, vendor strategy, and a $24M annual security budget as Director of Cybersecurity and Deputy CISO at a global food production and manufacturing company — $14B in revenue, more than 50,000 employees worldwide. I report to the CISO and present to the Executive Cybersecurity Committee and the board.

Before that I led information security at a leading global healthcare organization, directing a 100-person organization across security operations, threat management, IAM, GRC, engineering, architecture, and cloud security for a 76,000-employee academic medical center. Earlier I was the first enterprise security leader at a major sporting goods and outdoor retailer, and spent seven years assessing IT, cybersecurity, and compliance for more than 500 banks and credit unions.

The through-line is that I keep landing in places where the security function has to be built, rebuilt, or defended — usually while an audit, an IPO, a regulator, or an incident is already in motion.

Selected impact

Five problems worth reading about

Each of these is written the way I would brief an executive committee: what the situation actually was, what I decided to do, and what changed as a result.

Global Food Manufacturer

Turning vulnerability counts into $46M of risk removed

Remediation was being prioritized by severity score. Re-sequencing it around business impact took roughly $46M of quantified annual exposure off the books without adding headcount.

Read the case study
Global Food Manufacturer

An IPO-ready security program, one year early

Policies, control evidence, audit documentation, and executive reporting accepted by auditors, cyber-insurance underwriters, and regulators — delivered a full year ahead of schedule.

Read the case study
Global Food Manufacturer

Cutting security spend 27% without cutting coverage

Overlapping tools, duplicated effort between IT and security, and renewal-by-default. Rationalizing the portfolio returned 27% of annual spend and simplified the control environment.

Read the case study
Global Healthcare Organization

A 24x7 SOC that didn't hollow out the team

Outsourcing Tier 1 monitoring is easy. Doing it without losing detection engineering, incident response, and institutional knowledge is the hard part — that was the design constraint.

Read the case study
Sporting Goods Retailer

Standing up security for a $6.5B retailer from zero

No prior enterprise security function, 40,000 employees, card-present and e-commerce payment environments, and a PCI DSS obligation that was not optional.

Read the case study
Operating philosophy

How I actually run a security organization

The handful of positions I keep returning to: sequence by business impact, make the risk legible before you make it smaller, and never let the program depend on one person staying.

Read the approach

Where I go deep

Core expertise

The areas I have personally owned, built, or been accountable for — not a list of things I have read about.

  • Enterprise security strategy & roadmaps
  • Risk quantification & executive reporting
  • GRC, ISMS & audit readiness
  • Security operations & incident command
  • IAM, Zero Trust & cloud security
  • Secure SDLC & security architecture
  • Third-party & supply-chain risk
  • Budget, vendor & portfolio strategy
  • AI security & agentic governance
  • Board, regulator & customer advisory
  • Team building & operating models
  • NIST, ISO 27001, HITRUST & PCI DSS

Let’s talk

If you are hiring for senior security leadership, or working through a program build, an audit, or a risk-reporting problem, I’m glad to have the conversation.