C

Charlie Miller

CEO

Cambridge, Massachusetts, United States15 yrs 11 mos experience

Key Highlights

  • Expert in building enterprise security programs.
  • Proven track record in achieving compliance with major standards.
  • Strong collaboration with cross-functional teams for risk management.
Stackforce AI infers this person is a Cybersecurity and GRC expert with extensive experience in enterprise security and compliance.

Contact

Skills

Core Skills

Security GovernanceRisk ManagementSecurity Program ImplementationSecurity Team DevelopmentThreat ManagementInformation Security ManagementIncident ManagementSecurity Project ManagementApplication SecurityWeb Application SecurityInfrastructure SecurityPolicy DevelopmentTechnical SupportSystems Management

Other Skills

Active DirectoryApplication Security FrameworkAutomationCloud SecurityCompliance ManagementCyber Threat Intelligence (CTI)CybersecurityDevSecOpsDynamic Application Security TestingEndpoint ProtectionEnterprise Risk ManagementFirewallsGDPRHelpdesk AutomationISO 27001

About

I am an experienced security and GRC leader with expertise in building enterprise security programs, driving risk-based decision-making, and achieving compliance with ISO 27001, SOC 2, and privacy regulations. In multiple roles, I have transformed security into a business function, enabling executive teams to understand and evaluate risk. I believe security is built on collaboration with all business leaders, especially with engineering, product, and operations teams. A successful security program should not be a barrier but a strategic enabler—providing the right balance of risk mitigation, operational efficiency, and business growth.

Experience

Tango

Chief Information Security Officer

Jul 2025Present · 8 mos

Drivenets

Director of Information Security and GRC

Jun 2024Jul 2025 · 1 yr 1 mo · Remote

  • Building and leading the company’s first dedicated security program, aligning security with the business and establishing executive risk visibility. Responsible for enterprise risk management, security operations, application security, and compliance initiatives, including ISO 27001. Driving improvements in threat detection, vulnerability management, and overall security governance.
ISO 27001Security OperationsApplication SecurityCompliance ManagementEnterprise Risk ManagementSecurity Governance+1

Bluebeam, inc.

Director, Information Security

Jan 2022May 2024 · 2 yrs 4 mos

  • In my time at Bluebeam, I have implemented a robust NIST-based security program, integrating policies, risk management, and maturity models. I established and chair an executive Risk Committee, driving data-driven security decisions. I successfully guided the organization through SOC 2 Type I and Type II audits within my first 18 months, and I also created an ISO 27701-aligned Privacy program in collaboration with Legal, maturing our approach to GDPR, CCPA, and other frameworks. I actively supported our sales teams in our business transition to SaaS and subscription models through contract negotiations, customer webinars, and direct customer interactions, while pioneering application and cloud security programs emphasizing shift-left practices.
NISTSOC 2ISO 27701GDPRApplication SecurityCloud Security+3

Bullhorn

4 roles

Director, Global Information Security

Promoted

Jan 2021Jan 2022 · 1 yr

  • Grew security team from 4 to 8 engineers including building out an Application Security team dedicated to working with development teams to implement DevSecOps principles and tooling (SAST, DAST, SCA, and secure coding training). Implemented threat intelligence program with automated workflows driving IOCs into security tools, lowering Mean Time to Detect and improving perimeter defenses. Developed program to incorporate security in the sales process to improve customer experience, increase revenue, and lower operational cost of responding to customer security questionnaires.
DevSecOpsThreat IntelligenceApplication SecuritySecurity Incident ResponseCybersecuritySecurity Team Development+1

Senior Manager, Information Security

Sep 2019Jan 2021 · 1 yr 4 mos

  • Led a team of four InfoSec Analysts and Engineers in all functions of Information Security, including vulnerability management; threat detection and intelligence; incident response; and network, application, and infrastructure security architecture. Managed the security component of multiple major business acquisitions and resulting security team and tool integrations. Spearheaded multiple initiatives including transition to next-gen firewalls (Palo Alto), implementation of a software-defined perimeter for remote access, and organization wide implementation of a modern endpoint protection strategy.
Vulnerability ManagementIncident ResponseNetwork SecurityFirewallsEndpoint ProtectionInformation Security Management+1

Lead Information Security Analyst

Mar 2019Sep 2019 · 6 mos

  • Managed two InfoSec Analysts and led major InfoSec projects and initiatives, including implementation of a SIEM and development of an application security framework with product and development executives. This included formalization of a scoring matrix, metrics and reporting, and an organization-wide pentesting program.
Application Security FrameworkSIEM ImplementationPentesting ProgramSecurity Project ManagementApplication Security

Sr. Information Security Analyst

Jun 2018Mar 2019 · 9 mos

  • Led several cross-functional security projects including implementation of a WAF to protect public SaaS applications and architecting IDS/IPS in production networks. Managed technical incident response and internal forensic analysis and built an internal CSIRT toolkit.
  • Developed a dynamic application security testing (DAST) program and implemented it across multiple web applications. Performed manual penetration testing of web applications to identify vulnerabilities.
WAF ImplementationIncident ResponseDynamic Application Security TestingWeb Application SecurityIncident Management

Jounce therapeutics, inc.

Infrastructure and Security Engineer

Feb 2017May 2018 · 1 yr 3 mos · Greater Boston Area

  • Managed IT security for network, servers, and endpoints utilizing Carbon Black and Alert Logic SIEM and vulnerability management. Wrote IT security policies and ensured protection of company scientific data through auditing, reporting, and resilient data storage strategies. Assisted organization in implementation of SOC 2 and developed automations for IT controls.
  • Administered full stack of IT infrastructure including NetApp storage, Cisco switches, Palo Alto firewalls, VMware ESXI hosts, Windows and Linux servers, and AWS cloud services
IT Security PoliciesVulnerability ManagementSOC 2 ImplementationInfrastructure SecurityPolicy Development

Milton academy

Technical Support Analyst

Apr 2015Feb 2017 · 1 yr 10 mos · Milton, MA

  • Provided systems administration support for VMWare virtualized Windows, CentOS, and Ubuntu systems including server updates, user administration and creation, and availability and performance monitoring. Automated desktop support and helpdesk processes with Powershell and Symantec Altiris.
Systems AdministrationHelpdesk AutomationTechnical SupportSystems Management

American red cross

Disaster Program Specialist

Jan 2014Feb 2015 · 1 yr 1 mo

  • Developed and improved external relationships with local emergency managers, fire departments, and NGOs in nine counties. Managed all aspects of disaster services cycle for Red Cross in nine counties. Trained, supervised, and led volunteers in response to disasters ranging from single family house fires to floods and wildfires

Image stream medical

Data Migration Consultant

Jul 2013Oct 2013 · 3 mos · Littleton, MA

Kenyon college

Senior Helpline Consultant

May 2010May 2013 · 3 yrs

  • Assisted faculty, staff, students, and visitors of Kenyon College with technology issues and requests through phone, chat, email, remote desktop viewing, and face-to-face support.

College township fire department

Firefighter/ Paramedic

Aug 2009May 2013 · 3 yrs 9 mos · Gambier, OH

  • Responded to fire, rescue, and medical emergencies as a ALS provider, while training and managing junior members of the fire department

Education

Kenyon College

Bachelor of Arts (B.A.) — Psychology

Jan 2009Jan 2013

St. Paul's School

High School Diploma

Jan 2006Jan 2009

Stackforce found 100+ more professionals with Security Governance & Risk Management

Explore similar profiles based on matching skills and experience