Michael L. Woodson, CCISO • CISM

CEO

Boston, MA, USA34 yrs 2 mos experience

Key Highlights

  • Over 20 years of cybersecurity leadership experience.
  • Expert in aligning technology with business priorities.
  • Proven track record in building resilient enterprises.
Stackforce AI infers this person is a Cybersecurity Executive with expertise in enterprise risk management and digital transformation.

Contact

Skills

Core Skills

Cybersecurity Strategy & GovernanceRisk ManagementCybersecurityIt GovernanceInformation Security ManagementIncident ResponseCloud TransformationIncident ManagementForensic Services

Other Skills

Third-Party & Supply Chain Risk Management (TPRM)Security Operations Center (SOC) LeadershipData Privacy & Protection ProgramsSecurity Program ModernizationIT governance & investment alignmentModernize enterprise infrastructureCross-functional collaborationCyber resilience and data protection programsFraud InvestigationsRegulatory ComplianceChange ManagementCyber Threat Intelligence (CTI)Data SecurityOptimizationIdentity and Access Management (IAM)

About

​​​​​​​​​​​​​​​​Trusted global executive protecting enterprise value through technology and cybersecurity leadership.I am an enterprise-focused Chief Cybersecurity Strategist with over 20 years of experience helping organizations navigate complex technology and cyber risks while enabling sustainable, strategic growth. My career spans regulated and mission-critical industries;including transportation, financial services, hospitality, and government where I've partnered closely with boards and C-suite leaders to translate emerging technology challenges into informed, actionable decisions.I am passionate about building resilient enterprises. My work centers on aligning technology initiatives with business priorities, risk appetite, and regulatory expectations , whether that means: • Establishing enterprise IT and cybersecurity strategies ▸ Modernizing digital and cloud infrastructure ▸ Designing and maturing cybersecurity, privacy, and risk programsI bring deep expertise in AI governance, third-party risk, and supply chain cyber resilience helping organizations stay ahead of evolving threats while positioning technology as a driver of innovation and enterprise value. Beyond execution, I thrive on mentoring and enabling high-performing teams, fostering cultures where security, innovation, and operational excellence coexist. From guiding executive investment decisions to embedding security into large-scale digital transformations, my approach is always strategic, forward-looking, and results-oriented. I enjoy engaging with peers, boards, and emerging leaders on the future of cybersecurity, AI risk, and enterprise resilience. My goal: to help organizations become not just protected but empowered to leverage technology confidently in pursuit of their mission. Let's connect and collaborate.

Experience

34 yrs 2 mos
Total Experience
2 yrs 6 mos
Average Tenure
2 yrs 3 mos
Current Experience

Guardare, inc.

Customer Advisory Board Member

Apr 2025Mar 2026 · 11 mos

Nomad cyber concepts

Chief Information Officer & Chief Cybersecurity Strategist

Apr 2025Feb 2026 · 10 mos · United States

  • Partner with boards and executive teams to translate complex technology, AI, and cybersecurity risks into actionable business and operational strategies.
  • Lead IT governance & investment alignment, ensuring technology initiatives support enterprise priorities & enhance decision-making.
  • Modernize enterprise infrastructure to improve system reliability, operational resilience, and digital transformation outcomes.
  • Drive cross-functional collaboration to accelerate project delivery and embed risk-informed practices into business processes.
  • Strengthen cyber resilience and data protection programs to sustain stakeholder trust and regulatory alignment.
IT governance & investment alignmentModernize enterprise infrastructureCross-functional collaborationCyber resilience and data protection programsCybersecurityIT Governance

Onyx spectrum technology, inc

Fractional CISO / Chief Cybersecurity Strategist

Jan 2024Present · 2 yrs 3 mos · United States

  • Provide strategic cybersecurity advisory services for public-sector & transportation clients, translating risk into clear, board-ready insights.
  • Assess security maturity and implement risk-aligned remediation strategies to prioritize high-impact initiatives.
  • Align cybersecurity strategies with business objectives, balancing regulatory compliance with long-term resilience.
  • Design phased roadmaps that enhance operational feasibility while embedding governance and compliance best practices.
Cybersecurity Strategy & GovernanceThird-Party & Supply Chain Risk Management (TPRM)Security Operations Center (SOC) LeadershipData Privacy & Protection ProgramsSecurity Program ModernizationRisk Management

Sonesta hotels

Director, Information Security and Privacy

Feb 2021Jan 2024 · 2 yrs 11 mos · Newton, MA · On-site

  • Transformed global security and privacy programs, establishing scalable governance frameworks and high-performing teams.
  • Embedded security into enterprise initiatives, ensuring compliance with GDPR, CCPA, CPRA, and PCI DSS.
  • Modernized controls and awareness programs to strengthen risk posture and prevent security incidents.
  • Enabled secure cloud migrations and ITSM integration through governance-by-design strategies.
  • Partnered with executives to translate strategic objectives into operationally resilient security programs.
Fraud InvestigationsRegulatory ComplianceChange ManagementCyber Threat Intelligence (CTI)Data SecurityInformation Security Management+1

Mbta

Chief Information Security Officer

Mar 2019Feb 2021 · 1 yr 11 mos · Boston, MA · On-site

  • Led enterprise-wide security modernization, creating governance structures, operating models, and long-term roadmaps.
  • Established the agency’s first 24×7 Security Operations Center to enhance visibility and regulatory compliance.
  • Integrated security governance across asset management, change management, and business continuity processes.
  • Strengthened breach response and operational continuity, improving resilience across transit and legacy environments.
OptimizationIdentity and Access Management (IAM)Incident ResponseCross-functional Team LeadershipCybersecurity

Infosys

Principal, Enterprise Applications, Cloud Infrastructure and Security Advisory Services

Sep 2017Mar 2019 · 1 yr 6 mos · Quincy, MA · On-site

  • Advised Fortune 100 clients on large-scale enterprise and cloud transformations, embedding security and risk practices into architecture and change management.
  • Aligned technology strategies with business priorities to accelerate adoption and reduce operational risk.
  • Modernized ITSM and ESM platforms, improving operational control, compliance, and security posture.
  • Delivered end-to-end cybersecurity advisory services, balancing risk management, operational execution, and strategic outcomes.
Security OperationsChange ManagementSupply Chain ManagementCybersecurityCloud Transformation

Taino consulting group (sba 8a certified firm)

Senior Vice President Cyber Security Advisory Services

Dec 2016Sep 2017 · 9 mos · Boston, MA · On-site

  • Aligned and led a transformative initiative to enhance and architect cybersecurity services, significantly strengthening security controls across project teams.
  • Managed the Cybersecurity Advisory Services practice, specializing in digital governance, cybersecurity advisory, and risk assessment and management consulting for federal, state, and corporate entities.
  • Pioneered innovative strategies that drove measurable improvements in client satisfaction and retention, positioning the company as a trusted leader in cybersecurity advisory services.

State street

Director, Information Systems Security, V.P./ Cyber Risk Director

Jun 2015Dec 2016 · 1 yr 6 mos · North Quincy, MA · On-site

  • Strengthened defensive and resilience measures, rapidly detecting and mitigating potential attacks to safeguard business operations. Concurrently assumed Vice President and Risk Director responsibilities for six months, demonstrating adaptability and leadership.
  • Identified critical cybersecurity gaps and implemented advanced security technologies, including vulnerability, risk, and threat management; advanced endpoint security; user behavior analytics; and security operations management. Provided direct oversight to a dedicated team reporting to the CISO.
  • Developed strategic security initiatives to recover from sophisticated cyberattacks and mitigate associated risks, significantly enhancing the organization’s information security posture and resilience.

Santander bank, n.a.

Head, Forensic Information Security Services N.A.

Dec 2013Jun 2015 · 1 yr 6 mos · Dorchester, MA · On-site

  • Delivered end-to-end cybersecurity advisory services, balancing risk management, operational execution, and strategic outcomes.
  • Significantly strengthened continuity of banking operations by strategically managing the Cyber and Network Security portfolio, product roadmaps, and investigations, including the testing and operationalization of high-priority initiatives designed to reduce cyber risk and enhance the bank’s ability to identify, protect, detect, respond to, and recover from cyberattacks.
  • Streamlined North American network security operations through effective system monitoring, threat intelligence management, third-party services oversight, penetration metrics, and due diligence reporting.
  • Reduced cyber risk and enhanced cyber intelligence and information sharing by leading the testing, procurement, implementation, and operationalization of high-priority security initiatives to build out the bank’s computer forensics lab.
  • Designed and implemented the bank’s enhanced Incident Management System, delivering a crisis management solution for tracking and reporting cybersecurity incidents and events. This included a metrics dashboard to monitor costs related to incidents, events, losses, and recovery, resulting in the closure of a major OCC-issued Matter Requiring Attention (MRA).
Security OperationsIdentity and Access Management (IAM)CybersecurityIncident Management

Tata consultancy services

Head, Forensic Information Security Services N.A.

Jan 2010Jan 2013 · 3 yrs · Boston, MA · On-site

  • Served as the Forensics Security Services lead, overseeing the development and delivery of security forensic services, including insider surveillance and user behavior analytics. Provided leadership and support for Governance, Risk, and Compliance (GRC) engagements, Security Information and Event Management (SIEM) services, and Managed Security Services.
  • Designed and developed an Application Compliance Framework for the largest bank in the United States, defining minimum compliance standards for application development managers.
  • Conducted an assessment of the GRC platform for a major US-based financial investment firm, resulting in the retention of a key GRC application and the development of an integrated GRC implementation strategy.
  • Established and maintained frameworks that provided assurance and information security strategies aligned with business objectives and consistent with applicable laws and regulations.
  • Identified and managed information security risks, creating and maintaining programs to achieve business objectives. Planned, developed, and managed capabilities to detect, respond to, and recover from information security incidents across diverse industries, including financial services, oil and gas, biotech, and pharmaceuticals.
Security OperationsIdentity and Access Management (IAM)CybersecurityForensic Services

Onyx spectrum technology, inc

Vice President, Risk & Security Compliance Services

Jan 2008Jan 2010 · 2 yrs · Boston, MA · On-site

  • Directed the identification, development, implementation, and management of the organization’s Security, Risk, and Compliance strategies and programs.
  • Led strategy, execution, and relationship-building efforts for sales and monthly billings generated through Onyx Spectrum strategic partners and government accounts during both pre- and post-award processes.
  • Redesigned the firm’s approach to vendor management, including development and review of requests for proposals (RFPs), RFIs, contracts, due diligence, negotiations, contract fulfillment, budgeting, and vendor compliance audits, resulting in a more efficient operating model.
Security OperationsSupply Chain ManagementCybersecurityForensic Services

Huron consulting group holdings llc

Director, Legal Consulting Group

Jan 2007Jan 2008 · 1 yr · Boston, MA · On-site

  • Directed and coordinated e-discovery and digital evidence requirements for complex legal consulting engagements.
  • Managed quality control audits and reconciliations of data collection for a Securities and Exchange Commission restatement.
  • Advised clients on developing and implementing procedures for quality assurance and quality control audits related to records management and backup tapes.
  • Led IT internal controls and system assessments of support systems in a court-appointed review of a ready-mix concrete and asphalt company, including evaluation of system infrastructure, lifecycle management, and logical access controls.
Policies & ProceduresRisk Management

Lecg

Principal, Enterprise Risk, and e-Discovery Practice

Jan 2006Jan 2007 · 1 yr · Cambridge, MA · On-site

  • Provided strategic guidance and managed resources to deliver efficient, cost-effective processes for preserving, collecting, processing, culling, hosting, reviewing, and producing relevant information for litigation support.
  • Directed and coordinated multiple work streams to meet deadlines for data preservation, collection, processing, review, and production in legal disputes and forensic investigations.
  • Led local and global teams performing forensically sound physical collection of data and documents.

U.s department of justice/icitap, u.s. embassy

Senior Cyber Crime Technical Advisor

Jan 2003Jan 2006 · 3 yrs · Jakarta, Indonesia · On-site

  • Established and designed a plan to assist the Indonesian National Police Criminal Investigations Unit (INP/CCU) in developing effective enforcement capabilities to prevent, interdict, and investigate cybercrime.
  • Built innovative strategic partnerships with local training institutions to support the technical training needs of the INP, developing initiatives that enhanced the analytical and investigative skills of INP/CCU personnel.
  • Developed and nurtured dynamic relationships with key stakeholders, including the DOJ Criminal Division – Computer Crime and Intellectual Property Section, the State Department Economic Section, the ASEAN Secretariat, USAID, and multiple government, academic, civil, and private organisations, resulting in cohesive development of critical infrastructure protection initiatives and policies in Indonesia and Southeast Asia.

Boston police department

Police Officer/I.T. Specialist

Nov 1989Sep 2001 · 11 yrs 10 mos · Boston, Massachusetts, United States · On-site

  • Assisted management on information technology matters, including Computer-Aided Dispatch (CAD) systems, Mobile Data Terminal technology, Identification Imaging Systems, Personnel Management Systems, and Internal Affairs Case Management Systems.
  • Developed curriculum for a 10-month training program to teach IT fundamentals to officers at all levels of the force.
Policies & Procedures

Education

Boston University

Master of Science - MS — Criminal Justice/Police Science

Utica University

Master of Science — Economic Crime Management

Northeastern University

Institute of Experimental AI — Responsible Artificial Intelligence for Leaders: Executive Education

Jun 2024Jun 2024

University of Massachusetts Dartmouth

Bachelor of Applied Science (BASc)

Stackforce found 100+ more professionals with Cybersecurity Strategy & Governance & Risk Management

Explore similar profiles based on matching skills and experience