Randy Marchany

CEO

Blacksburg, Virginia, United States34 yrs 4 mos experience
Highly Stable

Key Highlights

  • Over 33 years of experience in cybersecurity.
  • Co-authored multiple influential cybersecurity publications.
  • Awarded ONCON Top 10 CISO award in 2024 and 2025.
Stackforce AI infers this person is a cybersecurity expert with extensive experience in information security management and education.

Contact

Skills

Core Skills

Information Security ManagementIncident ResponseCybersecurity

Other Skills

Computer SecurityIT AuditNetwork SecuritySecurity AwarenessIntrusion DetectionVulnerability AssessmentInternet SecurityMalware AnalysisComputer ForensicsISO 27001Disaster RecoveryFirewallsSecurity AuditsPenetration TestingSecurity Architecture Design

About

Randy is the Chief Information Security Officer of Virginia Tech and the Director of Virginia Tech's IT Security Laboratory. He has over 33 years of experience in cybersecurity and has been working on computer since 1972. He is a co-author of the original SANS Institute Top 10 Internet Threats, the SANS Consensus Roadmap for Defeating DDoS Attacks, and the SANS Incident Response: Step-by-Step guides. Randy is currently a senior instructor for the SANS Institute and joined SANS in 1992. He was a member of the original Center for Internet Security (CIS) development team that produced and tested the CIS Solaris, HPUX, AIX, Linux and Windows2000/XP security benchmarks and scoring tools. He was recently part of the team that wrote version 8 of the CIS Security Controls. He has written or co-authored over 45 papers on cybersecurity. He is a founding member of the US Cyber Challenge (USCC). The USCC mission is to identify, attract, recruit and place the next generation of cybersecurity professionals. He designs the curriculum for the USCC summer camps. He is a former member of the REN-ISAC board, a former member of the EDUCAUSE Higher Education Information Security Council (HEISC). He is a founding member of the Virginia Cyber Range (www.virginiacyberrange.org). He is one of the founders of VASCAN (www.vascan.org), a consortium of security practitioners and researchers from the major universities in Virginia. He received a ONCON Top 10 CISO award in 2024 and 2025, was a Capital ORBIE CISO Public Sector finalist and won a SANS Difference Maker Award in 2021 for his contributions to the cybersecurity field. He was awarded the 2016 Shirley C. Payne IT Security Advancement award, the 2000 SANS Institute's Security Technology Leadership Award, the 2003 VA Governor's Technology Silver Award, and a member of the team that won the EDUCAUSE Excellence in Information Technology Solutions Award in 2005. He is a co-holder of three cybersecurity patents. He was the author of the original theme song of National Public Radio's nationally syndicated radio program, "World Cafe". His band, "No Strings Attached" was nominated for or won "Indie" awards (independent record label's version of the Grammy) for Best Album (String Music) category in 1984, 1985, 1986, 1988, 1990. SANS Institute Bio: https://www.sans.org/profiles/randy-marchany/ Blog: http://randymarchany.blogspot.com Twitter: @randymarchany

Experience

34 yrs 4 mos
Total Experience
19 yrs 3 mos
Average Tenure
3 yrs 11 mos
Current Experience

Cyberedboard community

Executive Board Member

Mar 2024Present · 2 yrs 1 mo · Blacksburg, VA USA North America · On-site

Vigitrust

VigiTrust Global Advisory Board Member

May 2022Present · 3 yrs 11 mos · New York, London

  • VigiTrust Global Advisory Board - Member
  • Founded in 2011, the Board brings together 150+ CEOs, CxOs, board members, regulators, enforcement bodies, researchers, and other key stakeholders in the security & compliance industry - with Information Sharing as the prime objective. Members and guests exchange ideas about the direction in which the industry is moving in terms of innovation, upcoming laws and standards, case studies, and research work.

Virginia tech

Chief Information Security Officer

Jan 2010Present · 16 yrs 3 mos

  • Responsible for designing and implementing an enterprise wide security architecture for Virginia Tech. This includes IT Security policies, standard and guidelines for protecting sensitive data stored or transmitted on university IT resources and networks.
Computer SecurityInformation Security ManagementIT AuditNetwork SecurityIncident Response

Ren-isac

member

Jan 2006Jan 2016 · 10 yrs

  • Former board member 2018-2019

Va tech it security office

Director, VA Tech IT Security Lab

Aug 2003Present · 22 yrs 8 mos

Educause

member

Jan 2000Jan 2010 · 10 yrs

Sans institute

2 roles

SANS Senior Instructor

Promoted

Jan 1992Present · 34 yrs 3 mos

  • Instructor for the following: SEC401, SEC434, SEC440, SEC566. Course descriptions are at www.sans.org
CybersecurityIncident ResponseSecurity Awareness

Old Dude Instructor

Jan 1992Jan 2010 · 18 yrs

Education

Virginia Tech

bscs/msee — computer security

Jan 1970Jan 1992

O'Connell HS, St. James School

Stackforce found 100+ more professionals with Information Security Management & Incident Response

Explore similar profiles based on matching skills and experience