CISO · Cybersecurity Executive

Brandon
Bowlin

25+ years securing universities, health systems, and complex enterprises. Marine Corps discipline. Executive clarity. Risk that makes sense to boards.

Brandon Bowlin, Cybersecurity Executive and CISO
Brandon Bowlin CISO · Meridian, ID

25+

Years in security

From USMC communications to Fortune-500 enterprise boards

60%

Incident recovery ↓

Structured playbooks + ERM-aligned IR program at Boise State

Security that earns its seat at the table.

Most security leaders talk about frameworks. I talk about what the institution is trying to accomplish and how security can support that. Whether it's unlocking defense-funded research through a CMMC enclave, guiding a health system through regulatory complexity, or presenting breach risk to a board that wants clarity, not jargon.

My foundation started in the Marine Corps. That experience taught me how to operate clearly under pressure, make decisions with incomplete information, and keep people focused on what matters. Those habits carried directly into more than 25 years of consulting and executive leadership across higher education, healthcare, financial services, and manufacturing.

Security only works when the organization sees your team as a partner, not a gatekeeper. I start by understanding what people are trying to accomplish and figure out how security can support that, not by showing up with a list of things they can't do.

I've led M&A security diligence, stepped in as interim CISO during leadership transitions, guided organizations through multiple regulatory certifications, and presented to boards across a wide range of technical backgrounds. The constant is translating complex risk into decisions leaders can actually make.

Philosophy

How I think.

Security involves trust.

Programs succeed when people trust them and see security as a partner, not a gatekeeper.

Clarity beats complexity.

Executives don't need more dashboards; they need clear risk context and confident decisions.

Meet the organization where it is.

Every environment is different. Security has to align with your culture, structure, and goals.

Progress over perfection.

Practical, incremental improvements build momentum and create lasting change.

// Domain expertise

GRC Enterprise Risk Management Cyber Risk Quantification Zero Trust AI Governance & Security CMMC HIPAA FERPA NIST 800-53/171 Supply Chain / TPRM Cyber Resilience M&A Due Diligence Board Reporting vCISO ISO 27001 GDPR SOX PCI-DSS Vulnerability Management Data Governance Incident Response Multi-Cloud Security API Security Security Program Maturity Agentic AI Risk

// Experience

  1. 2023 – Present

    Chief Information Security Officer

    Boise State University

  2. 2019 – 2023

    Managing Director & Principal Consultant

    Stoneclad Technologies

  3. 2020 – 2023

    Director of Cloud Security

    Ascent Solutions

  4. 2016 – 2019

    Director of Information Security

    Enabling Technologies Corp

  5. 2015 – 2016

    Consulting Services Director

    Seitel Systems

  6. 2011 – 2015

    Infrastructure Services Manager

    Avanade

  7. 2008 – 2011

    IT Operations Manager

    Bechtel

  8. 1998 – 2008

    Communications Officer

    United States Marine Corps

// Credentials

  • Certified Information Systems Security Professional (CISSP)

    ISC²

  • Certified Information Systems Manager (CISM)

    ISACA

  • Certified Ethical Hacker (CEH)

    EC-Council

  • Cybersecurity Career Mentor

    EC-Council

  • Azure Security Engineer Associate

    Microsoft

  • Security Operations Analyst Associate

    Microsoft

  • Identity & Access Administrator Associate

    Microsoft

  • Security Administrator Associate

    Microsoft

  • ITIL Foundations

    EXIN

60%

Faster incident recovery

Structured playbooks, executive escalation protocols, and tabletop exercises embedded into ERM-aligned continuous improvement.

40%

Critical vulnerabilities ↓

First-year reduction at Boise State after consolidating onto a unified security stack with end-to-end visibility.

$200K+

Annual savings per engagement

Bloated security stacks rationalized into integrated cloud-native architectures without sacrificing coverage.

50%

Phishing click reduction

Role-specific, behavior-driven security education that changed actual user habits across client portfolios.

Get in touch

Ready to talk about your risk posture?

Whether you need a fractional CISO, board-level advisory, or someone to build a program from the ground up; let's have the conversation.