
The cyberthreat landscape is constantly evolving — creating new challenges, expanding vulnerabilities and leading to more sophisticated hacks and breaches. And when the COVID-19 pandemic hit and the nation turned to a largely remote workforce, government and industry had to find ways to secure work environments at home to fulfill critical missions. GovCon is in a never-ending fight to preemptively detect threats and to actively defend systems — in the office and at home — networks and enterprisewide IT infrastructures to secure the nation.
The cybersecurity execs leading these efforts are working to strategically, efficiently and securely improve and innovate system processes — no matter what comes their way. WashingtonExec’s Top 10 CISOs to Watch in 2021 highlights industry executives who consistently stay one step ahead of adversaries, equipped with the technical know-how to safeguard systems and information. They have achieved significant milestones and goals during an unprecedented year, with the support of strong leadership, teams and processes, and they possess the knowledge to navigate the complexities of the cyberthreat landscape.

Michael Baker
Staff Vice President & Chief Information Security Officer, GDIT
GDIT had just finished a years-long effort to integrate top cyber teams and revamp its cyber culture when work-from-home began en masse last spring. That foundational work would prove vital.
Through the new models, GDIT last year quickly rolled out and consolidated large-scale enterprise systems while focusing on cost containment.
“As soon as we finished this out, we had to immediately focus on universal remote work and the unique risks that accompany that, including the rapid rollout of new data protection schemes, remote access methods and large-scale video collaboration,” said Michael Baker, GDIT staff vice president and chief information security officer.
In 2020, GDIT received a perfect defense industrial base cybersecurity assessment center rating — a designation Baker said reflects “the executive and operational commitment” to customer mission. And the company has worked to continuously improve supply chain risk management practices before and after the SolarWinds-based breach.
“Before technology can be applied, it is imperative to position cybersecurity away from being the ‘party of no’ and more of a force for IT transformation and business value,” Baker said. “The focus to ‘get to yes’ safely and collaboratively is a differentiator for our company and customers that allows us to embrace innovation across a broad range of missions.”
Why Watch
Baker will continue to focus on evolving GDIT’s cyber teams while holding technical prowess and soft skills in equal importance — an approach that maximizes productivity and employee experience in a tough hiring market.
“We will be looking to deepen our focus on [artificial intelligence]and automation to increase our teams’ effectiveness, doubling down on zero trust principles across our networks, taking the next step in data awareness and tagging, and evolving our supply chain risk management program,” Baker said.

Jonathan Stammler
Chief Information Security Officer, LMI
As LMI’s chief information security officer, Jonathan Stammler leads enterprise cybersecurity governance, architecture design and risk management. He has played an instrumental role in LMI’s most pivotal moments since joining in 2014.
Within one week at the onset of the COVID-19 pandemic, Stammler and his team ensured employees had secure resources to transition to full-time remote work at all locations in support of government customers.
“When implementing any security program, we always look at user experience, operational effectiveness and compliance to ensure staff members are able to support their mission securely and effectively,” Stammler said. Appropriate architecture and procedures ensured the transition produced zero impact on LMI’s end-user base.
Stammler also had a key part in LMI’s most recent corporate acquisitions, The Tauri Group and Clockwork Solutions, based in Austin. Faced with aggressive timelines, Stammler performed the cyber due diligence and led IT integrations while maintaining security requirements.
Why watch:
As the Defense Department rolls out the first phase of Cybersecurity Maturity Model Certification this year, Stammler’s strategic efforts put LMI at the forefront for assessment and accreditation.
Understanding the growing need for security and resiliency in the federal space, Stammler built LMI’s security program, which scaled to meet Federal Information Security Management Act and National Institute of Standards and Technology requirements as LMI grew to nearly $400 million in revenue. He also built cyber solutions to decrease LMI’s time to deliver accredited environments to customers. Through these efforts, LMI is poised to meet CMMC requirements.

Jim Schifalacqua
Chief Information Security Officer, Peraton
Peraton Chief Information Security Officer Jim Schifalacqua successfully navigated two enormous cybersecurity challenges in 2020: supporting a remote workforce and avoiding a supply chain compromise.
With Peraton’s existing zero trust, cloud-first infrastructure, Peraton employees were immediately enabled to work from home. Schifalacqua layered additional guidelines and monitoring to address the added risks, and his team made rapid adjustments to Peraton’s endpoint threat and vulnerability management of these now always-off-network devices.
Even before the December 2020 SolarWinds incident, Schifalacqua focused on supply chain risk management by tightening up Peraton’s development environments and deploying DevSecOps controls and processes as a total risk management strategy for Peraton and its clients.
Peraton’s cloud-first approach to using Federal Risk and Authorization Management Program and high-assurance software-as-a-service for processing, secure storage, SD-WAN, IdAM, SIEM and advanced endpoint threat detection helped advance enterprise and federal missions with an agile and scalable platform. Peraton complied with NIST 800-171 and Cybersecurity Maturity Model Certification and also successfully employed the MITRE ATT&CK framework for threat detection and response.
Why Watch
Schifalacqua’s main focus in 2021 is to combine three sets of businesses from Northrop Grumman IT and Mission Systems, Perspecta and Peraton after two acquisitions. This integration, company leaders said, will combine the best-of-breed cybersecurity teams, services and solutions into what will become one of the largest IT services providers to the federal government.

Alicia Lynch
Vice President & Chief Information Security Officer, Science Applications International Corp.
Science Applications International Corp. Vice President and Chief Information Security Officer Alicia Lynch joined the company in 2018, bringing over 30 years of intelligence and cyber experience from the Defense Department, the defense industrial base and the private sector. She retired from the Army as a colonel in 2012.
Regularly asked to advise and assist on cyber best practices, Lynch has dealt with challenging threat landscapes since she was an intelligence lieutenant in the Army and is considered an expert in her field.
In 2020, she finished implementing a cyber threat and intelligence integration center for SAIC. The center assists in building situational awareness of internal and external threats, and it positions SAIC to proactively address challenges in real time before events impact corporate and program operations. The center also leads the effort in developing courses of action for mitigating adversary threat capabilities.
Lynch interacts daily with C-suite executives to ensure cyber messaging is effective and cyber policies are followed. She regularly delivers tough messages to protect SAIC systems and data from missteps by organizational components. Lynch has nurtured strategic relationships with influential stakeholders such as board members, the executive leadership team and the lines of business to support cyber hygiene.
Why Watch
Lynch has led a cyber resilience transformation by amalgamating a world-class team, cyber policies and framework designed controls. Additionally, she has engineered a best-in-market commercial cyber tool stack, which outperforms commercial managed cyber services, company leaders said.
Lynch has led her organization to implement best market practices such as zero trust, modern authentication and security orchestration automation and response to protect customer data and maintain customer confidence.
The business engagement team she created within SAIC assists with aligning the programs on customer requirements and expectations on the rising urgency and demand for cyber protection. Security is Lynch’s top priority, and she has infused her passion and energy into an executive leadership team-driven cyber awareness campaign.

Jim Rigney
Chief Information Security Officer, Alion Science and Technology
Alion Science and Technology Chief Information Security Officer Jim Rigney has led the company through numerous upgrades.
He modernized Alion’s security architecture by eliminating and replacing redundant, standalone technologies and appliances with solutions like next-generation firewalls that tie together critical components for more coordinated protection.
He enhanced Alion’s endpoint protection with industry best practice tools, leveraging traditional signature and heuristic technologies together, and outsourced tier-one security monitoring to a state-of-the-art industry leader to provide more robust, 24/7 coverage.
Rigney also supported Alion’s enterprise rollout of Microsoft 365 Cloud First initiative and automated many functions that were manual. He represents Alion externally to the federal government and defense industrial base community on issues related to cybersecurity strategy, policy and assurance. He is currently preparing Alion to obtain Cybersecurity Maturity Model Certification.
Why Watch
With over 30 years’ industry experience, Rigney is an organizational change agent and collaborative leader whose management acumen and ability to build customer relationships speaks for itself. He has a history of building cybersecurity organizations from the ground up and served as an original member of the Defense Security and Information Exchange, making him a standout in the cybersecurity peer community.
Rigney will continue focusing on security modernization and will upgrade policies and processes to meet the demands of the CMMC regulations and increase advanced threat and vulnerability management — tying together data from various platforms to produce specific, actionable intelligence to thwart attacks.

JR Williamson
Senior Vice President & Chief Information Security Officer, Leidos
Even before the pandemic hit, Leidos had an incredibly busy year planned, according to Chief Information Security Officer JR Williamson. One of its most significant milestones though was transitioning a large percentage of its employees to work from home — and doing so without weakening security controls or taking on more risks.
Last year, Leidos transformed its traditional security operations center into a security intelligence center, bringing in additional talent and establishing information-driven and adaptive threat hunting, zero trust policies, security orchestration automation and response, and threat intelligence to augment and enhance traditional approaches. Leidos also significantly improved its cybersecurity maturity and capability while running the security intelligence center 100% virtually through the pandemic.
This year, Williamson led efforts to implement standard and repeatable security capabilities and processes for cloud provisioning/deprovisioning for Leidos’ enterprise cloud management initiative. Under Williamson’s leadership, Leidos also led efforts to partner with the Defense Contract Management Agency in assisting to mature the Cybersecurity Maturity Model Certification cybersecurity standard. And Leidos onboarded both the Dynetics and L3Harris Security Detection and Automation acquisitions while ensuring the businesses could safely execute their business plans.
Additionally, Leidos’ Project LISA — short for Leidos Information Security Architecture — helped the company advance federal security missions and is designed to provide improved speeds, consistent governance, effective monitoring and risk management and data protection of various computing environments across Leidos’ global enterprise.
Based on focus group findings, Leidos recently established a new baseline assessment program for security awareness with measures to ensure the program helps improve the internal culture of cybersecurity and reducing risk. Leidos’ Data to Intelligence research and development project has also been instrumental in combining machine learning with advanced analytics to large volumes of telemetry data to discover the critical insights needed for fast and effective detection, which strengthens decision-making.
Finally, the successful implementation of security orchestration automation and response, or SOAR, capabilities into Leidos’ security intelligence center has significantly reduced time and effort needed for many standardized and repeatable tasks that analysts perform. Williamson will continue to lead efforts to build out more SOAR-based playbooks as Leidos focuses on hyperautomation.
Why Watch
In 2021, Leidos will transition from its traditional on-premise collaboration-based systems into Microsoft 365 GCC-High, work toward meeting the fourth level of CMMC, and launch a co-innovation pilot for combined cloud-based software defined perimeter and Secure Access Service Edge capabilities — a move designed to allow the company to expand its trusted application access more broadly and natively across the global internet without compromising security.
The company anticipates more room for growth and continued potential for mergers and acquisitions. And Leidos plans to build more user-centric security services with transparent consumption models in an effort to provide all of its security capabilities “as a service.”
As the vice chairman of the board for the Internet Security Alliance, Williamson also plans to contribute to two books on cybersecurity risk management, public-private partnerships and creating an enterprisewide culture of cybersecurity.

Nicole Dean
Chief Information Security Officer, Accenture Federal Services
Nicole Dean was just 35 when her executive abilities and accomplishments in technology landed her the nation’s highest civilian designation for leadership within the federal government — the Senior Executive Service.
Now the chief information security officer for Accenture Federal Services, Dean leads work protecting the internal information of one of the world’s largest consulting organizations, and works with account leads to securely implement their programs and safeguard client data.
The Security First employee engagement program — one of many innovative training and education programs she has launched — uses internal conferencing, social media and chat rooms to provide ethics training and counsel with an eye toward accountability. Applying a zero vulnerability standard to the program, Dean and her team cut the number of 30-day-plus open vulnerability cases by 90%. Security First also encourages participants to submit and ask questions. Over three years, the number of questions posed to the security office rose 300%.
Dean is also working to develop a system whereby a minimum-security bid factors into each proposal to ensure cyber protection is adequately considered in Accenture Federal Services’ delivery efforts. She and her team are developing standard language the teams can use to help educate current and prospective clients on the value of cyber investments.
Why Watch
Dean is highly regarded in the public and private sector as a proven, innovative and inclusive CISO, who is committed to new ideas, open dialogue and co-creating sustainable strategies with stakeholders across the business. She loves to think outside the box and challenge convention. Her strength is combining strong protective concepts with practical operational programs and bringing together an ecosystem inside and out to deliver security and value.

Nick Andersen
Public Sector Chief Information Security Officer, Lumen Technologies
As public sector chief information security officer for Lumen Technologies, Nick Andersen brings with him a suite of skills honed from working cybersecurity inside the Energy Department last year. He is proud of the government work he did to build, maintain and operationalize trusted partnerships with the private sector to increase the cybersecurity and resilience of critical infrastructure.
Now, Andersen is looking at cyber issues from a different angle. He joined Lumen in February to help ensure the company’s cybersecurity and IT products meet federal security requirements and risk management standards.
Governments, critical infrastructure partners and the collective supply chain are key targets for cyber compromise in a world where the frequency and sophistication of cyberattacks are ever increasing — which makes protecting them more challenging and more important than ever.
Lumen has one of the world’s largest internet backbones with 450,000 route miles of fiber and customers in more than 60 countries. That infrastructure, plus the ability to see cyber issues through a global lens and apply those insights to enabling, connecting and protecting government reasons, is why Andersen is excited to join Lumen.
Why Watch
Andersen is working to bring the government’s mission closer to its stakeholders by expanding the Lumen platform to support data-intensive, latency-sensitive requirements at the edge. The entire Lumen platform is backed by intelligent and automated cyber threat detection with built-in security to safeguard agencies’ data and applications. Andersen is focused on building on the company’s in-house threat intelligence to deliver best-in-breed cybersecurity and IT products that meet the government’s strict security requirements and risk management standards.

Omesh Agam
Chief Information Security Officer, Appian
When the COVID-19 pandemic hit, Appian’s security perimeter model had to fundamentally change to ensure resilience and security in the new era of 100% remote work.
“To support this, we did something big: We built our own . . . security, orchestration, automation and response to automate security incident investigations,” said Omesh Agam, chief information security officer. “With a lean staff working remotely, it was essential that we find ways to move faster. This application streamlines our investigations by pulling all the context and data we need into one place.”
Appian bolstered its stance by focusing on tools and process automation. The team added endpoint tools on laptops, additional checks through the system, and out to third party sites and services.
“When COVID started, it disrupted how people collaborate and how they get information at work,” Agam said. “By investing in increased automation, we countered the disconnections that could have slowed us down.”
The company also added two new security frameworks to its Trust Program: ISO 27017 and ISO 27018. These two new certifications are internationally recognized standards that provide additional controls for cloud-specific security risks.
“They are essential for our global enterprise clients,” Agam said.
In addition, Appian achieved Federal Risk and Authorization Management Program certification for its Robotic Process Automation offering.
“This is significant because government and defense organizations can now adopt cloud RPA directly from Appian that meets rigorous standards for security, compliance and scalability,” Agam said.
Why Watch
In 2021, Agam is working to scale up his information security team to support Appian’s growth. Externally, he is focused on customers’ requirements and ensuring Appian’s global security program continues to meet the requirements of the world’s largest companies and most demanding environments.

James Webster
Chief Information Security Officer & Vice President of Information Security, ManTech
ManTech CISO and Vice President of Information Security James Webster said his most significant accomplishment last year was successfully transitioning more than 4,000 employees to securely work from home.
Thanks to previous pandemic drills, a ready fleet of laptops and the ability to work over Virtual Private Network and leverage RSA SecurID tokens, ManTech’s work-from-home employees were able to continue in their jobs without losing access to any information services, he said.
“My team made a number of changes throughout the year — deploying cloud-based DNS protection and then pivoting to use cloud-based secure web gateways to improve user experience — all while keeping security and compliance as top priorities,” Webster added.
Applying zero trust in every iteration has been huge in advancing ManTech security.
“Because zero trust is a process and not a product, we are able to have conversations around identity, workloads and access with our business users that are allowing us to fundamentally change how we deliver services to the end user,” Webster said.
Increasing the understanding and details contained in an identity allows Webster and his team to make tailored access control decisions in real time instead of managing static access group lists that rapidly grow out of date.
“By tying these attributes to identities and workloads, we can better protect information while ensuring that users are able to access resources required to meet mission requirements,” Webster said.
Why Watch
In 2021, Webster will focus on continuing the zero trust journey, developing a security model that must support an increasingly mobile workforce even as employees return to the office, and Cybersecurity Maturity Model Certification compliance.
“In sum, the absolute highest levels of security,” Webster said.



