I build security programs from zero, and formalize them once you've scaled.
Twenty-nine years across Big 4 consulting, in-house enterprise security and CISO leadership, and two companies of my own. I work with venture- and private-equity-backed companies who need a security leader who has also run the business.
- CRISPR Therapeutics
- Kern Medical
- TeachTown
- HST Pathways
- OneSource Solutions International
- UC Extra
About
I'm a management consultant, operating CISO, and entrepreneur. I've served as Chief Information Security Officer at organizations including CRISPR Therapeutics, Kern Medical, UC Extra, HST Pathways, and TeachTown, and previously as CEO of a healthcare technology start-up I co-founded. Before that, I led business intelligence and enterprise security for a $12B Pacific Northwest health system, and spent over a decade in advisory roles at four of the five largest global accounting and consulting firms — Ernst & Young, PricewaterhouseCoopers, KPMG, and BDO Seidman.
That combination — operator, consultant, and founder — is the reason clients bring me in. I've sat on the other side of the boardroom table, made payroll, and raised capital, so I don't treat security as a technical function bolted onto the business. I treat it as part of how the business gets built, financed, and eventually sold.
I hold an Executive MBA from the Quantic School of Business and Technology and have completed executive education at The Wharton School and the Kellogg School of Management at Northwestern University. I'm a UCLA graduate, based in the San Francisco Bay Area, and have led engagements and teams across North America, South America, Europe, Africa, Australia, and Asia.
How I work
Companies need different things from a CISO depending on their stage. I take on both kinds of mandate.
Building
Standing up a security function from nothing — usually as the company's first dedicated security leader, working directly with engineering.
- Foundational security architecture and core controls
- Compliance build-out: SOC 2, HIPAA, ISO 27001, NIST 800-53
- Governance documentation ready before diligence starts, not assembled during it
Formalizing
Turning an existing security function into something a board, acquirer, or regulator can rely on.
- Third-party and vendor risk oversight
- Board and investor reporting, incident disclosure readiness
- AI and model risk governance, tooling and spend rationalization
- Security Program Development
- Risk & Security Assessments
- Third-Party & Vendor Risk Management
- Pre-Breach Planning & Incident Response
- Security Awareness Training
- Fractional CISO Services
- Staff & Project Augmentation
- Social Engineering & Phishing Assessments
By the numbers
Nearly three decades of consulting, in-house, and founder experience, condensed.
Selected highlights
- The first CISO for a California county public hospital system.
- Led the security response to an active federal OCR investigation at a multi-state 40-clinic healthcare provider, and rebuilt the compliant program ahead of its acquisition by a $7B+ health system.
- Co-founded and led a healthcare-data start-up as CEO and CISO, from bootstrapping through Seed financing.
- Helped scale a national fractional CISO practice as EVP of Consulting Services for a publicly traded cybersecurity consulting firm, delivering CISO leadership to numerous client companies, as well as overseeing multiple other fractional CISOs at our clients.
Credentials & board
Executive MBA, Quantic School of Business and Technology — Wharton Executive Programs, Corporate Governance & Entrepreneurship — Board Advisor, San Francisco Bay Area InfraGard — U.S. Secret Service Electronic Crimes Task Force — Infrastructure Liaison Officer, Northern California Regional Intelligence Center
Full education, certification, and board history available in the resume on request or on LinkedIn.
Let's talk about your security program.
I take on a small number of fractional and full-time CISO engagements at a time. If you're a venture- or private-equity-backed company thinking about your first security hire — or your next one — get in touch.
Email Miguel- Emailmiguel@inforgant.com
- Phone(415) 830-4080
- LinkedInlinkedin.com/in/miguelsanmateo
- LocationSan Francisco Bay Area, CA