Nigel Sampson, CISSP
Chief Information Security Officer · Security Program Architect · Board Advisor
Lyman, Maine (Remote) *********@*****.*** linkedin.com/in/nigelsampson
EXECUTIVE PROFILE
Transformational cybersecurity executive with 15+ years of progressive CISO leadership across healthcare, financial services, global technology, and higher education. Consistent record of building security programs from the ground up — achieving SOC 2 Type 2, HITRUST CSF, and PCI DSS certifications in compressed timelines, reducing organizational risk by up to 85%, and enabling business growth through strategic security architecture. Equally capable of configuring enterprise security tooling and presenting to a Board. Published author, advisory board member, and active participant in state and national cybersecurity governance. CISSP-certified since 2009. Holds dual US / UK citizenship.
LEADERSHIP PHILOSOPHY
Security is a business enabler, not a cost center. My approach is to earn a seat at the revenue table by connecting every security decision to business outcomes — protecting what the organization is building, not just defending what it has. I build programs that scale with the organization and produce executives and boards who view security as a competitive advantage. I hold myself to the same standard I hold vendors: demonstrate value, quantify impact, and deliver on time.
CAREER ACHIEVEMENTS
•Reduced organizational risk exposure by 85% at DoseSpot through Zero Trust architecture and full security stack rebuild — no inherited team, no legacy playbook
•Achieved SOC 2 Type 2 certification in under 6 months at Alegeus — fastest in company history — and reduced compliance risk by 60%
•Achieved HITRUST CSF certification across 6 lines of business at Cotiviti, managing a 12-FTE security organization
•Deployed Zero Trust Network Access across 65 countries and 4,500 employees at IDG; cut vulnerability exposure by 80% and IT risk profile by 40%
•Audited 60+ FDIC-regulated financial institutions over 9 years, developing deep regulatory fluency across FFIEC, GLBA, and OCC examination standards
•Active member: Vigitrust Global Advisory Board · SecureWorld Advisory Board · State of Maine Cybersecurity Advisory Council
•Recipient: MBTA Secretary of Transportation Innovation Award
BOARD-LEVEL CONTRIBUTIONS
•Deliver formal Information Security Program Reports to MCCS Board of Trustees annually covering risk posture, compliance status, incident activity, and strategic roadmap
•Presented to Cotiviti Board of Directors quarterly on enterprise security risk posture, HITRUST compliance status, and regulatory developments in healthcare data privacy
•Briefed executive leadership at IDG on global cyber risk posture, threat intelligence summaries, and M365 migration security architecture across seven business units
•Managed formal breach disclosure to Maine Attorney General; coordinated with General Counsel and external law firms on regulatory response and class action inquiry
•Appointed by the Governor of Maine, I sit on the State of Maine Cybersecurity Advisory Council, contributing to statewide public-sector security governance and policy development
PROFESSIONAL EXPERIENCE
Chief Information Security Officer / Cyber Response Officer · Maine Community College System (MCCS) · Maine · 7 Campuses · ~18,000 Students 2024 – Present
Strategic Leadership
•Manage [$500k] security budget and [$300k] technology portfolio across seven campuses serving ~18,000 students; report to CIO with board-level visibility on all material security matters
•Hold dual appointments as CISO and Cyber Response Officer — the single accountable executive for security strategy, incident command, and regulatory compliance across the system
•Serve as MCCS representative on the State of Maine Cybersecurity Council, contributing to statewide policy and coordinating threat intelligence sharing with municipal and state partners
•Architecting 80-hour Microsoft cloud security program (Defender, Entra ID, Purview, Sentinel, Intune) phased implementation supporting FERPA, GLBA, and NIST CSF 2.0 compliance objectives
Executive Impact
•Partnered with CIO and General Counsel to manage end-to-end Maine AG breach disclosure — incident characterization, regulatory filing, board briefing, and law firm coordination — within required notification windows
•Deliver annual Information Security Program Report to Board of Trustees covering Sophos MDR deployment, MFA rollout progress, NIST CSF risk assessment results, and 18-month strategic roadmap
•Collaborate with VP Financial Resources on security budget requests and vendor contract negotiations, including Barracuda ESG and Sophos MDR renewals
•Lead AI security governance program evaluating LLM-integrated productivity tools (Microsoft Copilot, Otter.ai, Fireflies.ai) for FERPA compliance and data-residency risk — enabling faculty and staff productivity while protecting student data
Program Maturation
•Elevated MCCS security program maturity from ad hoc to managed tier as measured by NIST CSF 2.0 — establishing formal risk register, incident response plan (CIRP v2.1), and governance documentation where none existed
•Driving enterprise-wide MFA rollout across all 7 colleges (Wave 1 active; full enforcement target 2027) reducing credential-based attack surface across [18,000] + student and faculty accounts
•Led active threat intelligence response to Sapphire Sleet supply chain compromise (axios/npm, 2026) IOC extraction, dependency analysis, credential rotation, and containment within 3 hours
•Founded MCCS Information Sharing and Analysis Center (ISAC) governance framework; delivered Q1 2026 threat briefing to system presidents and IT leadership
Founder & Principal Security Advisor · Cyber Design Associates · Lyman, ME · Independent Consulting 2024 – Present
•Founded independent security consulting practice advising clients across higher education, healthcare, and financial services on program architecture, cloud security, and AI risk governance
•Deliver security assessments, vendor risk frameworks, compliance roadmaps, and policy architecture; maintain active client engagements concurrent with institutional CISO role
Head of Cybersecurity & IT Operations · DoseSpot · Dedham, MA · Healthcare SaaS 03/2024 – 12/2024
Strategic Leadership
•Served as founding security executive for a healthcare SaaS platform; built full security program from zero with [$XM] budget and no inherited team or documentation
•Reduced organizational risk exposure by 85% through Zero Trust architecture implementation, security tool consolidation, and rebuild vulnerability management program
•Owned dual mandate: CISO-level security strategy plus full IT operations including infrastructure, helpdesk, and technology vendor management
Executive Impact
•Partnered with CEO and COO to establish security as a commercial differentiator in sales conversations with health system and pharmacy chain clients
•Developed SOC 2 Type 2 readiness roadmap and presented compliance timeline to board and investor stakeholders
Program Maturation
•Deployed endpoint, SIEM, vulnerability management, IAM, and cloud configuration controls — establishing HIPAA-aligned security architecture across a cloud-native platform
•Built third-party vendor risk program from scratch; assessed and tiered all critical integrations against HIPAA and organizational risk thresholds
Director of Global Cybersecurity / CISO · International Data Group (IDG) · Needham, MA · Global · 65 Countries · 4,500 Employees 02/2022 – 02/2024
Strategic Leadership
•Led global cybersecurity program for a multinational media and technology company spanning 65 countries, 7 business units, and 4,500 employees; managed $4M security budget and 5-FTE security organization
•Deployed Zero Trust Network Access (ZTNA) across all business units — reducing vulnerability exposure by 80% and overall IT risk profile by 40% while enabling business continuity across jurisdictions with conflicting data sovereignty requirements
•Architected Microsoft 365 migration security posture supporting a major infrastructure modernization program across globally distributed teams
Executive Impact
•Delivered quarterly cyber risk briefings to global executive leadership and business unit presidents across US, EU, and APAC regions
•Partnered with CIO and General Counsel to navigate GDPR, regional data-sovereignty requirements, and sector-specific press and media regulations across 65 operating countries
•Built and managed global SOC; led adversarial testing program including red team exercises, phishing simulation, and executive tabletop exercises across international business units
Program Maturation
•Unified fragmented, siloed security practices across 7 business units into a single governance framework — establishing common policy standards, incident response procedures, and risk reporting cadence
•Reduced mean time to detect (MTTD) and respond (MTTR) to security incidents through centralized SIEM deployment and automated playbook execution
Director of Cybersecurity / Information Security Officer · Alegeus · Waltham, MA · FinTech / Benefits Administration SaaS 01/2020 – 02/2022
Strategic Leadership
•Built security operations and engineering teams from the ground up; managed $1m security budget and 5-FTE team supporting PCI DSS, SOC 1, and SOC 2 compliance in a regulated financial services SaaS environment
•Reduced compliance risk by 60% and established security as a sales enablement function — enabling enterprise client acquisition by demonstrating SOC 2 and PCI compliance readiness
Executive Impact
•Presented compliance status and risk posture to executive leadership and external auditors; managed direct relationships with PCI QSA and SOC 2 audit firms
•Implemented third-party vendor risk program covering 200+ integrations; established security architecture review gate for all new product features and partner integrations
Program Maturation
•Achieved SOC 2 Type 2 certification in under 6 months — fastest in company history — through controls-first design and automated evidence collection
•Deployed SIEM, DLP, and vulnerability management program; automated compliance monitoring and reporting, reducing manual audit-prep effort by 50%
Director of Information Security / ISO · Cotiviti · North Waltham, MA · Healthcare Analytics 08/2018 – 10/2019
Strategic Leadership
•Led enterprise information security program for a healthcare analytics organization with $3m security budget and a 12-FTE team of analysts and engineers
•Achieved HITRUST CSF certification across 6 lines of business — one of the most rigorous healthcare compliance frameworks — managing a complex, multi-entity assessment process
Executive Impact
•Delivered quarterly security briefings to Board of Directors; translated technical risk posture into business-impact framing for non-technical governance audiences
•Partnered with Chief Compliance Officer and General Counsel on HIPAA, HITECH, and state-level data privacy requirements across multiple healthcare client environments
Program Maturation
•Elevated security program maturity through HITRUST CSF framework adoption — establishing documented controls, evidence management, and continuous monitoring across all six business lines
Head of Security Operations · Charter Communications · Andover, MA · Telecommunications 05/2017 – 07/2018
•Built and managed global SOC operations; oversaw security monitoring for 100+ client cloud environments in an MSSP-style managed security delivery model
•Developed security advisory practice producing client-facing risk assessments and threat briefings; received MBTA Secretary of Transportation Innovation Award for security program contributions
•Managed security engineering team; implemented SIEM, vulnerability management, and orchestration tooling supporting enterprise and government clients
Information Security Officer · Salem Five Bank · Salem, MA · Community Banking 2016 – 2017
•Served as ISO for a community bank with full accountability for FFIEC, GLBA, and regulatory examination compliance across retail banking and mortgage operations
•Managed security awareness, vulnerability management, and third-party risk programs; reported directly to Board Risk Committee
Senior Security Auditor · Network Systems Consulting · Financial Services · FDIC-Regulated Institutions 2008 – 2016
•Audited 60+ FDIC-regulated financial institutions over 9 years, delivering formal examination reports to C-suite and board risk committees across community banks, credit unions, and regional lenders
•Assessed IT controls, information security programs, business continuity plans, and vendor management frameworks against FFIEC, GLBA, and OCC standards
•Identified systemic control deficiencies; advised executive leadership on remediation roadmaps and regulatory examination readiness — building deep fluency in board-level risk governance
THOUGHT LEADERSHIP
•Vigitrust Global Advisory Board — contributing to international security governance, GRC frameworks, and global risk standards
•SecureWorld Advisory Board — speaker and panelist on CISO strategy, emerging threat landscape, and security program maturation
•Author: 'Understanding the Benefits of CMMI' (Tripwire, 2020); cybersecurity articles in Western Independent Bankers Magazine (2009–2010)
•State of Maine Cybersecurity Council — active participant in statewide public-sector cybersecurity policy and threat intelligence coordination
•Professional Networks: CISO Society, MS-ISAC, Boston CISO Exec Net · Aphinia CISO Network · ISC2
CERTIFICATIONS & EDUCATION
Certified Information Systems Security Professional (CISSP) ISC2 · Since 2009
Frameworks: NIST CSF 2.0 · HITRUST CSF · SOC 2 · PCI DSS · ISO 27001 · HIPAA · GLBA · FERPA · FFIEC · FedRAMP
Dual US / UK Citizenship