CHAD S. LORCH
Manager, Cyber Security
*******@*****.*** 512-***-**** Austin, TX CISSP, CEH
PROFESSIONAL SUMMARY
CISSP-certified security engineer with 20+ years securing enterprise and government networks, with the last decade focused on vulnerability management, application security, and DevSecOps at scale with the last five years managing security engineers and application security teams. Track record of cutting operational security costs by six figures, slashing false-positive rates by 90%, and building automated security tooling that gets adopted by engineering teams instead of fought. CORE COMPETENCIES
Vulnerability Management (Tenable, InsightVM, Nessus) · Web App Pen Testing (Burp Suite, IBM AppScan) · CI/CD Security Integration (GitHub, Perforce) · F5 APM & Identity-Based Access · PAM Security (Microsoft Entra ID) · SIEM (Microsoft Sentinel, Splunk) · Endpoint Protection (McAfee ePO/HBSS) · Network Security (Firewalls, IDS/IPS, VPN) · Risk & Compliance (NIST, CIS, HIPAA, PCI, ISO 27001) · Security Leadership & Cross-Functional Partnership PROFESSIONAL EXPERIENCE
Cyber Security Manager Feb 2020 – Oct 2025
Microsoft / ZeniMax Media Austin, TX
• Cut annual security tooling spend by $700K+ while improving detection coverage, by leading the migration of vulnerability scanning infrastructure across 100,000+ hosts at 11 global gaming studios.
• Reduced false-positive vulnerability alerts by 90% by integrating AI-driven scanning into GitHub, Git, and Perforce pipelines, cutting engineering triage time and embedding security checks directly into the development lifecycle.
• Built and managed a 5-person security and application security engineering team, standardizing security tooling and policy across 11 studios using AWS, Azure and on-prem datacenters environments.
• Managed the transition of security alerting from Splunk to Microsoft Sentinel for 60% of assets.
• Worked with IT teams and stakeholders to implement Microsoft Entra ID PAM solution across cloud and on-prem assets.
• Established secure-by-default development practices across all studios by partnering directly with Business Information Security Officers (BISOs) to align security roadmaps with game release timelines. Senior Security Engineer Oct 2016 – Feb 2020
ZeniMax Media Austin, TX
• Identified 2,000+ exploitable vulnerabilities across network infrastructure through hands-on penetration testing, prioritizing and closing critical-risk findings before they could be exploited.
• Deployed InsightVM across 100,000+ on-prem and cloud assets, giving the organization its first unified vulnerability visibility across hybrid infrastructure.
• Partnered with other security teams working incident response tickets to completion.
• Managed AWS and Azure IAM security across the organization.
• Established a CIS based risk management framework for reducing risk across cloud and on-prem environments.
• Secured all administrative portal access by architecting and deploying F5 Access Policy Manager, eliminating a previously unmanaged authentication gap.
• Drove remediation of systemic architecture weaknesses by leading deep-dive security reviews of complex, business-critical network systems.
Information Security Engineer May 2013 – Oct 2016
ProSphere Tek (U.S. Department of Veterans Affairs) Austin, TX
• Served as the sole web application penetration testing SME for the VA's in-house application portfolio, delivering full- spectrum tests and remediation roadmaps that directly shaped fix prioritization for stakeholders.
• Ran enterprise-wide vulnerability scanning (Tenable Security Center, Nessus), turning raw scan data into actionable reporting that leadership used to drive remediation cycles.
• Brought endpoint detection (McAfee ePO, HIPS/VSE) into compliance with federal security mandates by tuning detection rules across the managed fleet.
Information Assurance Security Officer Mar 2010 – May 2013 IZ Technologies (U.S. Marines) & Excelis Systems (U.S. Army) Afghanistan
• Owned network and endpoint security for a Regional Command theater of operations, managing Fortigate firewall policy, McAfee HBSS/EPO across all managed systems, and Bluecoat proxy/AD policy enforcement.
• Led incident response for classified data exposure events, including a negligent-disclosure incident, containing impact and documenting findings per DoD policy.
• Closed recurring compliance gaps by building a tracking system for vulnerability trends and unauthorized activity, used by subordinate units to correct deficiencies during IAVA compliance reviews. Senior Information Security Consultant / Systems Engineer Apr 2008 – Mar 2010 Denim Group San Antonio, TX
• Delivered enterprise risk assessments and penetration tests for clients including a multi-billion-dollar online auction company, a Fortune 500 SaaS provider, and a major insurance benefits provider against NIST, ISO 27001 and HIPAA security frameworks
• Led PCI compliance and wireless security assessments using Qualys Guard, NetStumbler, and Kismet, presenting findings directly to client leadership.
• Designed and deployed secure SharePoint intranet portals and hardened UNIX-to-Active-Directory integrations (Solaris, HP- UX, AIX, BSD) to NIST standards for enterprise clients. EARLIER EXPERIENCE
Senior Information Assurance Analyst, SecureInfo Corporation (Kuwait/San Antonio) — 2006–2008: Led penetration testing and risk analysis engagements; authored ST&E plans and security documentation for federal systems. Network Security Analyst, Computer Sciences Corp. (San Antonio) — 2003–2006: Provided incident response and COMPUSEC support to the Air Force Information Warfare Center across worldwide military field units. Network Security Analyst, Symantec Corporation (San Antonio) — 2001–2003: Monitored and triaged network intrusion detection alerts (Symantec IDS, Cisco Secure IDS) for enterprise customers. Intelligence Analyst / Network Security Analyst, United States Air Force — 1997–2001: Produced threat intelligence for the Air Force Computer Emergency Response Team (AFCERT); analyzed nationwide intrusion activity. CERTIFICATIONS & EDUCATION
CISSP — Certified Information Systems Security Professional Certified Ethical Hacker (CEH), 2014
ITIL Foundation V3
McAfee ePolicy Orchestrator & VirusScan Enterprise Administration, 2015