[ UNCLASSIFIED // CHANCO.DEV ]
CISO · VP, SECURITY & COMPLIANCE · ENTERPRISE SECURITY EXECUTIVE

Brandon Chanco

Security executive and Marine Corps veteran who builds and scales enterprise security, governance, and compliance programs from the ground up — across Fortune 100 and the Department of Defense, Impact Levels 2 through 6.

bchanco@shebash.io · LinkedIn · Hoover, AL · Active TS/SCI Clearance
Brandon Chanco
01 Summary

Security executive and U.S. Marine Corps veteran who builds and scales enterprise security, governance, and compliance programs from the ground up across Fortune 100 and Department of Defense environments. Founded IBM's Federal Compliance Program Office governing 500+ products, and has led first-of-kind authorization campaigns spanning DoD Impact Levels 2 through 6. Currently serves as CISO of a Top Secret–cleared defense firm, owning enterprise security strategy, risk governance, and CMMC posture. Known for translating complex regulatory mandates into board-ready strategy and measurable mission outcomes.

500+
Products governed
IL2–IL6
DoD authorization range
300K
Enterprise users impacted
100+
Global campuses led
02 Executive Competencies
Leadership
  • Enterprise Security Strategy
  • Security Program Build-Out & Scale
  • Governance, Risk & Compliance (GRC)
  • Board & C-Suite Engagement
  • Organizational & Team Leadership
Authorization & Cloud
  • FedRAMP & DoD Authorization (IL2–IL6)
  • Regulatory Strategy: RMF, NIST 800-53, FISMA
  • CMMC & DCSA/FSO Program Ownership
  • Cloud Security Strategy (AWS, Azure, GCP)
  • Zero Trust & DevSecOps Transformation
Program & Risk
  • M&A / Carve-Out Security (Kyndryl)
  • Vendor, Contract & Budget Oversight
  • 3PAO, JAB & Authorizing Official Relations
  • Cross-Functional Program Leadership
  • Risk Acceptance & Executive Decisioning
03 Professional Experience
JUN 2024 – PRESENT
SHE BASH LLC
Chief Information Security Officer

Enterprise security leader for a Top Secret–cleared, SBA-certified woman-owned DoD firm; owns security strategy, risk governance, the DCSA/FSO program, and CMMC posture.

  • Sets and executes enterprise security strategy as the senior security authority to the executive team
  • Owns the RMF authorization lifecycle for multiple DevSecOps platforms — SSP development, control implementation, and continuous monitoring — driving systems to authorization
  • Built the company's security policy framework and governance, aligned to NIST 800-53 and CMMC Level 2
  • Leads a team of security architects securing AWS and Kubernetes infrastructure to DoD mission standards while preserving platform scalability
JUN 2024 – JUN 2025Concurrent
Skylight — USAF BESPIN
Cybersecurity Leader

Security strategy advisor to the BESPIN CISO across the platform ecosystem.

  • Set security architecture and compliance strategy across the BESPIN platform ecosystem
  • Defined a secure-platform proof of concept and growth roadmap to expand BESPIN offerings across DoD, incorporating FedRAMP and IL5 requirements
  • Led RMF and platform authorization efforts for multiple AWS DevSecOps environments
MAY 2023 – JUN 2024Concurrent
Platform One CNAP
Cybersecurity SME Lead

Authorization lead for critical DoD systems spanning Impact Levels 2 through 6.

  • Directed ATO efforts across IL2–6 — gap analyses, POA&M remediation, and authorization for critical DoD systems
  • Drove Zero Trust adoption via Next-Generation Firewalls and Software-Defined Perimeter
  • Established policy-based access controls in Kubernetes for secure, scalable deployment across AWS and Azure
  • Led “Big Bang” integration strategies that delivered rapid, low-downtime security upgrades
JUL 2021 – MAY 2023
IBM
Cybersecurity Architect — Federal Lead & Advisor

Federal lead of IBM's enterprise compliance program for the government market.

  • Built and led IBM's Federal Program, defining the strategy to align 500+ products with FedRAMP and FISMA for government market access
  • Directed gap analyses against NIST 800-53, guiding software teams through remediation and evidence collection
  • Embedded compliance into product architecture reviews early in the lifecycle, accelerating ATO timelines
  • Shaped multi-cloud compliance strategy across AWS, Azure, GCP, Oracle, and IBM Cloud; influenced roadmaps for IoT, AI/ML, and Kubernetes capabilities
JUL 2021 – NOV 2022
IBM
Technical Project Manager / Solutions Architect

CIO-office program lead for global voice infrastructure and the Kyndryl carve-out.

  • Led global voice infrastructure strategy within the CIO office for 300,000 employees across 100+ campuses
  • Led the Kyndryl spin-off bifurcation, separating network, voice, and billing across global campuses with zero service disruption
  • Global Change Manager for Call Control; led CAB reviews and assessed contracts, SOWs, and vendor security posture to drive savings
NOV 2020 – JUL 2021
RiverTech LLC
Senior VoIP / Security Engineer

Led a 5-engineer team across monitoring, incident response, architecture, and policy for a classified DoD VoIP environment.

  • Designed and deployed a NIST-compliant secure VoIP solution to ATO for a critical DoD program at IL6; authored runbooks and DRP/BCP
NOV 2018 – NOV 2020
Cisco Systems
Senior Security / Voice Engineer

Led build, security, and operations of a Hosted Collaboration Solution for multiple DoD entities, including NOC Tier 1–3 training and client onboarding.

  • Drove Cisco products through DISA APL and STIG processes; supported 20K+ end users and earned seven peer awards in ten months
JAN 2016 – NOV 2018
MCS — Seymour Johnson AFB, NC
Network Engineer / Project Manager

Led a 5-person team modernizing USAF base infrastructure — replacing legacy systems, executing network upgrades, and resolving ~1,000 tickets annually.

04 Education & Credentials
Education
Doctor of Engineering (D.Eng.), Cybersecurity
George Washington University
Expected 2027
MBA, IT Management
Western Governors University
B.S., Cybersecurity & Information Assurance
Western Governors University
Military Service
U.S. Marine Corps Veteran
Combat-trained · Electronics Maintenance Technician Course (29 Palms, CA)
Certifications & Credentials
  • CISSP
  • CCSP
  • CRISC
  • CSSLP
  • PMP
  • CSM
  • ITIL v4
  • CCNP Collaboration
  • Cisco Certified Specialist
  • CompTIA Security+
  • CompTIA PenTest+
  • CompTIA CySA+
  • CompTIA Network+
  • CompTIA A+
  • CompTIA CSAP
  • CompTIA CSIS
  • CompTIA CNSP
  • CompTIA CNVP
  • CompTIA CIOS
05 Latest talk
06 Latest writing
07 Contact

Struggling with compliance, security, or buy-in on your product or technology? Let's talk.