Enterprise Information Security & Technology Executive

Translating Technical Architecture into Boardroom Value & Cyber Resilience.

Senior cybersecurity and technology leader with 20+ years scaling Identity Governance (IAM/NHI), Zero Trust fabrics, and continuous risk management across multi-billion-dollar supply chain ecosystems.

Paul Dumbleton, CISSP - Technology & Cybersecurity Executive

Paul Dumbleton

Sr. Director – Security Engineering & Identity

Core Focus Identity Security, Zero Trust, Board & SEC Governance
Enterprise Scale $20B+ Footprint | Hybrid Cloud & OT/IT
Leadership Retention 84% Engagement Benchmark | CISSP Mentor
CISSP #360079 ISSA Board Strategic Leadership Grad
$0B+
Enterprise Footprints Secured
0%
MTTR Incident Time Reduced
0%
Team Engagement Benchmark
0%
Shadow IT & Threat Reduction
Executive Summary

Bridging Deep Architecture with Board-Level Risk

With more than two decades in enterprise cybersecurity and technology infrastructure, I lead with a clear mandate: eliminate the bottleneck and create organizational leverage.

CEOs, Audit Committees, and Boards do not need 300 pages of technical vulnerability logs; they require a clear understanding of what is material, what could halt the business, and how security enables revenue generation. My leadership anchors security directly into operational workflows—transforming legacy technical debt into governed, automated, and defensible architectures.

Strategic Alignment

Structuring security roadmaps directly against enterprise EBITDA, supply chain uptime, and investor trust.

People & Leverage

Player-coach philosophy cultivating high-retention engineering and architect talent through intentional career pathways.

"Cybersecurity is not about enforcing friction—it is the foundational confidence that enables an enterprise to scale, innovate, and navigate evolving threat landscapes without disruption."
Paul Dumbleton, CISSP Executive Security Philosophy
Executive Capabilities

Interactive Board & Strategy Blueprint

Explore how I operationalize risk governance, enterprise identity, and scalable technical architecture.

Executive Risk Taxonomy & SEC Materiality

Boards require an actionable risk narrative. I establish repeatable protocols connecting cyber defense directly to financial governance.

  • SEC 10-K & 4-Day Disclosures: Materiality determination frameworks that decouple raw alert counts from true operational loss.
  • Audit & Framework Alignment: Strict adherence to NIST CSF 2.0, SOX, and PCI-DSS Level 1 controls without slowing business innovation.
  • Supply Chain & M&A Governance: Comprehensive technical integration blueprints ensuring acquired assets are securely unified into corporate baselines.
Enterprise Risk Velocity Live Matrix
Vulnerability Prioritization: Risk-Based (VPR 9+)
Material Incident Threshold: Documented Protocol
Non-Human Identity Ratio: Automated Lifecycle (45:1)
Legacy Enclave Isolation: Macro-Segmented

Enterprise Identity: The Modern Perimeter

Pioneering modern identity fabrics across workforce, customer (CIAM), and autonomous workload entities.

  • Human Identity Governance (IGA): Replaced fragmented legacy systems with automated Joiner-Mover-Leaver (JML) workflows and frictionless security SSO..
  • Non-Human Identity (NHI) Governance: Eliminating unmanaged service keys, bot sprawl, and static secrets in favor of short-lived workload federation.
  • Privileged Access Management (PAM): Establishing Zero Standing Privileges (ZSP) and Just-in-Time access for enterprise cloud and database infrastructure.
Identity Fabric State
1 Automated Lifecycle Governance (IGA)
2 Phishing-Resistant MFA & Passkeys (FIDO2)
3 Workload Identity Federation (Secret-less)

Continuous Threat Exposure Management (CTEM)

Shifting the paradigm from static CVSS volume counting to continuous exploitability validation and blast radius containment.

  • Vulnerability Management Redesign: Deployed dynamic Tenable VPR scoring, retiring noise to provide actionable remediation cadences for engineering teams.
  • Legacy Secure Enclaves: Isolated unsupported legacy applications in restricted network enclaves with strict ingress/egress filtering.
  • Network Microsegmentation: Transitioned flat networks into compartmentalized zones, preventing lateral movement of ransomware and malware.
Exposure Defense Pillars
SIEM/SOAR Triage:Automated Playbooks
Threat Prioritization:Exploitability-Driven
Lateral Containment:Micro-Segmented

High-Retention Cultures & Servant Leadership

Top security engineering talent requires clarity, psychological safety, and meaningful career progression.

  • 84% Engagement Score: Maintained high employee satisfaction and retention across major organizational restructuring.
  • Workforce Mentorship: Founded internal CISSP cohorts and structured growth plans, mentoring junior analysts into senior engineering roles.
  • Culture of Shared Responsibility: Partnering with Sales, Distribution, and Finance to ensure security is embraced as a business partner.
Team Health Metrics
Engagement Favorable:84% Top-Tier
Leadership Model:Servant Leader / Coach
Talent Development:CISSP Study Groups
Career Milestones

Proven Track Record of Enterprise Scale

2024 – Present

Senior Director – Security Engineering & Identity

US Foods, Inc. (Rosemont, IL)

Fortune 500 Foodservice Leader

Direct enterprise security engineering, identity governance infrastructure, and resilience roadmaps across five strategic enterprise risk themes.

Identity Modernization: Directed the multi-phase deployment of enterprise SailPoint IGA, automating Joiner-Mover-Leaver (JML) processes, deprecating legacy technical debt, and rationalizing SSO infrastructure to Microsoft Entra.
Continuous Threat Exposure (CTEM): Spearheaded the evolution of vulnerability management from static volume reporting to risk-based exploitability prioritization (VPR), establishing secure enclaves to isolate legacy platforms.
Talent Calibration: Maintained an 84% positive team engagement score while orchestrating talent calibration, establishing internal CISSP development cohorts, and managing multi-tier direct and offshore partner teams.
2018 – 2024

Enterprise Information Security Manager

Gordon Food Service (Grand Rapids, MI)

$20B North American Enterprise

Built and directed the SecOps, engineering, and identity architecture programs protecting a $20B supply chain enterprise.

SecOps & Automation: Rebuilt the core SecOps architecture with cloud SIEM/SOAR platforms (Google Chronicle), automating telemetry enrichment and cutting incident remediation time (MTTR) by 50%.
Identity & PAM Transformation: Centralized enterprise identity governance via Saviynt Enterprise Identity Cloud, established the Customer IAM (CIAM) practice, and rolled out enterprise Privileged Account Management (PAM).
Zero Trust Microsegmentation: Directed distribution center network macro-segmentation and multi-location OT/IT isolation, eliminating lateral attack paths for ransomware containment.
2012 – 2018

IT&S Global Infrastructure Security Engineering Manager

Perrigo Company (Allegan, MI)

$1.2B Global Footprint | 47 Countries

Promoted to lead the newly formed Security Solutions & Data Protection team for a global pharmaceutical manufacturing leader.

Cloud Security & CASB: Architected global cloud access policies and deployed Cloud Access Security Broker (CASB) technology, driving an 80% reduction in unauthorized Shadow IT services.
Perimeter & Threat Defense: Spearheaded next-generation anti-phishing/anti-spam infrastructure, decreasing malicious inbound threats by 80%.
Executive Thought Leadership

The Strategic Engineer

An architectural series unpacking complex enterprise security challenges and translating technical decisions into business risk outcomes.

Episode 1: The Non-Human Identity Explosion
Identity Governance

Episode 1: The Non-Human Identity (NHI) Explosion

Machine identities outnumber humans 45:1. Moving beyond legacy IGA to govern the "Shadow Mesh" of API keys with secret-less workload federation.

Episode 2: Beyond the Perimeter – Strategic Segmentation
Zero Trust Architecture

Episode 2: Beyond the Perimeter – Strategic Segmentation

Ending the outdated "M&M" security model. A pragmatic 90-day macro-segmentation roadmap to contain ransomware blast radius in OT/IT networks.

Episode 3: The Mythos Mandate – Autonomous Defense & Zero Trust
Autonomous Defense & AI

Episode 3: The Mythos Mandate – Autonomous Defense & Zero Trust

Addressing compressed threat timelines. Why machine-speed attacks mandate autonomous containment, immutable infrastructure, and human-on-the-loop controls.

Episode 4: The Agency Gap – Governing Agentic AI
AI Governance

Episode 4: The Agency Gap – Governing Agentic AI

Transitioning from data leakage to managing operational risks of autonomous, over-permissioned AI agents and prompt injection vectors.

Episode 5: The 47-Day Warning – Navigating Certificate Sprawl
Risk & Modernization

Episode 5: The 47-Day Warning – Navigating Certificate Sprawl

Machine identities and shrinking certificate lifespans. How automated ACME protocols prevent multi-million-dollar operational outages.

Industry Influence

Board Stewardship & Industry Leadership

ISSA West Michigan

Board Leadership

Collaborate on regional cybersecurity strategy, monthly executive forums, and community peer collaboration.

SIM West Michigan

Executive Member

Engage with senior technology leaders on corporate governance, business stewardship, and executive management best practices.

Cloud Security Alliance

Active Contributor

Advance hybrid cloud governance frameworks, Zero Trust architecture benchmarks, and AI governance standards.

SANS Institute & MiC3

Advisor & Reviewer

Course quality control testing for SANS and previous contributions to state infrastructure defense with MiC3.