Chicago’s CISOs to Watch: Security Leadership Citywide

Related

Share

Chicago has always been a city of markets, underwriters, and makers, and its security leadership reflects that mix. The CISOs below run cyber programmes at a ratings agency, a derivatives exchange, a mutual insurance group, a pharmaceutical manufacturer, and an AI legal technology firm, among others. What connects them is not a sector but a posture: regulated, board-accountable, and built for the long term.

Devin Rudnicki – CISO, Fitch Group

When Devin Rudnicki set a 2025 performance objective requiring every information security employee at Fitch Group to put AI to work inside one of their own team processes, she was signaling how he runs the function: practical, measurable, and a step ahead of the board’s questions. CISO since January 2024, she leads a department of more than 45 staff and consultants spanning all Fitch business units, Fitch Ratings included, and reports quarterly to the Board of Directors and Executive Committee on incidents, risk, controls, and metrics. She built and maintains a three-year, outcome-driven security strategy, owns the department budget, and serves as Incident Commander when events demand it. The path there ran through building Fitch’s application security programme from the ground up, and before that three and a half years at OCC, the Chicago clearing house, where she managed remediation of SEC and CFTC examination findings and drove alignment to NIST CSF against Regulation SCI. She sits on ChicagoCISO’s advisory board and belongs to Team8’s CISO Village.

Benjamin Lawson – CISO, Cboe Global Markets

Cboe Digital’s first security chief has become the parent company’s. Benjamin Lawson took the CISO seat at Cboe Global Markets in November 2024 after two and a half years securing its digital assets arm, a role he arrived at by way of ErisX, the crypto exchange Cboe acquired, where he ran information security. The acquisition could easily have been an ending; instead it made him the continuity candidate for one of the world’s largest options exchanges. Before markets came e-commerce and infrastructure: more than five years as Groupon’s director of information and application security, four and a half years at Akamai, and two years at Kohl’s on multichannel and e-commerce technical projects. Earlier still came seven years at Robert W. Baird, where he started as a software developer, and four years as a staff sergeant in the Air National Guard.

Michael Boucher – VP and CISO, Federal Home Loan Bank of Chicago

Thirty years, nine employers, and one recurring pattern: Michael Boucher keeps getting hired to build or mature security programmes at institutions that cannot afford to get it wrong. He joined the Federal Home Loan Bank of Chicago as VP and CISO in July 2026, arriving from JLL, where he spent eight years rising from CISO for the Americas to Vice President of Global Information Security. Before JLL came five and a half years as CISO at FTD, plus earlier stops at PwC, Xerox’s affiliated computer services arm as Director of Global Information Security, USG Corporation in IT risk management, and Grant Thornton. The foundation was six and a half years as network security lead at Arthur Andersen. His regulatory fluency runs from PCI DSS and GDPR through GLBA, FFIEC, SOX, HIPAA, NIST, ISO 27001, CMMC, and FedRAMP, a list that explains why a wholesale bank with housing-finance obligations came calling.

Mahmood Khan – SVP and Global CSO, CNA Insurance

Few security chiefs in Chicago can claim a career that touches banking, airlines, and insurance at scale. Mahmood Khan can. Since April 2020 he has served as SVP and Global CSO at CNA Insurance, one of the country’s largest commercial property and casualty underwriters. He arrived from United Airlines, where he spent two and a half years as Managing Director of Cyber Security Operations, and before that a decade at Bank of America, rising from VP to Senior Vice President for global information security. The foundation was nine years in security operations and engineering at ABN AMRO and LaSalle Bank, making almost his entire career a Chicago one even as his remit turned global. Board and public sector advisory work rounds out the profile.

Greg Bee – SVP and CISO, Hagerty

Thirty-nine years in information technology, twenty-four of them as a CISO, and Greg Bee is still collecting firsts: Chicago’s 2026 ORBIE winner in the large corporate category, and a board seat at ChicagoCISO taken up in June 2026. As SVP and CISO at Hagerty since November 2023, he secures the insurer best known for protecting collector cars and the community around them, a niche that turns out to involve the same enterprise risk discipline he honed over three decades at Country Financial, where he built and ran the information security and privacy programme against ISO 27001, COBIT 5, and NIST controls. Between the two came a year as CISO at Horace Mann and four and a half years as CISO and Chief Risk Officer at Pekin Insurance. He chairs his share of classrooms too, having led Illinois State University’s cyber security advisory board from 2022 to 2025 while teaching as an adjunct, and Security Connect has named him a Top 100 CISO every year since 2021.

Rizwan Mir – VP and Global CISO, Perrigo

Most CISOs arrive from security. Rizwan Mir arrived from running things: fifteen years at Lucent Technologies building a network engineering organisation from thirty people to more than two hundred, then a term as CEO of a $200 million sovereign technology fund. That operator’s grounding shows in how he holds the seat at Perrigo, where since July 2024 he has been VP Global CISO and head of IT enterprise risk management, owning enterprise security strategy with board and audit committee reporting and SEC cyber-disclosure readiness built in. He sits on the company’s AI governance committee and leads a major operational technology security maturity initiative across the manufacturing footprint. He came to Perrigo from Videojet Technologies in Wood Dale, where as Global CISO he covered 38,000 assets across operating companies in three countries, and he remains a governing body member of the Chicago CISO Community and sits on its advisory board.

Matthew Brothers-McGrew – CTO and CISO, Reveal

Scaling a startup into a global platform usually breaks something; at Reveal, Matthew Brothers-McGrew made sure it was not security. As Chief Technology and Information Security Officer since June 2021, and CISO and EVP of Technology for three years before that, he has overseen the integration of eight acquisitions into unified, SaaS eDiscovery platforms powered by AI, building the security processes and compliance frameworks that let legal departments trust the product with their most sensitive matters. His route to the role ran through enterprise architecture at Reveal itself and three and a half years as an analyst at Interhack, the Columbus forensic and security consultancy, where he has remained a visiting analyst throughout his decade at Reveal. Legal technology lives and dies on confidentiality, which makes his dual technology and security mandate less a luxury than a business requirement.

What This Group Says About Chicago

Read together, these seven careers describe a city whose security leadership grew up alongside its industries rather than being imported to manage them. Clearing houses, carriers, banks, and manufacturers produced CISOs who speak regulation natively and treat board reporting as craft, not chore. If there is a Chicago style, it is this: unglamorous, accountable, and quietly ahead of the mandate.

Related reading:

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.