Searchable public resume
View resume details

Ambrosine Kettleborough-Nwankwo

Chief Information Security Officer
Phoenix, United States

Professional Summary

Chief Information Security Officer with 18+ years building and leading enterprise security programs across healthcare and financial services. Trusted advisor to boards and executive teams, with a record of maturing security posture against NIST CSF, ISO 27001, SOC 2, and HIPAA while keeping budgets predictable. Known for standing up zero-trust architectures, high-performing SOC teams, and incident response programs that cut breach impact and audit findings year over year. Combines deep technical roots in security engineering with sharp business judgment on risk, M&A diligence, and regulatory examinations.

Employment History

Chief Information Security Officer
Desert Ridge Health System · Phoenix, AZ
Jan, 2020 · Present
• Led enterprise cybersecurity strategy for a 4-hospital regional health system, reducing critical findings by 62% and maturing the program to NIST CSF Tier 3. • Directed a $14.8M security budget and a 45-person team across SOC, GRC, IAM, and application security. • Achieved and maintained ISO 27001 and SOC 2 Type II attestation while sustaining HIPAA compliance across 1,200+ applications. • Cut mean time to respond from 9.5 hours to 74 minutes and presented quarterly risk reporting to the Audit & Compliance Committee.
VP Information Security
Copper State Payments · Phoenix, AZ
Mar, 2016 · Dec, 2019
• Built and led a 32-person information security function for a fintech processing 140M transactions annually. • Owned PCI DSS 4.0 readiness and SOC 2 Type II, passing audits with zero critical findings for 6 consecutive cycles. • Delivered zero-trust segmentation that reduced attack surface by 48% across cardholder data environments. • Managed a $9.2M annual budget and reported residual risk and security KPIs to the board quarterly.
Director of Security Operations
Mesa Verde Regional Bank · Tempe, AZ
Jun, 2012 · Feb, 2016
• Ran a 24/7 SOC of 18 analysts and engineers, improving MITRE ATT&CK detection coverage from 54% to 91%. • Led FFIEC and GLBA examinations with no material findings across four consecutive audit cycles. • Implemented an ISO 27001-aligned ISMS and cut mean time to detect from 6.2 hours to 38 minutes. • Hired and mentored 26 security staff, with 8 promotions into leadership roles.
Senior Security Engineer
Sonoran Data Systems · Scottsdale, AZ
Aug, 2008 · May, 2012
• Engineered intrusion detection, SIEM, and endpoint controls supporting 4,000 users across 9 data centers. • Automated patch and vulnerability workflows, shrinking critical remediation windows from 30 days to 72 hours. • Led incident response for 60+ security events annually, containing 100% of confirmed breaches without data loss. • Cut high-severity code findings by 44% by partnering with application teams on secure SDLC practices.

Education

MS Cybersecurity
Arizona State University · Tempe, AZ
Aug, 2006 · May, 2008
Network defense, digital forensics, and security architecture.
BS Computer Science
University of Arizona · Tucson, AZ
Aug, 2002 · May, 2006
Minor in Mathematics. Dean’s List.

Skills

NIST CSF & ISO 27001 program leadership
Zero-trust architecture
Incident response & crisis management
SOC 2, HIPAA, PCI DSS compliance
Security budget & vendor management
Board-level risk reporting
SOC operations & detection engineering
Cloud security (AWS, Azure)

Courses

CISSP — Certified Information Systems Security Professional
ISC2
Active CISSP credential.
CISM — Certified Information Security Manager
ISACA
Active CISM credential.
CCSP — Certified Cloud Security Professional
ISC2
Active CCSP credential.