Searchable public resume
View resume details

Rafael Ibarra

Chief Information Security Officer
Austin, United States

Professional Summary

Security executive with 18+ years building enterprise security programs for SaaS and fintech companies. Led a 45-person security organization across SecOps, GRC, product security, and identity; cut critical-vuln mean time to remediate by 68% and achieved SOC 2 Type II, ISO 27001, and PCI DSS Level 1 without audit exceptions. Board-facing communicator who translates cyber risk into business decisions and budget.

Employment History

Chief Information Security Officer
Lonestar Ledger Inc. · Austin, TX
Mar, 2020 · Present
Own a $14M security budget and 45-person team spanning SOC, GRC, AppSec, cloud security, and IAM for a 2,100-employee payments platform. Reduced mean time to remediate critical vulnerabilities from 41 to 13 days by rolling out risk-based patching SLAs and automated ticket routing. Achieved ISO 27001 and PCI DSS Level 1 certification in 14 months; maintained SOC 2 Type II with zero exceptions for 4 consecutive audits. Deployed zero-trust access (SSO, phishing-resistant MFA, device posture) for 100% of workforce; phishing-driven account compromises fell 92%. Present quarterly cyber-risk posture to the board audit committee; led tabletop exercises with the executive team and outside counsel. Negotiated cyber-insurance renewal that lowered premium 22% while raising coverage limits to $25M.
VP, Information Security
Brazos Cloud Systems · Dallas, TX
Jun, 2015 · Feb, 2020
Built the security function from 6 to 28 people as the company scaled from $40M to $210M ARR. Launched a 24/7 security operations center with SIEM/SOAR automation, cutting alert triage time 60%. Embedded secure SDLC and threat modeling into 30+ engineering teams; pen-test high findings dropped 75% year over year. Ran incident response for a third-party vendor breach, containing exposure within 6 hours and meeting all customer notification obligations.
Director, Security Engineering
Hill Country Health Network · San Antonio, TX
Aug, 2010 · May, 2015
Led HIPAA security program across 12 hospitals and 9,000 endpoints; passed OCR audit with no findings. Migrated perimeter to next-gen firewalls and network segmentation, isolating 4,000 medical IoT devices. Implemented DLP and email encryption that reduced reportable PHI incidents 80%.
Senior Security Analyst
Capitol Federal Systems · Austin, TX
Jul, 2007 · Jul, 2010
Performed vulnerability assessments and log analysis for state agency networks; authored 40+ incident reports.

Education

M.S. Cybersecurity
The University of Texas at San Antonio · San Antonio, TX
2008 · 2010
Graduate studies focused on enterprise security architecture, risk management, and cyber defense.
B.S. Computer Science
Texas A&M University · College Station, TX
2003 · 2007
Undergraduate foundation in computer science, systems, and software engineering.

Skills

Security Strategy & Roadmaps
Board & Executive Reporting
Zero Trust Architecture
Cloud Security (AWS, Azure, GCP)
Incident Response
SOC 2 / ISO 27001 / PCI DSS / HIPAA
Third-Party Risk Management
Identity & Access Management
Security Budgeting
Team Building & Mentoring