

Ramon Santiago, MBA, MSIT, CCISO
Founder & Fractional CISO
About Me
I am a cybersecurity professional with more than 16 years of experience leading enterprise and U.S. Department of Defense cybersecurity programs across highly regulated and mission-critical environments. My career spans energy, federal, and law enforcement sectors, where I have been trusted to protect complex organizations against advanced cyber threats while enabling business and operational objectives.
I bring deep expertise in governance, risk, and compliance (GRC), enterprise risk management (ERM), and cybersecurity program maturity. I've led and matured security programs aligned to industry-leading frameworks including NIST Cybersecurity Framework (v1.1 and v2.0), NIST, ISO 27001/27002, ISA/IEC 62443, CIS, COBIT, and FAIR cyber risk quantification. I am recognized for my ability to translate technical cyber risk into clear, business-focused insights for executive leadership and boards of directors.
In senior leadership roles at Fortune 500 energy companies, I have overseen security operations centers (SOC), incident response, cyber threat intelligence, vulnerability management, cloud security, data protection, and risk management programs. I've managed multi-million-dollar security budgets, negotiated vendor contracts, optimized capital and operating expenditures, and developed executive-level metrics (KPIs and KRIs) used to inform strategic investment and risk decisions.
Previously, I served as a Deputy Director of Defensive Cyber Operations, Cyber Protection Team Commander, and Cyber Warfare Officer. I've worked within and collaboratively with U.S. Cyber Command, Army Cyber Command, and the Army National Guard where I led multidisciplinary teams conducting thousands of defensive cyber operations in support of cyber national mission forces. My experience also includes intelligence and investigative roles with the U.S. Army, Houston Police Department, and FBI ISC (Investigative Support Center), providing a unique operational perspective on cyber threats, adversary behavior, and incident response.
Known as a collaborative and pragmatic leader, I've built high-performing teams, fostered a strong security culture, and partnered closely with business leaders to embed cybersecurity into enterprise decision-making. I hold a Master of Business Administration, a Master of Science in Information Technology, and multiple executive and technical cybersecurity certifications, including Certified Chief Information Security Officer (CCISO) and Certified Cyber Exercise Assessor (CCEA).