Buffalo’s Cybersecurity Leaders to Watch

Related

Richmond’s CISOs to Watch

Richmond's cybersecurity community is unusually well organized. The Virginia...

Oklahoma City’s Cybersecurity Leaders to Watch

The cybersecurity bench in Oklahoma City is built around...

Share

A Marine Corps sergeant. A cloud architect who moved 90 applications to AWS in four months. A privacy specialist who built a health insurer’s compliance program from the ground up. The cybersecurity leaders below came to Buffalo’s top security jobs through engineering, auditing, consulting, and operations, and each brought that range with them. What they protect now spans cancer treatment, health insurance, banking, stadium concessions, and frozen dough.

Adam Rosen – CISO, Roswell Park Comprehensive Cancer Center

Adam Rosen taught introductory computer science and programming at Daemen College for more than twelve years, a run that overlapped nearly his entire early career. He began as an engineer at the Naval Undersea Warfare Center in Newport, working on security and network infrastructure projects. He then ran his own consultancy, Buffalo Data Solutions, in Amherst for four years. Rosen spent nearly a decade as Director of IT at Twin City Ambulance in Tonawanda, managing infrastructure for data collection, analysis, and billing while building policies to meet regulatory requirements. He joined Roswell Park Comprehensive Cancer Center in 2017 as a cybersecurity analyst and senior information security engineer, then became CISO in December 2018. His focus has stayed on business survivability, restoring critical services within the timeframes the organization actually needs.

Peter Jabrucki – CISO, Independent Health

Privacy, not security, is where Peter Jabrucki started. He supervised shifts in food service for six years before joining Independent Health as a business security and privacy intern in 2008. He became Privacy Coordinator the following year, implementing the company’s Identity Theft Red Flag Rule program and designing its privacy event mitigation process. Four years as Privacy Manager followed, running the enterprise privacy program across affiliated organizations under HIPAA, HITECH, HITRUST, CMS, and New York State requirements. Since 2016 he has served as Program Manager for Information Risk, handling vendor risk assessments, data classification, and data loss prevention, and he took on the CISO title in July 2018. Jabrucki now leads privacy, vendor risk management, and the enterprise anti-fraud program alongside security, working against frameworks including HITRUST, NIST 800-53, and New York’s 23 NYCRR 500 cybersecurity requirements.

Patrick Zaffram – VP & CISO, Kaleida Health

Patrick Zaffram spent 17 and a half years at M&T Bank, arriving in 2000 as a desktop engineer. He moved into intrusion detection in 2007, building and supporting the bank’s enterprise IDS and consolidating security logs into an in-house SIEM. As a cybersecurity engineer he led the migration of SIEM and logging to a managed service for 24/7 monitoring, administered the bank’s wireless intrusion protection, and handled cyber operations transitions during several mergers and acquisitions. His final role there was Assistant Vice President and Security Technical Operations Manager, leading a five-person team protecting the bank’s electronic perimeter and managing 75 Checkpoint firewalls. Zaffram joined Kaleida Health in 2017 as a cyber security engineer and became VP and CISO in December 2021.

Kristopher Meier – CISO, M&T Bank

Kristopher Meier co-founded a company that acted as an outsourced CIO and CISO for its clients. He ran Station 28 as President for five years in Buffalo, handling operations, budgeting, and business development while consulting across disaster recovery, governance, risk management, and compliance. Before that he spent nearly six years as Director of IT at Algonquin Studios, overseeing uptime and PCI compliance for hosted sites and applications. A year as Cybersecurity Integration Leader at BlueCross BlueShield of Western New York followed. Meier joined M&T Bank in 2018 as Vice President and Advanced Threat Manager, then worked through Threat Intelligence Officer, Director of Threat Analysis and Information Protection, and Senior Vice President and Director of Cybersecurity Operations. He was named CISO in April 2026.

Brian Mercer – VP, Cybersecurity, Delaware North

Brian Mercer came to security through cloud architecture. He spent more than nine years at Delphic Digital in the Philadelphia area, rising from software developer to Director of Web Development, then joined Delaware North in 2013 as Senior Cloud Architect. There he helped move the hospitality company’s data center operations to AWS, a migration that included more than 90 applications in four months and became the subject of an AWS case study and a re:Invent presentation. He managed applications and DevOps before shifting into security as IT Director of Cybersecurity in 2017. Mercer has served as Vice President of Cybersecurity since January 2020, protecting a company that serves more than 500 million customers at 200 venues worldwide.

Sean Kelly – CISO, Centivo

Sarbanes-Oxley compliance occupied Sean Kelly for more than eleven years at HSBC, where he managed the IT SOX team for North America and then served as Global Head of the IT SOX Program. His career began in 1999 as an information security analyst and supervisor at Regence BlueCross BlueShield of Oregon, followed by analyst work at BlueCross BlueShield of Western New York, a year as an IT auditor at SunGard, and two years consulting. He later returned to BlueCross BlueShield of Western New York as Manager of Enterprise Information Risk Assurance, then spent three and a half years at Highmark Health, first managing the data protection team and then directing cyber governance, risk, compliance, and data protection. Kelly became CISO of Centivo in January 2025. He also spent four years reporting for the CISO Series Cyber Security Headlines podcast, and he holds CISSP, CRISC, and Security+ certifications.

Joe Mariscal – Senior Director, Cybersecurity and Risk Management, Rich Products Corporation

Four years as a Marine Corps sergeant came first for Joe Mariscal, who was honorably discharged with the Navy Achievement Medal and three Certificates of Commendation. He started in technology as a network assistant at Baird & Warner in Chicago, then spent more than fourteen years at TTC Marketing Solutions, rising from network administrator to Director of IT. There he managed a 24/7 data center supporting a 400-seat call center, implemented PCI DSS 2.0 compliant standards, and cut electrical costs by 25% through data center consolidation. Mariscal joined Ryerson in 2014 managing enterprise operations, then moved into security, advancing through Senior Manager and Assistant Director before serving five years as Director of Cybersecurity and Compliance. He became Senior Director of Cybersecurity and Risk Management at Rich Products Corporation in April 2025. He holds a master’s in computer science, an MBA, and CISSP and CISM certifications.

The Long Apprenticeship

None of these leaders came up through a security track that existed when they started. Zaffram spent seven years building desktop images and managing Windows servers before the bank put him on intrusion detection. Jabrucki worked privacy compliance for nine years before security joined his title. Mercer was a software developer for six years, then a cloud architect, and only after moving 90 applications to AWS did he shift into cybersecurity. Rosen ran an ambulance company’s IT department, Mariscal ran a call center’s data center, and Kelly tested SOX controls at a global bank. The common thread is patience: each of them spent a decade or more learning how organizations actually work before taking responsibility for defending one. In Buffalo’s hospitals, banks, and manufacturers, that kind of operational grounding tends to matter more than a direct route.

Discover more CISOs securing their organizations:

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.