Atlanta has more reason than most cities to take security leadership seriously. The 2018 ransomware attack on city systems and the 2017 Equifax breach both happened here, and both organisations appear on this list under new security leadership. The other five protect a transit authority, a research university, a crypto payments firm, a global travel management company, and a broadcaster reaching audiences worldwide. Several of these leaders came from federal service, and several more built their careers inside Atlanta’s corporate technology base.
Donald Graham – CISO, City of Atlanta
Donald Graham took over cybersecurity strategy for the City of Atlanta in September 2025, providing vision and leadership across municipal systems. He arrived from Deloitte, where he spent five years as Global Director of Cybersecurity Infrastructure, running a $17 million program supporting more than 400,000 employees and clients across 150 countries, scaling firewall, intrusion detection, WAF, and cloud security operations through regional hubs while serving as Global CISO delegate. Before that he was a security and networking executive at VMware and spent more than sixteen years at Cisco, where he managed systems engineering teams across six southern states and later led business development for energy and manufacturing, serving as the electric utilities subject matter lead for smart grid and NERC CIP compliance. He also serves as executive director of a 501(c)(3) STEM non-profit.
Jeremy Koppen – EVP and CISO, Equifax
Jeremy Koppen spent thirteen years responding to other organizations’ worst days before taking responsibility for one of the most scrutinized security programs in the country. He became EVP and CISO of Equifax in May 2025, arriving from Mandiant, now part of Google Cloud, where he rose from associate consultant to Practice Leader of Incident Response, the person accountable for how the firm handled the most advanced intrusions across industries. His focus at Equifax is mitigating emerging threats and scaling security operations through automation and AI. He began his career interning at the Rhode Island State Police Computer Crimes Unit and providing technical support at the University of Iowa College of Engineering. He joined the board of the National Technology Security Coalition in July 2025.
Sherron Burgess – SVP and Global CISO, BCD Travel
Sherron Burgess has spent more than twenty years at BCD Travel, joining as an information protection analyst in 2006 and rising through every rung to Senior Vice President and Global CISO in 2019. Her record is one of building things that did not exist: the company’s first ISO 27001 management system, its security growth and development function supporting global M&A, a partner risk management program that lifted secure practice uptake across more than a hundred countries, and its first cybersecurity internship program, which cut mean time to hire by 65 percent and brought more than thirty interns through in two years. She has driven certifications across ISO 27001, GDPR, TISAX-VDA, SOC 2 Type 2, CMMC, NIST 800-171, and PCI DSS. She has chaired the board of Cyversity, the non-profit working to increase the presence of women, underrepresented minorities, and veterans in cybersecurity, since January 2024, and was named to the CISOs Connect Top 100 in 2021 and 2022.
Colin Henderson – CISO, BitPay
Colin Henderson has built security programs at three Atlanta-area companies in five years. CISO of BitPay since May 2026, he arrived from Bakkt, where he spent four years as CISO of the digital asset platform, and before that spent seventeen months as CISO of OneTrust, building a security team and program at a cloud-native company during its period as one of the fastest growing in tech. He came to those roles from Morgan Stanley, formerly E*TRADE Financial, where he grew the security team from four people to forty-five and stood up the SOC, incident response, vulnerability management, insider threat, security analytics, and threat intelligence programs. Earlier he was a director in PwC’s cyber financial services practice and spent nearly seven years at HP building security operations centers for Fortune 100 companies. He began as a network vulnerability analyst at the National Security Agency.
Joe Lewis – AVP of IT and CISO, Georgia Institute of Technology
Joe Lewis came to Georgia Tech in July 2025 from the senior executive service. He spent two years as CISO and Director of the Cybersecurity Program Office at the Centers for Disease Control and Prevention, following a year as Director of Cyber Assessment Strategy at the Department of Energy and nearly eleven years with US Army Installation Management Command, where he finished as a division chief. Between the CDC and Georgia Tech he served six months at Leidos as Vice President of Cybersecurity Solutions and interim CISO for its health services business. His twenty-five years span public sector, private sector, and higher education, and his stated focus is identifying, coaching, and mentoring the next generation of security leaders, which he has pursued as an adjunct professor at NYU and an instructor at Northeast Lakeview College. He joined the GeorgiaCISO advisory board in January 2026.
Lawrence Williams – CISO, MARTA
Lawrence Williams leads cybersecurity strategy and operations for the Metropolitan Atlanta Rapid Transit Authority, protecting critical transit infrastructure since August 2022. His background is military and federal. He commanded the 11th PSYOP Battalion in the US Army Reserve, responsible for more than 600 soldiers, and served as Deputy G-6 for the 3rd Medical Deployment Command, advising a two-star general on network security and IT policy. As an operations officer with US Army Criminal Investigation Command he managed the implementation of a forensic science programme supporting operations in Afghanistan. His technical security grounding came at PeopleTec, where he worked as an information system security officer for Army Materiel Command, conducting assessments and accreditations under the Risk Management Framework and NIST 800-53. He also founded Sentinel Defense Group and worked as a cloud authorisation engineer at Cisco.
Shilpi Ganguly – SVP of IT, Cybersecurity, Data, and AI, The Weather Channel
Shilpi Ganguly is the top security leader at Allen Media Group’s Weather Group Television, serving as principal advisor to senior leadership on both technology and cybersecurity. She joined in October 2021 as VP of IT and Cybersecurity and expanded her remit to include data and AI in December 2023. She came from WarnerMedia, where she spent nearly five years, latterly as Director of Cybersecurity Governance designing policy frameworks and risk exception processes across Turner, WarnerMedia, and AT&T, and before that as a policy compliance manager handling SOX, PCI, GDPR, and CCPA. The twelve years before that were at Wood and its predecessor AMEC, where she built the company’s first SOX-driven IT control framework, led a 35-person team through an enterprise Microsoft 365 transformation, and designed its information classification framework. She holds an MBA from Emory and a CISSP, mentors with Women in CyberSecurity, and has spoken at NAB Show and Google Next.
What This Group Says About Atlanta
Atlanta’s security bench is defined by federal service and institutional memory. The NSA, the CDC, the Army, and Army Criminal Investigation Command all appear in these histories, and so does Mandiant, the firm that made its name cleaning up after the breaches that defined the last decade. The city and the credit bureau at the centre of this list both learned what failure costs, and both have since hired leaders whose entire careers were spent in environments where the consequences were never abstract. That is a particular kind of bench, and it is not an accident.
Discover more cybersecurity leaders:
-
- CISOs to Watch in Dallas-Fort Worth: From the Flight Line to the Boardroom
- Vancouver’s CISOs to Watch: From Campus to Cloud
- CISOs to Watch in Denver: From City Hall to the Fortune 500
- Seattle’s CISOs to Watch: Security Leadership Across the Sound
- Montreal’s CISOs to Watch: Securing Quebec’s Critical Systems
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

