CISOs to Watch in Charlotte: From Theme Parks to Financial Services

Related

Share

Charlotte’s reputation runs on banking, but the security leaders in this piece protect a far wider slice of American consumer life: aircraft engines and building controls, a lending marketplace, packaging for half the products on a grocery shelf, payroll software, a theme park chain, and the doughnuts sold in nearly every airport. Several of these leaders built their programs from zero, with no predecessor and no existing team, and most are active in the city’s own CISO community, which has become dense enough to function as a genuine talent pipeline.

Chase Carpenter – Chief Security Officer, Honeywell

Chase Carpenter has been Chief Security Officer at Honeywell since July 2019, responsible for cybersecurity, product security, physical security, and governance, risk, and compliance across all of the company’s businesses. He came from Microsoft after more than twenty years there, finishing as General Manager of Information Security for the Windows, Devices, and Gaming divisions, where he managed 325 employees and 100 vendors securing more than 400,000 servers. He built that security operations function from four people to 150 full-time staff and over 100 contractors, establishing Microsoft’s vulnerability management, security monitoring, and incident response programs for Xbox Live, the Microsoft Store, and Windows Update. Earlier he managed a $5 to $8 million budget developing security tools used by 350,000 customers worldwide and coordinated Microsoft’s relationships with defense agencies across multiple governments. He has served on Evanta’s CISO governing body for the Carolinas since 2020.

Arun Sankaran – CISO, LendingTree

Arun Sankaran has been CISO of LendingTree, the online lending marketplace, since October 2018. He came from Bank of America, where he served as SVP for Cyber Security Operations, and before that spent nearly a decade at Experian rising from senior security engineer to Director of Threat and Vulnerability Management. He had already spent seven years at Bank of America earlier in his career as VP of Corporate Information Security, giving him two separate stints inside the same institution a decade apart. His specialties run to e-commerce security, automation, and cloud infrastructure, and his career has moved consistently between consumer finance and credit data, the two industries LendingTree sits between.

Frank DePaola – VP and CISO, Sonoco

Frank DePaola became VP and CISO of Sonoco, the global packaging manufacturer, in September 2026. He came from EnPro, where he spent nearly six years, rising from Global Head of Information Security to VP and CISO and briefly holding the combined security and privacy officer title before his departure. Earlier he built his cybersecurity operations expertise at GE Appliances, then a Haier company, where he served as deputy CISO and led security operations, and before that as an IT security architect at Humana. He is a US Army veteran and a graduate of both the Carnegie Mellon CISO executive program and the FBI CISO Academy, and currently advises Crush Security, Zafran Security, and Bain Capital Ventures alongside his operating role.

Tom Watson – CISO, isolved

Tom Watson has been CISO of isolved, the HR and payroll technology platform, since September 2020, bringing more than thirty years of cybersecurity experience. Before isolved he was CISO at Sealed Air Corporation, and his earlier career spans Thermo Fisher Scientific, Bayer, Disney/ESPN, Oxford Health Plans, and the NASDAQ Stock Market, an unusually wide range of regulated industries for one security career. He initiated the Charlotte chapter of the CISO Executive Network and has served on Evanta’s CISO governing body since 2015. He is a National Guard veteran, a graduate of the FBI Citizens Academy, and has held InfraGard membership since 2002.

Jeff Slone – Corporate VP of IT Infrastructure, Operations and Cybersecurity, Six Flags Entertainment

Jeff Slone has held the combined infrastructure and security role for the theme park operator since Six Flags merged with Cedar Fair in mid-2024, having led the same function at Cedar Fair for three years before the merger and at the corporate director and manager level for nearly a decade before that. He is responsible for IT infrastructure, operations, and cybersecurity strategy across the company’s entire portfolio of parks. Before Cedar Fair he spent twelve years as lead network engineer at Advanced Computer Connections, where he led a team of twelve engineers and sat on the company’s strategic steering committee. His certification list is unusually deep and hands-on for an executive: CISSP, CEH, CHFI, and vendor-specific credentials across Cisco, Juniper, Palo Alto, and Rapid7.

Jerry Fowler – Senior Director of Infrastructure and CISO, Krispy Kreme

Jerry Fowler has led infrastructure and security at Krispy Kreme since June 2022, having started in IT support with no degree and worked up through a sequence of IT leadership roles at mid-market companies before reaching the CISO chair. He built the first IT department at Metrolina Greenhouses, cutting IT expenses by roughly $600,000 and architecting a private LTE network that saved $250,000 annually, and before that stood up IT from scratch at Carolina Handling following its separation from a Japanese parent company. Earlier he ran infrastructure across eight divisions at Wastequip through a private equity acquisition and rebuilt SMS Systems Maintenance Services’ infrastructure from a managed-service model to an internal team, migrating more than 1,500 email accounts with zero data loss. He also writes on AI-native security programs through his own press imprint.

Michael Irwin – CISO and VP of Technology Operations, Odyssey Logistics

Michael Irwin was recruited to Odyssey Logistics in December 2022 to build the company’s first cybersecurity program from zero, with no prior staff, policies, controls, or even the ability to obtain cyber insurance. Three years on, he leads more than 40 professionals across cybersecurity, infrastructure, cloud, GRC, and IT operations for the $2 billion multi-modal logistics firm, and reports cutting unprotected accounts from 1,959 to 22 in 90 days and phishing click rates from 37 percent to under 7 percent. He came from POLITICO, where he spent nearly thirteen years, finishing as Head of Cybersecurity and Executive Director of Technology Operations, leading a full cloud migration and GDPR compliance program across the organization’s US and European operations. His earlier career was pure infrastructure engineering, including an early role at a Washington, DC television station.

What This Group Says About Charlotte

Charlotte’s security leadership includes more program builders than program inheritors. Irwin and Fowler both took companies with no formal security function and built one from nothing, and Slone and Watson each spent years constructing the infrastructure their current programs now run on. The city’s CISO community, anchored by Evanta’s governing body and the CISO Executive Network chapter Watson founded, gives these leaders a shared forum that shows up repeatedly across their profiles. Banking may be Charlotte’s reputation, but its security bench increasingly protects the physical and consumer economy: aircraft parts, packaging, payroll, theme parks, and doughnuts.

Discover more CISOs to watch:

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.