CISOs to Watch in Denver: From City Hall to the Fortune 500

Related

Share

Denver’s security leadership carries an unusual split. Two of the people below protect the digital infrastructure of local government, serving residents who did not choose them and cannot switch providers. The others run programs at a national bank, a law firm, a children’s hospital, a satellite television group, and a global packaging manufacturer. The Front Range has produced CISOs who came up through credit unions, county emergency management, and the Marine Corps as readily as through consulting, and the seven careers here show what that mix looks like.

Merlin Namuth – CISO, City and County of Denver

Merlin Namuth leads cybersecurity across 55 agencies for the City and County of Denver, a role he took in September 2024. He created the city’s first enterprise cybersecurity strategy, established quarterly cybersecurity reporting to the Mayor’s Office, and launched cross-agency governance, while his team reduced enterprise vulnerabilities by 80 percent in eighteen months and restored momentum on PCI remediation. His twenty-seven years span public sector, financial services, healthcare, retail, insurance, and consulting. He was the first CISO of publicly traded payments processor REPAY, where he built the program from the ground up, grew the team fourfold, led security diligence for eleven acquisitions, and passed 35 PCI, SOC, HIPAA, and ICFR assessments. He also built Beazley Security’s first internal security program to ISO 27001, ISO 27701, and SOC 2, and led information security at ReedGroup and Guardian Life. He has served on the RSA Conference program committee and holds CISSP, CCSP, GCFA, GCIH, GICSP, and PMP.

Nicolle Rosecrans – CISO, Arapahoe County

Nicolle Rosecrans protects services for roughly 655,000 residents as CISO of Arapahoe County, one of Colorado’s largest. Her route into security is unlike anyone else’s on this list. She spent nearly seven years at Children’s Hospital Colorado as a medical staff coordinator and administrative assistant, then moved to the Northglenn Police Department, then into emergency management for Rio Grande County and disaster coordination for the state health department in the San Luis Valley. She joined Arapahoe County in 2020 as a homeland security planning and exercise support analyst, became its cybersecurity program manager, and now holds the CISO seat. She completed Carnegie Mellon’s executive CISO certificate program in 2025, serves as president of the Colorado Government Association for Information Technology, and sits as vice chair of the GovRAMP Approvals Committee.

Christian Winward – CISO, PNC

Christian Winward spent thirty-five years at one bank before a merger handed him a national mandate. He became CISO of PNC in July 2026, leading the enterprise information security organization from Denver, one of the bank’s technology locations. He arrived through PNC’s acquisition of FirstBank, where he had worked since 1991, rising from supervisor through systems engineer, IT manager, and a decade of senior vice president roles covering network services, applications development, and enterprise architecture, before serving as Chief Technology Officer and then Chief Information Officer. In that last role he helped integrate FirstBank into PNC. Twenty-five years in banking and more than twenty in IT give him depth across virtualization, storage, network architecture, identity management, and application portfolio management.

Tim Knighten – CISO, Brownstein Hyatt Farber Schreck

Tim Knighten has moved from service desk to CISO in under a decade. Appointed CISO of Brownstein Hyatt Farber Schreck in June 2026, he secures one of the largest law firms in the Mountain West, an environment where client confidentiality is both a professional obligation and a business asset. He arrived from FirstBank, where he served as Information Security Manager and then Director of Information Security over three years. Before that came three and a half years with the Colorado Judicial Branch, progressing from IT support technician through technical services team lead and systems security engineer to lead security architect. His earliest roles were hands-on support work at SiteWise, Optiv, and Credit Union of Denver. Few security leaders on any of these lists have covered that distance that fast.

DJ McArthur – VP of IT Security and CISO, Children’s Hospital Colorado

DJ McArthur has spent more than twenty-five years in information security, half of it in healthcare. VP of IT Security and CISO at Children’s Hospital Colorado since January 2018, and holding the same role for its Foundation, he owns the security program, incident response, identity access, IT audit and compliance, and the department budget, implementing NIST and PCI DSS frameworks across both clinical and fundraising technology. He previously spent six years as Director of IT Security at Centura Health, developing a program recognized for its HITRUST implementation and PCI DSS attestation, and earlier served as CISO of a healthcare provider entering the role after a breach, rebuilding the program while managing Office of Civil Rights and state attorney general scrutiny. He began his career as an administrative support officer in the US Marine Corps. He has taught for the SANS Institute, Regis University, and the University of Miami, and served on the international board of the Information Systems Security Association.

Artie Wilkowsky – SVP and CISO, DISH Network and EchoStar

Artie Wilkowsky once held responsibility for the security of the system that collects America’s income tax. As information security officer for the Electronic Federal Tax Payment System at First Data, part of US critical infrastructure moving more than $2 trillion annually, he maintained FISMA and NIST compliance through more than ten audits a year, sold over $6 million in program enhancements to the government, and successfully lobbied to triple the size of the security team. He has been CISO of DISH Network since March 2018, elevated to SVP in January 2022, covering the enterprise and all lines of business including Sling. Between First Data and DISH came three years as a cybersecurity leader at PwC and senior roles at managed security provider GBprotect, alongside earlier consulting and assessment practice leadership at CIBER and a year managing information security at Raytheon.

Joe Masud – CISO, Ball Corporation

Joe Masud became CISO of Ball Corporation in February 2026, taking the security seat at the Denver-headquartered packaging manufacturer. He arrived from Aristocrat Gaming, where he spent four years rising from senior director of enterprise security architecture to Vice President of Cybersecurity Technology and Strategy, leading the global security architecture and engineering function across enterprise IT and product environments, directing IAM, data protection, zero trust, and product security programs, and driving transformation using SABSA, TOGAF, and OWASP SAMM. He also served as acting CISO there during executive transitions, owning strategy, budget, incident response, and board-level updates. Before that came eight years at Oracle across security architecture, design and engineering, and risk management services, plus earlier work at Agilent Technologies and Ent Federal Credit Union. He describes himself as calm and decisive during incidents and transitions, which the acting CISO experience bears out.

What This Group Says About Denver

Denver’s security bench is notable for how many of its members built something that did not exist before they arrived: a city’s first enterprise cybersecurity strategy, a fintech’s first security programme, a county cybersecurity function assembled by someone who came to it from emergency management. The Front Range does not have the concentrated tech-giant pipeline of Seattle or the century-old regulatory institutions of Chicago, and its security leaders have compensated by being builders. That, plus an unusually strong public sector contingent, is what distinguishes the group.

Denver is one stop in an ongoing series profiling the security leaders shaping their cities, states, and sectors; explore more features from Colorado below.

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.