A surprising number of Kansas City’s security leaders learned the job by selling it first. The list below includes a managed security services veteran who worked through three of the region’s biggest security providers, a former RSA Security architect, a healthcare CISO who now advises other health systems from the vendor side, and an Army operating room technician who later built an IT team from 4 people to 120. It also includes the man who led technology and security for an NFL franchise. Healthcare, banking, sports, engineering, and security services all draw from the same bench on both sides of State Line.
Scott Cenfetelli – CISO, Blue Cross and Blue Shield of Kansas City
Scott Cenfetelli spent 11 years as a senior IT analyst at the Salt River Project, a public power and water utility, before he ever worked in security. He moved to Sprint Nextel in 2000 and stayed for more than a decade, working both as a Senior Network Security Specialist and as a Senior Product Manager for the carrier’s managed security services. That product experience shaped the next stage of his career. Cenfetelli became Director of Managed Security Services at FishNet Security and stayed on after it became Optiv, rising to Vice President of Enablement and Innovation and then Vice President of Global Cyber Operations. His teams there grew to more than 200 people across global operations. In May 2021 he moved to the buyer’s side as CISO of Blue Cross and Blue Shield of Kansas City.
Michael Meis – Associate CISO, The University of Kansas Health System
As a federal contractor, Michael Meis helped the US Department of Agriculture’s CISO merge 29 sub-agencies into a single department-level information security office, one of the largest security consolidations in federal government history. He came to that work after eight years as an Information Assurance Manager in the US Army and contract roles supporting the Marine Corps and the USDA’s Farm Services Agency. H&R Block then recruited Meis to rebuild its governance, risk, and compliance program. There he formed the company’s first fully integrated global GRC team and introduced the FAIR methodology to express cyber risk in financial terms. He joined The University of Kansas Health System in 2021 as Director of Cybersecurity and was named Associate CISO in 2022. In that role he leads AI and cybersecurity strategy for the academic medical center, including governance frameworks for its Enhanced AI Center for Human Focused Research. Meis also founded Kelevra, a board advisory and consulting firm, in 2022, and he holds three graduate degrees.
Kevin Higgins – VP of Information Technology, Kansas City Chiefs
Kevin Higgins spent most of his career in e-commerce before joining an NFL front office. He ran his own firm, Digital Research Enterprises, in Atlanta for eight years. He then led e-commerce technology at Anderson Press and product development at PRGX. At Collective Brands in Topeka, he spent nearly six years as Director of E-Commerce and Marketing Solutions, launching loyalty and CRM programs and building international online businesses. After IT leadership roles at the Society of Teachers of Family Medicine and Ad Astra Information Systems, where he was CTO, he joined the Kansas City Chiefs in April 2017 as Technology Director and CISO. He held both responsibilities for more than four years. In September 2021 he became the team’s Vice President of Information Technology.
Justin Rainey – SVP, CISO & Chief Privacy Officer, UMB Financial Corporation
For more than eight years at Invesco in Atlanta, Justin Rainey worked behind the scenes of a global security organization. As Chief Administrative Officer and Global Head of Strategy and Planning, he supported Invesco’s Global CSO across information security, privacy, corporate security, business continuity, and intelligence. He managed a budget of more than $35 million and co-chaired the firm’s Global Security Oversight Committee. Earlier at Invesco, Rainey built the Global Security Governance department and served as Information Security Officer for Invesco’s Trust Company. After a contract role with Franklin Templeton, he joined UMB in September 2021 as SVP, CISO, and Chief Privacy Officer, with oversight that also covers physical security, resilience, and third-party risk. He chairs the Investment Company Institute’s CISO Advisory Committee and sits on the American Bankers Association’s Cybersecurity and Operational Resilience Advisory Committee. Rainey holds the NACD Directorship Certification alongside CISSP and CIPP/US credentials, and he is a published author.
Ravi Monga – Field CISO – Healthcare, Zscaler
Ravi Monga spent five years in Bangalore as Cerner’s Director of Global Technology Delivery, part of a decade at the company that ended with a role as Lead Security Architect. His earlier infrastructure career ran through Merrill Lynch, Altria, Julius Baer, and NYU Medical Center. Monga then moved into healthcare security leadership in Kansas City. He served as Director of Cybersecurity at Children’s Mercy Kansas City and then as CISO of Saint Luke’s Health System. At Propio Language Services, he led the company to HITRUST e1 certification within six months. Since December 2024 he has worked from Kansas City as Field CISO for healthcare at Zscaler, advising boards and executive teams across the industry on what healthcare cyber risk looks like in practice. He holds CISSP, CISM, CRISC, and CHCIO certifications.
Neil Watkins – Director, Technology & Cybersecurity Services, Burns & McDonnell
Neil Watkins left the US Army after 12 years as a Facility Systems Engineer and Operating Room Technician, having earned the Meritorious Service Medal and the Audie Murphy Medal. His civilian career started with database work at Eclipsys. At Epiq, he grew the IT team from 4 people to 120, managed a $40 million capital budget, and cut data center costs by 65% through consolidation. He later launched Epiq’s global security, risk, and compliance department from scratch as Global CISO. Watkins went on to co-found Asureti, serve as CISO of Therapy Brands, and act as both CIO and CISO at i3 Verticals. He joined Burns & McDonnell in June 2025, where he holds full CISO responsibility for the engineering and construction firm’s global security posture. He also leads eight specialized teams across technology, cloud, compliance, and AI strategy, including the firm’s work under NIST 800-171 and CMMC.
Raj Atluri – CISO, NKC Health
Raj Atluri worked as a Principal Architect at RSA Security for about 11 years before moving into application and product security at MetraTech in Waltham, Massachusetts. He then ran his own Boston-based security firm, BuiltinIS, for seven years as Managing Director. He came to Kansas City with SS&C Technologies, first leading information security operations at SS&C Eze and then serving as Senior Director and Head of Global Security Operations. Atluri became CISO of NKC Health in August 2023. He holds seven professional certifications, including CISSP, CISA, CRISC, CDPSE, and PMP.
Built on Both Sides of the Table
Kansas City’s CISOs know what security looks like from the seller’s side. Cenfetelli built managed security products at Sprint, FishNet, and Optiv before protecting a health insurer. Atluri designed security technology at RSA and ran his own firm, and Watkins co-founded a managed assurance company between CISO roles. Monga made the opposite move, leaving a hospital CISO seat to advise health systems as a vendor. Meis and Rainey built security programs in federal government and global asset management, and Higgins brought an e-commerce builder’s instincts to an NFL front office. Together they form a bench that understands both how security gets built and how it gets bought, which is a practical advantage in a region where many organizations rely on outside security providers.
Discover more CISOs securing their organizations:
- Capital of the Buckeye State: Columbus CISOs to Watch
- Indy’s CISO Bench: Leaders to Watch
- The Inner Harbor’s CISOs to Watch
- Guarding the Peach State: Atlanta’s Security Leaders to Watch
- Securing the Capital Region: CISOs to Watch in the DMV
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

