Two people on this list have held the top security job at Texas Roadhouse, one after the other. Another spent 11 years protecting the systems behind the Kentucky Derby before moving to a bank three miles away. A third sold pharmaceuticals before he ever touched a firewall. Louisville’s cybersecurity leadership bench is unusually interconnected, built around a handful of large employers in restaurants, healthcare, banking, and spirits, and the people below keep showing up in each other’s histories.
Ethan Steiger – CISO, Yum! Brands
Ethan Steiger built security programs at Bear Stearns in the late 1990s, then at Covisint, the automotive industry’s early B2B exchange, before spending two years as a Security Architect at RSA Security. Nine years at IHS Automotive followed, where he served as VP and Chief Security Officer. In 2014 he became VP and CISO at Domino’s in Ann Arbor, a role he held for more than five years. He then spent five years as SVP and CISO at Advance Auto Parts in the Raleigh-Durham area. Steiger joined Yum! Brands as CISO in August 2024. His 25-year career has produced security programs at six major companies, most of them consumer brands with large distributed footprints.
Sailaja Kotra-Turner – VP, CISO & Director of Global Infrastructure and Operations, Brown-Forman
Sailaja Kotra-Turner spent 18 years at Texas Instruments, and she started as a UNIX administrator. She was promoted to lead the compute operations team, then managed the Unix administrators running the grid compute farm that let designers simulate semiconductor designs. Her scope widened from there: manufacturing IT across North America and Asia, then enterprise applications including SAP and PeopleSoft, then security operations, where she standardized disaster recovery processes across data centers in the US, Asia, Japan, Mexico, India, and Germany. After a brief stint establishing 24/7 security operations at JCPenney, she became CISO at Brinker International, improving the company’s NIST CSF scores in under a year and helping contain a data exposure incident. Kotra-Turner joined Brown-Forman in 2020 as Senior Director and CISO, adding VP and global infrastructure and operations responsibility in April 2022. She now owns the spirits company’s worldwide technology environment alongside its cybersecurity program.
Ethan Yehud – CISO, University of Louisville
Ethan Yehud started as a systems analyst at Ashland in 2002 and moved into IT audit there four years later. Humana brought him to Louisville as a security consultant, then an audit consultant. He spent nearly four years at CynergisTek, first consulting and then directing the firm’s information security services. From 2018 to 2023 he served as CISO of MedAllies, a health information network in Fishkill, New York, operating a DirectTrust accredited certificate authority and supporting interoperability for more than 700 hospitals, 5,000 organizations, and 100,000 providers. Yehud returned to Louisville in February 2023 as CISO of the University of Louisville. His regulatory expertise spans HIPAA, FISMA, HITRUST, NIST, ISO, and PCI DSS, and he holds an MBA along with CISSP and CISA certifications.
Kenny French – Senior Director of IT & Head of Information Security, Texas Roadhouse
The helpdesk is where Kenny French started at Texas Roadhouse, back in 2007. He has been there ever since, working through roles as an Exchange administrator, network administrator, LAN support lead, LAN operations manager, and senior manager of network engineering. That last role ran three and a half years before he moved into security in February 2021 as Senior Manager of IT Security. A year later he became Director of Cyber Security, and in January 2026 he was named Senior Director of IT and Head of Information Security. Before Texas Roadhouse, French worked as a business analyst at Constellation New Energy Gas and spent four months teaching Microsoft coursework at the National College of Business & Technology. His entire 19-year run at the company has been a single continuous climb.
Joe Harrington – CISO, Stock Yards Bank & Trust
For 11 and a half years, Joe Harrington ran cybersecurity at Churchill Downs Incorporated, protecting the customer, financial, and operational systems behind the Kentucky Derby along with casino gaming, racetrack, and online wagering platforms across regulated jurisdictions. He led the company’s readiness for SEC cybersecurity disclosure requirements, implemented Zero Trust network segmentation, and built a security operations capability using SIEM, SOAR, and advanced analytics. He then spent nearly two years as Senior Manager of Cybersecurity at Texas Roadhouse, where he cut mean time to detect and respond by 40% through platform consolidation and SOAR automation, and reduced external incident response mobilization time by roughly 60% with a third-party retainer. Harrington became CISO of Stock Yards Bank & Trust in July 2026, where he also serves as the bank’s designated Information Security Officer. His career began at the University of Louisville, where he built an on-truck mapping application for local fire departments, and continued through eight years at the Louisville Metropolitan Sewer District leading network segmentation across IT and operational technology networks. He sits on the board of ISACA’s Kentuckiana Chapter as Academic Relations lead and serves as Louisville Regional Director for the Cloud Security Alliance’s Ohio River Valley Chapter.
Ross Bobenmoyer – CISO, Republic Bank
Ross Bobenmoyer sold pharmaceuticals for four years before he worked in technology. He was a Senior Sales Representative at Ortho-McNeil Pharmaceutical starting in 2003, then moved to Johnson and Johnson for three years. His pivot into IT came at Bellwether Software, where he served as VP of Information Systems and Director of Information Security and Risk Management, managing web application development while identifying security risks in how customers accessed the software. Bobenmoyer became CISO of Republic Bank in January 2012. He has held the role for nearly 15 years.
Brian McCarthy – System VP & CISO, Norton Healthcare
Brian McCarthy co-founded a sports program management platform and ran it for eight and a half years while building a technology career at UPS. At the logistics company he managed infrastructure across Microsoft, Linux, and VMware environments, then served four years as Director of Applications Development, leading development and deployment of more than 80 business-critical applications supporting UPS Airlines, WorldPort, and global transportation operations. He joined Norton Healthcare in 2014 as Director of IS Operations and Security. As System Director from 2021 to 2024, McCarthy guided the health system through two cybersecurity events while leading IT operations, cybersecurity, and clinical engineering across its hospitals and outpatient network. He became System Vice President and CISO in 2024. His background spans healthcare, airline, transportation, finance, and startups, and he also taught IT project management as an adjunct professor at Bellarmine University.
A Bench That Trades Among Itself
Louisville’s security leaders keep landing in each other’s former seats. Harrington left Texas Roadhouse in July 2026, and French took over the company’s security function six months earlier, the two overlapping inside the same organization. Harrington’s move from Churchill Downs to Stock Yards Bank kept him within a few miles of where he started his career at the University of Louisville, the same institution Yehud now protects. McCarthy built his foundation at UPS before crossing town to Norton Healthcare, and Bobenmoyer came to Republic Bank from a software company in the same market. Only Steiger and Kotra-Turner arrived from outside, bringing security programs built at Domino’s, Advance Auto Parts, Texas Instruments, and Brinker to Louisville’s two best-known consumer brands. For a city its size, that is a remarkably self-sustaining pipeline.
Discover more CISOs securing their organizations:
- Where the Ohio River Bends: Cincinnati’s CISOs to Watch
- Portland’s Security Leadership Bench
- City of Fountains: Kansas City’s CISOs to Watch
- Capital of the Buckeye State: Columbus CISOs to Watch
- Indy’s CISO Bench: Leaders to Watch
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

