Atlanta’s security leadership bench includes a Marine Corps veteran who trained more than 1,400 fellow Marines in signals intelligence before ever holding a corporate title, an executive who built his security career across three continents, and a rising leader still working his way toward the CISO seat rather than sitting in it already. Manufacturing, energy, payments, law, healthcare, and auto parts distribution all draw from the same regional talent pool, and this list moves through each of them.
Andy Abercrombie – Director of Global Information Security/CISO, Novelis
Andy Abercrombie built his security career across three continents before settling into Atlanta, working as a Security Architect for Cisco’s Scientific Atlanta division, then moving to the UK as Senior Security Architect for Old Mutual’s wealth management arm, and later relocating to Sydney for a series of audit and security architecture roles at Commonwealth Bank. He spent four years at KPMG as a Manager within the firm’s Information Protection and Business Resilience Division before his move to Australia. Abercrombie has served as Director of Global Information Security and CISO for Novelis since June 2017, leading a global team at the $15 billion aluminum manufacturer owned by the Aditya Birla Group. His role carries particular weight in operational technology security, balancing global manufacturing security outcomes against the need to keep production systems continuously available, and he has since taken on responsibility for the company’s global privacy strategy as well.
Curley Henry – CISO, Southern Company
Curley Henry spent ten years in the US Army Reserves, including four years managing global security operations at Army Reserves Command Headquarters, before building a civilian career that moved through IBM, Hewlett Packard Enterprise, and E*TRADE Financial. Henry spent six years at IBM Security, rising from Senior Manager of Managed Security Services to Global SIEM Practice Executive, before joining Hewlett Packard Enterprise in 2012 as Associate Director for the Americas region within the company’s Security Intelligence and Operations Consulting practice. He joined Southern Company in 2015, initially as Executive Director of Cybersecurity Strategy, Architecture and External Engagement, then advanced to Deputy CISO in 2020 before being named Chief Information Security Officer in 2025. Henry now serves as Vice Chair of the Executive Committee for the National Technology Security Coalition, a role he has held since 2022.
Jonathan Kennedy – SVP, Global CISO, InComm Payments
Jonathan Kennedy served three combat deployments across the Middle East, Asia, and South America as a Special Intelligence Communicator with the Marine Corps’ 2nd Radio Battalion, maintaining classified satellite communications and leading teams of more than 20 operators in remote areas of Afghanistan. Kennedy later became a Master Instructor at the USMC’s Center for Information Dominance, personally training more than 1,400 Marines in network security and satellite communications as chief of the Special Intelligence Communicator course’s curriculum. After leaving the Marine Corps, he worked as an Interactive Operator and Digital Network Warfare Operator for United States Cyber Command, configuring signals intelligence systems to respond to real-time operational targets. Kennedy moved into the private sector as a Cyber Forensic Investigator at Fiserv, then led a 30-person global cyber incident response team there before joining Agilysys and, in December 2020, InComm Payments as Director of Security Operations. He advanced to VP and CISO in 2022 and was promoted to SVP and Global CISO in June 2025.
Nick Bettes – CISO, Kilpatrick Townsend & Stockton
Nick Bettes built his risk management background auditing hospitals for Blue Cross Blue Shield of Georgia before moving into corporate IT risk and compliance work. Bettes spent nearly four years at Exide Technologies as a Senior Internal Control Analyst, serving as the company’s corporate focal point for SOX compliance across North America, Europe, and Asia-Pacific, before joining NCR Corporation in 2010, where he built and managed an IT Risk Management team from the ground up and developed the company’s governance, risk, and compliance platform. He moved into legal-sector security in 2015 as Cyber Risk Manager at King & Spalding, later working as a Consultant in the firm’s Data, Privacy, and Security practice. Bettes joined Kilpatrick Townsend & Stockton as Director of Information Security in April 2022 and was promoted to Chief Information Security Officer in April 2026.
Andrew Clinton – AVP Cybersecurity, Aveanna Healthcare
Andrew Clinton has spent his entire security career in Atlanta, building 12 years of experience in IT and security infrastructure across payments, networking, and healthcare companies. Clinton started as an IT Support Specialist in Ohio before moving into system and Linux administration roles, then became a Security Architect and eventually Director of Security and Compliance at Vanco Payment Solutions. He worked as a Senior Security Engineer at nGuard and a Senior Security Consultant at Coalfire before joining Aveanna Healthcare as Director of Cyber Security in December 2020. Clinton was promoted to AVP Cybersecurity in December 2024, a title one step below the CISO seats held by most of his peers on this list, but one that reflects a security career built entirely through hands-on infrastructure and compliance work rather than a management-track climb.
David Nagel – VP & Global CISO, Genuine Parts Company
David Nagel spent nearly 13 years at IBM, most of it focused on federal government security sales, building the company’s first consolidated security business unit by combining identity management, application security, infrastructure, and threat intelligence functions that had previously operated separately. Nagel worked as IBM’s Manager of National Security and Justice from 2012 to 2015, driving business across the Department of Defense, the intelligence community, and federal system integrators. After brief stints at Apperian and McAfee, he joined Genuine Parts Company in 2017 as Senior Director of Enterprise Cyber Security, was named CISO the following year, and was promoted to Vice President and Global CISO in April 2022. Nagel also served for more than five years as President of the Atlanta Chapter of the Virginia Military Institute Alumni Association, coordinating activities for current cadets and alumni in the region.
A Bench Still Filling In
What sets Atlanta apart from some of the other regional lists is that its security leadership isn’t uniformly senior yet, and that’s not a weakness. Kennedy and Henry both built their credibility inside the military before the corporate world ever gave them a title, and Bettes spent a decade in internal audit and IT risk before anyone called him a CISO. Clinton is simply earlier in that same arc, still building the operational depth that turned Kennedy from a Marine Corps instructor into an SVP and turned Bettes from a hospital auditor into a law firm’s top security executive. Abercrombie and Nagel show where that arc eventually leads, global manufacturing and federal-facing distribution businesses that now depend entirely on people who spent years in the trenches before they ever sat in the seat. Atlanta’s bench isn’t just deep. It’s still being built, in real time, by people the region will likely be watching again in a few years under different titles.
Discover more CISOs securing their organizations:
- Securing the Capital Region: CISOs to Watch in the DMV
- Guarding the Steel City: Pittsburgh’s Security Leaders to Watch
- Securing the Bay: Tampa’s CISOs to Watch
- Guarding the Gateway: St. Louis’s Security Leaders to Watch
- Securing Music City: Nashville’s Cyber Leaders to Watch
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

