Raleigh-Durham’s security leadership bench includes people who never held the words “Chief Information Security Officer” as part of an official title, and people who have carried that title for over a decade at the same company. Both groups show up on the roster below, running security programs for enterprise software, data storage, networking, telecom, consumer products, and state government agencies based in the Triangle.
Brian Wilson – CISO, SAS
Brian Wilson led the rollout of multi-factor authentication to more than 16,000 employees and contractors at SAS, one of several firsts he pioneered during more than two decades at the company. He has directed SAS’s Global Information Security and Identity & Access Management functions for over 21 years, guiding the program through certifications including FedRAMP, StateRAMP, and ISO 27001 as the company’s cloud business grew. NC TECH named him CISO of the Year in 2025. One project stands apart from the usual governance work. Wilson partnered with SAS’s Internal Communications team to produce “True Crime at SAS,” an eight-part video series that walks employees through real security incidents the company has faced. His career at SAS started decades earlier as a student at North Carolina State University, where he supported Unix-based campus computing systems before joining the company full time. He holds a CISSP certification and stays active in the regional security community through CarolinaCISO, InfraGard, the FBI’s Eastern Shield partnership, Raleigh ISSA, and (ISC)².
Gavin Guttersen – CISO, NetApp
Gavin Guttersen sold educational computers to schools in rural North Carolina in the late 1980s, a job that forced him to teach himself sales engineering because no local technical support existed. That early self-reliance carried him through years of entrepreneurship, including a regional ISP and an early cloud development business built before the industry used the term cloud. He eventually moved into corporate IT security. Guttersen joined NetApp in 2009 as a Security Architect and worked through Network Security, IAM, GRC, Vulnerability Management, Incident Response, and Architecture roles before becoming CISO in October 2023. Since then he has completed a transformation of NetApp’s Incident Response Plan to align with new Security Exchange and CMMC requirements and established an international cyber practice in Cork, Ireland, with follow-the-sun support running through India and US offices. He now serves as Programs Chair on the CarolinaCISO Advisory Board. Guttersen is also a father of three and grandfather of six.
Philip Swain – CISO, Extreme Networks
Philip Swain‘s job at Extreme Networks means keeping product development, internal audit, legal, sales, and IT aligned on a single security strategy, a coordination challenge he has managed since 2016. He moved from Senior Director of Information Security into the combined CISO and VP of Information Security title in October 2023. Swain also works directly with Extreme’s customers and partners on security matters. Before Extreme, he spent nearly a decade at ABB in the Raleigh-Durham-Chapel Hill area, moving from IS compliance and risk management work into a role overseeing infrastructure, risk, and security operations for North and South America, and later into a global portfolio position covering threat and vulnerability management along with red team testing. His background totals more than 20 years of building cyber security control frameworks tied to ISO and NIST compliance.
Crystal Pitts – CISO, NC Department of Commerce – Division of Employment Security
Crystal Pitts holds two security leadership roles at once. She has served as CISO for the NC Department of Commerce Division of Employment Security since November 2017 while also working as Enterprise Security Manager for the City of Raleigh Municipal Government, a position she has held since July 2016. Pitts built her security background over more than a decade administering PeopleSoft security for the city’s HRMS, FSCM, EPM, and portal systems, a role she still holds today. Earlier in her career she served as the primary point of contact for the Department of Homeland Security, the FBI, and the Multi State Information Sharing and Analysis Center during security incidents, alongside running PCI compliance documentation, two-factor authentication administration, and vulnerability scans across servers, websites, and applications. That consistent focus, cutting risk by investing in both people and technology, runs through her entire career.
Andrew Grimmett – VP of Information Security, Bandwidth
Andrew Grimmett has led information security at Bandwidth as Vice President of Information Security since May 2016, after nearly 14 years holding the CISO title itself at LSSiDATA, a role that carried over briefly when Neustar acquired the company in 2015. At Bandwidth he oversees Security Operations, Application Security, and Governance, Risk, and Compliance, working to keep the company aligned with NIST, ISO 27001, GDPR, HIPAA, CCPA, SOX, and SOC 2 Type II requirements. Grimmett’s approach favors proactive defense: layered security models, threat intelligence, and automated response systems built to catch threats before they escalate. His career started in the 1990s managing network, systems, and security functions at nTelos Wireless and 11880 Internet Services AG in Germany before he moved into the CISO role at LSSiDATA in 2002. He now has more than 25 years in the field.
Chip Wentz – CISO, Keurig Dr Pepper Inc.
Chip Wentz‘s team at Keurig Dr Pepper delivered more than $15 million in annual savings and zero major SOX or PCI issues over five years, output that traces back to a career that started in the same bank’s internal audit department. Wentz began as a Senior Internal Auditor at First Citizens Bank in 1997, then rose to SVP of Information Security at the same bank by 2004. He spent over 11 years at EY as Principal and Cyber Analytics Leader, advising Fortune 500 clients on cyber risk, digital transformation, and cloud strategy while leading multimillion-dollar GRC, IAM, and privacy initiatives. Wentz joined Keurig Dr Pepper as CISO in October 2019 and later added the VP of Technology title, a combined CTO and CISO role he still holds. Under his leadership the company has cut cloud run rate by roughly $300,000 a month through FinOps, reduced major incidents by 12%, and managed a budget of more than $60 million with under 3% variance. He also established Keurig Dr Pepper’s GenAI governance program and Center of Excellence. He currently serves on NC State’s Poole College of Management ITAO Advisory Board.
The Triangle Promotes From Within
What stands out across this group is how many of these leaders grew into their security roles rather than arriving in them. Wilson moved up through SAS over 22 years, starting as a student administrator years before the CISO title landed on his desk. Pitts has held two active security roles inside Raleigh’s city and state government systems for close to a decade. Grimmett ran security at one company for almost 14 years before the title on his badge changed to VP at Bandwidth, and Wentz worked his way from internal auditor to security executive without leaving the bank that trained him. The Triangle’s biggest employers appear to be building security leadership internally rather than importing it.
Discover more CISOs securing their organizations here:
- San Diego’s CISOs to Watch: A City That Keeps Its Security Leaders
- Philadelphia’s CISOs to Watch: Securing Health Systems and Heavy Industry
- CISOs to Watch in the Twin Cities: From State Government to the Supply Chain
- CISOs to Watch in Charlotte: From Theme Parks to Financial Services
- CISOs to Watch in LA: From Movie Studios to Storage Units
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

