Houston’s Security Leaders to Watch: From the Refinery Floor to the Boardroom

Related

Share

Houston’s security leadership is shaped by an industry where a compromised system can vent a pipeline or shut down a refinery. Four of the six leaders below came through oil, gas, or oilfield services, and operational technology security, SCADA, industrial control systems, and IEC 62443 appear in these careers far more often than in any other American city. The other paths run through public hospitals, a research university, and enterprise retail. Several of them overlap: two came out of Motiva, and two have served on the HoustonCISO advisory board.

Jerich Beason – CISO, WM

Jerich Beason has been CISO of WM, the waste and environmental services company, since August 2023. He arrived from Capital One, where he served as CISO for the Commercial Bank and later for Capital One Software as well. He is among the most publicly visible security leaders in the city, hosting podcasts, co-chairing SANS summits, teaching LinkedIn Learning courses on SOC 2 compliance and securing generative AI, and writing for Forbes and CSO Online. He has advised a string of security startups including Axonius, Ericom, ByteChek, Reco, and SecureCo, several through to acquisition. A former Big Four consultant, he describes himself as an aspiring board member, and the breadth of his external work suggests a deliberate strategy for getting there.

Mary Dickerson – AVP and CISO, UTHealth Houston

Mary Dickerson has spent her entire career in Houston higher education. She became AVP and CISO of UTHealth Houston in August 2023, after more than twenty-five years at the University of Houston, where she joined as an enterprise system administrator in 1998, became interim executive director for IT security in 2008, and held the CISO title for twelve years, latterly as Assistant Vice President and Assistant Vice Chancellor. Moving from a large public university system to an academic medical centre is a shift from open research networks to regulated patient data, but the institutional shape is familiar territory. She holds CISSP, CISM, PMP, and MCSE certifications.

Salman Khan – VP and CISO, Harris Health System

Salman Khan became VP and CISO of Harris Health System, the public hospital district serving Harris County, in September 2025. He came from MRC Global, where he rose from senior director of information security to CISO, and before that spent nearly seven years as IT security manager at UTHealth, leading security for the medical school and clinics and handling the Epic implementation from a security perspective. His route into security ran through audit and delivery: nearly ten years at Enbridge Energy as an IT project manager, senior business analyst, senior internal auditor, and finally IT audit manager, developing and running the audit programme for US operations. That combination of healthcare, energy, and audit is well suited to a safety-net hospital system with both clinical and public accountability.

Mark Alvarado – CISO, Academy Sports + Outdoors

Mark Alvarado has led IT security and compliance at Academy Sports + Outdoors since July 2020, reporting to executive leadership and influencing board-level risk decisions. He reports maturing the cyber program to improve detection and data protection capability by 76 percent and establishing an incident response framework that cut recovery time by 90 percent. His path was hands-on and largely energy-sector: information security engineer at Parker Wellbore, enterprise backup and recovery lead at Marathon Oil, senior information security analyst at Norton Rose Fulbright handling incident response alongside the legal team, and the same role at Ovintiv. He served on the HoustonCISO advisory board and writes and speaks on security leadership through his “Tales of a CyberGuy” series.

Bemi Anjous – Director of Information Security, Noble Corporation

Bemi Anjous was recruited to Noble Corporation in September 2022 to build the enterprise cybersecurity function from the ground up for an offshore drilling contractor operating more than forty drilling ships across eighty countries. His specialism is operational technology in heavy industry: he implemented the refinery OT cybersecurity program at Motiva’s Port Arthur refinery, one of the largest in North America, covering industrial control systems, SCADA security, and cyber-physical detection across segmented networks, reporting to the CISO and CIO. Before that he managed global risk, cybersecurity, and compliance at Baker Hughes through the post-merger integration with GE Oil and Gas, and worked in compliance at Calumet refinery services. His frameworks run to IEC 62443 and Purdue model segmentation alongside ISO 27001 and NIST. He joined the HoustonCISO advisory board in May 2025.

Ming Yeo – Senior Director of Security, PMO and Governance, Nabors Industries

Ming Yeo holds the top security seat at Nabors Industries, the land drilling contractor, where he has worked for nearly twelve years. He joined in 2015 as IT governance manager, moved into security in 2019 as IT Director for Security, PMO and Governance, and was elevated to senior director in 2023, holding security, project management, and governance under a single remit. His grounding is consulting: four years at Deloitte and Touche in advisory, rising from consultant to senior consultant. Before that he served as a second sergeant in the Singapore Armed Forces. Combining the security function with the PMO is unusual, and it puts him in the room for every technology project the company runs rather than reviewing them after the fact.

What This Group Says About Houston

Houston is the only American city where a security leader’s fluency with the Purdue model matters as much as their board reporting. The energy sector built this bench, and its priorities show: OT and IT convergence, refinery and drilling control systems, post-merger integration across global operations, and regulatory frameworks that predate most cybersecurity practice. What is striking is where those skills have travelled. Two of these leaders now secure hospitals and one a retailer. The discipline that came from protecting physical processes at scale turns out to transfer, and Houston has become a net exporter of it.

Discover more cybersecurity leaders:

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.