Tulsa’s cybersecurity leaders took some of the most unlikely routes in this series. Among the six below are a former blackjack dealer, a former petroleum inspector who also delivered frozen food, a Marine imagery analyst stationed in Okinawa, and a corporate security executive who spent a decade as a volunteer firefighter and assistant chief of a county dive rescue team. One moved into IT from a career in marketing. Another spent 17 years securing a pipeline company before taking charge of security at the region’s largest bank. Together they protect banking, energy, manufacturing, higher education, and convenience retail across northeastern Oklahoma.
Paul Tucker – CISO, BOK Financial
Paul Tucker started as an account manager at ComputerLand before joining Williams in 1998. He spent 17 years there as IT security manager and later manager of information security and risk management, building the energy company’s security program, governance structure, and awareness training, with experience spanning computer forensics, incident response, and industrial control system security. He also taught an ethical hacking class at Oklahoma State University’s Tulsa campus. Tucker joined BOK Financial in 2015 to lead information security program management, building its information security management system and identity and access program. He rose to SVP and director of cybersecurity and has served as CISO since March 2020. His work draws on more than 30 years in the field and on frameworks including ISO 27005 and the NIST Cybersecurity Framework.
DeWayne Hixson – (Former) VP & Global CISO, Helmerich & Payne
DeWayne Hixson started as an assistant support manager at a Walmart store in Weatherford, Oklahoma, in 1999 and spent the next 23 years at Walmart Technology. He worked as a Windows systems engineer and network engineering supervisor, led the implementation of Walmart’s PCI compliance program across its U.S. and international businesses, and helped create the company’s IT project management office. He then moved into security governance and enterprise risk, and from 2016 to 2022 led international cybersecurity as director, overseeing more than 160 professionals across 27 countries. As CISO of Bass Pro Shops he ran an integrated cybersecurity, fraud, and investigations organization of about 70 people following the Cabela’s integration. He then served as VP and Global CISO of Helmerich & Payne in Tulsa from June 2025 to March 2026, building a cybersecurity strategy to unify IT, OT, and industrial control environments across global drilling operations. For a decade he also served as a firefighter and EMT in Bentonville, as assistant chief of Benton County Dive Rescue, and later as a Benton County deputy sheriff.
Sarfraz Shaikh – CIO & CISO, ONEMESA
Sarfraz Shaikh began as a systems and market research analyst at Levings Learning, an educational testing firm, then directed marketing and international licensing at Lady Americana. He joined MESA Products in 2010 as marketing manager and moved into technology in 2014 as manager of information and technology, supporting 14 corporate offices in a hybrid on-premises and cloud environment. He became director of information and technology in 2020 and CIO and CISO of ONEMESA in July 2025. He now leads IT, OT, and cybersecurity across the group’s manufacturing and field services companies, including MESA Products, MESA Services, Bass Engineering, and Hansen Drilling, guided by a principle he describes as “simplicity is non-negotiable.”
Chris Iverson – Director, IT Security (Acting CISO), Tulsa Community College
Chris Iverson started as a maintenance technician for Depew Public Schools and worked as a facilities host at Central Technology Center in Drumright. He went on to work as a personal banker at SpiritBank in Sapulpa, a delivery driver for Schwan’s, and a petroleum inspector and operations coordinator at Intertek in Cushing. He moved into IT as a network engineer at TeleComp in 2021 and joined Tulsa Community College as a system administrator the following year. Since August 2025 he has served as Director of IT Security and acting CISO, leading the college’s cybersecurity strategy, risk management, compliance, and incident response. He holds a CISSP.
David Malicoat – Director of Cyber Security, QuikTrip
David Malicoat served seven years in the U.S. Marine Corps, starting in security forces and as an infantry rifleman before becoming an imagery interpretation specialist in Okinawa, Japan, maintaining Unix systems used in national imagery exploitation. He spent the following decade in Unix administration and IT operations at Weblink Wireless, Perot Systems, and Neospire, then led service delivery at Dell for financial services and government clients. He served as interim executive director of infrastructure and architecture at Cleveland Clinic, spent five years as a principal consultant at WGroup, and founded BAMCIS Cybersecurity, a security operations services business. Malicoat was CISO of Direct Marketing Solutions for five and a half years before joining QuikTrip as Director of Cyber Security in December 2025. He hosts The Professional CISO Show podcast and has taught digital forensics and penetration testing at Collin College.
Shauna Stockton – VP & Information Security Officer, Vast Bank
Shauna Stockton spent more than seven years as a blackjack dealer at Gila River Casino in Chandler, Arizona. She moved into technology as IT lead and networking specialist for Oklahoma Med Tech, then worked in Tier III support at Realize Information Technology and as a network administrator at CamTech MSP in Broken Arrow. She joined Vast Bank in 2023 as an IT security operations administrator and became Vice President and Information Security Officer in October 2025. She now oversees the bank’s cyber risk, regulatory compliance under FFIEC guidance, incident response, identity and access management, and vendor risk.
Built From the Ground Up
Very few of Tulsa’s security leaders started in security. Hixson stocked shelves at a Walmart store before leading the company’s international cybersecurity. Iverson inspected petroleum and delivered groceries before running security at the region’s community college. Stockton dealt blackjack, Shaikh ran marketing, and Malicoat analyzed imagery for the Marines. Tucker is the closest to a traditional path, and even he spent 17 years at a pipeline company before moving to banking. What they share is a willingness to learn on the job. In a city built on energy and industry, these leaders earned their roles by building skills one step at a time.
Discover more CISOs securing their organizations:
- The Salt City’s Cybersecurity Leaders to Watch
- The Lilac City’s Cybersecurity Leaders to Watch
- The Scenic City’s Cybersecurity Leaders to Watch
- Heart of the Valley: Fresno’s Cybersecurity Leaders to Watch
- Mid-Pacific Defenders: Honolulu’s Cybersecurity Leaders to Watch
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

