The Delaware Valley runs on two industries that could not be less alike in culture and are nearly identical in regulatory weight. On one side are the health systems, insurers, and pharmaceutical companies, governed by HIPAA and HITRUST and holding the medical records of most of the region. On the other are the chemical, alloy, and energy companies, some more than two centuries old, where the security program has to account for plants as well as networks. The seven leaders below work across both. Several rose through the organizations they now protect, and several more teach at the region’s colleges alongside the day job.
Mark Odom – SVP, CTO and CISO, Jefferson
Mark Odom holds both the technology and security seats at Jefferson, the combined university and health system, elevated to Senior Vice President in March 2026 after more than two years as VP, CTO and CISO at Thomas Jefferson University. He joined the organization in 2019 as Enterprise VP and CISO for the hospitals and IT executive for the north region, and also served as CISO of Health Partners Plans, the system’s insurance arm. Before Philadelphia he spent four years at Deloitte in risk advisory, specializing in healthcare technical risk, and held the CIO seat at St. Bernards Healthcare in Arkansas. Earlier he was director of IT and security at Lubbock Heart Hospital and information security and business continuity officer at Ozarks Medical Center. More than twenty years in healthcare technology, almost all of it inside provider organizations rather than advising them from outside.
Charles Crabtree – VP and CISO, Independence Blue Cross
Charles Crabtree built his way to the top security seat at Independence Blue Cross from inside. He joined in 2019 as an information security manager, became interim CISO in 2023 while holding the director title, took the CISO role outright in 2025, and was elevated to Vice President in April 2026. He now leads security for one of the largest Blue Cross Blue Shield organizations in the country, aligning security strategy with business priorities and translating cyber risk into terms the executive team can act on. He came to the insurer from Contender Solutions, where he was director of customer success, and before that held systems management at Vanguard and ran IT for law firm Ballard Spahr for five years. That combination of legal, financial services, and health insurance is well matched to an organization that answers to all three kinds of regulator.
Ryan Rathbun – CISO, DuPont
Ryan Rathbun has been CISO of DuPont since May 2021, running security for one of the oldest industrial companies in the United States from its Wilmington headquarters. Alongside that he has served in the Delaware Air National Guard for more than twenty-five years and holds the position of State Command Chief, the senior enlisted leader advising the state’s Air National Guard command on the readiness, training, and welfare of its entire enlisted force. Very few corporate security chiefs carry a concurrent command responsibility of that weight, and fewer still have sustained one across a quarter century while moving into an enterprise CISO role.
Michael Hoehl – Global CISO, Carpenter Technology
Michael Hoehl returned to Carpenter Technology as CISO in July 2018, more than a decade after leaving the specialty alloys manufacturer where he had been network architect and security manager. In between he built an unusually varied record: Global IT Security Officer and Director of Internal Controls at Godiva Chocolatier for six years, Global Director of Security at QVC, head of security operations at Guardian Life Insurance, and interim CISO engagements at both B&H Photo Video and FactSet. That span across manufacturing, retail, financial services, and healthcare is the foundation for a career recognized by Forbes, ORBIE, and Cyber Defense Magazine. He also teaches and volunteers at Reading Area Community College.
Nari Narayanan – AVP and CISO, Incyte
Nari Narayanan leads global cybersecurity for Incyte, the biopharmaceutical company, having joined in 2017 as director of IT security, become senior director and CISO in 2019, and been elevated to Associate Vice President in January 2023. His background pairs deep pharmaceutical experience with privacy specialization: sixteen years at Pfizer across IT management, associate director, and senior manager roles, followed by identity and access management program leadership at Comcast and four years as an enterprise risk services manager at Deloitte. He holds CISSP alongside both CIPP and CIPT privacy certifications, plus PMP and Lean Six Sigma Black Belt. He has served as president and board member of SRUTI, the Philadelphia-area Indian music and dance society, since 2012.
Tracey Brand-Sanders – VP and CISO, UGI Corporation
Tracey Brand-Sanders has been VP and CISO of UGI Corporation, the King of Prussia energy holding company, since April 2020, responsible for the security program across the parent and its business units and for meeting federal, state, and international regulatory obligations. Her preparation was fourteen years at Prudential Financial, where she served as Director and Business Information Security Officer, chaired the Information Protection Governance Council, and presented the state of security to senior executives and the risk committee. She also spent two and a half years directing records and information management for Prudential’s group insurance business. Earlier in her Prudential career she managed the information security program, leading a team of nine and overseeing access administration across mainframe, UNIX, and Windows platforms under Gramm-Leach-Bliley and SOX.
Michael DaGrossa – VP of Information Security, Genesis
Michael DaGrossa is the top security leader at Genesis, the healthcare services company, where since 2020 he has overhauled security across the group’s companies, supervised migration to Google Cloud, deployed EDR and SIEM capabilities, and maintained PCI, HIPAA, and SOX compliance. He is a licensed private investigator and a named forensics investigator for several insurance and law firms, and his career is built on incident response as much as governance. He was global CISO at Amber Road, running security operations across teams in the US, China, India, and Germany, spent four years as CISO at Essextec, and founded ionRISK, a risk and forensics firm he built and sold in 2012. Earlier he created the IT risk management practice at Clifton Gunderson and led information security for AIG’s personal lines business. He teaches graduate courses in penetration testing, cryptography, and forensics at Wilmington University.
What This Group Says About Philadelphia
The Delaware Valley’s security leadership is defined by regulatory density rather than by any single industry. HIPAA, HITRUST, SOX, PCI, and Gramm-Leach-Bliley run through nearly every one of these careers, often several at once, and three of these leaders spent formative years in audit, risk advisory, or the Big Four before taking an operational seat. What distinguishes the region is how many of them built their way up inside one organization. Crabtree went from manager to vice president at the same insurer in seven years, Narayanan from director to AVP at the same pharmaceutical company in six. In a market where CISOs typically move to advance, Philadelphia appears to promote from within.
Discover more CISOs to watch:
-
- CISOs to Watch in the Twin Cities: From State Government to the Supply Chain
- CISOs to Watch in Charlotte: From Theme Parks to Financial Services
- CISOs to Watch in LA: From Movie Studios to Storage Units
- CISOs to Watch in Austin: From the County Courthouse to the Cloud
- Houston’s Security Leaders to Watch: From the Refinery Floor to the Boardroom
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

