Portland’s Security Leadership Bench

Related

Share

Two of the security leaders below have spent more than a decade at a single Portland institution, and one has been at hers for twenty years. Others took far less direct routes. One started in construction project management, another ran IT and digital marketing for a chain of car dealerships, and a third held a NATO Top Secret clearance while engineering satellite networks. Nike appears on more than one résumé here, and so do a regional hospital in Montana, a health insurer, and the county government. Portland’s security bench is local in some places and well traveled in others, and the mix shows in how these leaders approach the work.

Steve Person – CISO & VP Infrastructure & Operations, Cambia Health Solutions

Steve Person handled every security task himself at North Valley Hospital in Whitefish, Montana, from requirements gathering to vendor selection to day-to-day operation. He later wrote about how a critical access hospital should choose its security products. Before that, he spent nearly nine years as a systems and network administrator at Sun Microsystems in Hillsboro, followed by a systems and network engineering role at Oracle’s internal manufacturing facility. Person joined Cambia Health Solutions in 2014 as a Security Architect covering the Regence plans and Cambia’s other companies. He overhauled vendor security risk management and set up secure use of Amazon Web Services for big data workloads. After a year managing security architecture and engineering, during which he launched a formal application security program, he became CISO in July 2016. In April 2026 he added VP of Infrastructure and Operations to that role. He sits on the Blue Cross Blue Shield Association’s Cyber Security Subcommittee and has written certification exam questions in healthcare information security for (ISC)² since 2013.

Kuli Mavuwa – VP, Chief Technology, Security & Privacy Officer, OHSU

Kuli Mavuwa joined Oregon Health & Science University as a network engineer in 2006 and has never left. Over two decades he moved from network engineering into systems analysis, then into security as Associate Information Security and Privacy Officer and Security Engineering Manager. He became OHSU’s Chief Privacy Officer in 2016, took on security as well in 2021, and has served as VP and Chief Technology, Security and Privacy Officer since April 2022. Mavuwa is also a licensed attorney, which is unusual among technology executives. That legal training informs his work at the point where technology, law, and compliance meet in an academic health system.

Ranee Bray – CISO, Multnomah County

Ranee Bray began her career managing projects for a design and construction firm in the San Francisco Bay Area. Program management consulting at Coopers & Lybrand and Arthur Andersen followed, then more than a decade of independent consulting. She moved into security through CynergisTek and then spent six years as Managing Director of Cybersecurity Engineering at Charles Schwab. She went on to lead global security transformation at Silicon Valley Bank and to serve as Senior Director of Cybersecurity at Cloudflare. Across those roles, Bray has built security programs from the ground up twice and led IAM transformations, critical incident response, and AI governance work. She became CISO of Multnomah County in June 2026. Her credentials include an MBA along with CISSP, CISM, CRISC, PMP, and AAISM certifications.

Sherry Carpenter – CISO, BBSI

For nearly four years, Sherry Carpenter ran both technology and digital marketing for Bud Clary Auto Group’s dealerships across Washington. Her IT career began earlier at Con-way, where she worked her way from IT specialist to senior field services technician. She then spent six years at NAVEX Global in Lake Oswego as a senior enterprise systems engineer supporting mission-critical hosted systems. Nike hired Carpenter in 2016 as Lead Cybersecurity Strategist. Over five years there, she built the company’s three-year corporate information security strategy, developed its GDPR compliance strategy, and advised the CISO and senior directors across insider threat, cloud, identity, and cyber operations. She became CISO of BBSI in June 2021.

Chris Nolke – Founder & Managing Director, Skycrane

As CISO of Portland General Electric, Chris Nolke led 65 staff and 30 contractors through a multi-year security roadmap presented to the C-suite and board. He also secured Public Utilities Commission support for its budget. He joined PGE in 2017 as Director of Cyber Security and took on the governance function and CISO title in 2020. Outside the security roadmap, he co-created Chris n’ Dave’s B-School, a lunchtime business school attended by more than 300 employees. His first CISO role came at SureID in Hillsboro from 2015 to 2017, where he built a multi-year roadmap grounded in threat modeling and the kill chain. Before that, Nolke spent more than 11 years at Nike. There he wrote the company’s first Information Security Policy with Nike Legal, and he led the Keep It Tight awareness campaign, which reached 89% global completion without a compliance mandate and won a Nike Maxim Award. He later stood up Nike’s Cyber Threat Intelligence function in nine months. His career started in satellite network engineering at Hughes Network Systems, where he held a NATO/US Top Secret clearance, and continued as Chief Architect for firewall appliances at Dell. He founded Skycrane in 2023 to advise critical infrastructure clients on security.

Where Portland’s Security Talent Comes From

Nike is one clear source. Carpenter and Nolke both built strategy inside the company’s security organization before leading programs of their own at a staffing firm, a utility, and an identity verification startup. Local institutions are another. Mavuwa has spent his entire career at OHSU, and Person has spent twelve years at Cambia after starting his career at Sun and Oracle in Hillsboro. Bray shows a third path, bringing decades of financial services and technology experience to a county government. Portland develops its own security leaders and also draws in experienced ones, and its organizations benefit from both.

Discover more CISOs securing their organizations:

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.