The DMV’s CISO roster includes people who built parts of the federal government’s cybersecurity infrastructure before moving into corporate security leadership. One helped create the Department of Homeland Security’s national incident coordination center. Another is a named author on federal identity standards still used to validate smart cards and biometric systems in roughly 40 countries. A third built a machine learning tool for students with learning disabilities before ever touching a security program. Financial services, museums, federal contractors, international development agencies, hospitals, and software platforms all draw from the same regional bench, and the six profiles below show how differently each person got there.
Mike Newborn – CISO, Navy Federal Credit Union
Mike Newborn’s fascination with home automation technology runs alongside his day job protecting one of the world’s largest financial institutions. Newborn has served as CISO of Navy Federal Credit Union since August 2019, leading cyber risk management for a credit union serving millions of military members and their families. Before joining Navy Federal, he built his own cybersecurity consultancy, Newborn Associates, from 2016 to 2019, advising startups and established companies on program development, project prioritization, and technical strategy. During that same period, he also served as CISO for McKinsey Digital Labs and as a cybersecurity senior expert for McKinsey & Company, providing advisory services to the firm’s clients. Newborn spent four years as a Stars Mentor for MACH37, a Virginia-based accelerator that invests in early-stage information security product companies, coaching founders through a three-month validation program. He now serves on multiple advisory boards, including Expel, George Mason University’s College of Engineering and Computing, Longbow, IANS, and Accenture, and has advised Blu Ventures as a cyber advisor since 2023.
Joseph Dyer – VP & CISO, ICF
WashingtonExec named Joseph Dyer one of its Top CISOs to Watch in 2023, a recognition that landed roughly midway through a tenure now stretching past 17 years in the same seat. Dyer has served as VP and CISO of ICF since April 2009, based in Fairfax, Virginia, building on IT and security leadership he began at Macro International, which ICF later acquired, where he served as Vice President of Information Technology, Facility Services, and Information Security starting in 2002. His career in technology goes back further still, to a Director of IT Client Services and Operations role at Acterna in 1998 and a Network Services management position at Computer Sciences Corporation beginning in 1994. Dyer holds CISSP, CCISO, GISF, Security+, CCFE, CHFI, Network+, and GIAC certifications, and he authored the book Securing Your Digital Social Life. He won a Top 100 CISO award in 2022 and now serves on the OnCon Senior Council, a cross-industry group of senior executives that meets for confidential peer benchmarking roundtables.
Nabil Ghadiali – Deputy CIO & CISO, National Gallery of Art
Nabil Ghadiali once served as the “Gatekeeper” for a federal evaluation list used by roughly 40 countries to validate identity technology products, a role that grew out of his work supporting the creation of the GSA’s FIPS 201 Evaluation Program. He joined the National Gallery of Art as CISO in March 2011, building the museum’s IT security program from governance and risk management through federal compliance, and he was promoted to Deputy CIO in July 2026 while continuing to lead the Gallery’s security function. In that combined role, he partners with the CIO on enterprise IT strategy and capital planning while also briefing the Gallery’s CFO, Treasurer, and Board Members on security status. Ghadiali is a named author on several NIST publications, including FIPS 201 and multiple entries in the SP 800 series. Earlier in his career, as Product Manager at Lexign between 2001 and 2003, he oversaw a tool that let users digitally sign and encrypt documents in Microsoft Word, Excel, and Adobe Acrobat, a product President Clinton used to sign the E-Sign Law and that four subsequent presidents also used. Before the National Gallery, Ghadiali spent eight years as Vice President of Information Assurance at Electrosoft Services, leading identity management and information security projects for federal agencies.
Khalid Nayyar – CISO, Peace Corps
Khalid Nayyar spent the first decade of his career managing IT infrastructure for a hip-hop clothing company and a New York advertising agency before moving into federal information security. He built networks and security policies for Akademiks and Grey Group between 2002 and 2010, then became a systems administrator supporting federal disaster recovery efforts at Datawiz Corporation. Nayyar joined the Peace Corps as an Information Security Engineer in 2014, then advanced to Information System Security Manager the following year, a role he held for five years before brief stints as an Information Security Specialist at the FDA and an IT Specialist at the Department of Health and Human Services. He returned to the Peace Corps in 2021 as an Information Security Expert, was named Acting CISO in January 2025, and became the agency’s permanent Chief Information Security Officer in May 2026, based in Washington, DC. Nayyar holds a CISSP certification and lists vinyl records among his personal interests, alongside technical specialties in cloud security, FedRAMP compliance, and network administration.
Nate Lesser – VP & CISO, Children’s National Hospital
Before building cybersecurity programs, Nate Lesser built a machine learning therapeutic system for students with learning disabilities as President of Sandbox Labs, taking the product from concept through prototyping and testing at four sites in under 18 months. He later worked as a Policy Analyst at the Office of Management and Budget, managing regulatory processes for the Department of Homeland Security and the Federal Aviation Administration and coordinating with the National Security Council and the Domestic Policy Council. Lesser moved into hands-on cybersecurity work at Booz Allen Hamilton in 2009, leading a team supporting federal agencies including Homeland Security, Defense, State, Health, and Transportation. He then spent nearly four years as Deputy Director of the National Cybersecurity Center of Excellence at NIST, setting the research agenda and managing partnerships with technology vendors for the country’s cybersecurity national laboratory. Lesser founded Cypient in 2016, providing cyber risk management and fractional CISO services to small and medium businesses, and later co-founded Cypient Black, a company offering digital protection services for executives and their families. He became CISO of Children’s National Hospital in July 2020 and was promoted to Vice President and CISO in January 2022, a role he has now held for more than four years.
Patrick Beggs – CISO, ConnectWise
Patrick Beggs served as the first Director of Operations at the Department of Homeland Security’s National Cybersecurity and Communications Integration Center, a role he took on in 2010 when the 24/7 operations center was created as the federal government’s central coordination point for significant cyber incidents. Before that, he built the Cyber Resiliency Review at DHS’s National Cyber Security Division, a framework still used to measure how organizations adopt and mature their cybersecurity risk management practices, and he created the Cyber Security Advisor initiative that places federal employees in regions across the country to help state, local, and private organizations protect critical infrastructure. Beggs left government service in 2012 for Bank of America, where he spent more than four years as Senior Vice President of Global Information Security leading the bank’s Cyber Insider Threat Response group. He went on to hold cybersecurity leadership roles at Amazon Web Services, Booz Allen Hamilton, and AIG before spending a year and a half as Global Head of Cybersecurity Operations at Cognizant, where he led a team of more than 150 people across five countries covering SOC operations, incident response, and threat hunting. Beggs became CISO of ConnectWise in 2022, working remotely from the Washington, DC-Baltimore area to protect the company’s global SaaS platform. He is also an Army veteran.
Federal Roots Run Through Every Résumé
What connects this group is not the CISO title itself but where most of them learned the job. Beggs built federal incident response infrastructure from inside DHS before ever holding a corporate security title. Ghadiali co-authored the NIST standards that later shaped identity management programs nationwide. Lesser ran NIST’s own cybersecurity laboratory before founding two companies of his own. Even Nayyar and Dyer, whose careers ran mostly through corporate and nonprofit IT, ended up leading security for federal agencies and government contractors. In the DMV, the line between building the rules and enforcing them tends to blur, and that overlap shows up in how this group approaches the job.
Discover more CISOs securing their organizations:
- Guarding the Steel City: Pittsburgh’s Security Leaders to Watch
- Securing the Bay: Tampa’s CISOs to Watch
- Guarding the Gateway: St. Louis’s Security Leaders to Watch
- Securing Music City: Nashville’s Cyber Leaders to Watch
- Guarding the Gateway: Security Leaders to Watch in Miami
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

