The Bold City’s Cybersecurity Leaders to Watch

Related

Share

Jacksonville’s cybersecurity leaders tend to put down roots. Of the eight below, one has spent nearly 30 years at the same children’s health system, another 28 at the state’s Blue Cross plan, and a third more than 25 years at the same university. Several came up through the military: a Navy gunner’s mate, an Air Force network manager who ran secure email for Air Combat Command, and an FBI unit chief. Others started in internal audit, AOL technical support, and desktop repair. Together they protect railroads, banks, health systems, insurers, a state property insurer, and a public university.

Joseph Baglino – SVP & CISO, EverBank

Joseph Baglino started in technical support at America Online in 1996, then spent years as an application developer and network and Exchange administrator at Mac Papers and PPR Talent Management Group. He managed application development for the City of Jacksonville and directed IT at SuperStock before joining EverBank in 2012 as VP and IT director of information security. He went on to serve as VP and deputy CISO at TIAA Bank for nearly five years, became its SVP and CISO in 2023, and has been SVP and CISO of EverBank since December 2023. He holds CISSP, CISM, and PMP certifications.

Ken Morris – Deputy CISO, GuideWell / Florida Blue

Ken Morris served ten years in the U.S. Air Force, starting as a computer and resource security officer at Holloman and Langley Air Force Bases. As a network manager at Osan Air Base in South Korea he led the network operations center handling email for the base and remote units, and back at Langley he maintained the secret network used to coordinate Air Combat Command’s wartime missions. He then worked as a senior analyst supporting U.S. Army and Air Force Special Operations Forces. Morris joined Blue Cross and Blue Shield of Florida in 1998 as a principal IT security architect and has spent 28 years there and at parent GuideWell, serving as interim CISO for Florida Blue and as deputy CISO since 2017. He directs the program protecting health information for 5 million subscribers.

Jim Loveless – CISO, Nemours Children’s Health

Jim Loveless has spent nearly 30 years at Nemours, starting as a desktop support technician in 1997. He went on to manage desktop support across six sites, direct information systems for five Florida locations, and manage IT for the opening of a new 600,000-square-foot hospital in Orlando. As director of systems administration he oversaw about 1,800 servers and more than 10,000 endpoints while leading identity federation, multifactor authentication, and vulnerability management. Loveless has been CISO since November 2018, leading a team of about 20 and briefing the board on cyber risk across Nemours’s clinical, research, and business environments.

James Case – VP & CISO, Baptist Health

James Case spent seven years as a systems engineer at Hewlett-Packard, then worked as a senior project analyst at Winn-Dixie. He first joined Baptist Health in 2005 as a senior project manager and, after a year at FIS, returned to lead infrastructure project management and then manage information security for seven years. He served as an information security officer at Citi and VP of information security at ERC before returning to Baptist Health as VP and CISO in December 2021.

Tim Craig – VP & CISO, Citizens Property Insurance Corporation

Tim Craig started as an internal auditor at Huntington National Bank in West Virginia and Ohio, working on bank acquisitions and fraud investigations, followed by audit roles at United McGill and Bank of America. He spent more than 26 years at VyStar Credit Union in Jacksonville, first as a senior internal auditor and then as its first information systems security officer, a role he created in 2004. As VP of information security for 12 years he built the credit union’s security program, managed a $5.5 million budget, and brought identity and access management for 1,900 employees under security. Craig became VP and CISO of Citizens Property Insurance Corporation in November 2024. He holds CISM, CISA, CIA, GSLC, and GCCC credentials.

Clay Maddox – CISO, University of North Florida

Clay Maddox served four years in the U.S. Navy as a gunner’s mate, then led a high-speed data support team at MediaOne handling network abuse. He joined the University of North Florida in 2000 as a computer applications coordinator and has spent more than 25 years there, aside from a brief stint as a systems engineer. He worked as a network security engineer for seven years, served as assistant director of information security, and later led network engineering and cyberinfrastructure. He became senior director of cyber infrastructure and information security in 2024 and was named UNF’s CISO in March 2026.

Simon Scully – VP & CISO, Venerable

Simon Scully started as a business systems analyst on HR information systems at CitiStreet, working through Y2K testing and later moving into programming and project management. At ING he led identity and access management projects as a senior IT security project manager. At Voya Financial he managed security risk for its retirement and annuity businesses, then directed the security incident response team and the cyber fusion threat center, building threat intelligence and threat hunting programs. He joined Venerable in 2018 to lead security operations and has served as VP and CISO since October 2021. He holds CISSP and CEH certifications and a master’s degree in computer information systems.

Alex Borhani – (Former) CISO, CSX

Alex Borhani started as a Java and Python developer at GEICO before spending nearly 12 years at the FBI, rising from special agent to supervisory special agent and unit chief. He moved to Jacksonville as CISO of Web.com, then joined CSX in 2019 as director of information security. He served four years as deputy CISO and became CISO in July 2025, leading security for the railroad until January 2026. He also co-founded Start Left Security. Since early 2026 Borhani has been on a career break, rehabilitating a 100-year-old home, launching a venture called Nestmarket, and building a suite of hybrid agentic AI services. Given his range from FBI casework to software to enterprise security, where he lands next will be worth watching.

Roots Run Deep in the Bold City

Jacksonville’s security leaders tend to grow with their institutions. Loveless, Morris, and Maddox have each spent a quarter century or more at a single employer, moving from desktop support, security architecture, and network engineering into the top security roles. Craig spent most of his career at VyStar before taking on a statewide insurer. Case and Baglino left and came back to the organizations they now protect. Borhani and Scully brought experience from the FBI and national financial firms. Together they show how a mid-sized city can build a deep bench by keeping its talent close.

Discover more CISOs securing their organizations:

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.