Baltimore’s CISO roster includes a security executive who unified two traditionally separate C-suite functions into one role, a federal veteran who spent more than a decade defending Treasury systems before moving into higher education, and an energy company’s first-ever CISO who built an entire cybersecurity department from scratch after a corporate divestiture. Healthcare, energy, retail, and two of the city’s universities all draw from the same regional bench, and the five profiles below trace strikingly different paths into the seat.
Rob Suarez – VP & CISO, CareFirst BlueCross BlueShield
Rob Suarez built his security career inside the medical device industry before moving into healthcare insurance. Suarez started as a Software Engineer at Siemens Corporate Research in 2008, then spent five years at Siemens Healthcare working through Product and Solution Security Expert roles before becoming a Program Manager overseeing the division’s broader security expert community. He joined BD in 2015 as Director of Corporate Product Security, building the company’s center of excellence for securing its medical products and solutions, and was promoted to VP and CISO in May 2019, a role spanning both enterprise information security and product security across BD’s manufacturing, service, and third-party partner ecosystem. Suarez became VP and CISO of CareFirst BlueCross BlueShield in July 2023, based in Baltimore.
Dan Sadler – VP & CISO, Constellation Energy
Dan Sadler became Constellation’s first-ever Chief Information Security Officer in February 2022, the same month the Fortune 200 carbon-free energy company separated from Exelon, and he built the entire cybersecurity organization, its operating model, governance structure, and budget, from the ground up. Sadler’s path to that role ran through nearly a decade at Exelon, where he led business continuity, crisis management, and threat intelligence functions for a 45-person department, and coordinated the security organizational design during Exelon’s separation from Constellation as the divestiture took shape. Earlier still, he spent years in Exelon’s business continuity practice, managing portfolios of hundreds of department recovery plans and coordinating crisis response for events including Hurricane Sandy and the Boston Marathon bombing. Sadler also fulfills the role of NERC CIP Senior Manager, overseeing Constellation’s compliance with critical infrastructure protection standards for the energy grid, and he serves on the board of the National Technology Security Coalition.
Alex Attumalil – Global CISO, Under Armour
Alex Attumalil has spent more than two decades unifying two roles that most companies keep separate, serving simultaneously as Under Armour’s Global CISO and Head of Infrastructure and Operations. Attumalil built his cybersecurity foundation at Lockheed Martin, where he spent nearly a decade as a Senior Staff Cyber Security Engineer leading the company’s CERT team, and later worked as a CERT Lead for a US Government Intelligence Agency and as a Threat Intelligence Architect at Vencore, managing a Cyber Threat Operations Center that triaged security alerts in real time. He joined Under Armour in 2013 as Senior Manager of Global Information Security, then advanced through Director and Deputy CISO roles before being named Global CISO in May 2022, based in Baltimore. In his combined role, Attumalil now oversees global network operations, data centers, hybrid cloud infrastructure, and identity management alongside the company’s cybersecurity strategy, including AI risk governance for large language model deployments. He also serves on the board of the Arbutus Volunteer Fire Department.
Stacy Cahill – CISO, University of Maryland, Baltimore County
Stacy Cahill spent the last 11 of her 22 years at the Bureau of the Fiscal Service serving as the agency’s Chief Information Security Officer, work that involved partnering across federal organizations to secure and modernize critical national services. Cahill became CISO at the University of Maryland, Baltimore County in April 2024, returning to the school where she earned her undergraduate degree in Information Systems, with a minor in Computer Science, in 2001. Her background spans software development, middleware administration, enterprise architecture, and identity and access management, and she has described her focus at UMBC as using architectural design to reduce institutional risk.
Chris Breeden – CISO, University of Baltimore
Chris Breeden spent 12 years at Uline, working his way from Systems Engineer to Senior IT Security Engineer across roles based in Pleasant Prairie, Wisconsin, before returning to the security leadership track in Maryland. Breeden built his early IT career in the Baltimore-Washington corridor, starting as a Help Desk Coordinator and Junior Network Administrator at Potomac Valley Orthopaedics Associates in 2005 and later working as an IT Project Coordinator for Merkle in Columbia, Maryland. He has served as CISO of the University of Baltimore since 2023, following a year as CISO for a High Intensity Drug Trafficking Area program. Breeden’s technical background centers on Microsoft Azure cloud security and identity and access management, particularly deploying IAM policies at the parent level to reduce the scope of privileged access across an organization.
A City Actively Building Its Bench
What stands out in Baltimore is how many of these leaders came to the city, and to their current employer, relatively recently. Cahill arrived at UMBC in 2024 after more than two decades in federal service. Sadler took on his role the same month Constellation Energy itself came into existence as an independent company. Suarez has been in Baltimore only since 2023, and Breeden’s current seat dates to 2023 as well, following a shorter stint leading security for a regional drug enforcement program. Attumalil is the exception, having spent his entire tenure since 2013 building toward the combined CISO and infrastructure role he holds today at Under Armour. Together, this group shows a city that knows how to attract seasoned security leadership when it needs it.
Discover more CISOs securing their organizations:
- Guarding the Peach State: Atlanta’s Security Leaders to Watch
- Securing the Capital Region: CISOs to Watch in the DMV
- Guarding the Steel City: Pittsburgh’s Security Leaders to Watch
- Securing the Bay: Tampa’s CISOs to Watch
- Guarding the Gateway: St. Louis’s Security Leaders to Watch
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

