Four of the seven leaders below came into security through audit desks and engineering benches rather than security operations centers. One wrote C++ applications for a mortgage insurer in 1993. Another spent six years at Johns Hopkins earning a master’s in electrical engineering before a bank ever asked him about web authentication. Cincinnati’s insurance and financial services concentration shapes this bench, but so does a quieter pattern: this is a city where people tend to stay, and where the same few institutions keep turning up on résumé after résumé.
Michael Speas – VP, CISO & Infrastructure, Western & Southern Financial Group
Michael Speas spent more than 18 years at RMIC, starting in 1993 as a PC Support Programmer writing C++ applications. He worked his way up through network engineering to managing voice and data communications for a network of over 5,000 devices across 28 remote offices, then became the company’s Information Security Officer in 2007. A stint at Inmar followed, where he oversaw network and application security and worked with outside consultants on SOC 2 reporting. In 2013 he joined the Federal Home Loan Bank of Indianapolis as Director of IT Assurance and Shared Services, adding the CISO title two years later along with responsibility for business continuity and the vendor management office. Speas moved to Western & Southern Financial Group in May 2018. He now carries a $54 million budget and leads 120 professionals across cybersecurity and infrastructure at the Fortune 500 insurer, with enterprise AI governance among his responsibilities. He also serves on the board of Northern Kentucky University’s Center for Information Security.
Elizabeth Hays-Najlepszy – CISO, Federal Home Loan Bank of Cincinnati
The audit desk is where Elizabeth Hays-Najlepszy learned the business. She started with a co-op in IT and logistics at GE Aviation in 2004, then joined PricewaterhouseCoopers as a Systems Process Assurance Associate. Nearly five years as a Senior IT Auditor at Fifth Third Bank came next, followed by four years managing IT audit at Vantiv and two years at GE as Manager of Operational Controllership for IT. She joined the Federal Home Loan Bank of Cincinnati in 2019 as Senior Manager of IT Audit. From there the path ran through Internal Audit Officer, AVP of Operational Risk and Compliance, and Assistant CISO before she took the top security seat in July 2024. Her entire career has been built in Cincinnati.
Jake Lorz – VP, Information Technology & CISO, Cintas
Jake Lorz taught information security nights and weekends at Sinclair Community College while working full time as a network and information security supervisor. His career began in 2003 as an IT support technician at Globe Motors, a Safran company in the Dayton area, where he stayed nearly a decade. Safran then sent him to Paris as International Infrastructure Manager. He returned to the US in 2015 as CISO of MorphoTrak in Anaheim, later becoming Director of Information Security for the Americas at IDEMIA, work that included CJIS compliance for law enforcement systems. Lorz joined Cintas in 2021 as Director of IT Security and was promoted to VP of Information Technology and CISO in June 2023. He holds a bachelor’s in management information systems, a master’s in information technology, and CISSP, CISM, CRISC, and GCIH certifications.
JD Rogers – CISO, American Financial Group
When JD Rogers arrived at American Financial Group in 2014, the company had no enterprise-wide information security group. He built the first one. That meant forming a security council to pull 15 decentralized IT organizations into a single program and serving as what he describes as a security evangelist to 33 separate business units. His earlier work at GAFRI produced measurable results: a role-based security model automated from HR systems cut new employee setup from five days to one, and a new vulnerability management program mitigated 7,490 vulnerabilities in its first year with no production impact. Rogers spent 11 years at Cinergy as IT Security Principal, where he was the primary source of security requirements for NERC 1200 compliance, the project that secured the utility’s SCADA systems controlling the power grid. He later joined four integration teams during the Duke Energy and Cinergy merger. A brief stop at Toyota put him in charge of implementing the Toyota Security Guidelines across 17 North American manufacturing operations, a certification Toyota of Japan required before releasing confidential engineering data.
Mike Kelley – CISO, Total Quality Logistics
Mike Kelley began at KPMG in 2004 doing Sarbanes-Oxley compliance work, then joined The E.W. Scripps Company as a Senior Associate. There he cut the company’s SOX IT general control framework by 33% and, as a Senior IT Auditor, used data mining tools to identify $135,000 in cost recovery during an accounts payable audit. He left for Dana Holding Corporation in 2011 as global Information Security Officer, where he reduced control defects by 500% within his first year and secured executive funding for a three-year program modernization. Kelley returned to Scripps in 2015 as VP and CISO, a role he held for nine years before adding infrastructure operations to his scope. He became CISO of Total Quality Logistics in July 2025. He also sits on the board of advisors at Dune Security, a machine learning company focused on identifying and training an organization’s highest-risk employees.
Sean Sweeney – VP & CISO, Cincinnati Financial and Cincinnati Insurance
For 15 years, Sean Sweeney taught information systems in Northern Kentucky University’s Master of Information Systems and MBA programs. His day job has been at Cincinnati Insurance Company since February 2002, where he came up through IT leadership with direct responsibility for quality assurance and testing, the vendor management office, IT budget management, and IT security. He also serves as Vice President and Director of Information Technology, participating in the Project Prioritization Committee and the IT Expense Committee. Sweeney took on the CISO role in November 2021. Before insurance, he spent three years consulting at IBM on ERP software selection and business process reengineering, and managed ERP implementations at The Summit Group with Lawson HR and general ledger expertise.
Craig Kobren – CISO & Chief of Enterprise Information Management, The Christ Hospital Health Network
Craig Kobren holds a master’s degree in electrical and electronics engineering from Johns Hopkins University, and his career started in defense. He spent six years as an Electronics Engineer and Lead Analyst at the Army Materiel Systems Analysis Activity, then moved to Harris Corporation and Raytheon as a systems and software engineer. Banking came next. At Bank of America he managed enterprise web authentication, and after three years at Fifth Third Bancorp he joined Citi, where he spent more than eight years running information security architecture, consulting, and cryptography before leading global consumer mobile and application security as a Senior Vice President. His last role there was Global PCI Program Director. Kobren became CISO of The Christ Hospital Health Network in August 2015 and added responsibility for enterprise information management in April 2025. He holds CISSP and CRISC certifications.
The Audit Desk Pipeline
Cincinnati produces security leaders from its audit and compliance functions more reliably than most cities. Hays-Najlepszy came up through PwC, Fifth Third, Vantiv, and GE before running security at a federal bank. Kelley followed nearly the same route through KPMG and internal audit at Scripps. Two of these leaders spent formative years at Fifth Third, and two have ties to Northern Kentucky University, Sweeney as faculty and Speas as a board member of its security center. The others came through engineering instead. Rogers secured a power grid, Kobren analyzed Army weapons systems, and Speas wrote C++ before anyone gave him a security title. What holds across both groups is staying power. Rogers has led security at American Financial Group for nearly 13 years, Kobren at The Christ Hospital for 11, and Sweeney has worked at the same insurance company since 2002.
Discover more CISOs securing their organizations:
- Portland’s Security Leadership Bench
- City of Fountains: Kansas City’s CISOs to Watch
- Capital of the Buckeye State: Columbus CISOs to Watch
- Indy’s CISO Bench: Leaders to Watch
- The Inner Harbor’s CISOs to Watch
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

