Where Two Rivers Meet: Sacramento’s Cybersecurity Leaders to Watch

Related

Share

One person on this list operated intelligence ground stations in Iraq and Afghanistan before he ever worked in healthcare security. Another spent 17 years as a security architect for the California Highway Patrol. A third has run a lending and real estate business for 23 years while building a state government career in parallel. Sacramento’s cyber bench draws heavily on public service, and two of these leaders have held the same seat at the same health system within the past year.

Andrew Hartridge – CSO, Golden 1 Credit Union

Andrew Hartridge is a named inventor on patents related to financial services and risk management. His career began with technical and management roles at STERIS Corporation in Cleveland, then moved into security architecture at KeyBank, where he focused on identity management and access control. After three and a half years at Deloitte & Touche managing security services engagements, he joined the Internal Revenue Service. There he served as Deputy Director and then Director of Cybersecurity Architecture and Implementation, responsible for all cybersecurity policy, engineering, strategy, and capital planning at one of the largest civilian government IT organizations in the country, before taking over cybersecurity operations. Hartridge spent eight and a half years as CISO and Executive Vice President at M&T Bank, managing 160 employees at a top 10 US super-regional bank. He redesigned the entire program around the NIST CSF, implemented a large-scale SIEM, and built the bank’s identity and access management strategy. He joined Golden 1 Credit Union as Chief Security Officer in April 2025. He also teaches cybersecurity and technical courses at an accredited university.

Nathan Zierfuss-Hubbard – CISO, California State University, Sacramento

Nathan Zierfuss-Hubbard spent nearly a decade in Fairbanks, Alaska before coming to California. He started as a network intern with the State of Alaska in 1999, then worked as a systems analyst at the University of Alaska Fairbanks supporting the satellite downlink station and data archival center serving multiple countries’ space agencies. Eight years followed at the Arctic Region Supercomputing Center handling mass storage, UNIX administration, and security for high performance computing infrastructure. In 2010 he became CISO of the University of Alaska, where he shifted security operations from reactive to proactive and consolidated identity and access management across the system. He also helped create an information security emphasis within the university’s Homeland Security and Emergency Management program, developing and teaching a 400-level cybersecurity management course. Zierfuss-Hubbard moved to California State University, Stanislaus as Information Security Officer in 2017 and became CISO at Sacramento State in December 2023.

Michael Mosier – CISO, Sutter Health

Before he worked in healthcare, Michael Mosier operated intelligence ground stations in Iraq and Afghanistan. He spent five and a half years as a lead aircraft sensor technician and ground station operator supporting an experimental multi-intelligence ISR system, administering UNIX, Linux, and Windows servers while troubleshooting sensor systems in a combat environment. Earlier still, he served nearly six years as a Naval Aircrewman. He returned to Sacramento and worked as a computer network defense engineer at Beale Air Force Base for General Dynamics, supervising network defense monitors and handling FISMA compliance. Mosier joined Sutter Health in 2016 as a Senior Cyber Security Analyst, advancing through Cyber Security Manager and Director of Cyber Security before stepping into the interim CISO role in January 2026. He was named permanent CISO in July 2026. He now oversees threat detection, security engineering, incident response, and resilience for 24 hospitals and hundreds of clinics across a hybrid on-premises and cloud environment.

Mike Marshall – State CISO, California Department of Technology

Mike Marshall has owned Marshall Lending & Real Estate since 2003, running the business alongside a state government technology career that now spans more than two decades. He started as a business analyst at AT&T, then worked as a functional architect, security architect, and project manager at AT&T Wireless. Nearly a decade as Information Security Architect at CalPERS followed. In December 2017 he became CISO of the California Environmental Protection Agency, a role he held for more than six years before moving up to Agency Chief Information Officer, coordinating with six department CIOs across CalEPA. Marshall was appointed State Chief Information Security Officer at the California Department of Technology in September 2026, taking responsibility for cybersecurity across California’s state government.

Dylan Pletcher – CISO, CalSTRS

“Yes, securely” is the motto Dylan Pletcher brings to protecting the largest educator-only retirement system in the world. His career started at the California Highway Patrol in January 1995, where he spent 17 and a half years as the agency’s IT Security Architect. He then served nearly 13 years as CISO of the California Department of State Hospitals. Pletcher became CISO of CalSTRS in April 2025. Across more than 25 years in security roles, he has built a practice of engaging business stakeholders at every level rather than working around them. He participates regularly in State of California information security workgroups and mentors current and future professionals across the community.

Jacki Monson – SVP, Deputy CISO, CVS Health

Jacki Monson holds a Juris Doctor from Mitchell Hamline School of Law along with certifications in healthcare law, privacy, information security, and compliance. Her healthcare career began in compliance and privacy roles at a children’s hospital and a pharmacy benefit management company, followed by two and a half years as Chief Privacy Officer at Mayo Clinic. She joined Sutter Health in March 2013 as VP, Chief Technology Risk Officer, CISO, and Chief Privacy Officer, a combined role she held for a decade. During that period she also served ten months as Sutter’s interim Chief Information Officer. In March 2023 she became SVP, Chief Integration Officer, CISO, and CPO. Monson moved to CVS Health as SVP and Deputy CISO in April 2026. Becker’s Hospital Report has recognized her as a top 20 CISO and CPO to know in healthcare. She sits on the National Committee on Vital and Health Statistics and previously served on the Department of Health and Human Services Health Care Industry Cybersecurity Task Force, and she has testified before government and legislative committees.

Public Service Runs Through It

Four of these six built their security careers inside government or public institutions. Pletcher spent 30 years across the Highway Patrol, State Hospitals, and now CalSTRS without ever leaving California state service. Marshall came up through CalPERS and CalEPA before taking the state’s top security job. Zierfuss-Hubbard has spent his entire career at public universities in Alaska and California, and Hartridge ran cybersecurity for the IRS before moving into banking. The handoff at Sutter Health is its own kind of continuity: Monson led the health system’s security and privacy programs for 13 years before leaving for CVS in April 2026, and Mosier, who joined Sutter as an analyst in 2016 and worked his way up through the same organization, now holds the CISO seat. In Sacramento, security leadership tends to be built rather than recruited.

Discover more CISOs securing their organizations:

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.