TM.
Available — boards · advisory · speaking NEW YORK · —:—:— EST

~/whois.tomas
$ whois tomas-maldonado
$  
02
Career timeline

Twenty-three years, told as a system log.

2003
Merrill Lynch

First line of defense

Joined the information security team at a global investment bank. Cut my teeth on identity, access, and the hard parts of doing security inside a regulated giant.

2008
Wall Street

Crisis as classroom

The financial crisis reshaped how I thought about risk — not as a checklist but as a living system that fails in ways nobody modeled.

★ MOMENT
2011
JPMorgan Chase

Scaling the program

Helped lead enterprise information security at one of the largest banks on the planet. Learned that great security at scale is mostly great operations.

2016
Industry boards

Advisor & operator

Began serving on advisory boards for security startups and industry consortia — translating between practitioners, founders, and regulators.

2018
NFL

From finance to football

Joined the National Football League as Chief Information Security Officer. New industry, same first principles: protect the people, the data, the live event.

★ MOMENT
2020
NFL

The empty stadium

Ran a season unlike any other — broadcast operations, distributed workforce, and a threat surface that doubled overnight.

★ MOMENT
2022
SoFi Stadium

Super Bowl LVI

Led security operations for the most-watched broadcast of the year. Months of planning compressed into one Sunday.

★ MOMENT
2024
London · Frankfurt · São Paulo

International series

Cybersecurity for live NFL games on three continents. Different jurisdictions, different telecom stacks, same standard.

★ MOMENT
2026
Today

What’s next

Building the next chapter of the league's security program — and mentoring the people who'll run it after me.

03
The library

6 pieces. Pick your angle.

04
On stage

Live. Loud. On record.

T01
32 min
RSA Conference 2025

Risk at the speed of broadcast

"Downtime is measured in seconds when 100 million people are watching."

T02
40 min
Black Hat USA 2024

Security at the scale of a season

"A 17-week season forces your program to operate like a distributed system."

T03
28 min
Gartner Summit 2023

Building a championship security team

"Coach the people. The program follows."

T04
35 min
FS-ISAC Summit 2022

The CISO as translator

"Security leadership is a translation job."

05
From the field

Posts that landed.

TOMAS MALDONADO 2 weeks ago

Three things I tell every new analyst on day one: 1. Curiosity beats credentials. Always. 2. Write things down. Future-you will thank present-you. 3. Be the person on the team who's calm at 2am. That's the job.

18,243 ↳ 412 ↺ 1280
TOMAS MALDONADO 2 months ago

I've never regretted hiring someone curious. I've often regretted hiring someone who only had the right letters after their name. Hire for character. Train the rest.

9,210 ↳ 188 ↺ 540
TOMAS MALDONADO 5 months ago

If your security program only works when the senior people are awake, you don't have a program. You have a personality. Build the runbook. Trust the team. Go to sleep.

12,480 ↳ 233 ↺ 720
TOMAS MALDONADO 9 months ago

Every Sunday is a tabletop exercise that grades itself in real time. The score is on the scoreboard. The lessons are in the postmortem.

6,433 ↳ 121 ↺ 310
06
Advisory · boards

Where I show up between roles.

2022
Sports-ISAC
Founding Member, Executive Committee
Information sharing across major sports leagues and venues.
2021
Cybersecurity Coalition
Board Advisor
Policy and practitioner perspectives on national cybersecurity priorities.
2014–2018
FS-ISAC
Past Member, Board of Directors
Threat intelligence sharing across the global financial services sector.
2024
Stealth-mode security startup
Technical Advisor
Identity infrastructure for high-stakes live events.
2019
University CISO mentorship program
Mentor
Quietly meeting with the next generation of security leaders.
LET'S
WORK
TOGETHER.
© 2026 TOMAS MALDONADO · NEW YORK