Chief Information Security OfficerAtlanta, GACISSP, CISM

Twenty-five years on the defending side, from CDC's field network to Zero Trust on 100,000 endpoints.

Kevin Stallard

My work sits where security operations meets architecture. At U.S. Bank that meant building the first Blue Team in about six weeks and chairing a review board for more than 1,500 applications. Through Microsoft's $69B acquisition of Activision Blizzard King, it meant restarting a stalled Zero Trust program and finishing it across 35 studios. Today I run Threat Tape, building cyber governance and AI-agent security.

Kevin Stallard, Chief Information Security Officer

The perimeter cutover

At Activision the Zero Trust program had stalled for years. My job was to restart it there, carry it through the acquisition, and finish it at Microsoft. The result: every endpoint across 35 studios on ZTNA, about 70 paired firewalls retired, and no studio taken offline.

Schematic of 35 studios moving from a network perimeter to Zero Trust Thirty-five studio nodes surround a central core. In the perimeter model each studio connects through paired firewalls inside a network boundary. In the Zero Trust model the firewalls and boundary are gone and every studio connects through identity and policy. network perimeter Corporate network trust by location
Program status
Stalled for years
Endpoints on Zero Trust
100,000+ in scope
Paired firewalls
About 70 in service
Studios taken offline
35 studios in scope
Endpoints on ZTNA100% of 100,000+
Paired firewalls retiredAbout 70
Studios taken offline0 of 35

Schematic. Node positions are illustrative; the outcome figures are from the program record.

Experience

Each role opened with a mandate. These are the mandates and what came of them.

  1. Jan 2025 to present
    Atlanta, GA

    Founder, CTO & CISO

    Threat Tape LLC, security and AI governance practice

    Build security-critical products and take fractional CTO engagements. Bootstrapped, with an 8-person contractor team.

    • Governed about 10,000 Azure endpoints for a national-government client as fractional CTO to EDD-i Technologies (2025 to 2026), deploying RiskTape white-label with data sovereignty built in.
    • Built RiskTape, a cyber-governance System of Record mapping live telemetry to more than 20 frameworks with FAIR risk quantification.
    • Eliminated information-disclosure vulnerabilities in Galxee AI's shipping product as fractional CTO (2026 to present), then led the 0-to-1 build of CfAM, an AI-agent containment layer.
  2. Oct 2023 to Dec 2024
    Remote

    Director of Security Architecture

    Microsoft, Xbox Gaming

    Secure the post-close integration of Activision Blizzard King after the $69B acquisition.

    • Restarted a Zero Trust program at Activision that had stalled for years, then finished it at Microsoft: 100% of more than 100,000 endpoints across 35 studios, ZTNA fully implemented.
    • Retired about 70 paired firewalls without taking a studio offline while reconciling Activision's framework with Microsoft standards across identity, network, and governance.
    • Influenced a $20M annual security budget for the Activision Blizzard King studios and briefed the CISO weekly on posture and risk decisions.
    • Owned the data-protection and privacy program for the Activision Blizzard King studios, including GDPR.
    • Performed root-cause analysis during the July 2024 CrowdStrike global outage; operations were back up within 48 hours.
  3. Dec 2022 to Oct 2023
    Remote

    Director of Security Architecture

    Activision Blizzard King, continuous through the Microsoft acquisition

    Direct target-side security architecture across the global studio network through the acquisition.

    • Led 6 senior security architects and 2 principal engineers across 35 studios and more than 100,000 endpoints.
    • Unified IAM and network security across legacy Activision, Blizzard, and King environments.
    • Recommended spend for a $20M annual cybersecurity budget and eliminated redundant tools within it.
    • Secured launch infrastructure for AAA titles including Diablo IV.
  4. Jul 2017 to Nov 2022
    Atlanta, GA

    Lead Security Architect

    U.S. Bank, a top-5 U.S. bank

    Lead enterprise-wide security architecture after promotion from Director of Threat Hunting.

    • Founded the Security Architecture Review Board with steering committee approval, then as sole chair for two years governed more than 1,500 applications at one-week turnaround.
    • Influenced $35M to $50M in annual security investment through risk quantification and executive business cases.
    • Served as primary security SME in OCC, FDIC, and international regulatory examinations.
    • Cut development cycles 50%, from three years to 18 months, with a DevSecOps methodology.
  5. Jul 2015 to Jun 2017
    Atlanta, GA

    Director of Threat Hunting

    U.S. Bank

    Stand up threat hunting as a formal capability.

    • Built the bank's first Blue Team in about six weeks, taking detection from no hunt capability to a 48-hour mean time to detect.
    • Caught an authorized red-team exfiltration of card-number records at several kill-chain points after NetFlow analysis flagged 4GB of outbound DNS traffic, then wrote the remediation roadmap.
    • Led a 4-person threat intelligence program across 12 international offices.
  6. Feb 2013 to Aug 2015
    Atlanta, GA

    Information Security Advisor, CDC Center for Global Health

    U.S. Centers for Disease Control and Prevention, via GFR Technology under Laulima Solutions

    Serve as embedded security advisor to the CISO of CDC's Center for Global Health across a 75-country field network.

    • Led malware and nation-state intrusion response with U.S. and allied intelligence agencies, sustained through the 2014 to 2015 Ebola response.
    • Owned business continuity planning and ran security awareness, phishing, and executive tabletop exercises.
    • Directed IAM for the HIPAA-regulated Secure Data Network, and ran the encrypted-device program protecting CUI, including key management.
  7. Jan 2011 to Oct 2015
    Atlanta, GA

    Principal Consultant, Owner

    GFR Technology, independent security consultancy

    Run a sole-practitioner security practice serving federal, public-health, financial services, and automotive clients.

    • Achieved DIACAP compliance for Oversight Systems from a zero baseline in 18 months.
    • Cut LeasePlan's identified vulnerabilities from more than 16,000 to under 100.

Earlier career

  • Internet Security Systems (ISS)Led a 14-person team.
  • Northrop GrummanSenior Security Engineer on a CDC contract.
  • EarthLinkSenior Abuse Engineer, preventing $45M in fraud.
  • Lancope and IBMSoftware engineering and security roles.

What I build now

Threat Tape is where the defender's roadmap turns into working software, held to one rule: no performance claim goes to a customer or investor unless a pilot measured it.

RiskTape

Cyber-governance System of Record

Maps live telemetry to more than 20 frameworks, including NIST CSF 2.0, ISO 27001, CMMC, and PCI DSS, with FAIR risk quantification.

CfAM for Galxee AI

Fractional CTO, 2026 to present

A production Python and FastAPI layer that sandboxes autonomous-agent tool calls, logs them to a tamper-evident hash-chained ledger, and flags anomalies in real time.

EDD-i Technologies

Fractional CTO, 2025 to 2026

About 10,000 Azure endpoints governed for a national-government client, with RiskTape deployed white-label and data sovereignty built in.

OSTRAQ

Co-founder, 2024

A post-quantum election-security platform (ML-KEM-1024, ML-DSA), validated in a 500-voter live proof of concept.

Where I lead

Four areas a security organization runs on, each backed by a program I built or ran.

Security operations and detection

Took a top-5 bank from no hunt capability to a 48-hour mean time to detect, and led nation-state intrusion response for CDC.

Splunk, McAfee SIEM, CrowdStrike, Microsoft Defender, Carbon Black, Tanium, NetFlow analysis

Zero Trust and security architecture

Zero Trust, IAM, and cloud security architecture through a $69B acquisition, across 35 studios and five cloud platforms.

ZTNA, IAM, AWS, Azure, GCP, Oracle Cloud, OpenStack, secure SDLC, DevSecOps

Governance, risk, and privacy

Founded and chaired an architecture review board, served as primary security SME in OCC and FDIC examinations, and owned a data-protection program covering GDPR.

FAIR, NIST CSF 2.0, ISO 27001, CMMC, PCI DSS, HIPAA, third-party risk, business continuity

AI security

Building security for AI systems, including execution-layer containment for autonomous agents and governance for the platforms they run on.

AI agent containment, agentic development, post-quantum cryptography, key management

Credentials

Certifications and education.

CISSPCertified Information Systems Security Professional, ISC2
CISMCertified Information Security Manager, ISACA
CBPCertified Blockchain Professional, EC-Council
Kennesaw State UniversityBachelor of Science, Information and Computer Science
Georgia Institute of TechnologyCoursework, Information and Computer Science
Portrait of Kevin Stallard

Looking for a security leader who has run the program, not just written it?

Open to Chief Information Security Officer, Head of Information Security, and CTO roles. Based in Atlanta, open to on-site, hybrid, and remote.