CISSP CISM C|CISO CDPSE ITIL

Charles
Valdes

Chief Information Security Officer · Fractional CISO
AI-First Security Leader

📍 Dallas–Fort Worth, Texas

18+
Years Experience
12M+
Customers Protected
$3M+
Security Savings
Charles Valdes — Chief Information Security Officer, Dallas TX
🏆 2026 Dallas ORBIE CISO of the Year Finalist
"Security must operate as a business enabler, not a brake."
— Charles Valdes, CISO

I lead enterprise cybersecurity at Leon Capital Group, where I built the firm's comprehensive security, data privacy, and AI security program from the ground up — protecting 9,000+ employees and 12M+ customers across financial services, healthcare, and real estate.

We've deployed both passive generative AI (analyst augmentation, log triage, policy generation) and agentic AI (autonomous threat response, vulnerability remediation, compliance monitoring) across the security stack — a working, measurable program redefining how modern security operates.

Across Fortune 100 and Fortune 500 enterprises — U.S. Bancorp, The DTCC, Trellix, Mitek Systems, Kubota North America, and American Airlines — I've architected and matured global security programs spanning cloud (Azure, AWS, GCP), fintech, banking, and critical financial infrastructure.

Proven Results

Results at Scale

$3M+
Annual Security Savings
Via pen testing program redesign at U.S. Bancorp
#1
BitSight Peer Bank Ranking
Highest cybersecurity rating among all peer banks
61%
Engineering Labor Reduction
Through proprietary security automation
12M+
Customers Protected
Across financial services, healthcare, and real estate

Services & Engagements

Fractional, Full-Time &
Advisory Engagements

Available for full-time CISO roles, Fractional CISO engagements, board advisory, and cybersecurity consulting — flexible to what your organization needs.

Fractional / vCISO Services

Full CISO leadership on a flexible engagement model. Strategy, governance, and execution without the full-time overhead.

Cybersecurity Risk Assessment

Identify, quantify, and prioritize your organization's cyber risks aligned to NIST, ISO 27001, or custom frameworks.

Ransomware Readiness

Evaluate your defenses, response plans, and recovery posture against ransomware and extortion threats.

Board & Executive Advisory

Translate cyber risk into board-ready capital decisions. Prepare your leadership team to govern security as a business asset.

Incident Response Consulting

Plan, test, and respond. From tabletop exercises to live incident containment and post-incident review.

Security Program Transformation

Build or mature your enterprise security program from the ground up — strategy, team, tools, and culture.

Experience

18+ Years of Security Leadership

Leon Capital Group

Feb 2025 – Present

Chief Information Security Officer (CISO) · Dallas, TX

  • Built enterprise-wide cybersecurity, data privacy, and AI security program across financial services, healthcare, and real estate
  • Protected 9,000+ employees and 12M+ customers annually
  • Embedded SEC-, FINRA-, and SOX-aligned controls enabling RIA and Broker-Dealer regulatory licenses

Trellix

Aug 2024 – Jan 2025

Deputy Chief Information Security Officer · Plano, TX

  • Led global information security strategy aligned to NIST 800-53 CSF and HITRUST CSF
  • Conducted internal supply chain security assessment across all software development environments
  • Oversaw SOC performance and managed rigorous vendor risk assessment process

Mitek Systems

Jan 2024 – Aug 2024

Interim Chief Information Security Officer · San Diego, CA

  • Built security program from zero for a publicly traded global fintech specialising in AI and biometrics
  • Positioned security as a core market differentiator supporting M&A-driven growth strategy
  • Centralised critical security policies across global entities

U.S. Bank

May 2022 – Dec 2023

Senior Vice President · Minneapolis, MN

  • Achieved #1 BitSight cybersecurity rating among all peer banks
  • Delivered $3M+ in annual savings via pen testing program redesign
  • Drove full lifecycle automation of vulnerability management across 14 teams using AI and machine learning

The Depository Trust & Clearing Corporation (DTCC)

Apr 2021 – May 2022

Executive Director, Global Security Engineering & Operations · Coppell, TX

  • Migrated enterprise to CrowdStrike ETDR for advanced endpoint threat detection and response
  • Established the first unified Security Operations portal for self-service and continuous improvement analytics
  • Embedded security-first culture across 12 engineering squads

Kubota North America

Nov 2017 – Mar 2021

CISO — Information Security & Privacy · Grapevine, TX

  • Architected Azure hub/spoke security model for all North America subsidiaries
  • Implemented ForgeRock IAM platform for enterprise-wide SSO and access management
  • Launched DevSecOps tools across CI/CD pipeline including RASP and dynamic code analysis

American Airlines

Aug 2012 – Dec 2017

Senior Security Manager · Dallas/Fort Worth

  • Led critical enterprise security hardening initiatives across corporate infrastructure
  • Implemented Deep Security Manager (DSM) host-based firewall management
  • Drove Skybox Firewall Management system for comprehensive network security governance

Credentials

Certifications & Recognition

Certifications

CISSP CISM C|CISO CDPSE ITIL Foundation Certified Scrum Master

Recognition & Affiliations

2026 Dallas ORBIE CISO of the Year Finalist
Top recognition for technology leadership in Dallas
ISACA Member · ISC² Member · InfraGard Member
Active member of leading international security organisations
OneTrust Privacy Connect — Chapter Chair
Dallas chapter leadership, 2020–2021
Education · University of Texas at Austin · Collin County Community College · Brookhaven Community College

Get In Touch

Let's Connect

Hiring for a CISO role?

Let's talk about the opportunity.

Whether you're looking for a full-time CISO, an interim leader, or a board-level security advisor — Charles brings 18+ years of proven executive leadership.

Need vCISO or advisory services?

Start the conversation.

Typical response within 24 hours.