Banking
10 CISOs in Banking
These ten executives hold or have held the chief information security officer title at banks. A reader can learn how bank security leaders build information security programs, work with risk and audit functions, and report on cyber risk to senior management and boards.
Professionals to explore
01—10Anthony Scarola
LinkedInExperience: EVP, Chief Information Security Officer · Apple Bank
EVP, Chief Information Security Officer at Apple Bank since July 2025, where his profile says he serves as the enterprise security executive for a $19B regional bank, leading a 10-person information security team across 12 program domains and overseeing the security budget and a portfolio of security technology vendors. He was previously SVP, IT GRC Director at Apple Bank (2020–2025).
Emrah Duran
LinkedInExperience: Chief Information Security Officer (CISO) & Head of Information Security · Türkiye İş Bankası
Chief Information Security Officer (CISO) & Head of Information Security at Türkiye İş Bankası since April 2024; his profile describes it as the largest private bank of Turkiye. His earlier roles at the bank include Information Security & IS Risk Management Unit Manager (2022–2024), Information Security Manager (2017–2021) and Senior Information Security Architect (2014–2017).
Hazel Diez Castaño
LinkedInExperience: Global Chief Information Security Officer · Santander
Global Chief Information Security Officer at Santander since June 2023. At Santander she was previously Global Head of Cyber GRC & CISO Central Services (2021–2023) and CISO Central Services & Head of IT SOX (2020–2021), and she was Chief Information Security Officer at Santander Digital Services (2018–2021). Before Santander she was Global CISO at Dufry (2017–2018).
James OBrien, CISSP, CISA
LinkedInExperience: Chief Information Security Officer · Banc of California
Chief Information Security Officer at Banc of California since December 2025. He was previously Deputy Chief Information Security Officer at First Republic (2013–2025) and Chief Information Security Officer at East West Bank (2007–2013), after operations and program management roles at the Federal Home Loan Bank of Chicago (2000–2007).
Jeffrey Evans
LinkedInExperience: Chief Information Security Officer · Bank OZK
Chief Information Security Officer at Bank OZK since June 2022, after serving there as Director of Information Security (2021–2022), Information Systems Security Officer (2019–2021) and Third Party Risk Officer (2018–2019). His profile says he is responsible for enterprise-wide cybersecurity, cyber fraud risk, data privacy, third-party risk and AI governance programs for a $40B+ publicly traded financial institution, reporting to the Chief Risk Officer.
Kristopher Fador
LinkedInExperience: Chief Information Security Officer · Bank of America
Chief Information Security Officer at Bank of America since April 2023. Before that he was Deputy CISO and Head of Cyber Security Operations (2022–2023), Cyber Security Defense Executive (2019–2022) and Business Information Security Officer (2014–2019) at Bank of America. His profile describes responsibility for leading the bank's Cyber Security Defense function and lists membership on the FS-ISAC Board of Directors.
Lance Murray, CISA, CRISC
LinkedInExperience: Chief Information Security Officer · First Financial Bank
Chief Information Security Officer at First Financial Bank since July 2024. He was earlier Chief Information Security Officer at Fifth Third Bank (2009–2013) and later Senior Vice President, Technology & Security Business Controls there (2015–2017), then held security and technology risk oversight leadership roles at U.S. Bank from 2017 to 2023.
Nick Schappacher
LinkedInExperience: Chief Information Security Officer · KeyBank
Chief Information Security Officer at KeyBank since April 2026. His earlier KeyBank roles include SVP & Deputy CISO - Head of Corporate Information Security (2023–2026), SVP & Deputy CISO - Head of Information Security Governance (2021–2023) and SVP & Senior Director - Head of Cybersecurity and Technology Risk Oversight (2016–2021).
Richard White, PhD
LinkedInExperience: SVP & Chief Information Security Officer · Flushing Bank
SVP & Chief Information Security Officer at Flushing Bank since August 2018, a role in which the profile says he oversees and coordinates security efforts across the enterprise. He was previously Managing Director at Barracuda SKOUT Managed XDR (2013–2018) and Chief Information Security Officer at the US Capitol Police (2009–2013).
Vivin Varghese
LinkedInExperience: EVP, Chief Information Security Officer · Customers Bank
Former EVP, Chief Information Security Officer at Customers Bank (2022–2024), where he also served as SVP, Deputy CISO (2021–2022) and Vice President of Digital Compliance and Architecture (2019–2024). He has been Chief Information Security Officer at Provident Bank since August 2024. His profile cites over 16 years of cybersecurity experience across financial services, government and higher education.
Choose the right perspective
Match the bank's size and structure to yours, since a global group CISO and a regional bank CISO manage very different teams, budgets and regulators. Look at the path each person took to the role, such as security operations, governance and risk, or architecture, and pick the one closest to the problem you need to solve.
Questions to take into the conversation
- 01How do you set security priorities and budget each year, and how do you explain those choices to the board and regulators?
- 02How is your security organization split between operations, governance and risk, and what would you change?
- 03How do you assess and manage security risk from third-party vendors and fintech partners?
About this directory
This is a professional research starting point based on business profile data retrieved on . Titles and companies reflect that source snapshot and may describe past or present roles. Check the linked profiles for current details. Inclusion does not imply Instant Expert membership or availability.
Request a correction or removal