Brett Coon
Director of Information Security @ McGuireWoods LLP
About
I am a Carnegie Mellon-certified Chief Information Security Officer (CISO) and trusted enterprise risk and security strategy partner to senior leadership. My work centers on helping organizations make informed, business-aligned decisions about cyber risk, security investment, and resilience—particularly in regulated and professional services environments. I have led enterprise information security and cyber risk programs across global organizations, advising executive leadership on risk posture, prioritizing security investments aligned with business objectives and risk appetite, and strengthening governance and assurance programs. I regularly partner with senior leaders during periods of change, regulatory scrutiny, and elevated threat activity. I have served as the head of incident response, leading executive coordination and decision-making during active security events, with a focus on balancing risk, business continuity, and client impact. My background spans enterprise infrastructure, security operations, architecture and engineering, and executive risk ownership—allowing me to approach cybersecurity as an enterprise resilience and governance function, not just a technical discipline.
United States
Charlotte Metro
Legal Services
AI Prompting, Risk Management, Crisis Communications, Information Security Strategy, Executive-level Communication, Servers, Disaster Recovery, SDLC, Virtualization, System Deployment, Microsoft SQL Server, IT Management, Computer Security, High Availability, Routers, Process Improvement, Network Security, VPN, Service Delivery, Strategy
Experience

Director of Information Security
• Transformed the firm’s enterprise information security and cyber risk program, advising executive leadership and managing partners on risk posture, investment priorities, and regulatory expectations. • Established a firm-wide, risk-based security strategy across governance, identity and access management, vulnerability management, and security operations aligned with business objectives and risk appetite. • Sustained ISO 27001 certification across all critical applications, providing ongoing assurance to clients and regulators and reinforcing trust in the firm’s security posture. • Served as the firm’s head of incident response, leading security incident response and executive coordination during active threats. • Prioritized and implemented enterprise security investments across email, data protection, endpoint security, identity and access management, and security monitoring to reduce firm-wide risk exposure. • Matured the vulnerability management program by identifying systemic patching and configuration gaps and improving accountability for remediation across core business systems. • Revised and standardized all information security policies by aligning governance with industry standards and formalizing review and approval processes to improve consistency and oversight. • Guided cyber risk assessment and decision-making for major business initiatives and application implementations prior to deployment to ensure risks were addressed or formally accepted. • Oversaw outsourced security operations and vendors supporting the firm’s global operations, improving service level performance and alignment with firm risk expectations. • Directed firm-wide security awareness and training programs, including new hire education, annual training, phishing simulations, and threat communications to strengthen security culture. • Delivered regular executive briefings on security strategy, risk posture, KPIs, and emerging threats to support informed leadership decision-making.

Director Security Solutions Architecture and Engineering
• Directed enterprise security architecture and engineering teams responsible for endpoint and network security across on-premises and cloud environments supporting regulated and client-facing platforms. • Partnered with senior technology and risk leaders to align security architecture decisions with enterprise risk appetite and strategic initiatives. • Defined and evolved security architecture standards aligned with PCI DSS, FFIEC, and NIST CSF to improve consistency and regulatory readiness across the enterprise. • Guided security investment and design decisions for endpoint and network security programs to reduce risk exposure and support business scalability. • Established and guided Purple Team collaboration, coordinating remediation of vulnerability assessments, penetration testing findings, and MITRE ATT&CK-aligned threats to improve defensive readiness. • Architected a centralized cloud automation solution for security policy compliance management to strengthen governance and operational efficiency. • Conducted governance, risk, and regulatory assessments, advising leadership on risk treatment decisions including acceptance, mitigation, and transfer of residual risk. • Cultivated strategic vendor partnerships, influencing contract renewals and service alignment to optimize security capabilities and cost efficiency.

Senior Manager Information Security Operations and Engineering
• Oversaw global information security operations and engineering teams responsible for protecting enterprise endpoints and core business systems. • Restructured security operations into an engineering-led, 24x7x365 model, strengthening incident response, escalation, and operational resilience. • Delivered enhanced insider threat visibility and data protection across web, network, print, and email channels to support data privacy and regulatory requirements. • Implemented database access monitoring to improve oversight and protection of regulated and sensitive data. • Integrated security programs across multiple major acquisitions, establishing consistent controls and governance in newly acquired environments.

Senior Manager Information Security
Hickory, NC
• Directed enterprise information security architecture and security operations supporting manufacturing and corporate environments, responsible for endpoint protection, perimeter security, incident response, vulnerability management, and security operations across core business systems. • Developed and executed 12-, 24-, and 36-month security strategies aligned with business priorities and risk appetite, improving consistency, resilience, and operational readiness during organizational and technology change.

IT Security Manager Information Security Endpoint Controls
• Managed global endpoint security operations, including malware protection, application control, and incident response capabilities. • Established the organization’s first dedicated information security tools team, improving control deployment, governance, and operational consistency. • Reduced exposure from unapproved software through structured allow-listing and control standardization. • Reinforced incident response processes and coordination across IT and security teams.

IT Manager Information Systems and Infrastructure
Charlotte, NC
• Directed enterprise IT infrastructure strategy covering architecture, engineering, operations, availability, security, and recovery readiness. • Developed multi-year technology roadmaps supporting operating and capital investment planning. • Managed geographically distributed teams responsible for enterprise computing platforms supporting financial institution clients. • Established business continuity and disaster recovery capabilities supporting enterprise resilience and service availability. • Improved cost efficiency and operational stability through infrastructure modernization and organizational alignment.

IT Manager Distributed Systems
Managed all IT infrastructure hardware decisions and planning for 1,000 servers, 6 mainframes for 3000+ financial institutions, with 8 professionals in 3 locations and a $10 million operating and capital budget. • Decreased annual budget by almost 20% from $12 million to $10 million by server virtualization of 85%, power reduction, and team realignment. • Sustained a 99.99% availability while revamping data center support from 250 to 1200 servers. • Developed business continuity and disaster recovery solutions for resiliency of 50+ applications with recovery time of the full environment in less than 24 hours.

IT Manager Open Systems
Supervised availability and recoverability of 250 servers supporting 2000+ financial institutions using current and emerging technologies with 3 analysts and an $8 million operating and capital budget. • Deployed log management across environment, improving event management by 100%. • Implemented automated operating system patch management, providing better than 95% compliance. • Consolidated 3 data centers into a strategic facility, decreasing corporate capital and operational expenses by $1.75 million annually.
Brett Coon's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.






