Andrew Nowlin

Andrew Nowlin

Cybersecurity and Information Technology Leader
Oklahoma City, Oklahoma· 10+ years experience

About Me

Andrew Nowlin is a cybersecurity and technology leader with over a decade of experience building resilient security operations and IT environments across corporate, nonprofit, and consulting settings.

His track record spans hands-on and strategic work: leading incident response teams to cut Mean Time to Response by over 60%, managing 300+ security controls under SOC2, HITRUST, and CMMC frameworks, and earlier deploying SIEM/EDR solutions that reduced incident response times by 50%. As Director of Information Technology & Security for a global anti-trafficking nonprofit, he built an entirely volunteer-staffed IT and security function from the ground up that supported the rescue and recovery of more than 250 human trafficking victims, missing persons, and runaways. He has also led global infrastructure initiatives, including a five-country firewall refresh, AWS and on-premise cost optimizations that cut operational spend by 20%, and cybersecurity training programs that raised phishing resilience by over 50% across 1,000+ employees.

Andrew's expertise covers incident response and crisis management, regulatory compliance (SOC2, GDPR, CMMC, HITRUST), cloud security across AWS, Azure, and Google Cloud, zero trust architecture, and security team leadership. He holds an A.A.S. in IT-Network Engineering and continues to combine technical depth with organizational governance and cross-functional leadership.

Andrew is now seeking to bring this blend of hands-on security operations leadership and strategic compliance expertise into a director-level Information Security or IT Security role, where he can drive enterprise-wide risk reduction and build high-performing security teams from within an organization.

Professional Experience

Jan 2025 — Present

Lead, Security Operations (Director-Level Scope)

Trace3

Reporting directly to the CISO, leads internal security operations to strengthen Trace3's cyber defense capabilities and overall risk posture, functioning at a director level within the security organization.

60%reduction in Mean Time to Response
300+security controls owned
25%risk reduction target
  • Direct internal incident response efforts, including investigation, remediation, and recovery, reducing Mean Time to Response (MTTR) by over 60%
  • Own and refine 300+ security controls across SOC2 and CMMC frameworks (plus, historically, HITRUST), ensuring continuous compliance readiness
  • Lead 10+ concurrent initiatives to advance the organization's cybersecurity maturity and adapt to evolving threat landscapes
  • Set and drive toward a 25% measurable risk reduction target across the security program
  • Operate as a key advisor to the CISO and other executive leaders on operational security strategy and risk prioritization as part of the Board Risk Committee
  • Leverage a modern security stack including CrowdStrike, Splunk, Tenable, Microsoft Sentinel, Microsoft Purview, Abnormal.AI, and Valimail to drive detection, vulnerability management, and email security initiatives
  • Designed and built a self-maintaining AI agent cluster in Azure AI Foundry, leveraging GPT models and orchestrated using Hermes — a leading open agent harness — performing automated threat intelligence gathering, vulnerability monitoring, EDR alert triage, and proactive threat hunting (e.g., IOC searches in CrowdStrike and CVE searches in Tenable) driven by MSSP bulletins and threat intel feeds
  • Supported evaluation of multiple AI solutions (ChatGPT, Claude, AskTuring, Glean) for business use, and regularly support security reviews for other applications under consideration
Jun 2021 — Jan 2025

Sr. Engineer – Practice Lead, Incident Prevention & Response

Trace3
50+client organizations supported annually
20+proactive engagements per year
$1Mannual practice revenue
  • Delivered 24/7/365 incident response support and advisory breach coaching services to more than 50 client organizations annually
  • Led 20+ proactive client engagements each year, including tabletop exercises, threat intelligence workshops, and business risk assessments
  • Coordinated forensic analysis and reporting with internal teams, partner engineers, legal counsel, and law enforcement to identify root causes and implement long-term corrective actions
  • Provided post-incident advisory guidance to strengthen clients' long-term cybersecurity posture
  • Supported sales engineering efforts for threat intelligence and MSSP services, directly contributing $1,000,000 in annual practice revenue
Sep 2020 — Dec 2022

Director, Information Technology & Security

The National Child Protection Task Force
250+victims, missing persons, and runaways recovered
$500Kin donated software and services managed
  • Built and led the organization's entirely volunteer-staffed IT and Security Department, overseeing support, operations, development, data, and security teams (including self)
  • Developed and executed enterprise technology strategy, including policy development and compliance initiatives, aligned with organizational goals
  • Built the technology budget and managed vendor and software relationships, leveraging over $500,000 in donated software and services
  • Supported a mission ultimately contributing to the rescue/recovery of more than 250 human trafficking victims, missing persons, and runaways
Jun 2019 — Jun 2021

Systems & Security Engineer

CFS Brands
1,000+employees trained in security awareness
50%improvement in phishing resilience
5countries and 6 US states in the network refresh
  • Served as the sole security resource during a corporate spin-off, maintaining continuity of existing security tooling under new licensing agreements while decoupling infrastructure from the former parent company
  • Managed company-wide cybersecurity training, training over 1,000 employees through annual awareness programs and simulated phishing exercises, improving phishing resilience by over 50%
  • Led a business-wide firewall refresh and network upgrades across five countries and 6 US states, improving network reliability by more than 20%
  • Directed network architecture, configuration, and cybersecurity integration for newly acquired companies in the US, Mexico, Belgium, France, and Spain
Jun 2017 — Jun 2019

Systems Administrator

CFS Brands
99.9%uptime across US and Mexico sites
25%reduction in ecommerce costs
12+security tools re-licensed and deployed
  • Administered global network and server infrastructure, ensuring 99.9% uptime across US and Mexico sites
  • Designed and deployed a new data center, migrating services from cloud-based to on-premises infrastructure and reducing ecommerce costs by 25%
  • Led proof-of-concept for Rapid7's InsightIDR SIEM/EDR platform, later deployed organization-wide
  • Directed security initiatives following a corporate spin-off, including re-licensing and deploying 12+ essential security tools
Jul 2014 — May 2017

Director of Information Technology

Tate Publishing and Enterprises, LLC
10person team across the US and Philippines
$150Kannual technology spend managed
20%reduction in operational costs
  • Restructured IT operations from an ad-hoc, shared-mailbox support model into a distributed, 10-person team spanning the US and the Philippines, split into a dedicated support function and a larger development team
  • Managed technology spend against an informal, month-to-month budget of approximately $150K annually, prioritizing infrastructure and tooling needs without a formal budget process
  • Re-engineered AWS cloud infrastructure, migrating select services on-premises to reduce operational costs by 20%
  • Designed and implemented a corporate cybersecurity program, including SIEM deployment and IT policy development, supporting the organization for 3 years until its closure

Skills

Leadership & Organizational

Team Leadership & Development Strategic Planning & Decision-Making Cross-Functional Collaboration Executive & Board-Level Communication Change Management Mentorship & Talent Development

Compliance & Risk

SOC2 CMMC HITRUST GDPR Risk Assessment & Mitigation Incident Response & Crisis Management Business Continuity & Disaster Recovery Incident Command System (ICS) Management

Technical & Security Operations

Cybersecurity Strategy & Threat Intelligence Cloud Security (AWS, Azure, Google Cloud) SIEM Administration & Threat Hunting Identity and Access Management (IAM) Network Security & Vulnerability Management Zero Trust Architecture

Platforms & Tooling

CrowdStrike Splunk Tenable Microsoft Sentinel Microsoft Purview EntraID Abnormal.AI Valimail OpenCTI OSForensics AI-Augmented Security Operations (Copilot, Claude, Glean, Azure AI Foundry, Hermes, GPT models)

Volunteer & Community

Apr 2026 — Present
Treasurer & Board Member Logan County ARES (Amateur Radio Emergency Service)
Jun 2026 — Present
Public Service Events Coordinator Edmond Amateur Radio Society
Aug 2020 — Present
Co-Founder & Board Member conINT
Nov 2020 — Present
Member InfraGard Oklahoma
May 2021 — Present
Threat Intelligence Contributor Pulsedive Community
Feb 2021 — Present
Community Volunteer Oklahoma Medical Reserve Corps
Apr 2020 — Present
Volunteer / Community Participant COVID-19 Cyber Threat Coalition

Education

August 2010
A.A.S., Information Technology — Network Engineering Northern Oklahoma College

Certifications

OSForensics Triage Certification (OSFTC) Amateur Radio Operator (Technician), FCC Fortinet NSE 2 — Network Security Associate VMware Certified Associate — Data Center Virtualization
Connect on LinkedIn © 2026 Andrew Nowlin