loading...

I'm Andrew Nowlin

Proven Cybersecurity and Information Technology Leader

Experienced Incident Responder and Case Manager

Vetarn Security Analyst and Engineer

Skilled Enterprise Infrastructure Architect

Trusted Critical Infrastructure Security Specialist

Dedicated Cybersecurity Practitioner

About Me

Andrew is a cybersecurity and technology leader with 10+ years of experience driving operational excellence and resilience across IT and security functions. Currently serving in a director-level security operations capacity — reporting directly to the CISO and contributing to Board Risk Committee initiatives — he has built and led security programs spanning incident response, regulatory compliance, and enterprise technology strategy. His background includes both internal security leadership roles and consultative incident response advisory work, giving him a well-rounded perspective on defending organizations from the inside and guiding them through crisis from the outside. Andrew's approach favors building strong teams and surrounding himself with deep technical experts, prioritizing strategic leadership and organizational resilience over individual technical specialization.

  • Name: Andrew Nowlin
  • Location: Oklahoma City, OK
  • Experience: 10+ years
Leadership & Organizational Skills
  • Team Leadership & Development
  • Strategic Planning & Decision-Making
  • Cross-Functional Collaboration
  • Organizational Governance & Policy Development
  • Executive & Board-Level Communication
  • Change Management & Adaptability
  • Mentorship & Talent Development
Regulatory Compliance & Risk
  • Regulatory Compliance (SOC2, CMMC, HITRUST)
  • Risk Assessment & Mitigation
  • Incident Response & Crisis Management
  • Business Continuity & Disaster Recovery
  • Incident Command System (ICS) Management
Technical & Security Operations
  • Cybersecurity Strategy & Threat Intelligence
  • Cloud Security (AWS, Azure, Google Cloud)
  • SIEM Administration & Threat Hunting
  • Identity and Access Management (IAM)
  • Network Security & Vulnerability Management
  • Zero Trust Architecture
Professional Experience
January 2025 - Present
Lead, Security Operations (Director-Level Scope)
Trace3

Reporting directly to the CISO, I lead internal security operations to strengthen Trace3's cyber defense capabilities and overall risk posture, functioning at a director level within the security organization.

  • Direct internal incident response efforts, including investigation, remediation, and recovery, reducing Mean Time to Response (MTTR) by over 60%
  • Own and refine 300+ security controls across SOC2 and CMMC frameworks (plus, historically, HITRUST), ensuring continuous compliance readiness
  • Lead 10+ concurrent initiatives to advance the organization's cybersecurity maturity and adapt to evolving threat landscapes
  • Coordinate forensic analysis and reporting to identify root causes and implement long-term corrective actions
  • Set and drive toward a 25% measurable risk reduction target across the security program
  • Operate as a key advisor to the CISO and other executive leaders on operational security strategy and risk prioritization as part of the Board Risk Committee
June 2021 - January 2025
Sr. Engineer – Practice Lead, Incident Prevention & Response
Trace3

Serving as a client-facing incident response and advisory lead, I supported organizations before, during, and after security incidents, combining hands-on breach response with proactive risk reduction programs.

  • Delivered 24/7/365 incident response support and advisory breach coaching services to more than 50 client organizations annually
  • Led 20+ proactive client engagements each year, including tabletop exercises, threat intelligence workshops, and business risk assessments
  • Coordinated with internal and partner engineering teams on forensic investigations, remediation, and recovery efforts
  • Provided post-incident advisory guidance to strengthen clients' long-term cybersecurity posture
  • Supported sales engineering efforts for threat intelligence and MSSP services, directly contributing $1,000,000 in annual practice revenue
September 2020 - January 2023
Director, Information Technology & Security
The National Child Protection Task Force

Leading the IT and Security function for a global nonprofit, I built the department from the ground up, aligning technology strategy with the organization's mission while ensuring regulatory compliance across a growing, international operation.

  • Built and led the organization's IT and Security Department, overseeing support, operations, development, data, and security teams
  • Developed and executed enterprise technology strategy aligned with organizational goals
  • Managed compliance initiatives, policy development, and successful completion of audits across 3 regulatory frameworks
  • Built the technology budget and managed vendor and software relationships, leveraging over $500,000 in donated services
  • Supported a mission ultimately contributing to the rescue/recovery of more than 250 human trafficking victims, missing persons, and runaways
January 2020 - June 2021
Systems & Security Engineer
CFS Brands

In this role, I owned the organization's network security architecture and workforce cybersecurity readiness, supporting a rapidly expanding international footprint following multiple acquisitions.

  • Managed company-wide cybersecurity training, including annual awareness programs and simulated phishing exercises, improving phishing resilience by over 50%
  • Led a business-wide firewall refresh and network upgrades across five countries, improving network reliability by more than 20%
  • Directed network architecture, configuration, and cybersecurity integration for newly acquired companies in the US, Mexico, Belgium, France, and Spain
June 2017 - December 2019
Systems Administrator
CFS Brands

I administered the organization's global infrastructure, ensuring reliable operations across international sites while leading a transition to a modernized, in-house data center.

  • Administered global network and server infrastructure, ensuring 99.9% uptime across US and Mexico sites
  • Designed and deployed a new data center, migrating services from cloud-based to on-premises infrastructure and reducing ecommerce costs by 25%
  • Led proof-of-concept for Rapid7's InsightIDR SIEM/EDR platform, later deployed organization-wide
  • Directed security initiatives following a corporate spin-off, including re-licensing and deploying 12+ essential security tools
July 2014 - May 2017
Director of Information Technology
Tate Publishing and Enterprises, LLC

I led a from-the-ground-up restructuring of the IT department, building infrastructure, support, and development functions while managing a distributed international team through the company's final years of operation.

  • Restructured an unstructured IT department, building out help desk, infrastructure, and development functions from the ground up
  • Managed a 15-person distributed team across the US and Philippines, including help desk staff and custom ERP developers
  • Re-engineered AWS cloud infrastructure, migrating select services on-premises to reduce operational costs by 20%
  • Designed and implemented a corporate cybersecurity program, including SIEM deployment and IT policy development, supporting the organization for 3 years until its closure
Volunteering & Community Involvement
August 2020 - Present
Board Member/Co-Founder
conINT
November 2020 - Present
Member
InfraGard Oklahoma Members Alliance
April 2020 - Present
Volunteer/Community Participant
COVID-19 Cyber Threat Coalition
May 2021 - Present
Threat Intelligence Contributor
Pulsedive Community
February 2021 - Present
Community Volunteer
Oklahoma Medical Reserve Corps
Education
Class Of 2010
A.A.S. Information Technology - Network Engineering
Northern Oklahoma College
Class Of 2009
High School Diploma
Ponca City Sr. High School