Key People
Cyber M&A is a people business: the warm-intro path beats the cold pitch. This relationship map organizes the human graph by role and decision power, cross-referenced against the 8,234 LinkedIn contacts for warm-intro pathfinding (a core Cyber Ecosystem Graph capability).
The map lists roles and archetypes plus named anchors where they are public and stable. Named executives shift as people move (exec moves are themselves M&A signals); specific individuals are enriched from the LinkedIn graph and CyberDB rather than stored speculatively.
See Key People by Role for the decision-maker map by role (authority vs. priority), named anchors per role, and warm-intro economics.
Decision-maker roles by deal relevance
| Role | Where they sit | Why they matter | relevance |
|---|---|---|---|
| CEO (vendor) | Target & buyer | Final decision on sell or buy | Sell-side: the founder/CEO is the client. Buy-side: the acquirer's CEO sets strategy |
| CFO | Both | Owns valuation, financing, board case | Key in any process |
| CTO / CPO | Both | Product/tech fit & integration | Diligence counterpart |
| CRO / VP Sales | Both | Revenue quality, GTM synergy | Diligence + value story |
| CISO (buyer/customer) | Enterprises, gov | The buyer of security; voice of demand | Validates target's product-market fit; reference network |
| PE Operating Partner | Sponsors | Drives portfolio M&A | Retainer decision-maker for portfolio mandates |
| VC/Growth Partner | Investors | Board influence on exits | Sell-side origination & warm intros |
The personas that matter most to 's three objectives
Notable public figures (stable anchors)
- PE: Orlando Bravo, Seth Boro, Chip Virnig (Thoma Bravo); Robert Smith (Vista); Greg Clark, Hugh Thompson (Crosspoint).
- Vendor CEOs: George Kurtz (CrowdStrike), Nikesh Arora (Palo Alto), Jay Chaudhry (Zscaler), Tomer Weingarten (SentinelOne), Todd McKinnon (Okta). CyberArk was led by Matt Cohen through its acquisition by Palo Alto Networks, which completed in February 2026, following the long tenure of founder Udi Mokady.
- Investors: Richard Seewald (Evolution), Alberto Yépez/Don Dixon (Forgepoint), Dave DeWalt (NightDragon), Yoav Leitersdorf (YL Ventures).
(Names are illustrative anchors; the LinkedIn graph is the live source of truth for current titles and moves.)
Recent executive moves (rolling)
| Date | Person | Move | Why it matters |
|---|---|---|---|
| Sep 2026 | Yossi Dagan | Appointed Chief Financial Officer, Zero Networks | The finance seat, filled at a venture-backed microsegmentation vendor. A first or replacement CFO is the appointment that most reliably precedes a capital event, because the work it exists to do — closing the books to a standard an outside party will diligence, and building the forecast that supports a price — is work a company does not need until it intends to raise, sell or be bought. It is a weaker signal than a corporate-development hire, which has no purpose other than acquiring, and the two should not be read as equivalent. Zero Networks sells network microsegmentation and identity-segmentation, a sub-segment with strategic buyers in both the SASE and identity camps (03d, 03a). No process is implied and none is reported |
| Sep 2026 | Brian Levey; Puja Jaspal | Appointed Chief Legal Officer and Chief People Officer, Proofpoint (Thoma Bravo-owned) | Two corporate-function seats filled at the same sponsor-owned asset in one cycle, alongside the SOC Analyst Agent shipped out of the OpenAI Daybreak Defense Network on Sep 3 (20). A legal chief and a people chief are integration and transaction infrastructure rather than growth hires; at a platform that has acquired repeatedly under Thoma Bravo they are consistent with continued buy-and-build, and also with preparing a larger exit. Both readings are available and the appointments do not settle between them (06, 03j) |
| Sep 1 2026 | Chris Jones (25+ years across SaaS and the US federal and intelligence communities; most recently Deputy CISO at Cisco, leading cybersecurity strategy for a network platform organisation of more than $10B in revenue; earlier CLEAR and Nike; founded the FBI's Cyber Profiling Program) and Dan Schoenbaum (30+ years in go-to-market and partnership leadership; from Hive Pro, CMO and head of technology partnerships; four years at Team Cymru building partner programmes with Google, Microsoft, Palo Alto Networks and ServiceNow; earlier President and COO of RiskIQ, acquired by Microsoft) | Appointed Chief Trust & Security Officer and Senior Vice President of Business Development respectively at Axonius | A late-stage venture-backed vendor installing the two functions that enterprise and federal buyers audit. A Chief Trust & Security Officer drawn from a hyperscale-adjacent deputy-CISO seat with an intelligence-community background is a public-sector and regulated-enterprise credential, and the business-development seat is a technology-partnership mandate rather than a corporate-development one — the appointee's record is alliances and go-to-market, not M&A. Recorded as such: this is not the Head-of-Corp-Dev appointment class tracked below, and it should not be counted as one. What it does indicate is the configuration a cyber-asset-management platform assembles when it is preparing to sell into procurement organisations that diligence the vendor's own posture, which historically precedes either a growth round or a process. Axonius sits in the exposure-management and asset-intelligence lane on 03k. (GlobeNewswire, Sep 1 2026) |
| Sep 2026 | Tom Bonos; Sean Forkan | Appointed Chief Revenue Officer, Sumo Logic and Chief Revenue Officer, Optiv respectively | Two revenue seats filled at sponsor-owned assets in the same cycle. Sumo Logic was taken private by Francisco Partners in 2023 and competes in the observability-adjacent SecOps lane on 03e and 42a; Optiv is the KKR-held security solutions and services integrator on 05b and 04d. A CRO change at a sponsor-held asset is a commercial-plan signal rather than a transaction signal on its own, and neither is treated here as a trigger event; both are relevant as hold-period datapoints on assets already carried. (SecurityWeek People on the Move) |
| Aug 24 2026 | David Pieterse (ex-Chief Revenue Officer, Recorded Future, through its acquisition by Mastercard; ex-CRO Snow Software, through its acquisition by Flexera; earlier SVP Global Revenue, Kong) and David Soto (25+ years; most recently Head of Infrastructure Security at Amazon, covering 4,000+ sites in 30 countries; earlier Check Point, Optiv, Pacific Life) | Appointed Chief Operating Officer — Go-To-Market and Chief Information Security Officer respectively at Trellix | Commercial-leadership rebuild at a sponsor-owned platform, and a buy-side trigger event. Trellix is the McAfee Enterprise/FireEye combination held by a financial sponsor, and installing a dedicated GTM operating officer — a seat distinct from a CRO — signals a revenue-architecture change rather than a replacement hire. Pieterse's two most recent revenue mandates each ran to a sale, which is the profile sponsors recruit when the value-creation plan runs through commercial re-platforming ahead of an exit. CEO Vishal Rao framed the appointment around an AI-native response to attacker capability, aligning the GTM reset with the platform positioning on 03m. (Trellix, Aug 24 2026) |
| Aug 2026 | Dali Rajic (ex-President and Chief Operating Officer, Wiz, through its $32B acquisition by Google; ex-President and COO, Zscaler; ex-Chief Customer and Revenue Officer, AppDynamics) | Appointed Chief Revenue Officer, OpenAI | The commercial leadership of two of the largest cloud-security scaling stories moves to a frontier AI lab. Rajic ran revenue at Zscaler and Wiz through the periods that produced the sector's two most-cited go-to-market case studies; the destination is not a security company. Read as a market-structure datum rather than a personnel one: enterprise-security GTM expertise is being priced most highly by the labs, which is consistent with the labs' own entry into the cyber value chain on 20e. (OpenAI) |
| Aug 2026 | Vincent Merlin (ex-SVP Global Growth Marketing, Proofpoint, more than a decade; earlier Aveva, RSA Security) | Appointed Chief Marketing Officer, Forcepoint | A second sponsor-owned platform rebuilding its commercial function in the same month, drawing from the largest independent email-security vendor. Forcepoint's government business was separated as Everfox, and the remaining commercial entity competes in data security and SASE (03g, 03d). (Forcepoint) |
| Aug 2026 | Sonu Shankar (previously Strategic Advisor to the Department under the Business Operators for National Defense programme; earlier leadership roles at Phosphorus Cybersecurity, Arctic Wolf and Cisco) | Appointed Principal Deputy Chief Information Officer, U.S. Department of War | Vendor-side operator into the department's CIO office — a commercial-sector path into the seat that shapes enterprise IT and security requirements across the department, relevant to the procurement channels described on 14 and 14c. (DoW CIO) |
| Aug 2026 | Naveen Bhateja (ex-Medidata, Juniper Networks, Amazon, JPMorgan Chase) | Appointed Chief People Officer, HackerOne | A people function built out at a crowdsourced-testing platform whose delivery model rests on a researcher community rather than headcount — the segment under the most direct substitution pressure from autonomous discovery (04f, 04h). (HackerOne) |
| Aug 19 2026 | Mike Durso (ex-Ping Identity, CyberArk, Snyk, VMware) and Clarence Hinton (Chief Strategy & Corporate Development Officer, Everfox; previously Chief Strategy Officer and Head of Corporate Development at CyberArk, SVP Corporate Development at Nuance, strategy and corp dev at BMC; earlier Dell, Bain and Capital One; MBA, Harvard) | Durso appointed Chief Revenue Officer, AppViewX; Hinton joined the AppViewX Board of Directors | A commercial build-out at a machine-identity vendor, and a corp-dev datum that lands on the prospect screen. AppViewX is expanding from certificate lifecycle management, PKI and post-quantum readiness into machine and AI-agent identity — the crypto-agility lane 16 and 16g identify as demand-catalysed by the 2030/2031 federal PQC deadlines, and the lane where Keyfactor now sits with $1B+ of growth capital. Installing a CRO with Ping/CyberArk/Snyk pedigree alongside a board member whose career is M&A is the standard pre-scale configuration. Separately and more usefully for Objective 1: the appointment confirms Everfox — the TPG carve-out on the 27 screen — carries a named Chief Strategy & Corporate Development Officer with a platform-scale M&A record. The role is pre-existing rather than a new hire, so it is not itself a trigger event; it is the mandate-holder to map. (GlobeNewswire, Aug 19 2026 · Security Ledger) |
| Aug 2026 | Seth Robbins (internal promotion, Cycode) | Promoted to President and Chief Revenue Officer, Cycode | Commercial-leadership consolidation at a venture-backed AppSec/ASPM vendor — combining the president and revenue seats in one internal appointment typically precedes a scaling push or a process, and Cycode sits in the sub-segment 03f identifies as under absorption pressure from repository platforms. Objective-1 watch. (SecurityWeek People on the Move) |
| Aug 2026 | Daniel Dubowski | Appointed Senior Vice President and Chief Information Security Officer, Marriott International | Demand-side anchor in a repeat-breach hospitality estate — a new CISO at a group with a long public incident history is a budget-reset signal for identity, data security and third-party risk. (SecurityWeek People on the Move) |
| Aug 2026 | Jordan Avnaim | Appointed Global Chief Information Security Officer, Allied Universal | Physical-security operator installing a global CISO — the convergence lane tracked on 42h; a services business at that scale building in-house cyber leadership is a demand signal for OT/IoT and workforce-identity controls. (SecurityWeek People on the Move) |
| Aug 2026 | Andrew Park | Appointed Chief Information Security Officer, UltraViolet Cyber | A security-services provider appointing its own CISO — relevant chiefly as an assurance credential in a segment where buyers increasingly ask providers to evidence their own posture (04a). (SecurityWeek People on the Move) |
| Jul 2026 | John DeSimone (ex-CEO Nightwing — RTX's Cybersecurity, Intelligence & Services business carved out and sold to Blackstone for ~$1.3B in 2024, rebranded Nightwing) | Appointed Chief Operating Officer, Everfox | Government-cyber operator consolidation: Everfox (the government-security business carved out of Forcepoint) adds a defense-cyber CEO-caliber operator as COO, days after ex-Everfox CEO Sean Berg took the CEO seat at Carlyle's Secturion (see 11, 14). A second senior government-cyber leadership placement in the same orbit firms a repeatable sourcing pattern — carve-out/defense-cyber alumni cycling into sponsor- and platform-CEO/COO seats. (SecurityWeek People on the Move) |
| Jul 2026 | Ron Dovich (4 years as SVP Engineering, Brinqa; earlier engineering leadership in security) | Appointed Chief AI and Automation Officer, Brinqa | AI/automation C-suite creation in a PE-backed risk & compliance platform — signals board-level prioritization of agentic capabilities and automation in GRC/risk-management workloads; a pattern echoed across platforms as vendors position for autonomous-agent integration. Brinqa Objective-1 watch |
| Jul 2026 | Sherrod DeGrippo (two decades in threat intelligence; most recently senior threat-intel leadership at Microsoft; earlier Proofpoint) | Appointed Head of Threat Intelligence, Unit 42, Palo Alto Networks | Marquee threat-intel talent consolidating at the largest platform vendors — Unit 42's research output is a demand-generation and brand asset for PANW's platformization; talent flow from Microsoft to PANW mirrors the platform-vs-platform contest. (MarTech360, Jul 2026) |
| Jun 2026 | Philip Martin (ex-Chief Security Officer, Coinbase — led a 250+ person global security org; earlier Palantir, Amazon) | Appointed Chief Information Security Officer, Uber | Large-enterprise demand-side anchor: a top-tier consumer-platform CISO seat filled from crypto's largest exchange; continues the pattern of high-pedigree CISOs moving between mega-cap digital platforms. (SecurityWeek, Jul 2026) |
| Jul 2026 | Adrian Vallino | Appointed Group CEO, WhiteHawk (effective Jul 1, 2026) | Leadership transition in an incident-response / forensics / managed detection platform — signal worth monitoring for capital/M&A activity. (LinkedIn, WhiteHawk) |
| Jul 2026 | Rupesh Chokshi (ex-Senior VP & General Manager, Application Security, Akamai Technologies; 25+ years networking/cloud/security) | Appointed Executive Vice President, Global Business Head of Network Services, and Chief Technology Officer, Tata Communications | Demand-side signal: Large telco/carrier hardening its security and network infrastructure leadership; ex-Akamai SVP signals enterprise-platform vendor deep experience moving into operator infrastructure. |
| Jul 2026 | Kevin Hanes (ex-CEO Reveal Security; ex-CEO Cybrary; ex-COO 8+ years, Secureworks) | Appointed CEO, Quorum Cyber | Operator-CEO install, and the M&A consequence has since landed. The Secureworks MDR/services background pointed to value creation through acquisition or service-attach; roughly two months later Quorum Cyber announced the acquisition of Ontinue from EQT (announced Sep 16, 2026), an MXDR and agentic-SOC business of over 200 employees — a platform acquisition in the same sub-segment the incoming chief executive had operated in (11, 04b). |
| Jul 2026 | Christopher Porter (10-year CISO tenure at Fannie Mae) | Appointed Global Chief Information Security Officer, Booz Allen Hamilton | Large systems integrator / consultant deepens in-house CISO posture — signals BAH's own security maturity becoming a strategic selling point for federal/agency clients; demand-side anchor. |
| Jul 2026 | Michael Fitch (ex-Executive Director, Cybersecurity & Critical Operations, SAIC) | Appointed Chief Technology Officer for health, state and local sector | Government-adjacent sector deepening cyber leadership — demand-side signal for healthcare/SLTT cybersecurity investment. |
| Jul 2026 | Toby O'Brien (3-year tenure as CFO, Intelsat, culminating in SES sale 2025) | Joined as Chief Financial Officer at cybersecurity company (name not disclosed) | Telecom/satellite-sector CFO transitions into cyber M&A exposure — potential indicator of PE-backed or growth-stage company; value-creation signaling. |
| Jul 2026 | Michael Sikorski (ex-CTO & VP Engineering, Palo Alto Networks; VP Mandiant/FireEye) | Appointed CISO, Coinbase to oversee enterprise security, cyber risk, governance, compliance, IT strategy | Senior fintech demand-side hire: a high-pedigree CISO from the largest pure-play acquirer signals Coinbase's security posture is becoming a board/strategic asset; part of broader crypto-industry hardening against regulatory and threat scrutiny. Demand-side signal; lower M&A relevance but monitors exec flow. |
| Jul 7 2026 | Scott Rachford (GuidePoint veteran of 10+ years; most recently Regional Partner, North Central) | Appointed CEO, GuidePoint Security; founder and former CEO Michael Volk → Executive Chairman | Succession signal at one of the largest US pure-play security services firms (see 04a, 05b): a founder-to-executive-chairman transition with an insider operator promoted to CEO is a pattern worth monitoring at founder-owned services platforms — it often accompanies or precedes a capital event (recapitalization, minority raise, or sale). Objective-1 / sell-side watch. (BusinessWire, Jul 7 2026) |
| Jun 2026 | Robert M. Lee | Stays Dragos CEO; will run runZero + NetRise post-Accenture | Now leads Accenture's combined xOT platform; the integration counterparty for any OT-adjacent process |
| Jun 2026 | Jonathan Trull | Joined Oracle as Global Head of Cyber Defense | Senior demand-side mover; Oracle deepening security posture |
| Jun 2026 | Sean Cassidy | Appointed CISO, Plaid | Fintech demand-side validator |
| Jun 2026 | Ann Barron-DiCamillo | Named EVP & Global CISO, U.S. Bank | Large-enterprise demand-side anchor |
| Jun 3 2026 | Dr. Bartley Richardson (ex-NVIDIA — led engineering for agentic AI, cybersecurity AI & AI infrastructure; built NeMo Agent Toolkit / AI-Q) | Appointed Chief AI and Autonomous Systems Officer, CrowdStrike (announced alongside Q1 FY27 results) | Strategy / "build" signal at the largest pure-play: a net-new C-suite AI seat — created, not vacated — to drive Charlotte AI, the agentic SOC and AI Detection & Response (AIDR) toward "level-5 SOC autonomy." Reads as CrowdStrike doubling down on organic agentic-AI capability (build over buy) and pressing its data-flywheel advantage; the agentic-SOC arms race (cf. 04c, 20) is now a board-level talent contest. Cross-read with the Q1 FY27 print on 23 |
| Jun 1 2026 | Wael Mohamed (ex-CEO Forescout; Operating Partner, Advent International; co-founder Third Brigade → Trend Micro 2009) | Appointed CEO, Rapid7 (board member → CEO), effective immediately; Corey Thomas → Executive Chairman (retains tech/AI/policy vision) | Sell-side / take-private trigger: a PE-operating-partner-pedigree CEO installed at an activist-pressured public pure-play (exposure-mgmt/VM) is the classic prelude to a value-creation reset and/or take-private; Rapid7 is a long-rumored sponsor target. The reset arrived on Aug 7, 2026: a board-approved 2026 Restructuring Plan cutting ~12% of the workforce ($10–11M of charges) alongside a Q2 print showing ARR down 2.0% to $824.0M, with FY26 guided to a 20% non-GAAP operating margin in Q4 and ~$130M of free cash flow — growth traded for margin within ten weeks of the transition. Strong Objective-1 / sell-side watch — see 03k, 12a, 23 |
| Mar 23 2026 | Ed Jennings (ex-CEO Quickbase; ex-COO Mimecast) | Joined Darktrace as President & CEO (Thoma Bravo-owned); succeeded Jill Popelka | Buy-side trigger: seasoned operator-CEO installed at a TB take-private (~£4.3bn / ~$5B, completed Oct 2024); Darktrace's 3rd CEO in ~18 months signals a value-creation reset — bolt-on M&A and a re-platforming around "control layer for enterprise AI" are likely. Classic Objective-1 watch |
→ Signal note: A new Head of Corp Dev hire at a PE-backed platform is a top-tier buy-side trigger event — they have a mandate and a budget and no incumbent advisor. The signal feed should flag these.
Updated 2026-10-04 19:34 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.