Skip to main content
Travis MorrowTM
Open to opportunities

Travis Morrow

@travismorrow

Chief Information Security Officer building AI-first security operations and exploit-reachability systems from zero.

United States
Message

What I'm looking for

I want to build or scale an AI-first security organization: agentic SOC automation, secure-by-design across engineering, and practical exploit-reachability risk reduction—partnering credibly with engineers, architects, and boards.

I’m a CISO who builds the security function from zero and runs it AI-first, with agentic SOC automation and exploit-reachability systems live in production. I’ve spent 20 years across offensive, cloud, and security operations—always focused on measurable risk reduction.

At Digibee, I founded security and IT for a global iPaaS platform—owning product security, SecOps, GRC, identity, and corporate IT. I architected agentic tier-1 and tier-2 SOC automation that enriches alerts, runs first-response playbooks autonomously, and escalates only validated incidents.

I also built AI-powered exploit-reachability analysis that filters thousands of theoretical CVEs down to what’s actually exploitable in production, clearing false-positive noise from engineering backlogs. I drove secure-by-design practices to reduce critical and high runtime vulnerabilities by 80%.

Previously at Okta, I scaled the security organization from 2 to 22 and led offensive and cloud security from Series B through IPO. I led the OffSec first-responder investigation during the Lapsus$ incident, briefed the C-suite, and served as a technical SME for major acquisition security diligence.

Experience

Work history, roles, and key accomplishments

DI
Current

CISO -- Security & IT

Digibee

Jan 2023 - Present (3 years 6 months)

Founded Digibee’s security and IT function from zero, covering product security, SecOps, GRC, identity, and corporate IT. Architected AI-first SOC automation and exploit-reachability analysis and drove secure-by-design improvements across cloud operations.

OK

Senior Director Offensive & Cloud

Okta

Jan 2019 - Jan 2023 (4 years)

Led offensive and cloud security for a cloud-native identity platform, embedding product security across the software lifecycle and running red-team operations, bug bounty, and threat intelligence. Scaled the security organization and led critical incident response for the Lapsus$ identity breach while supporting compliance validation across FedRAMP, GovCloud, NIST, PCI, and ISO 27001.

OK

Principal Offensive Security Engineer

Okta

Jan 2014 - Jan 2019 (5 years)

Directed web and mobile penetration testing focused on Okta’s identity core, including APIs, browser plugins, IWA SSO, and SAML/OAuth authentication. Built multi-region, multi-cloud secrets management and led AWS cloud security architecture reviews, while automating vulnerability management and compliance reporting for regulated programs.

BH

Information Security Engineer

Booz Allen Hamilton

Jan 2006 - Jan 2012 (6 years)

Provided security engineering and operational leadership on engagements advising DoD, federal civil, and commercial customers on penetration testing, threat hunting, and enterprise vulnerability programs. Modernized SIEM and supporting tooling to reduce false positives and remediated critical IG findings through layered hardening, patching, DLP, and reporting.

Education

Degrees, certifications, and relevant coursework

Virginia Tech logoVT

Virginia Tech

Bachelor of Science, Computer Science

Earned a Bachelor of Science in Computer Science from Virginia Tech.

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan