Travis Morrow
@travismorrow
Chief Information Security Officer building AI-first security operations and exploit-reachability systems from zero.
What I'm looking for
I’m a CISO who builds the security function from zero and runs it AI-first, with agentic SOC automation and exploit-reachability systems live in production. I’ve spent 20 years across offensive, cloud, and security operations—always focused on measurable risk reduction.
At Digibee, I founded security and IT for a global iPaaS platform—owning product security, SecOps, GRC, identity, and corporate IT. I architected agentic tier-1 and tier-2 SOC automation that enriches alerts, runs first-response playbooks autonomously, and escalates only validated incidents.
I also built AI-powered exploit-reachability analysis that filters thousands of theoretical CVEs down to what’s actually exploitable in production, clearing false-positive noise from engineering backlogs. I drove secure-by-design practices to reduce critical and high runtime vulnerabilities by 80%.
Previously at Okta, I scaled the security organization from 2 to 22 and led offensive and cloud security from Series B through IPO. I led the OffSec first-responder investigation during the Lapsus$ incident, briefed the C-suite, and served as a technical SME for major acquisition security diligence.
Experience
Work history, roles, and key accomplishments
CISO -- Security & IT
Digibee
Jan 2023 - Present (3 years 6 months)
Founded Digibee’s security and IT function from zero, covering product security, SecOps, GRC, identity, and corporate IT. Architected AI-first SOC automation and exploit-reachability analysis and drove secure-by-design improvements across cloud operations.
Senior Director Offensive & Cloud
Okta
Jan 2019 - Jan 2023 (4 years)
Led offensive and cloud security for a cloud-native identity platform, embedding product security across the software lifecycle and running red-team operations, bug bounty, and threat intelligence. Scaled the security organization and led critical incident response for the Lapsus$ identity breach while supporting compliance validation across FedRAMP, GovCloud, NIST, PCI, and ISO 27001.
Principal Offensive Security Engineer
Okta
Jan 2014 - Jan 2019 (5 years)
Directed web and mobile penetration testing focused on Okta’s identity core, including APIs, browser plugins, IWA SSO, and SAML/OAuth authentication. Built multi-region, multi-cloud secrets management and led AWS cloud security architecture reviews, while automating vulnerability management and compliance reporting for regulated programs.
Information Security Engineer
Amazon
Jan 2012 - Jan 2014 (2 years)
Assessed security across cloud, application, and infrastructure and led penetration testing and red-of-red reviews covering payments and the AWS-Amazon shared-service boundary. Reduced high and medium vulnerability backlog and supported compliance through automated external testing and evidence collection.
Information Security Engineer
Booz Allen Hamilton
Jan 2006 - Jan 2012 (6 years)
Provided security engineering and operational leadership on engagements advising DoD, federal civil, and commercial customers on penetration testing, threat hunting, and enterprise vulnerability programs. Modernized SIEM and supporting tooling to reduce false positives and remediated critical IG findings through layered hardening, patching, DLP, and reporting.
Education
Degrees, certifications, and relevant coursework
Virginia Tech
Bachelor of Science, Computer Science
Earned a Bachelor of Science in Computer Science from Virginia Tech.
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Travis?
You can contact Travis and 90k+ other talented remote workers on Himalayas.
Message TravisGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
