Illustrated portrait of Joe Bernik delivering a keynote on the cyber threat landscape
On stage · the threat landscape, by the numbers

Leading cybersecurity at global banks and Fortune 100 companies.

Teams of 300+ across four continents. Cyber strategy, insider threat, regulatory compliance, supply chain risk, and product innovation with top-tier vendors.

Slow inbox by design — I'll get back to you. Also on Substack.

Animated portrait of Joe Bernik

Hi, I'm Joe

I lead enterprise-wide cybersecurity and risk programs at global financial institutions and Fortune 100 companies, building and transforming security organizations and leading teams of 300+ across four continents. I sit at the intersection of boards, regulators (SEC, OCC, FRB), and engineering teams, aligning technology strategy with business resilience.


Career · 1996 — Present

+ Select any role for the full record

Cyber Executive — Network Security & AI Risk

BNY · 2024 — Present

Lead cybersecurity for networks building AI and manage cyber risk across the enterprise network.

  • Direct cybersecurity for networks building and operating AI systems — model training environments, inference platforms, and the data pipelines feeding them.
  • Manage cyber risk across the enterprise network — perimeter, segmentation, east-west traffic, and identity-aware access for both human and AI agents.
  • Lead cyber engineering for network and server architecture, including AI-driven automation of detection and response workflows.

Lead Cyber Executive

Merrill Lynch / Bank of America · 2019 — 2024

Built and secured the trading environment for market-making and broker-dealing operations.

  • Managed cyber risk for Banking & Markets technology, operations, and front-line units. Led 300 professionals on four continents with a $100M annual budget, reporting into the CIO and Vice Chairman of Markets & Trading.
  • Directed global cyber operations, metrics, incident management, and executive reporting.
  • Built risk-strategy framework covering regulation, attestations, identity governance, and architecture.
  • Strengthened policy governance and transparency, elevating executive decision-making.
  • Modernized security architecture to protect trading, operations, and client platforms.

CTO & Chief Strategist

Intel Security / McAfee · 2016 — 2019

Owned strategy and portfolio for enterprise cybersecurity products at the largest cybersecurity company by revenue, with $8B annual ARR.

  • Advanced cloud security platforms (CASB, SASE) and endpoint protection against ransomware.
  • Championed machine learning and big-data analytics for proactive threat intelligence.
  • Scaled automation through SIEM and SOAR, improving efficiency and time-to-response.
  • Guided corporate development for acquisitions and partnerships.

Managing Director, Cyber Practice

Promontory Financial (IBM) · 2013 — 2016

Founded and scaled the firm's global cybersecurity consulting practice; managed a team of 50.

  • Advised Fortune 100 banks on enterprise cyber strategies and regulatory compliance.
  • Delivered resilient architectures addressing operational and systemic financial risk.
  • Supported cyber due diligence and governance for multinational mergers.

Global Head of Technology Risk, Managing Director

BNY · 2011 — 2013

Led 200+ professionals to establish the firm's global cyber risk program.

  • Directed application security, access control, and risk-architecture functions globally.
  • Developed and led the vulnerability management program.
  • Built the third-party risk management program for vendor risk across cyber and technology.
  • Built enterprise risk reporting, dashboards, and analytics for board visibility.

Chief Information Security Officer

Fifth Third Bank · 2008 — 2011

Directed 150 staff with a $30M budget, overseeing all aspects of cybersecurity and risk.

  • Achieved compliance across PCI DSS, GLBA, HIPAA, SOX, and fraud regulations.
  • Strengthened threat intelligence, incident response, malware analysis, and fraud programs.
  • Implemented enterprise GRC system to unify risk reporting for board and regulators.
  • Enhanced disaster recovery and business continuity for mission-critical systems.

Chief Information Security Officer

ABN AMRO / LaSalle Bank · 2004 — 2008

Directed 300 personnel across global footprint; partnered with C-level executives to mitigate technology risks.

  • Designed and deployed IT risk-assessment methodology across the enterprise.
  • Oversaw global security operations, incident response, patch/configuration, and forensics.
  • Directed architecture and application security; presented directly to board and regulators.

Manager — Red Team & Penetration Testing

KPMG LLP · 1999 — 2003

Led the red team and penetration testing practice within Financial Services for major banks and insurers.

  • Adversary emulation, application and network pen testing, social-engineering campaigns, and post-engagement remediation guidance for major banks and insurers.
  • Ran engagements of 5–20 associates generating $7M in revenue.
  • Advised clients on SOX 404, GLBA, and IT governance compliance.
  • Designed disaster recovery and business continuity strategies for major financial institutions.
  • Delivered board-level reporting and training programs in IT risk and audit.

Information Systems Manager

Citibank · FX Systems · 1998 — 1999

Managed security and operations for global FX trading platforms.

  • Designed security model and certificate authority for global trading systems.
  • Conducted Y2K certification and security testing for mission-critical trading.
  • Supported client trade operations, troubleshooting, and online trading security.

DoD Cybersecurity Consultant

U.S. Department of Defense · 1996 — 1998

Contributed to modernization of defense technology infrastructure across multiple branches of the U.S. military.

  • Built and deployed the TCP/IP backbone for defense networks spanning all service branches.
  • Designed and implemented secure architectures and patterns for C2 (Command & Control) and B2 (Battlefield)–compliant systems.
  • Deployed classified data-management systems supporting weapons inventory tracking and defense readiness.
Off the Wire
Joe Bernik moderating a panel at Nasdaq

Nasdaq, New York

Moderating · Prioritizing People
Joe Bernik at the witness table before the House Committee on Financial Services

U.S. Congress, Washington

At the witness table · 2018
Joe Bernik atop Mount Lovćen, Montenegro

Lovćen, Montenegro

Four continents and counting
Joe Bernik hiking in Torres del Paine, Patagonia

Torres del Paine, Patagonia

Field research
Joe Bernik at Notre-Dame Basilica, Montréal

Notre-Dame, Montréal

Legacy architecture review
Joe Bernik at home with his French bulldog

Home Base

Chief Morale Officer
Credentials
CISMCertified Information Security Manager
CISACertified Information Systems Auditor
CISSPCertified Information Systems Security Professional
U.S. CONGRESSCongressional Advisor — House Committee on Financial Services
FS-ISACMember — Financial Services Information Sharing & Analysis Center
OWASPSteering Committee Member — Open Web Application Security Project
HI-SECSteering Committee · Hi-Sec Security Executive Council — mentorship & community leadership
Education
B.A. / MISUniversity of Mary Washington — Director for Student Activities department. Designed the campus-wide network for the University.
M.B.A.City University of New York — Master's studies in Business Administration
Languages
ESPAÑOLFluent
PORTUGUÊSConversational

Written Work · Selected 2010 — 2024

+ Select any piece for the full abstract and link

Securing Artificial Intelligence in the Real World

De Gruyter · 2024

The practical security challenges around AI deployment in enterprise environments.

An authoritative treatment of the practical security challenges around AI deployment in enterprise environments — governance, threat modeling, and the unique risk surface introduced by ML at scale, drawn from operational experience across global financial institutions. Volume V · Chapter 6 · pp. 113–124.

Read at De Gruyter →

Statement for the Record on Cybersecurity in Financial Services

U.S. Congress · 2018

Testimony before the House Committee on Financial Services on threats facing the U.S. financial system.

Public-private cooperation, the inadequacy of the SSN as a digital identity credential, and the case for modernizing federal procurement of next-generation security solutions.

"The financial sector is ready and waiting. As good a job as institutions like Bank of America and US Bank are doing, they can't be expected to deter a nation state on their own." — Statement for the Record · Subcommittee on Financial Institutions
Read full testimony (PDF) →

In a New Role, He Melds Business and Security

BankInfoSecurity · 2010

A profile on the evolving role of the CISO at the intersection of technology and business strategy.

Building trust with business partners, the rise of organized cybercrime targeting financial institutions, and the shift from infrastructure-centric security to business-risk leadership. CISO Profile · Fifth Third Bank.

Read profile →

Strengthening Cyber Resilience

BNY Mellon Perspectives

A discussion on the human element of cybersecurity.

Why people are the first and most important line of defense against social engineering and advanced threats. Podcast transcript · BNY Mellon.

Read transcript (PDF) →

Speaker Profile — Speakerpedia

Speakerpedia

Featured speaker profile covering decades of leadership across financial-sector cybersecurity and global technology risk.

Speaker Profile — International Economic Forum of the Americas

IEFA

Featured speaker profile covering a career in global financial cybersecurity.

Featured speaker profile from the International Economic Forum of the Americas, covering a career in global financial cybersecurity and work with FS-ISAC and the Federal Reserve.

View profile →

Speaking, board work, advisory — the occasional press inquiry

Slow inbox by design — I'll get back to you. Reach me directly by email, or connect on LinkedIn. For writing and ongoing analysis, find me on Substack and at the Internet Cyber Health Index.

bernik@gmail.com

Joe Bernik atop Mount Lovćen, Montenegro
The wire runs everywhere