Resume PDF ↓
Technology & Cybersecurity Executive

Michael
Quiles.

CISSP · New Castle, Kentucky · Available for CIO / VP IT / CISO roles

Technology. AI. Security. Enterprise Transformation.

Technology executive with 24+ years bridging business strategy, cloud, cybersecurity, infrastructure, and operations. Former CIO/CISO who moves comfortably between executive strategy and technical architecture — turning ambiguous business problems into practical, executable technology solutions.

24+ Years IT & Security · Former CIO/CISO · Executive & Board Leadership · $1M–$5M Budgets · Public Company Experience · Secret Clearance
Michael Quiles
Get in touch
michaelquiles@gmail.com502-689-3769LinkedIn ↗
New Castle, Kentucky
24+Years in IT & security
$1M–$5MBudgets owned as IT leader
$420KAnnualized Azure savings (50%)
95%Malware infection reduction

Executive profile

01 / 06

Hands-on technology executive who builds technology and security programs from the ground up, modernizes legacy environments, evaluates emerging technologies, and aligns technology investment with business objectives. Known for quickly understanding complex environments, identifying gaps and opportunities, challenging assumptions, and bringing executives, engineers, security teams, vendors, and business stakeholders together around an executable solution.

01 — Translator

Business + Technology

Translates business objectives and ambiguous problems into practical technology strategies, architectures, security requirements, and execution plans.

02 — Technical

Hands-On Depth

Maintains hands-on credibility across cloud, cybersecurity, infrastructure, identity, DevOps, enterprise systems, and integration while operating at the executive level.

03 — Solver

Problem Assessment

Quickly assesses unfamiliar environments, identifies dependencies and risks, evaluates technology options, and determines practical solutions.

04 — Builder

Program & Platform Build

Builds cloud environments, cybersecurity programs, governance frameworks, operational processes, compliance programs, and resilient infrastructure.

05 — Leader

Cross-Functional Alignment

Brings executives, engineers, security professionals, vendors, and business stakeholders together around common business and technology outcomes.

06 — Operator

Pragmatic Judgement

Balances security, compliance, technical debt, cost, operational reality, and business speed rather than pursuing technology for technology’s sake.

Selected leadership impact

02 / 06
01Served as CIO and CISO, owning a multi-million-dollar IT/security budget, leading 9+ staff, and reporting directly to executive leadership and the Board.
02Delivered $420K in annualized Azure savings (50% reduction) through governance, rightsizing, FinOps, and cost optimization at Semler Scientific (NASDAQ: SMLR).
03Cut operational downtime 70% through infrastructure, GRC, and disaster recovery improvements.
04Reduced malware infections 95% by designing and standing up a formal IT security program at Winston Industries.
05Led technical due diligence and post-merger IT/security integration associated with Semler Scientific’s affiliation with Strive Asset Management.

Experience

03 / 06
OCT 2021 — PRESENT

Senior Security Infrastructure Engineer

Semler Scientific · Campbell, California · NASDAQ: SMLR · Strive Asset Management company
  • Lead enterprise Azure architecture, engineering, security, governance, and operational strategy for a public company and its portfolio affiliate.
  • Translate business, regulatory, and customer requirements into secure cloud architectures, operating standards, and executable technology roadmaps.
  • Own Azure security policy design and enforcement — Azure Policy, security baselines, RBAC, network security groups, Defender for Cloud, and cloud security posture management.
  • Drive CMMC Level 1, NIST 800-53, NIST CSF, FedRAMP, and HITRUST control implementation, documentation, and audit readiness.
  • Direct FedRAMP-aligned deployments for government/VA customers, addressing NIST 800-53 and FIPS 140-2 requirements.
  • Reduce annualized Azure cloud spend 50% (~$420K) through FinOps-driven governance, rightsizing, and cost optimization.
  • Lead technical due diligence and post-merger IT/security integration for the Strive Asset Management affiliation.
  • Lead containerization and DevSecOps with Docker, Azure Container Apps, Jenkins, and Terraform; modernize legacy VM services to cut patching risk and speed deployment.
  • Own vulnerability management, privileged identity reviews, SIEM monitoring, incident triage, identity/endpoint security, vendor risk, and security architecture reviews.
  • Evaluate generative AI tools including Microsoft Copilot and Gemini for security, data governance, and risk implications, advising leadership on safe adoption.
  • Own enterprise backup and disaster recovery using Veeam and Wasabi, and maintain documentation supporting audits, security reviews, and recovery planning.
  • Mentor engineers and IT staff while partnering across business, application, security, and infrastructure teams.
OCT 2021 — PRESENT

Virtual CISO (vCISO)

Independent / Freelance · Self-Employed · Remote

Fractional security leadership for organizations that need a senior security voice without a full-time hire — acting as an extension of the client’s information security and governance function across strategy, program maturity, risk, compliance, and day-to-day security operations.

Security strategy & governance
  • Define and lead client information security vision, roadmap, and operating model, aligning security investment to business objectives through risk-based prioritization.
  • Review current security and service management programs, assess program maturity, and build a corresponding roadmap that key stakeholders can act on.
  • Serve as the client’s virtual CISO in executive and board-level discussions, translating security posture into language leadership can act on.
  • Develop, implement, and oversee information security programs, roadmaps, and plans of action across infrastructure, cloud, applications, and endpoints.
Assessments, compliance & risk
  • Lead cybersecurity risk assessments and security posture reviews, producing high-quality reports including gap analysis, POAMs, prioritized recommendations, and remediation planning.
  • Guide compliance and framework alignment — NIST CSF, NIST 800-53, CIS Controls, ISO 27001, SOC 2, HIPAA/HITECH, CMMC, PCI, and GDPR — including policy and procedure development.
  • Lead internal and external audits, risk assessments, and vendor security reviews.
  • Coordinate and advise on vendor-specific partnerships, third-party risk programs, and due diligence.
  • Develop business continuity, disaster recovery, and incident response plans — including ransomware readiness, tabletop exercises, response playbooks, and post-incident remediation guidance.
Operational leadership
  • Provide oversight of security operations — SOC, threat detection, incident response, and vulnerability management — and build playbooks for threat mitigation and breach containment.
  • Lead and manage security analysts, providing direction, oversight, expertise, and mentoring, and support professional development across consulting teams.
  • Advise on security controls and technologies, and stay engaged in architecture reviews, IAM and zero trust, encryption, secure networking, penetration testing, and secure-by-design practices with engineering, IT, and DevOps teams.
  • Establish KPIs, metrics, and security dashboards that give leadership a clear view of risk and program performance.
Executive engagement, budget & growth
  • Support annual security and technology budgeting, forecasting, and investment prioritization, and provide strategic oversight of client IT and security initiatives.
  • Build long-term client relationships within recurring consulting programs, and support business development through scoping, statements of work, resource estimates, and RFP responses.
  • Communicate risk, incidents, and program performance to executive leadership and the board; develop expert-level content and contribute to panels and speaking engagements.
MAR 2021 — OCT 2021

Chief Information & Security Officer

Park DuValle Community Health Center · Louisville, Kentucky
  • Served as CIO and CISO, leading a multi-million-dollar IT/security budget, enterprise technology strategy, and a team of 9+, with direct reporting to executive leadership and the Board.
  • Defined the information security vision, roadmap, operating model, policies, security architecture, data protection strategy, and third-party risk program.
  • Built enterprise data governance covering retention, access control, and secure data lifecycle management.
  • Oversaw security operations, threat detection, incident response, breach response planning, and tabletop exercises.
  • Aligned cybersecurity and risk management with HIPAA, HITECH, NIST CSF, NIST 800-53, ISO 27001, SOC 2, and GDPR requirements.
  • Led audits, risk assessments, vendor security reviews, and executive/Board reporting on risk posture and performance.
  • Built and led IT operations teams supporting enterprise infrastructure, SaaS platforms, and healthcare applications; recruited, mentored, and retained technical talent.
  • Cut operational downtime 70% through infrastructure modernization, GRC improvements, and disaster recovery planning.
  • Built organization-wide security training and awareness programs to strengthen compliance culture and reduce human-factor risk.
JUN 2020 — MAR 2021

Sr. Systems Engineer

University of Louisville Health · Louisville, Kentucky
  • Engineered Azure, identity, network security, and enterprise systems supporting healthcare operations across hybrid on-premises and cloud environments.
  • Administered Windows Server and Linux Server infrastructure, including server deployment, hardening, and patch management tooling.
  • Built infrastructure as code and automation to standardize provisioning and configuration across enterprise platforms.
  • Implemented infrastructure and platform monitoring plus backup and disaster recovery technologies to improve availability and reduce recovery time.
  • Rolled out Microsoft MFA organization-wide and led SSL/TLS certificate lifecycle management across Linux and Windows platforms.
  • Designed Azure AD/Entra ID, Okta, ADFS, and secure Azure network segmentation using VNets, NSGs, and UDRs.
  • Partnered with security teams on HIPAA compliance, PAM, DLP, vulnerability management, access controls, and audit remediation.
JUN 2010 — JUN 2020

IT Operations Manager

Winston Industries · Louisville, Kentucky
  • Led a 9+ person infrastructure, security, and help desk organization, owning budget, staffing, performance management, and technology operations.
  • Built and stood up the organization’s first formal IT security program, reducing malware infections 95%.
  • Architected VMware vCloud Director IaaS environments on Cisco UCS and Dell PowerEdge infrastructure and directed enterprise identity and access management.
  • Led data center relocation, enterprise wireless deployment, secure remote access/VPN, facility access-control systems, and major infrastructure modernization programs.
  • Directed server lifecycle and Office 365 migration initiatives while building more than 70% of the organization’s file servers.
  • Led the launch of a new electronics division, including website, servers, networking, and technology infrastructure.
2008 — 2008

SOC Analyst / Infrastructure Services Security Analyst / Systems Administrator

Humana Inc. · Louisville, Kentucky
  • Monitored and triaged security alerts and incidents using SIEM and EDR tooling — investigating events through log review, containing and remediating incidents, and documenting findings through ticket closure.
  • Deployed and configured security tools including SIEM, endpoint protection, and identity solutions alongside senior team members and vendors to protect the organization’s digital assets.
  • Maintained and improved SIEM detections — updating and tuning alerts, assisting with platform upgrades, and building and refining detections with query language.
  • Conducted internal and external vulnerability scans, analyzed results, and coordinated remediation with system owners based on risk and priority.
  • Audited user access and permissions by reviewing access reports, validating approvals with system owners, and documenting findings to support least-privilege governance.
  • Responded to security-related inquiries and requests — following up on security tickets and user/vendor reports such as phishing submissions or suspicious activity, and providing cybersecurity guidance to employees.
  • Supported cross-functional security projects alongside Information Security Engineers, contributing to governance, architecture, research, and compliance initiatives.
  • Performed periodic security audits to verify that policies and procedures were followed, and assisted with audit evidence collection and follow-ups.
  • Participated in a limited on-call rotation (typically 2–3 weeks per year) supporting urgent security incidents and escalations outside normal business hours.
  • Administered Active Directory, Domain Controllers, GPOs, and Exchange while supporting disaster recovery policy development.
APR 2001 — FEB 2007

Sr. Systems Administrator

U.S. Army · Fort Campbell, Kentucky · 160th Special Operations Aviation Regiment
  • Administered Active Directory and a 35,000+ mailbox Exchange environment; monitored network vulnerabilities and led remediation.
  • Implemented antivirus and patch management programs that eliminated hundreds of active infections, and maintained data center, backup, and disaster recovery infrastructure for mission-critical operations.
2007 — 2008

Systems Integration Engineer · Jefferson Audio Video Systems — Windows hardware/software integration and test-bed development.

Tier III Helpdesk Technician · Kindred Healthcare — Improved imaging throughput from 114 to 560 units/week and completed rollout three months ahead of schedule.

Selected work

04 / 06
01

Azure FinOps Transformation

Reworked cloud governance, rightsizing, and cost optimization across the enterprise Azure environment, pairing FinOps discipline with a containerized platform strategy.

50% spend reduction · ~$420K annualized savings
02

FedRAMP-Aligned VA Environment

Designed and directed secure Azure deployments supporting government and Veterans Affairs customers, with documented control implementation, security policy, and network segmentation.

NIST 800-53 · FIPS 140-2 · FedRAMP
03

Security Program Build

Built formal security, monitoring, governance, incident response, and recovery capabilities from zero — including tabletop exercises and organization-wide security awareness training.

70% downtime reduction · 95% malware reduction
04

Container & DevSecOps Migration

Led migration of legacy VM-based services to containerized architecture and CI/CD delivery, reducing patching risk and improving deployment speed and reliability.

Docker · Azure Container Apps · Jenkins · Terraform
05

M&A Technology Integration

Led technical due diligence and post-merger IT/security integration work as part of Semler Scientific’s affiliation with Strive Asset Management.

Due diligence · IT integration · Security integration
06

AI Governance & Risk

Evaluated generative AI tooling including Microsoft Copilot and Gemini for security, data governance, and risk implications, and advised leadership on safe, governed adoption.

AI governance · Data governance · Copilot · Gemini

Capabilities

05 / 06
Leadership & strategy
Technology strategy & transformation
Executive leadership & team building
Executive & Board communication
Cloud & enterprise architecture
Budget, vendor & third-party risk
IT operating model & governance
M&A / IT-security integration
Security, risk & platforms
Cybersecurity strategy & GRC
Risk, compliance & audit readiness
Identity & access management / Zero Trust
Secure SDLC / DevSecOps / containers
AI governance & security risk
FinOps & cloud cost optimization
Healthcare technology & interoperability
Business continuity & disaster recovery
AzureEntra IDVMwareTerraformKubernetesDockerJenkinsGitLabCisco UCSActive DirectoryPowerShellCrowdStrikeOktaAuth0ZscalerProofpointTenableMicrosoft SentinelDefender for CloudDatadogGraylogPRTGPagerDutyMirth ConnectHL7 / FHIRMySQLSQL ServerFedRAMPCMMCNIST 800-53NIST CSFISO 27001SOC 2HIPAAHITRUSTGDPR

Education & credentials

06 / 06
Education · Sullivan University
Ph.D. in Management: Information Technology — Candidate (ABD)
MBA & MS, Managing Information Technology — Summa Cum Laude, President’s Cup
BS, Information Technology — Database & Network Administration
AS, Information Technology
Certifications & distinction
CISSP — Certified Information Systems Security Professional (ISC²)
Certified ScrumMaster — Scrum Alliance
ITIL v4 Foundation
Microsoft Certified: Security, Compliance & Identity Fundamentals
Microsoft Certified: Azure Fundamentals
U.S. Army veteran · Secret clearance, 2001–2007
Bilingual: English / Spanish
CISSPCertified ScrumMasterITIL v4 FoundationSC-900AZ-900Secret ClearanceBilingual EN / ES