Ed Goff

CISSP - Certified Information Systems Security Professional

Enterprise Cybersecurity Executive - Security Architecture, Identity and Access Management, and AI Governance

Raleigh, NC - 919-995-1529 - edgoff33@gmail.com - linkedin.com/in/edgoff3

Approach

For twenty-five years I have been handed the problems that did not yet have an owner. Build an enterprise security architecture function where none existed. Converge the identity estates of two banks through a merger of equals without interrupting a single customer. Secure a grid modernization program before the standards governing it had been written.

What I actually do is narrower than the title suggests: I turn ambiguous, high-consequence technology risk into a capability the organization can operate long after I have moved on. That last clause is the part most programs get wrong. A control that depends on its architect is not a control.

I invest early in learning the business, because a cybersecurity strategy earns funding when its objectives, goals, tactics, and measures are expressed in the terms the business already uses to make decisions - not when the risk is described more vividly. Third-Party Cyber Risk Management, enterprise Data Protection, Security Architecture, Identity and Access Management: each of these began as an argument about business value and ended as an operating capability with a budget, a team, and a measurement model that outlasted me.

The work that I am most known for outside my employers has been collaborative and public - national standards, sector-wide maturity models, and procurement language now used across the energy industry. That work is collected below, with links to the source documents.

Current

I concluded my tenure as Senior Vice President and Head of Identity and Access Management at Huntington National Bank in September 2026.

I am in conversation with organizations about enterprise cybersecurity leadership - Chief Information Security Officer, Head of Security Architecture, and Head of Identity and Access Management - and I take a small number of advisory engagements in identity, AI governance, and operational technology security. I currently advise CyberCodee on product strategy for agentic AI applied to IAM and cybersecurity maturity assessment.

Based in Raleigh, North Carolina. The most reliable way to reach me is email.

Published Work

Each of these is a public document. The links go to the publishing organization, not to copies hosted here.

Cybersecurity Procurement Language for Energy Delivery Systems

U.S. Department of Energy - April 2014

I led the industry initiative to update the federal procurement language for energy delivery systems, convening asset owners, operators, vendors, and integrators to establish a baseline of minimum cybersecurity requirements that buyers could put directly into contracts. The premise was that security requirements arrive too late when they arrive after procurement.

Read at energy.gov

Cybersecurity Procurement Language for Energy Delivery SystemsPeer reviewed

Proceedings of the 9th Annual Cyber and Information Security Research Conference (CISR '14) - ACM

Lead author of the conference paper presenting the procurement language work to the research community, with a co-author from Pacific Northwest National Laboratory.

View in the ACM Digital Library - DOI 10.1145/2602087.2602097

Employee Identity and Access Management: A BITS Primer

BITS - Bank Policy Institute - March 2022

A cross-industry reference on workforce identity for financial institutions, covering the identity lifecycle from creation through privileged access management. Produced by a working group drawn from twelve member institutions. I led the group responsible for the privileged access management section and contributed to the wider document on behalf of Truist.

Read at bpi.com

Framing the Issues: Building Bridges Between Operational Technology, Information Technology, and Supply Chain

The CIP Report, Volume 11 Number 2 - George Mason University Center for Infrastructure Protection and Homeland Security - August 2012

On the organizational seam where operational technology, corporate IT, and procurement meet - and why supply chain risk in critical infrastructure lives in that seam rather than inside any one of the three.

The CIP Report archive

Standards and National Initiatives

Contributions to frameworks and standards that were subsequently adopted across the energy sector and beyond.

NIST Cybersecurity Framework

Contributed to the development of the original Framework as an energy and operational technology subject matter expert, participating in the workshop series and authoring content. Separately contributed to NISTIR 7628, Guidelines for Smart Grid Cybersecurity, through the NIST Smart Grid Cyber Security Working Group, and served as a voting member of the NIST Smart Grid Interoperability Panel.

NIST Cybersecurity Framework - NISTIR 7628

Electricity Subsector Cybersecurity Capability Maturity Model (ES-C2M2)

Subject matter expert contributor to the White House initiative led by the Department of Energy with the Department of Homeland Security, advising on cybersecurity, business operations and procurement, business systems, control systems, and communications networks. The model was adopted across the electricity subsector and became the basis for the cross-sector C2M2.

Cybersecurity Capability Maturity Model at energy.gov

NERC CIP Secure Remote Access Standards Update

Convened and led a large multi-stakeholder group of industry experts working with government agencies and the Department of Energy to address a critical secure remote access vulnerability. The effort resulted in an update to the NERC CIP standards adopted across the industry.

NERC Cyber Attack Task Force

Member of the task force established under NERC's High-Impact, Low-Frequency event work to assess the effect of a coordinated cyber attack on the reliable operation of the bulk power system and to identify improvements to protection, resilience, and recovery. Contributed to the Final Report accepted by the NERC Board of Trustees in 2012.

Roadmap to Achieve Energy Delivery Systems Cybersecurity

U.S. Department of Energy - 2011

One of more than eighty energy sector stakeholders contributing to the update of the sector's 2006 roadmap, defining the high-level cybersecurity needs of asset owners and operators and a common path forward.

Read at energy.gov

Industry Leadership

Career

Huntington National Bank

March 2023 - September 2026

Senior Vice President - Head of Identity and Access Management

Led enterprise IAM strategy, architecture, engineering, governance, and 24x7 operations across workforce, privileged, customer, and non-human identity, reporting to the Chief Information Security Officer as a member of the Cyber Leadership Team.

  • Developed the enterprise IAM strategy and multi-year transformation roadmap aligning cybersecurity investment with business growth, regulatory expectations, operational efficiency, and enterprise resilience.
  • Led IAM enablement of Microsoft Copilot and emerging agentic AI initiatives, establishing identity governance, role-based access boundaries, data protection guardrails, data minimization controls, logging requirements, and human oversight standards.
  • Built the enterprise framework and standards for non-human and agentic AI identity governance, scoping lifecycle management, access certification, and privileged access controls for AI agents as adoption scaled.
  • Led privileged access management modernization and platform migration, re-architecting session and credential management with pre-production resilience testing, disaster recovery validation, and failover and rollback runbooks.
  • Led customer identity and access management modernization and implemented a 24x7 IAM support model integrated with the Service Desk, Network Operations Center, and Security Operations Center, codifying L1, L2, and L3 responsibilities and major incident procedures specific to identity services.
  • Established a formal post-incident review program with documented root cause analysis and tracked remediation, and built executive dashboards putting IAM service health and residual risk in front of the CISO, CIO, and line-of-business heads.

Truist Financial, formerly BB&T

2019 - 2022

Senior Vice President - Cybersecurity Division Manager, Identity and Access Management

Led a 336-person global IAM organization through the merger of equals between BB&T and SunTrust, which formed Truist as the sixth-largest United States bank holding company. Directed enterprise identity architecture, engineering, operations, governance, and transformation across thousands of applications.

  • Led all IAM architecture and technology integration supporting merger convergence across 1,987 enterprise applications, delivering cross-company access between multiple heritage data centers through numerous conversion and testing events with virtually no customer or teammate disruption.
  • Delivered Active Directory Trust and Sync for the merger of equals at .99999 accuracy with no negative teammate impact across all conversion events, contributing to a successful Client Day 1.
  • Led development of dozens of reusable IAM patterns for federation, single sign-on, virtual directory, cloud identity, privileged access, third-party access, and application onboarding.
  • Created and led implementation of a new cloud IAM lifecycle and tenant management model integrating multiple hosted solutions and a multi-cloud strategy.
  • Led a department-wide Agile transformation producing a documented 595 percent improvement in organizational delivery efficiency within four months.
  • Served as CISO delegate during regulatory examinations, executive committee presentations, cyber incidents, Board communications, and enterprise business disruption events.

BB&T, now Truist Financial

2014 - 2019

Senior Vice President - Information Security Architecture and Strategic Planning

Selected to establish and lead enterprise security architecture for one of the nation's largest financial institutions, building a new organization accountable for cybersecurity strategy, secure technology design, enterprise standards, architecture governance, and long-term cybersecurity investment planning.

  • Built and led an organization of 36 enterprise security architects aligned to business and technology domains, establishing the architecture governance, review disciplines, and technology standards that became foundational to enterprise engineering.
  • Led the security architecture and secure development lifecycle design review for the original implementation of Zelle, working with the development team through multiple rounds of code quality review, security testing, and authentication, authorization, and logging architecture ahead of a nationally scaled real-time payments launch.
  • Architected highly secure SWIFT payment environments using isolation, segmentation, dedicated shared services, and layered controls, then led the transition to a full SWIFT compliance program.
  • Conceived, justified, and implemented enterprise third-party cyber risk management, partnering with Procurement, Legal, Vendor Management, and business executives to build and scale a risk-prioritized program including onsite assessments and remediation plan management.
  • Created the enterprise data protection strategy and carried it from ideation to sustained operation, implementing encryption of data at rest, certificate lifecycle management, cloud access security broker, and data loss prevention capabilities.
  • Served as lead architect for customer identity and access management modernization, and partnered with the Digital organization to deliver a modern internally developed authentication capability with risk-based and adaptive authentication and device-health signals.
  • Authored merger and acquisition due-diligence kits used across numerous acquisitions and divestitures, and led the ecosystem evaluation and recommendation for all cybersecurity capabilities supporting planned convergence.

Duke Energy, formerly Progress Energy

2000 - 2014

Enterprise Architect Leader - Cybersecurity Architecture Leader

Joined in a security engineering role and advanced into architecture leadership in 2004, creating and leading the enterprise and solution architecture function for cybersecurity at one of the nation's largest electric utilities. Led a team of seven security architects across transmission, distribution, generation, corporate IT, and operational technology in a no-downtime, heavily regulated environment. Served as the senior-most cybersecurity architect at Progress Energy, led the function into the merger of equals with Duke Energy, and held the same position for the combined company.

  • Created and led the cybersecurity and interoperability portions of the Progress Energy Smart Grid grant application, resulting in the maximum 200 million dollar federal Department of Energy award within a 526.6 million dollar total project budget. Authored the cybersecurity and interoperability Security Plan submitted to the Department of Energy, one of only four accepted nationwide without comment, then led its implementation.
  • Developed cybersecurity architecture supporting industrial control systems, SCADA, operational technology, identity management, network segmentation, remote access, and critical infrastructure protection.
  • Drove the design and implementation of enterprise cybersecurity governance, working directly with the Chief Risk Officer and Enterprise Risk Management to align cybersecurity risk with the enterprise risk framework.
  • Led the enterprise response to Executive Order 13636, Improving Critical Infrastructure Cybersecurity, owning the work from ideation through the design of the people, process, and technology solution and leading the implementation that brought the enterprise into compliance.
  • Designed and implemented the enterprise e-Discovery capability as a full people, process, and technology solution managed in house, spanning legal hold, collection, processing, keyword review, privilege screening, and production to opposing counsel, and established the governance model connecting IT, Legal, and outside counsel through live litigation matters.
  • Invested significant time in substations and plants earning the trust of the engineers supporting operational technology and protection system engineering, developing practical security solutions that balanced reliability and protection.

Advisory Engagements

Current and prior

CyberCodee Current
Advisor, product strategy for an agentic AI platform reimagining IAM and cybersecurity maturity assessments, applying enterprise IAM, identity governance, privileged access, Zero Trust, CIAM, and OT and ICS expertise to adaptive assessment and framework mapping across NIST CSF, ISO 27001, and IEC 62443.

Axilon
Advisor, product development, national lab testing coordination, and business development for an early-stage operational technology and critical infrastructure security venture.

United States Air Force

Early career

Systems, network, and database administration supporting mission-critical command and control systems, enterprise infrastructure, and directory services. Requested as a subject matter expert on unclassified-to-secret interfaces to consult with Pentagon officials, and partnered with Lockheed Martin Mission Systems and the Air Force Systems Program Office on secure command and control capability. Delivered the DISA accreditation package that formally authorized the Wing Command and Control System and its multilevel security capability. B-52 Crew Chief. Operations Desert Shield and Desert Storm veteran.

Capabilities

Security Architecture and Engineering

Enterprise security architecture, secure-by-design, architecture governance, reference architectures, security standards, architecture review boards, threat modeling, cloud security architecture, application and API security, Zero Trust.

Identity and Access Management

Identity governance and administration, privileged access management, customer identity, single sign-on and federation, multi-factor authentication, role engineering, access certification, separation of duties, cloud identity and entitlement management, non-human and agentic AI identity.

AI Governance

Microsoft Copilot and Copilot Studio governance, agentic AI guardrails, non-human identity lifecycle, AI access boundaries, data minimization, human-in-the-loop oversight, NIST AI Risk Management Framework, shadow AI risk.

Enterprise Cybersecurity Leadership

Cybersecurity strategy, enterprise risk management, technology transformation, security operations, cyber resilience, executive governance, Board communication, regulatory leadership, cyber investment strategy, budget and portfolio management.

Operational Technology and Critical Infrastructure

Industrial control systems, SCADA, smart grid, NERC CIP, critical infrastructure protection, Executive Order 13636, secure remote access, grid modernization, OT and IT convergence.

Risk, Compliance, and Third Party

Three lines of defense, control mapping, regulatory examination readiness, risk register and issue management, third-party and supply chain cyber risk, evidence automation, audit defensibility.

Operations and Service Management

24x7 operations, L1 through L3 models, major incident command, post-incident review and root cause analysis, SLA, KPI, and KRI design, disaster recovery and business continuity, ITIL and ITSM integration, Agile and operating model transformation.

Platforms

SailPoint, CyberArk, Delinea, Oracle Identity Manager, Ping Identity, RSA, Active Directory, Microsoft Entra ID, SAML, OAuth, OpenID Connect, FIDO2, AWS, Azure, Google Cloud, CASB, DLP, certificate lifecycle management.

Credentials

Certification
CISSP - Certified Information Systems Security Professional, ISC2 (Active)
Certified since 2004
Verify this credential with ISC2
Education
Bachelor of Science, General Studies, Concentration in Computer Applications
Louisiana Tech University - Summa Cum Laude
Associate of Applied Science, Aircraft Systems Technology
Community College of the Air Force
Frameworks and Regulatory Environments
NIST Cybersecurity Framework, NIST SP 800-53, NIST SP 800-63B, NIST AI Risk Management Framework, NERC CIP, IEC 62443, ISO 27001, SOX, PCI DSS, GLBA, HIPAA, GDPR, NYDFS, SWIFT, CMMI, and federal banking examination environments.
Professional Development
Linked entries carry a certificate of completion that can be verified with the issuer. Entries without a link are training or coursework for which no credential was issued. Professional certification is listed separately above.
Artificial Intelligence
Google AI Essentials Specialization (Google) - AI Fluency: Framework and Foundations (Anthropic) - Claude 101 (Anthropic)
AI Foundations - DataCamp statements of accomplishment
Introduction to AI for Work - AI Ethics - Generative AI Concepts - Large Language Models Concepts - Understanding Machine Learning Concepts - Understanding ChatGPT
Architecture and Delivery
TOGAF Architecture - SAFe Agile Framework - SAFe Lean Agile Portfolio Management
Security and Incident Response
SANS Incident Handling Step-by-Step - Computer Crime Investigation - Network Security and Firewall Administration
Operational Technology
ISA Introduction to Industrial Automation and Control - Intermediate Supervisory Control and Data Acquisition (SCADA) Security
Networking
Cisco Certified Network Associate (CCNA) Training - coursework completed