Andrew Valcich

I build and run the programs that make enterprises harder to attack. With 25+ years driving cybersecurity and IT initiatives inside large-scale environments, I translate complex security challenges into funded roadmaps, executed programs, and measurable outcomes — reduced risk, lower cost, stronger posture.

I started as a certified infrastructure engineer — three MCSEs, a CCNA, and two CCAs — before moving into security program leadership. That technical foundation means I still speak the language of the architects and engineers I work alongside, not just the language of a project plan. A business degree means I speak the language of the leadership I report to as well.

How I Work

1. Identify — I start by understanding the strategy, not just the symptoms. What is the organization actually trying to accomplish, and what's standing in the way?
2. Build — I translate that understanding into a structured, budgeted portfolio — programs, projects, timelines, and the resourcing to make them real.
3. Deliver — I stay through execution, working alongside program managers, project managers, and engineers to drive the plan to business-as-usual, not handing off a deck and moving on.

What I've Led

Zero Trust transformations, MDR deployments, enterprise vulnerability management programs, DDoS protection, PAM and IGA implementations, SD-WAN modernization, enterprise DLP rollouts, and cloud/AI governance — each tied to a clear business objective and an accountable outcome.

Certifications

CISSP CISM CRISC CompTIA Security+ PMP Certified ScrumMaster