Cybersecurity Executive David E. Smith

Chief Information Security Officer  ·  Pharmaceutical & Life Sciences

The most effective security program exists to clarify decisions, not to manage technology.

Nearly 30 years leading enterprise cybersecurity across biopharmaceutical, financial services, and technology sectors. The common thread: problems nobody had fully solved yet, environments without playbooks, and risk that does not wait for the next budget cycle.

David E. Smith, Cybersecurity Executive

The work I'm doing now is a full-program transplant – function for function, tool for tool, control for control – all while the business stays protected. I'm currently leading that build at CHI (Capsules & Health Ingredients), a pharmaceutical ingredients manufacturer completing its divestiture carveout from Lonza Group to Lone Star Funds. My team's mission is to protect a global manufacturing network serving approximately 60 percent of the global market in pharmaceutical gelatin capsules, ensuring the supply chain patients depend on doesn't stop.

This isn't the first time I've started without a foundation. At Amgen, I built the global cyber defense function from fragmented capabilities into a unified program: 28 people, 75,000 assets across four continents, IT and OT domains running in parallel. In the 13 years before that, I built consulting practices that advised CISOs across 200+ organizations through Symantec and my own independent firm. My first opus was a division security program at Transamerica, where the audit position ranked last in the company when I arrived and first when I left.

Every role has been a variation on the same puzzle. I'm drawn to structurally hard problems: situations where the risk is real, the governance is immature, and the margin for error is low. Post-quantum cryptography, AI data governance, OT security in GxP manufacturing environments – these are the problems most security organizations are still deciding to prioritize. Problems like these require someone who can translate the technical reality into decisions the board can actually make.

I'm currently pursuing a Juris Master in Cybersecurity Governance at Florida State University.
I've been CISSP-certified since 2000.

AI Governance GRC Strategy NIST CSF 2.0 Post-Quantum Cryptography SCADA / OT Security Endpoint Defense Data Protection Board Advisory M&A Due Diligence Incident Response ISO 27001 NIST AI RMF

For speaking, expert commentary, and board advisory engagements, reach out through the form below.

Location
Tampa, FL