Andrew Douma
Innovative Cybersecurity Leader | Architecting Next-Gen Security at Major League Baseball
- Role
- VP of Information Security at Major League Baseball (MLB)
- Location
- New York, NY, US
- LinkedIn followers
- 500 followers
About Andrew Douma
Andrew is a Certified Information Security Professional with a robust blend of executive leadership and hands-on technical depth. He designs and runs cybersecurity programs that align to business outcomes and regulatory requirements—and increasingly, to the realities of GenAI and agentic AI in production.He specializes in AI agent security and LLM security across the full lifecycle: threat modeling, secure architecture, tool/action hardening, RAG and data-access controls, prompt-injection and jailbreak resilience, secrets protection, IAM/authorization design, logging/monitoring, and AI red teaming with actionable remediation.Andrew bridges executive strategy and deep technical execution. His core competencies span Defensive Security Architecture, Security Engineering, and Offensive Security Testing, helping organizations proactively reduce risk while preserving speed and scale. He’s known for uncovering logic flaws, abuse paths, and complex attack chains others miss—then leading pragmatic fixes that teams actually ship.Vendor-neutral and user-centric, Andrew conducts thorough IT audits, full-stack penetration tests, and comprehensive security and risk assessments with meticulous attention to detail. He communicates clearly from boardroom to engineering teams, enabling informed decisions and a durable security culture.If you’re deploying LLM-enabled products, AI agents, copilots, or automation workflows, Andrew helps you build security that’s real: measurable controls, repeatable processes, and resilient systems.
Experience
VP of Information Security
Jan 2022 — Present · New York, NY, US
Information Security Program Development: Crafting and implementing robust security policies, standards, and Enterprise Risk Management (ERM) programs to manage enterprise risk effectively Full-Stack Security Architecture: Designing and implementing security strategies for infrastructure across public, private, and hybrid cloud environments - including ZTN and SASE Comprehensive Protection: Securing all IP-addressed devices, including IT, OT, and ICS/SCADA systems, through proactive and reactive measures Achieving PCI-DSS v4.0 Level 1 ROC Compliance: Ensuring full PCI compliance while optimizing costs and meeting timelines Identity Security: Protecting digital identities and assets by securing and monitoring a single identity across networks, endpoints, IaaS, and SaaS Endpoint Protection & Vulnerability Management: Implementing strategies for endpoint security and managing vulnerabilities without negative business impact Adversary Emulation Exercises: Performing persistent adversary emulation to enhance security defenses Network, System, & Web Application Security Testing: Conduct comprehensive manual and dynamic security assessments Email Security: Leveraging AI, ML, and NLP technologies to thwart sophisticated phishing and financial email attacks targeting high-risk individuals Vendor Management: Leading vendor selection and negotiating contracts to ensure top-tier security services Cybersecurity Recruitment: Crafting unbiased job descriptions, sourcing, and hiring skilled cybersecurity professionals Illegal Streaming: Identifying and neutralizing illegal streaming facilitators Ticketing Security & Financial Fraud: Providing expert consultation to safeguard against financial, barcode, and inventory fraud schemes across ticketing ecosystems
Education
SANS Technology Institute
GIAC Red Team Professional (GRTP), Information Systems Security/Information Assurance
2014 — 2025
University of Maryland
Specialization in Cybersecurity
2016 — 2017
Stanford University
Advanced Computer Security
2017 — 2024
University of Washington
Information Security & Risk Management
2014 — 2015
Hanze
Bachelor of Commerce (B.Com.), Marketing & Economics
2002 — 2007
Skills
- Information Security
- Penetration Testing
- Vulnerability Assessment
- IT Risk Management
- IT Management
- IT Consulting
- Cyber-Security
- Enterprise Risk Management
- Regulatory Compliance
- Project Management
- Technical Writing
- Security Audits
- Cisa
- IT Audit
- Incident Response
- Unix Security
- Osi Model
- Tcp/Ip
- Python
- Bash
- Cryptography
- Windows Security
- Active Directory
- Mac Os X Server
- Linux System Administration
- Network Security
- Firewalls
- Palo Alto Networks
- Cisco Firewall Security
- Intrusion Detection
- Wireless Security
- Endpoint Security
- Unified Threat Management
- Web Application Security
- Application Security
- Pci Dss
- Devops
- Amazon Web Services (Aws)
- Puppet
- Optimizing Performance
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.