Chicago, IL · Security, Risk & Technology Executive

Sebastiaan Gybels

Two-time Chief Information Security Officer — and CIO — for financial and digital-asset institutions. I migrated a crypto platform's entire infrastructure from on-premise data centers to 100% multi-region cloud, took its operations from a single U.S. office to three continents, and built security programs at startup speed and systemically-important-bank scale alike. The audit and bank-examiner background underneath it all is why boards trust the numbers I bring them.

CISSP
CISA
CRISC
CDPSE

424-272-6463  ·  Sebastiaan.Gybels@outlook.com  ·  Fluent English & Dutch, conversational French & German

Sebastiaan Gybels

Fifteen years, three vantage points on the same problem

2025 — Present

SVP, Cyber Security

Northern Trust — Cyber Risk & Governance

Own the cyber risk assessment program and board/executive reporting for one of the largest wealth managers in the world — rebuilding it around AI-driven analysis rather than manual data-chasing, and integrating risk quantification directly into how decisions get made, so priorities are more targeted, efficient, and effective.

3 weeks → 3 days reporting cycle
2021 — 2024

Chief Information Security Officer & CIO

CoinFlip

First CISO hire, promoted to combined CISO/CIO within six months, with the full security and IT organization under me — DevOps, IT helpdesk, and infrastructure alongside security. Owned the technical execution myself: led a 65-person global organization through a full data-center-to-cloud migration, taking the platform from a single U.S. footprint to multi-region infrastructure spanning three continents. Given the pace of a crypto-native business, worked in close coordination with Software Engineering and QA on every new product launch.

0 → 3 continents of cloud infrastructure 7 new country launches 95% fewer security events 60% faster investigations 30%+ cost reduction ORBIE CISO of the Year finalist, 2024–25
2020 — 2021

SVP, Cyber Security

Northern Trust — Internal Audit

Built the firm's first global cloud-security audit framework and led enterprise-wide cyber assessments reporting directly to the Audit Committee.

2016 — 2020

Chief Information Security Officer

NextCapital Group

First dedicated security hire. Built the program that let the company grow from $1B to $5B+ in assets under management, underpinned by SOC 2 and ISO 27001.

2011 — 2016

Risk Management Team Leader

Federal Reserve Bank of Chicago

Led the 7th District's IT and Cyber Risk Specialist team and created the Cyber Horizontal Program — the framework used to assess the largest U.S. banks before NIST CSF existed. Trained regulators across three continents.

2001 — 2009

IT Audit Manager

PricewaterhouseCoopers — Brussels & Chicago

Started in penetration testing and security assessments, then broadened into Sarbanes-Oxley assurance, financial audit, data analysis, and forensics across Europe and the U.S. — a range that still shows up in how I lead cybersecurity today, and where the translation work between technical risk and board-level decisions began.

The parts that don't fit in a job title

Hands-on, not just oversight

Live hacking demonstrations, three continents

Personally designed and delivered live technical demonstrations — penetrating a network and compromising critical assets in front of the room — while training international regulators in Sydney, São Paulo, and Lima for the Federal Reserve.

What actually held under pressure

Cross-functional response in a fast-moving environment

CoinFlip's pace demanded constant, close coordination across legal, compliance, business, IT, and security. Leading incident response quickly is expected of a CISO — what mattered more was building the muscle for those teams to move together, fast, without friction.

Shaping the standard, not just following it

Helped write the exam I now get evaluated against

Contributed to the FFIEC handbook rewrite and led the creation of the Federal Reserve's Cyber Horizontal Program, the risk framework used to assess the largest U.S. banks before NIST CSF existed. Both are still in active use today.

Beyond the day job

Published author and industry panelist

Featured through EC-Council and wrote cybersecurity articles for community bankers, with panels at Money2020, the American Bar Association, and DePaul's Risk Conference.

Certified, examined, and still learning

CISSP
Certified Information Systems Security Professional
CISA
Certified Information Systems Auditor
CRISC
Certified in Risk & Information Systems Control
CDPSE
Certified Data Privacy Solutions Engineer
CBSP
Certified Blockchain Security Professional
CCE
Certified Cryptocurrency Expert
Commissioned Bank Examiner
AI GOV
AI security & governance certification, in progress

Where I show up outside the day job

Committee

CISO of the Year Program, Chicago

ORBIE finalist 2024–25, now contributing to the program that recognizes the region's security leaders.

Board

ISSA Chicago

Active in chapter leadership and Special Interest Group work supporting the local security community.

Speaking

EC-Council CyberTalks

Panelist on AI-augmented vulnerability research — risk, opportunity, and governance.

Upcoming

CornCon 12 — CISO Executive Summit

Davenport, IA — October 2026. Invite-only gathering of security leaders.