Chicago, IL · Security, Risk & Technology Executive
Two-time Chief Information Security Officer — and CIO — for financial and digital-asset institutions. I migrated a crypto platform's entire infrastructure from on-premise data centers to 100% multi-region cloud, took its operations from a single U.S. office to three continents, and built security programs at startup speed and systemically-important-bank scale alike. The audit and bank-examiner background underneath it all is why boards trust the numbers I bring them.
424-272-6463 · Sebastiaan.Gybels@outlook.com · Fluent English & Dutch, conversational French & German
The record
SVP, Cyber Security
Northern Trust — Cyber Risk & Governance
Own the cyber risk assessment program and board/executive reporting for one of the largest wealth managers in the world — rebuilding it around AI-driven analysis rather than manual data-chasing, and integrating risk quantification directly into how decisions get made, so priorities are more targeted, efficient, and effective.
Chief Information Security Officer & CIO
CoinFlip
First CISO hire, promoted to combined CISO/CIO within six months, with the full security and IT organization under me — DevOps, IT helpdesk, and infrastructure alongside security. Owned the technical execution myself: led a 65-person global organization through a full data-center-to-cloud migration, taking the platform from a single U.S. footprint to multi-region infrastructure spanning three continents. Given the pace of a crypto-native business, worked in close coordination with Software Engineering and QA on every new product launch.
SVP, Cyber Security
Northern Trust — Internal Audit
Built the firm's first global cloud-security audit framework and led enterprise-wide cyber assessments reporting directly to the Audit Committee.
Chief Information Security Officer
NextCapital Group
First dedicated security hire. Built the program that let the company grow from $1B to $5B+ in assets under management, underpinned by SOC 2 and ISO 27001.
Risk Management Team Leader
Federal Reserve Bank of Chicago
Led the 7th District's IT and Cyber Risk Specialist team and created the Cyber Horizontal Program — the framework used to assess the largest U.S. banks before NIST CSF existed. Trained regulators across three continents.
IT Audit Manager
PricewaterhouseCoopers — Brussels & Chicago
Started in penetration testing and security assessments, then broadened into Sarbanes-Oxley assurance, financial audit, data analysis, and forensics across Europe and the U.S. — a range that still shows up in how I lead cybersecurity today, and where the translation work between technical risk and board-level decisions began.
In the field
Hands-on, not just oversight
Personally designed and delivered live technical demonstrations — penetrating a network and compromising critical assets in front of the room — while training international regulators in Sydney, São Paulo, and Lima for the Federal Reserve.
What actually held under pressure
CoinFlip's pace demanded constant, close coordination across legal, compliance, business, IT, and security. Leading incident response quickly is expected of a CISO — what mattered more was building the muscle for those teams to move together, fast, without friction.
Shaping the standard, not just following it
Contributed to the FFIEC handbook rewrite and led the creation of the Federal Reserve's Cyber Horizontal Program, the risk framework used to assess the largest U.S. banks before NIST CSF existed. Both are still in active use today.
Beyond the day job
Featured through EC-Council and wrote cybersecurity articles for community bankers, with panels at Money2020, the American Bar Association, and DePaul's Risk Conference.
Credentials
Visibility & contribution
Committee
ORBIE finalist 2024–25, now contributing to the program that recognizes the region's security leaders.
Board
Active in chapter leadership and Special Interest Group work supporting the local security community.
Speaking
Panelist on AI-augmented vulnerability research — risk, opportunity, and governance.
Upcoming
Davenport, IA — October 2026. Invite-only gathering of security leaders.