← Back to Home
Anthony McCloskey

Anthony McCloskey

Information Security & Data Privacy Leadership · GRC & Cloud Security · AI Risk Governance

📍 Jenkintown, PA (Greater Philadelphia) 📧 anthony@nordalai.com 🔗 linkedin.com/in/anthonymccloskey 🌐 anthonymccloskey.com

Summary

I lead at the intersection of cybersecurity, data, and compliance — helping organizations translate complex technical and regulatory challenges into scalable, real-world solutions. With a foundation in cybersecurity and a strong focus on modern data platforms and AI, I'm particularly interested in how automation and AI can enhance governance, surface risk earlier, and support better decision-making at scale. I'm known for a pragmatic, systems-oriented approach to problem-solving and a leadership style grounded in accountability, trust, and continuous improvement.

Information Security Leadership Data Privacy & Governance GRC & Compliance Cloud Security Identity & Access Management Security Operations AI Risk Governance Executive Advisory

Experience

Energage Current
Head of Cybersecurity and Data Privacy
Greater Philadelphia (Remote)
Sep 2026 – Present

Own the enterprise information security and data privacy program for a workplace culture research and talent management SaaS platform, recently expanded through the acquisitions of TalentQuest and Engagedly.

  • Lead information security, data privacy, governance, risk, and compliance functions across a newly combined, multi-platform organization, partnering with Product, Engineering, and executive leadership
  • Extending ISO/IEC 27001 certification scope to newly acquired entities, harmonizing security posture across legacy Energage, TalentQuest, and Engagedly
  • Participate in the enterprise AI governance and data governance committees, applying deep AI risk management expertise to a newly formalized governance function
  • Own third-party and vendor risk management, customer security questionnaires, and audit readiness across the combined platform
Comcast 1 year 9 months
Director, Data, AI, and Security Technology
Philadelphia, PA
Dec 2024 – Sep 2026

Lead information security, data privacy, and AI governance strategy for Legal Compliance at one of the largest telecommunications and media enterprises in the world, advising executive leadership on risk and compliance.

  • Drove the Legal organization to over 90% security compliance — among the highest-scoring organizations at Comcast — by embedding security posture directly into legal operations workflows
  • Personally designed and built an agentic AI platform with a custom retrieval-augmented-generation pipeline and Model Context Protocol tool integrations, from initial concept through enterprise deployment
  • Authored Architecture of a Nightmare: Why AI Agents Are a Security Regression, a published analysis aligned to NIST AI RMF, ISO 42001, and the OWASP LLM Top 10, evaluating emerging AI-related risk ahead of regulatory expectations
  • Lead third-party and vendor risk assessments, security questionnaires, and customer due-diligence support in coordination with Legal and executive leadership
  • Develop security metrics, KPIs, and executive dashboards, translating technical and privacy risk into clear business decisions for senior leadership
Salesforce 3 years
Director, Cybersecurity: Sensors, Control Points & TVM Product Management
Greater Philadelphia (Remote)
May 2023 – Jan 2025

Led an enterprise-wide security program at Salesforce, a cloud-native SaaS platform, covering the global environment, subsidiaries, customers, employees, and partners.

  • Owned identity and access management architecture using Okta across Salesforce's global cloud infrastructure, governing provisioning, role-based access, and continuous entitlement review
  • Directed identity, endpoint, and network security control-point architecture across AWS and hybrid cloud environments
  • Owned incident response planning, detection, monitoring, and escalation processes across a complex global environment, serving as senior escalation point for real incidents
  • Managed and developed a globally distributed technical team, building scalable security processes to support continued organizational growth
Director, Cybersecurity — Threat and Vulnerability Management (TVM)
Greater Philadelphia (Remote)
Feb 2022 – Jun 2023
  • Secured FedRAMP accreditation for multiple Salesforce operating environments, owning regulatory audit readiness, control documentation, and assessor relationships end to end
  • Achieved a 98.6% reduction in P0 vulnerabilities and boosted patching SLA compliance to over 97% through a standardized vulnerability management program, cutting mean-time-to-respond by 25%
  • Doubled Cloud Security Posture Management (CSPM) coverage on AWS while reducing costs, and managed a penetration-testing program and remediation tracking across global infrastructure
Comcast 7 years
Director, Product Management — Cybersecurity Tools
Philadelphia, PA
Jul 2020 – Dec 2021

Led a 20-member cross-functional team of Product Managers, Project Managers, and Engineers, personally implementing and managing the security technology stack for Comcast's enterprise cybersecurity organization.

  • Implemented and managed Splunk SIEM at enterprise scale, owning platform architecture, detection-rule governance, and data onboarding
  • Implemented and managed XSOAR (formerly Demisto) SOAR platform, architecting automation and orchestration across security operations
  • Managed Tenable vulnerability management platform and endpoint security tooling across the enterprise
  • Directly managed and developed Product Managers on the team, mentoring the next layer of security leadership
Sr. Manager, Privacy and InfoSec Compliance
Greater Philadelphia
Jan 2019 – Jul 2020
  • Key architect in standing up the Comcast Privacy Program from inception, owning the data privacy and governance program end to end using OneTrust as the core platform, across CPNI, GDPR, CCPA, COPPA, SCF, PCI, and SOX
  • Managed security-related audits, regulatory inquiries, and compliance assessments in direct partnership with Legal, Compliance, and Internal Audit — earning the Comcast Circle of Success and Circle of Innovation Awards
Manager, Legal/Regulatory Compliance
Greater Philadelphia
Jul 2017 – Jan 2019

Ensured complex technical voice and data operations aligned with legal and regulatory requirements, implementing NIST 27001, SCF, NIST RMF, and NIST CSF compliance frameworks. Served as a trusted advisor to leadership and cross-functional teams, modernizing internal operations through automation and collaboration tools.

Senior Compliance Analyst
Philadelphia, PA
Jul 2015 – Jul 2017

Provided business performance analysis and process gap identification to establish governance for operations compliance. Developed and maintained compliance metrics, produced reports and data validation, and participated on cross-functional teams to reduce company risk exposure.

Regulatory Analyst
Oaks, PA
Jan 2015 – Jul 2015

Maintained legal and regulatory compliance; researched and analyzed regulatory requirements; worked with independent auditors; supported FCC regulatory filings, tax analysis, and compliance governance.

Twitter
IT Project Manager
Mar 2014 – Feb 2015

Senior-level role responsible for creating a PMO and managing complex IT projects in support of the Workplace IT department and Network Security. Led internal and external resources, managed budgets and vendor contracts, and mitigated project risks.

Step-Up Philadelphia (Non-Profit)
Executive Chairman & Founder
Mar 2014 – Jul 2015

Founded Step-Up Philadelphia to provide computer, technology, business, and finance education to under-served populations in the Philadelphia Metro area. Partnered with other non-profits and local universities to expand educational opportunities across the city.

NAMIC
Frontend Developer
Jan 2017 – Feb 2021

Built and maintained production-level web applications using HTML5, CSS/SASS, JavaScript, jQuery, PHP, and Ruby on Rails. Managed Git repositories, integrated APIs, ensured cross-browser compatibility, and collaborated with UI/UX teams.

Nordalai.com
Principal Consultant
2001 – Jan 2015

IT and Information Security consulting for regulated-industry clients spanning HIPAA, SOX, and NIST 27001 compliance, network security architecture, penetration testing, data redundancy, and Microsoft 365 and Azure identity and access management tooling including Entra ID and Intune.

U.S. Navy 13 years 11 months
Chief Master-at-Arms / Facilities Security
Southeast Regional Maintenance Center, Mayport, FL
Oct 2010 – Apr 2012

Responsible for physical security, Force Protection, and Anti-Terrorism Measures for a 177,000 sq ft military maintenance facility with 600+ military and civilian personnel.

Facilities Leading Chief Petty Officer
Southeast Regional Maintenance Center, Mayport, FL
Jan 2010 – May 2011

Facilities/Maintenance Director managing 20+ military/civilian personnel. Coordinated maintenance, contracting, and logistics for a 177,000 sq ft facility and a 50-vehicle motor pool worth over $1 million.

Chief of Information Operations
CJTF-76 Afghanistan
Jan 2006 – Feb 2007

Responsible for all Information Operations related to the Civil Affairs/Psychological Operations Mission for the entire Afghanistan Area of Responsibility. Served as ground combat convoy commander, ensuring the security of 100+ ground assault convoys for Combined Joint Task Force 76.

Information Systems Security Officer
NAVICP Philadelphia
Sep 2003 – Oct 2007

Responsible for Information Security, Network Security, and Network Operations for a 1,000-terminal multi-OS DoD network, plus database management and backup/recovery for the local server farm at the Naval Inventory Control Point, Philadelphia.

Anti-Terrorism Officer
USS Hué City (CG 66)
Oct 2007 – Jan 2010

Responsible for Anti-Terrorism, Force Protection, Security, and Weapons Maintenance and Training. Qualified Small Arms Marksman, Marksmanship Instructor, Crew-Served Weapons Instructor, and Non-Lethal Weapons Instructor.

Combat Gunnery Division / MK86 Work Center Supervisor
USS Thomas S. Gates (CG 52) & USS Ticonderoga (CG-47)
Jun 1998 – Nov 2003

MK86 Gunfire Control Systems Technician and Work Center Supervisor. Managed 12 personnel and over $10 million in equipment including Gunfire Control System RADAR, Gunnery Control Systems, and mainframe computers.

Education

La Salle University
Master of Science, Cybersecurity
Aug 2024 – May 2026
University of Maryland University College
Bachelor's Degree, Accounting
2011 – 2014
DeVry University
Bachelor of Science, Technical Management
2003 – 2007
Syracuse University
Project Management Certification
2015 – 2016
New Horizons
A+ Hardware Certification
2001

Core Competencies

Information Security & Privacy Leadership
Data Privacy & Governance Program Build from Inception Executive Advisory Security Awareness & Education
Compliance & Certification
SOC 2 ISO 27001 NIST CSF NIST RMF FedRAMP GDPR CCPA PCI-DSS SOX HIPAA
Cloud Security & Identity
AWS Azure Okta Microsoft Entra ID Microsoft Intune Identity & Access Management
Security Operations
Splunk SIEM XSOAR / Demisto SOAR Tenable CrowdStrike Falcon Incident Response Vulnerability Management
AI Governance
NIST AI RMF ISO 42001 OWASP LLM Top 10 Architecture of a Nightmare (Published) Agentic AI Platform (Production)

Honors & Awards

🏆 Comcast Circle of Success Award
💡 Comcast Circle of Innovation Award
🎓 Sigma Alpha Pi (National Society of Leadership and Success)

Publications

🛡️ Architecture of a Nightmare: Why AI Agents Are a Security Regression — aligned to NIST AI RMF, ISO 42001 & OWASP LLM Top 10
✍️ The Sandbox