People & Leadership

Gigamon Hands Its Security Function to a Former Intelligence Community Operator

Gigamon named Grant Yacomeni, a veteran of the U.S. Intelligence Community, Department of Defense and Marine Corps, as its new Chief Information Security Officer, reporting directly into the COO rather than the CIO.

PublishedSeptember 7, 2026
Read time5 min read
Share

A national security background lands at a network intelligence vendor

Gigamon, the deep observability and network intelligence company, announced on September 2 that Grant Yacomeni will become its Chief Information Security Officer. Yacomeni spent over a decade in cybersecurity and national security roles inside the U.S. Intelligence Community and the Department of Defense, where he managed enterprise security initiatives and oversaw round-the-clock defensive cyber operations. He also served in cybersecurity and intelligence roles with the Maryland Army National Guard and is a Marine Corps veteran.

That pedigree is a specific kind of signal to enterprise buyers of network detection and response tools. Vendors in this category sell the promise of seeing every packet and every anomaly across increasingly complex hybrid networks, and a CISO whose entire career has been built around defensive operations at the highest classification levels lends direct credibility to that promise in a way a more conventional corporate security background would not.

The reporting line is the real story

Yacomeni will report to Chief Operating Officer Gareth Maclachlan, not to a CIO or a general counsel, and his scope spans information and product security, cybersecurity and IT operations, and governance, risk and compliance. Folding all four of those functions under one leader who answers to operations, rather than splitting them across a CIO's technology mandate and a legal or risk team's compliance mandate, is a deliberate structural choice, and it is one that gives the CISO direct standing to shape how quickly product and engineering decisions move rather than acting purely as a downstream reviewer of decisions made elsewhere.

Maclachlan said Yacomeni has spent his career operating in some of the world's most demanding cybersecurity environments and called his experience invaluable as Gigamon strengthens security across its own products and operations. Combining product security with corporate IT security under a single CISO who sits inside operations, rather than as a peer to engineering leadership, is worth studying for any enterprise weighing how to structure its own security function as AI raises the stakes of getting that org chart wrong.

Yacomeni's own framing of the AI threat

In his own comment on the appointment, Yacomeni said AI raises the stakes for security leaders because it can act on information at a speed and scale organizations have not faced before. That statement, coming from someone whose background is defensive cyber operations rather than product marketing, carries more weight than the same line from a vendor spokesperson, and it is consistent with what CISOs across industries have been saying privately about agentic AI systems acting on data faster than human review cycles can keep pace with.

For enterprise security buyers evaluating network observability and detection platforms, Yacomeni's framing is a useful gut check. If your current network detection vendor's leadership cannot articulate a similarly concrete point of view on how AI changes the speed and scale of the threats their tools need to catch, that is a legitimate reason to ask harder questions in your next vendor review.

What this means for your own security org design

Every CIO and CISO who has debated whether security should report through IT, through operations, or as an independent function with a direct board line should treat Gigamon's choice as a live data point. Reporting the CISO into the COO, with product security folded in alongside corporate IT security and GRC, reflects a bet that security decisions are fundamentally operational decisions that need to move at the speed of the business, not technology decisions that can wait for a separate governance cycle.

That structure will not fit every organization, particularly ones where product security and corporate IT security have genuinely different risk profiles and stakeholders. But it is a useful prompt to revisit your own reporting lines this budget cycle, specifically asking whether your current structure lets your CISO move at the speed AI-driven threats now require, or whether layers of technology governance are slowing down decisions that need to happen in hours, not weeks. Document the answer explicitly rather than assuming your existing structure was designed with this specific speed requirement in mind, since most reporting lines in place today predate the current pace of AI-driven threat activity.

The talent pipeline signal

Yacomeni's hire also reflects a broader pattern worth tracking: enterprise security vendors are increasingly recruiting directly from intelligence and defense backgrounds rather than exclusively from corporate CISO ranks or big consultancies. That pipeline brings operational rigor forged under far higher-stakes conditions than most commercial breaches, and it is becoming a competitive differentiator in how vendors position their own security credibility to enterprise customers.

For CISOs building their own succession plans and recruiting pipelines, this is worth noting as a source of talent that has historically been underutilized in commercial cybersecurity leadership. If your next CISO search is limited to candidates with prior public-company CISO titles, you may be passing over operators with more relevant, higher-intensity experience defending against exactly the kind of fast-moving, AI-accelerated threats your organization now faces.

Why network observability vendors specifically need this kind of hire

Gigamon competes in a network detection and observability market where the core promise is visibility into every flow of traffic across increasingly hybrid, multi-cloud environments, a promise that becomes both more valuable and more difficult to deliver as AI agents generate machine-to-machine traffic at volumes and speeds no human analyst can review in real time. A CISO with Yacomeni's specific background in round-the-clock defensive cyber operations is well positioned to stress-test whether the company's own products can actually deliver on that promise against realistic adversary behavior, not just synthetic benchmark traffic.

That internal credibility matters commercially too. Enterprise buyers evaluating network observability platforms increasingly ask vendors to demonstrate their own security posture and operational maturity as part of due diligence, and a CISO whose background includes defending classified government networks against nation-state-level threats gives Gigamon's sales and customer success teams a concrete answer when prospective customers ask how the vendor protects its own infrastructure and validates its product claims.

Tagged#news#people#leadership#cio#cto#cxo#gigamon#ciso#network-security#governance-risk-compliance#security-leadership