U.S. Bank hands its top security seat to a US-CERT and Citi veteran, Ann Barron-DiCamillo
People & Leadership

U.S. Bank hands its top security seat to a US-CERT and Citi veteran, Ann Barron-DiCamillo

U.S. Bank named Ann Barron-DiCamillo executive vice president and global CISO, elevating a leader who has defended at both Wall Street and national scale, and setting a benchmark for what the modern security chief now demands.

PublishedJuly 27, 2026
Read time7 min read
Share

A public-sector operator takes a bank's top security seat

U.S. Bank has named Ann Barron-DiCamillo executive vice president and global chief information security officer, handing one of the largest banks in the country to a security leader whose resume runs from Wall Street to the federal incident-response trenches. She takes ownership of the bank's global information security strategy, including the systems, customer data, and digital assets that a top-tier financial institution has to defend continuously. The bank described her as a cybersecurity executive with more than 25 years of leadership across banking, financial services, government, and critical infrastructure. For an industry where a single breach can move a stock and summon regulators, the choice of operator says a great deal.

The appointment continues a pattern worth naming. Banks are increasingly filling their top security jobs with leaders who have run national-scale defense alongside enterprise programs. Barron-DiCamillo spent three years running US-CERT inside the Department of Homeland Security, where she coordinated the country's response to major cyber incidents. Layering that experience over a recent Wall Street tour gives U.S. Bank someone fluent in both the regulator's expectations and the attacker's playbook. Technology leaders outside banking should read the hire as a benchmark for what a mature security function now demands at the very top of the org chart, because the bar keeps rising.

From US-CERT to Citi to Minneapolis

Barron-DiCamillo's path is unusually broad. Most recently she served at Citi as managing director and global head of technology optimization, a role she took in early 2025 after leading the bank's global cyber operations. Before Citi she was vice president of cyber threat intelligence and incident response at American Express, and earlier still she directed US-CERT at DHS between 2013 and 2016. She has also taught cybersecurity risk management as an adjunct professor at American University and sits on the board of FS-ISAC, the financial sector's threat-sharing body. The blend of operations, intelligence, and governance is exactly the mix boards now want overseeing security.

That combination matters because the CISO job has changed shape. A decade ago the role was largely technical, owning firewalls, detection, and incident response. Today it carries board reporting, regulatory engagement, third-party risk, and a growing brief around AI systems and the data that feeds them. Barron-DiCamillo's stops map cleanly onto that expanded mandate: threat intelligence at American Express, national coordination at DHS, and enterprise transformation at Citi. For CIOs and CTOs deciding how to structure their own security leadership, the profile is a useful checklist of the capabilities a modern head of security is now expected to carry into the boardroom.

Why banks keep hiring for resilience

The word U.S. Bank keeps attaching to the role is resilience, and the emphasis is deliberate. Financial regulators have spent the past two years pushing operational resilience rules that treat a prolonged outage or a compromised third party as a systemic risk, not a private problem for one firm. A CISO with national incident-response experience is precisely who a board wants when the standard has shifted from preventing every breach to recovering fast and provably when one lands. Barron-DiCamillo's mandate to advance cyber resilience reads as an answer to that regulatory direction as much as to the threat landscape itself.

Resilience also reframes the security budget conversation for technology leaders everywhere. Spending judged only on breaches avoided is impossible to prove and easy to cut. Spending judged on recovery time, tested failover, and demonstrated containment gives a CISO a defensible story for the board and the regulator alike. U.S. Bank hiring a leader who ran recovery at national scale suggests it wants security measured that way. Enterprises outside finance face softer versions of the same pressure from customers and insurers, and the resilience frame travels well beyond banking to any organization that simply cannot afford to go dark for long.

The AI and data dimension

A modern bank CISO inherits a fast-growing surface: the AI systems the institution is racing to deploy and the sensitive data those systems consume. Fraud detection, customer-service agents, and analytics platforms all widen the attack surface and create new questions about model integrity, data leakage, and the provenance of automated decisions. Barron-DiCamillo's threat-intelligence background is relevant here, since defending AI-enabled workflows depends on understanding how adversaries probe them. Her appointment coincides with a period when banks are pushing generative and agentic AI into production, which makes securing those pipelines a first-order responsibility rather than a side project for the new security chief.

This is where security leadership and AI strategy collide inside every large enterprise. The teams shipping AI features want speed, and the security function has to make that speed survivable while avoiding the reputation of the office of no. A CISO who has run both intelligence and transformation is better positioned to broker that tension than one drawn purely from either camp. For technology leaders standing up AI governance, the lesson is to seat security at the table early, while pipelines are being designed, rather than bolting controls on after a model already touches customer money. U.S. Bank has signaled it wants that seat filled by a genuine heavyweight.

What the hire signals to the sector

Executive security moves at a bank of this size ripple outward. Peer institutions benchmark against one another on talent, and a marquee hire raises the bar for what a credible security leader looks like across the sector. It also tightens an already thin market for CISOs who combine regulatory fluency, board presence, and real operational depth. Financial firms competing for that talent should expect compensation and mandate to keep climbing, and should think hard about whether they are developing internal successors or planning to buy from the same shallow pool. The scarcity is structural, and it will not ease soon.

There is a governance signal too. Giving the role the global and executive vice president framing, rather than burying it under a CIO, tells the market that U.S. Bank treats security as a board-level function with its own voice. Many enterprises still fold security under infrastructure, where it competes for attention and budget with uptime and delivery. The elevation of the CISO title, paired with a heavyweight occupant, is a template other regulated firms will study. For CIOs, the question it raises is uncomfortable and worth asking: does your security leader carry the authority this threat environment now requires?

The roadmap implication

For technology leaders, U.S. Bank's choice compresses several trends into one data point. Security leadership is being pulled toward resilience and recovery, toward AI and data protection, and toward the board, and the talent that can span all three is rare and expensive. The bank answered by hiring someone who has defended at national scale and operated inside two of the largest financial institutions in the world. Whether or not you run a bank, that combination now defines the ceiling of the role, and it sets expectations that will trickle down into how boards evaluate their own security chiefs over the next several cycles.

The practical move for CIOs and CTOs is to pressure-test their own security posture against this benchmark before an incident does it for them. Ask whether recovery is tested rather than assumed, whether AI pipelines were designed with security in the room, and whether the head of security can speak to the board without translation. U.S. Bank has made its answer visible with a single appointment. The firms that treat it as a prompt to examine their own arrangements will be readier for the regulatory and threat pressure still building than those that read it as merely another executive shuffle.

Tagged#news#people#leadership#cio#cto#cxo#us-bank#ciso#ann-barron-dicamillo#banking#financial-services#cyber-resilience#citi#us-cert#security-leadership#fs-isac