Ken Armstrong

CISO • Fintech + Healthtech

Open to opportunities, consulting, and conversations
Ken Armstrong Headshot

Security gets a bad reputation for slowing things down. I've made it my career to fix that.

For 15 years I've built security programs at fintech and healthtech companies, the kind of environments where you're staring down OCC examiners, PCI QSAs, and enterprise customer security reviews all at once, often with a team of three. The goal has always been the same: make security something the sales team leads with, not apologizes for.

Right now I'm at Tendo Systems, where I get to work on one of the harder problems in healthcare: keeping AI innovation moving without compromising patient data or regulatory standing.

Outside of work I spend my free time fishing for salmon and steelhead back in my native NW, listen to far to many podcasts, try to read a book a week or so, and play zone defense with my wife as we're outnumbered at home by our four kids.

Always happy to talk about building security programs that actually hold up.

📍 Based in Salt Lake City, Utah 🧰 Focus Security Compliance AWS AI ZTA
Résumé LinkedIn
15+Years Experience
14Active Certs
4Degrees
$10M+Revenue Impact

💼 Experience

Director, Information Security
Tendo Systems
View details →
Dec 2023 — Present
Position Summary

Led team securing and stabilizing controls and cloud infrastructure for Series B healthtech startup across AWS environments, AI/analytics platforms, and client installations. Owned SOC 2, PCI, TX-RAMP, and HIPAA compliance.

  • Developed initial security framework, strategy, budget, and control stack – bringing Tendo into compliance in first 30 days.
  • Saved >$250K/year in recurring spend by consolidating endpoint and cloud security controls post MDsave acquisition.
  • Led security due diligence and handover for a multimillion-dollar divestiture, delivering a secure and seamless transaction.
  • Drove >$10M in revenue by leading security pre-sales engineering, including assessments, panel reviews, and risk mitigations.
  • Onboarded Okta for all key business applications and desktops, bringing consistent and compliant access across Tendo.
  • Decreased untreated SAST, DAST, and SCA production vulnerabilities >95% through deployment of Tenable and Aikido.
  • Reduced endpoint vulnerability MTTR >90% by automating triage and remediation processes with Kandji and Action1.
  • Integrated Tendo and MDsave SOC 2 Type 2 and HIPAA audits into joint compliance framework, resulting in clean opinion.
  • Obtained PCI 4.0 QSA AOC & ROC in 35 days, meeting a customer deadline and securing a >$1M engagement.
Security Compliance Automation Manager
SoFi
View details →
Nov 2022 — Dec 2023
Position Summary

Led GRC projects providing oversight over technical and administrative controls across SoFi's multiple entities, including Galileo, Technisys, and Golden Pacific Bank. Developed compliance automation program, configuration management, and vulnerability management.

  • Automated SOC 2, ITGC/SOX, GLBA, PCI, OCC CWS, CRI Profile, FFIEC CAT, and NIST CSF evidence collection.
  • Led PCI 4.0 assessment: onboarded new QSA, evidence collection, remediation, and successful completion of clean report.
  • Developed new vulnerability management processes, dashboards, escalations, and reporting structure to address IA findings.
  • Accomplished 100% of assigned Q4 2022 – Q4 2023 key results within budget, schedule, scope, and established pass criteria.
Interim CISO / Information Security Manager
Varo Bank
View details →
Jun 2020 — Nov 2022
Position Summary

Led second line initiatives providing oversight, strategy, compliance, and governance over IAM, TPRM, DLP, physical security, and vulnerability management. Responsible for FFIEC CAT, PCI-DSS, and NIST CSF assessments for first chartered fintech bank (>$2.5B valuation, >1K staff, ~5M active accounts).

  • Led Information Security Program (team of 3) as Interim Chief Information Security Officer (CISO) Aug 2021 – Feb 2022.
  • Successfully represented Varo Bank as Security Officer for OCC and FDIC examinations, resulting in zero findings.
  • Developed, managed, and led initial assessments and documentation for OCC supporting successful bank open in Sep 2020.
  • Created advanced vendor security assessment, leveraging NIST CSF, GLBA, & FFIEC CAT to resolve TPRM deficiencies.
  • Eliminated 100% of IAM SLA violations by creating new automations, dashboards, alert mechanisms, and audit processes.
  • Improved endpoint vulnerability management SLA compliance >80% by developing new standard and remediation workflow.
  • Decreased MTTR >50% for dependency vulnerabilities by automating analysis, notification, and reporting processes.
  • Discovered critical vulnerability in production user-facing system, leading to >25% reduction in fraudulent transactions.
Security Consultant
HIPAA One
View details →
Jul 2019 — Jun 2020
Position Summary

Led security engagements and HIPAA security assessments for clients across >30 states supporting HIPAA One SaaS applications, including security risk assessments, vulnerability scanning, and penetration testing.

  • Completed 100% of assigned engagements within scope, schedule, and budget with 100% internal review pass rate.
  • Generated >$100K in additional revenue in Q2 2020 by developing Advanced Technical Baseline and NIST CSF products.
  • Clients included Centene, UnitedHealth, Global Payments, Domo, The Ohio State University, and the City of Santa Monica.
  • Implemented automation to eliminate redundant assessment processes, saving up to several days per engagement.
Information Security Manager
Valley Behavioral Health
View details →
Jan 2018 — Jul 2019
Position Summary

Led security and cloud operations (team of 4) for largest behavioral health organization in Utah with >20K patients, >70 units, and >30 locations. Managed >$100K budget and held Security Officer role for GRC compliance.

  • Improved performance of EMR >50% by leading migration to AWS to resolve systemic performance and DR/BCP issues.
  • Reduced password ticket volume >40% by rolling out SSO and aligning authentication standard with NIST SP 800-63B.
  • Deployed multi-factor authentication to >1K accounts for all remote access and business applications on-time and budget.
  • Decreased BYOD support ticket volume >40% by designing and implementing new standard, policy, and procedure.
  • Cut phishing rates >80% by implementing KnowBe4 security awareness training and testing across organization.
  • Pushed Jamf remote management to >200 iOS devices, decreasing unscheduled downtime and support volume by >50%.
  • Procured and deployed SentinelOne EDR across all organization assets (>900 endpoints) on-time and under budget.
IT Program Manager
Valley Behavioral Health
View details →
Mar 2016 — Jan 2018
Position Summary

Advanced security, development, and operations of EMR deployment (>$60M/year, >3K services/daily, >1K users). Led administration of application servers, databases, and load balancers. Designated interim Security Officer and created security team.

  • Reduced unplanned EMR outages >90% by overhauling infrastructure, administration practices, and development practices.
  • Generated >$700K additional annual revenue by designing and leading implementation of internal laboratory billing system.
  • Improved EMR performance >40% by deploying APM tools, identifying constraints, and optimizing backend processes.
  • Cut labor costs >40% while improving throughput >50% by designing new secure document processing workflow.
  • Designed transition from failing Parallels 2x VDI implementation, resulting in >50% decrease in EMR support requests.
  • Created HIPAA, HITECH, Meaningful Use, and State audit programs, satisfying requirements on-time and under budget.
MBA Intern
Valley Behavioral Health
May - Aug 2015
Web Developer
Decagon Devices
Dec 2010 — Mar 2014
Web Developer
Washington State University
May 2008 — Aug 2010
Help Desk Manager
Washington State University
Apr 2006 — May 2008

🎓 Education

MS in Information Systems
University of Utah
Graduated Dec 2018
Verify
MBA
University of Utah
Graduated May 2016
Verify
BSBA in Accounting
Western Governors University (COVID project)
Graduated Jan 2022
Verify
BA in Economics
Washington State University
Graduated May 2007
Verify

🏆 Active Certifications

Certified Information Systems Security Professional (CISSP)
(ISC)2
Issued Mar 2017
Verify
Certified Cloud Security Professional (CCSP)
(ISC)2
Issued Apr 2017
Verify
HealthCare Information Security and Privacy Practitioner (HCISPP)
(ISC)2
Issued Apr 2017
Verify
Information Systems Security Management Professional (ISSMP)
(ISC)2
Issued Sep 2017
Verify
Information Systems Security Engineering Professional (ISSEP)
(ISC)2
Issued Sep 2023
Verify
Certified Information Security Manager (CISM)
ISACA
Issued Mar 2019
Verify
Certified Information Security Auditor (CISA)
ISACA
Issued Apr 2019
Verify
Certified in Risk and Information Systems Control (CRISC)
ISACA
Issued Mar 2019
Verify
Certified in the Governance of Enterprise IT (CGEIT)
ISACA
Issued Feb 2022
Verify
Certified Data Privacy Solutions Engineer (CDPSE)
ISACA
Issued May 2023
Verify
Advanced in AI Security Management (AAISM)
ISACA
Issued Dec 2025
Verify
Advanced in AI Audit (AAIA)
ISACA
Issued Jan 2026
Verify
Certified Information Privacy Professional/United States (CIPP/US)
IAPP
Issued Feb 2022
Verify
Project Management Professional (PMP)
PMI
Issued Jun 2017
Verify
Professional Scrum Master 1 (PSM 1)
PMI
Issued May 2023
Verify

🚀 Projects

Kernel of Truth
Side Project

A digital provenance platform for creating cryptographic records of content claims. Generates SHA-256 fingerprints of text, quotes, documents, and images, then registers an immutable timestamped record. Everything is processed in the browser so the actual content never leaves the user's device — only the fingerprint gets stored. Produces shareable verification URLs so anyone can confirm a claim without the original content being exposed. Includes an API and webhook support for programmatic integration. Built in response to how easily AI systems remix and misattribute content at scale, with the goal of giving anyone a simple way to establish what they actually said and when.

NBAPrimes
Side Project

A personal project born from curiosity about whether prime numbers appear in NBA final scores more or less often than chance would predict. Built full-stack with statistical significance testing, score density heatmaps, historical era analysis back to the 1976 ABA merger, and Mastodon integration. Less about basketball, more about whether the data says anything, and being honest when it doesn't.

OmniaCrypta
Side Project

A free, privacy-first cryptographic toolkit that runs entirely in the browser. No accounts, no servers, no tracking — everything stays on your device. Built because strong cryptography has always belonged to institutions and governments, and that shouldn't be true anymore. Covers one-time pads with full mathematical proofs, RSA key generation and encryption, password and diceware generation with entropy analysis, and base conversion utilities. Every feature ships with enough explanation that a curious person can follow the math, not just trust the output.

OCRStats
Side Project

An analytics dashboard for HIPAA breach data reported to the HHS Office for Civil Rights. Pulls from the public OCR breach portal and presents it in a user friendly way: interactive charts, geographic breakdowns, breach type cross-tab analysis, repeat offender tracking, and filterable breach records with CSV and JSON export.

Security Now CPE
Side Project

Steve Gibson's Security Now podcast has been a fixture of my career in information security. When I started submitting it for CPE credit with ISACA and (ISC)2, credits kept getting rejected because I had no way to document completion. This site fixes that. It generates quizzes from the official episode transcripts and issues verifiable certificates when you pass. Certificates carry a SHA-256 hash and a cryptographically signed verification URL so any auditor can confirm authenticity, with no personal data stored on the server. Everything identifying stays in your own browser. Built as a fan project out of genuine respect for what Steve and Leo have built over 20 years.