About Emil Chukalov

I lead security where decisions become systems.

I’m a cybersecurity leader and engineer with 19+ years across enterprise technology and cybersecurity, including more than a decade in dedicated security roles.

My work has moved between executive decisions and the engineering underneath them: security programs, architecture, vulnerability and exposure management, adversary simulation, automation, and the teams that make those systems operate.

Portrait of Emil Chukalov
Security leadership grounded in engineering.

19+ yearsEnterprise technology and cybersecurity

100K+ hosts · 4K+ applicationsPrograms operated at enterprise scale

Teams of over 20Built, coached, and led through change

Why I write

Security at Depth examines what the summary leaves out.

A score, framework, or executive dashboard may be directionally useful. Its real value depends on the assumptions, data, architecture, incentives, and operating choices beneath it.

I publish independent insights for leaders and practitioners who need to make those layers visible. Each article connects a security decision to implementation evidence and closes with a lesson that can improve the next decision.

Career arc

Built from infrastructure upward.

Enterprise operations led to security engineering, program building, organizational leadership, governance, and independent product work.

  1. 2025 — present

    Engenso LLC

    Principal Cybersecurity Advisor

    Advisory work and hands-on product development spanning secure architecture, private and multi-cloud infrastructure, MCP integrations, and review-first AI controls.

  2. 2022 — 2024

    Fifth Third Bank

    Vice President & Director, Information Security Engineering

    Led multidisciplinary security-engineering scope, overhauled application security and vulnerability management, built the enterprise bug bounty program, and owned the company-wide information security policy and standards framework.

  3. 2017 — 2022

    Freddie Mac

    Director, Information Security Engineering

    Scaled vulnerability management and penetration testing, grew the team from two to over 20, and established Red and Purple Team exercises—including an automated exercise that ran 2,000 TTP simulations in parallel.

  4. 2016 — 2017

    Axxum Technologies

    Information Security Consultant

    Built Freddie Mac’s enterprise vulnerability-management and penetration-testing programs from the ground up before joining the organization full time.

  5. 2013 — 2016

    Booz Allen Hamilton

    Lead Security Engineer · Penetration Tester

    Built the enterprise vulnerability-management program, completed a zero-disruption platform migration, then moved to Red Team penetration testing, adversary simulation, and threat hunting.

  6. 2007 — 2013

    CompuCom

    Lead Systems Engineer

    Led enterprise infrastructure and security engineering work supporting more than 25,000 users—the operating foundation for the security leadership roles that followed.

Governance beyond the enterprise

Board service with operating responsibility.

Board of Directors · Executive Committee · Finance/Audit Committee Chair

Love The Golden Rule Inc. · 2025–2026

Governance, compliance, and technology-risk oversight for a federally funded healthcare nonprofit with 340B pharmacy operations.

Education

Master of Science, Information Security

George Mason University · Summa Cum Laude

Primary credentials

  • CISSP
  • GSLC
  • GCSA
  • GCPN
  • GXPN
  • OSCP

Working principles

How I approach the work.

  • Start with the decision

    Name the owner, the tradeoff, and the evidence required before choosing a control or committing resources.

  • Trace the claim to the system

    Dashboards summarize. Architecture, data lineage, incentives, and operating behavior determine whether the summary deserves trust.

  • Keep strategy buildable

    Leadership has to create direction that engineering teams can implement, verify, and improve without guesswork.

Read next

Follow the decision, then inspect the system beneath it.