About Emil Chukalov
I lead security where decisions become systems.
I’m a cybersecurity leader and engineer with 19+ years across enterprise technology and cybersecurity, including more than a decade in dedicated security roles.
My work has moved between executive decisions and the engineering underneath them: security programs, architecture, vulnerability and exposure management, adversary simulation, automation, and the teams that make those systems operate.

19+ yearsEnterprise technology and cybersecurity
100K+ hosts · 4K+ applicationsPrograms operated at enterprise scale
Teams of over 20Built, coached, and led through change
Why I write
Security at Depth examines what the summary leaves out.
A score, framework, or executive dashboard may be directionally useful. Its real value depends on the assumptions, data, architecture, incentives, and operating choices beneath it.
I publish independent insights for leaders and practitioners who need to make those layers visible. Each article connects a security decision to implementation evidence and closes with a lesson that can improve the next decision.
Career arc
Built from infrastructure upward.
Enterprise operations led to security engineering, program building, organizational leadership, governance, and independent product work.
2025 — present
Engenso LLC
Principal Cybersecurity Advisor
Advisory work and hands-on product development spanning secure architecture, private and multi-cloud infrastructure, MCP integrations, and review-first AI controls.
2022 — 2024
Fifth Third Bank
Vice President & Director, Information Security Engineering
Led multidisciplinary security-engineering scope, overhauled application security and vulnerability management, built the enterprise bug bounty program, and owned the company-wide information security policy and standards framework.
2017 — 2022
Freddie Mac
Director, Information Security Engineering
Scaled vulnerability management and penetration testing, grew the team from two to over 20, and established Red and Purple Team exercises—including an automated exercise that ran 2,000 TTP simulations in parallel.
2016 — 2017
Axxum Technologies
Information Security Consultant
Built Freddie Mac’s enterprise vulnerability-management and penetration-testing programs from the ground up before joining the organization full time.
2013 — 2016
Booz Allen Hamilton
Lead Security Engineer · Penetration Tester
Built the enterprise vulnerability-management program, completed a zero-disruption platform migration, then moved to Red Team penetration testing, adversary simulation, and threat hunting.
2007 — 2013
CompuCom
Lead Systems Engineer
Led enterprise infrastructure and security engineering work supporting more than 25,000 users—the operating foundation for the security leadership roles that followed.
Governance beyond the enterprise
Board service with operating responsibility.
Board of Directors · Executive Committee · Finance/Audit Committee Chair
Love The Golden Rule Inc. · 2025–2026
Governance, compliance, and technology-risk oversight for a federally funded healthcare nonprofit with 340B pharmacy operations.
Education
Master of Science, Information Security
George Mason University · Summa Cum Laude
Primary credentials
- CISSP
- GSLC
- GCSA
- GCPN
- GXPN
- OSCP
Working principles
How I approach the work.
Start with the decision
Name the owner, the tradeoff, and the evidence required before choosing a control or committing resources.
Trace the claim to the system
Dashboards summarize. Architecture, data lineage, incentives, and operating behavior determine whether the summary deserves trust.
Keep strategy buildable
Leadership has to create direction that engineering teams can implement, verify, and improve without guesswork.
Read next