GAVIN LUJAN8 · 15 · 2026 · CISO / CIO EXECUTIVE

CISO · CIO · Statewide Cybersecurity · Research Computing · Responsible AI

Gavin
Lujan

New Mexico technology executive, CISSP and CCSP, with 25+ years spanning CIO leadership, cybersecurity governance, Linux and mission-critical computing, statewide networking, cloud and virtualization, enterprise modernization, GIS, responsible AI, Agile/Scrum delivery, education, and public service. Combines executive judgment and communication with a hands-on technical foundation — protecting the mission while enabling people to do their best work.

25+ Years in technology
CISSP Security leadership
CCSP Cloud security
HPC Linux · mission critical

EXECUTIVE FIT · 8.8.2026

Two leadership lanes.
One operating philosophy.

STATEWIDE CYBERSECURITY

CISO leadership

Cybersecurity governance, enterprise risk, policy, NIST CSF/RMF/800-53, Zero Trust, cloud security, identity, resilience, incident readiness, compliance evidence and executive communication. CISSP and CCSP certified, with continuing CGRC-aligned governance, risk and compliance study.

RESEARCH + ADVANCED COMPUTING

CIO leadership

Linux and mission-critical clustered computing, high-speed interconnects, enterprise networking, virtualization, cloud, storage, multi-site operations, disaster recovery, technical teams, budgets, procurement, vendors and executive technology strategy.

PEOPLE + DELIVERY

Human-centered Agile

Scrum/Agile discovery and delivery, clear priorities, coaching, facilitation, stakeholder alignment and plainspoken communication. Values employees as the force that turns strategy into durable outcomes.

RESPONSIBLE AI

Govern it. Use it. Learn fast.

AI is a game-changing capability to be welcomed with responsible stewardship: clear human accountability, bounded permissions, secure data, auditability, transparency and mission-focused adoption.

TIME STEWARDSHIP Time is our most finite asset. Prioritize deliberately, protect focus, delegate with trust, automate responsibly, and reserve human attention for judgment and relationships.

Executive Summary

Strategy translated into action.

Public-sector CIO recognized for converting complex mission needs into governed, funded, secure, and executable transformation portfolios. Brings the security depth for enterprise CISO leadership together with infrastructure roots in Linux, clustered computing, high-speed networking, virtualization and multi-site operations. Leads executive steering, cybersecurity governance, budgets, procurement, architecture, cloud adoption, modernization and Agile delivery.

Known for translating between executives, engineers, researchers, program leaders, vendors, educators, and the public. Builds shared language, clear decision rights, visible risk evidence, practical roadmaps, and teams where people are trusted, developed, and accountable. Treats responsible AI as both a strategic opportunity and a governance responsibility.

CIO Strategy NIST CSF 2.0 NIST RMF Zero Trust Enterprise Architecture Cyber Resilience Cloud Integration Responsible AI GIS DevSecOps Agile Product Delivery IT Governance Appropriation Strategy Executive Communication CISSP CCSP CGRC-aligned Study Linux / HPC Scrum / Agile Security Governance

Security Operating Model

Risk managed as a life cycle.

01 PREPARE
02 CATEGORIZE
03 SELECT
04 IMPLEMENT
05 ASSESS
06 AUTHORIZE
07 MONITOR

Selected Innovation Project · 2026

Portable AI Pen Tester Workstation.

Piranha Sensor · Hybrid AI Security Assessment

Designed and built a portable, containerized cybersecurity analyst workstation for authorized network assessments. The platform orchestrates specialized discovery and assessment agents — a “school of piranhas” — while a local AI analyst correlates evidence and generates a live web report visible to both the security analyst and customer.

  • Docker-based isolation creates a repeatable field deployment and separates tools, evidence services, models, and reporting components.
  • Local-first AI keeps sensitive analysis on the workstation, reduces cloud token consumption, and supports operation where privacy or connectivity is constrained.
  • Selective cloud AI provides higher-order reasoning when policy and data classification permit, creating a practical hybrid AI architecture.

Security engineering and governance

  • Designed as the root sensor for a broader cyber command dashboard, progressing from asset discovery to evidence-backed findings and prioritized remediation.
  • Live reporting turns technical observations into a shared, continuously updated assessment view for analysts, executives, and customers.
  • Rules of engagement enforce written authorization, explicit target scope, rate limits, non-destructive checks, data minimization, evidence integrity, audit logs, and human approval gates.
  • Architecture combines containerization, local models, agent orchestration, Zero Trust principles, telemetry, and human-accountable AI.

Professional Experience

Career leadership.

AUG 2025 · PRESENT Santa Fe, New Mexico

Chief Information Officer

State of New Mexico Office of the State Engineer

  • Provide executive leadership for technology supporting water administration, water rights, engineering, hydrology, field operations, GIS, and critical public infrastructure.
  • Direct IT governance, budgeting, cybersecurity, enterprise applications, infrastructure, architecture, vendor management, procurement, and modernization planning.
  • Serve as executive sponsor for WATERS modernization, establishing governance, stakeholder engagement, acquisition strategy, architecture direction, roadmaps, and executive decision structures.
  • Lead appropriation requests for enterprise document imaging, records digitization, workflow transformation, and modernization initiatives.
  • Advance cloud integration, API strategy, identity management, enterprise data, DevSecOps, mobility, interoperability, disaster recovery, and responsible AI adoption.
  • Align security governance with NIST CSF, RMF, Zero Trust, continuity planning, risk evidence, and continuous monitoring.
  • Champion responsible AI adoption with attention to human accountability, data protection, auditability, transparency, and appropriate authorization boundaries.
JUL 2022 · AUG 2025 New Mexico

Chief Information Officer

State of New Mexico Department of Game and Fish

  • Led Applications, Operations, and Security teams supporting statewide conservation, licensing, enforcement, grants, field operations, and public digital services.
  • Directed mission-critical online and vendor sales platforms processing more than 600,000 annual transactions and supporting more than $115 million in annual revenue.
  • Led modernization discovery, funding strategy, procurement, Agile delivery, cloud architecture evaluation, resilience planning, and executive technology governance.
  • Strengthened PCI compliance, vulnerability management, security awareness, penetration testing, continuity, and risk-based decision making across mission-critical public services.
  • Led Applications, Operations, and Security as an integrated executive portfolio, developing staff while creating clear accountability for service, risk, and delivery.
  • Facilitated discovery workshops, outcome mapping, epics, user stories, acceptance criteria, and delivery roadmaps across business and technology teams.
FEB 2016 · JUL 2022 New Mexico

Network Infrastructure Bureau Chief

State of New Mexico Department of Transportation

  • Directed statewide network, systems, security, telecommunications, enterprise infrastructure, vendor, and operational services supporting a distributed transportation mission.
  • Led the NMDOT broadband initiative, promoted Dig Once policy, and advanced fiber infrastructure and Smart Highway strategy.
  • Built interagency partnerships with educational institutions, local governments, public agencies, and industry stakeholders.
MAR 2013 · FEB 2016 New Mexico

System Administrator

State of New Mexico Children, Youth and Families Department

  • Implemented and administered VMware Horizon virtual desktop infrastructure, vSphere, ESXi, vCenter, and enterprise systems.
  • Supported secure, reliable computing services for statewide human-services operations.
APR 2009 · MAR 2013 Farmington / National

Technical Support Engineer · Mission Critical TAM

Hewlett-Packard

  • Delivered global technical support for mission-critical Linux computing clusters and high-speed network interconnects, building hands-on experience directly relevant to HPC and research-computing environments.
  • Applied ITIL practices to strengthen service delivery, incident coordination, communication, and operational discipline.
JAN 1999 · MAY 2008 Española, New Mexico

Adjunct Professor

Northern New Mexico College

  • Designed and taught courses in databases, cybersecurity, networking, computer technology, and information technology literacy.
  • Translated technical concepts into practical learning for students entering a changing technology workforce.
OCT 1998 · AUG 2007 Santa Fe, New Mexico

System and Network Administrator

Santa Fe County

  • Managed Cisco-based WAN, server, network, and user-support infrastructure serving county government operations.
  • Supported enterprise availability, security, telecommunications, and technology modernization.
FEB 1996 · OCT 1998 National User Base

IT Manager

CDK Contracting Company

  • Oversaw IT operations supporting a national user base, providing reliable enterprise technology services across a distributed organization.
  • Managed Novell NetWare and IBM AS/400 systems supporting core business operations.

Education & Credentials

Academic and professional foundation

  • Undergraduate education, University of New Mexico
  • Certified Information Systems Security Professional, CISSP
  • Certified Cloud Security Professional, CCSP
  • Geographic Information Systems Professional, GISP
  • ITIL v3 and Agile / Scrum practice
  • Continuing governance, risk and compliance training aligned to ISC2 CGRC domains

Executive Capabilities

Where strategy meets delivery

  • Cybersecurity governance, NIST CSF, RMF, 800-53, Zero Trust
  • Enterprise modernization, cloud, infrastructure, architecture, DevSecOps
  • Responsible AI, document intelligence, automation, enterprise search
  • GIS, data strategy, analytics, visualization, field enablement
  • Budgeting, appropriations, procurement, vendor and portfolio management
  • Linux, clustered / mission-critical computing, high-speed networking and virtualization
  • Facilitation, workshops, executive communication, employee development and change leadership
  • Portfolio prioritization, time stewardship, delegation and responsible automation / AI