Profile / About

Hi, I'm Adalberto.

Adalberto Trujillo

I am a cyber risk, policy, and systems security practitioner working at the convergence of enterprise IT, risk mitigation, and emerging technology policy.

IT infrastructure came first, policy second. Ten years of running enterprise systems taught me that most security problems are decision problems, and I am drawn to the gap between what a finding says and what leadership can act on. The test I care about is whether the mission still runs when something fails.

My approach follows that order: start with how the systems actually run, assess the controls against NIST CSF, NIST 800-53, and ISO 27001, write the policy that makes them enforceable, and build the risk cases decision-makers can act on directly. I am strongest at the point where a technical finding has to become a decision.

I also understand the other side of the brief firsthand. At CUNY, I support a 1,000-plus user institutional environment and serve as the escalation authority for cabinet-level and senior leadership technology issues. I know what breaks when a recommendation ignores how the systems are actually run.

As technical lead on a DHS Office of Strategy, Policy, and Plans engagement, I briefed smart city infrastructure risk to a Deputy Under Secretary and more than fifty DHS Science and Technology personnel.

I am particularly interested in the work frameworks alone cannot do: deciding which risk actually matters, getting leadership aligned on it, and writing the policy people will follow. Frameworks give a program its structure. Judgment decides what it protects first.

Currently exploring full-time opportunities in New York in infrastructure security, security operations, GRC, and cyber policy. If that is what you are building, let's talk.

Experience

IT Specialist / Cybersecurity Liaison

2018 — Present

The City University of New York

Serve as the cybersecurity liaison between IT and 25,000+ users at one of the largest urban university systems in the U.S. Lead vulnerability assessment, security awareness, policy and standards development, systems administration, identity and access management, and service operations across campus systems.

Cyber Security Consultant — Project Lead

2022

U.S. Department of Homeland Security

Planned and executed an all-of-society digital network architecture and technology horizon-scanning effort. Delivered threat and vulnerability analysis on emergent technologies, executive research briefings on smart-city and mission-critical cyber-physical systems, and policy development for technology risk and network security — presented to DHS Science & Technology leadership.

Strategic Technology Development Consultant

2022

Freelance

Used analytic tools, data, and frameworks to develop technical solutions and present them to senior stakeholders; built implementation plans for deploying new technology solutions.

Information Technology Support Assistant

2016 — 2018

The City University of New York

Provided first-level support across computer hardware, repair, and help desk operations; maintained and resolved hardware, software, and network issues across campus.

Education

M.S., Global Security, Conflict, and Cybercrime

New York University

Cyber Strategic Planning & Policy specialization, Center for Global Affairs, 2020–2022. NYU Cyber Security Club, NYU Cyber Policy Professional Society, Atlantic Council Cyber 9/12 Strategy Competition (Washington DC, 2022).

B.S., Criminal Justice — Minor, Cybercrime

John Jay College (CUNY)

Cum Laude. Focus on cyberlaw, legal research and analysis, and computer forensics.

Focus areas

Cyber Risk, Policy & StrategyCyber Threat IntelligenceEnterprise IT & Security OperationsSystems Security EngineeringThreat & Vulnerability AssessmentIncident ResponseIdentity & Access ManagementNetwork & Endpoint SecuritySecurity Policy & Standards DevelopmentRisk, Governance & ComplianceBusiness Continuity & ResilienceStrategic Planning