I'm

CHUCK PEWITT

Enterprise Security Leadership, Risk and Compliance, Security Architecture, Identity and Zero Trust, Incident Preparedness, Fraud and Revenue Protection, Cloud and DevSecOps

About

About Me

Cybersecurity and Technology Leader

Strategic cybersecurity leader with 20+ years experience architecting and governing enterprise scale security programs across Fortune 30 retail and distributed environments supporting 300k+ associates and 2000* locations. Operates at the intersection of governance, architecture and risk management, translating cyber exposure into measurable operations and financial impact.

Design and execute measurable security transformation programs that reduce risk exposure, lower operating costs, and improve delivery velocity. Experience includes defending against Advanced Persistent Threat actors, executive level reporting, integrating security into mergers and divestitures, securing multi-cloud estates, and deploying Zero Trust architectures at enterprise scale.

Approach cybersecurity as a disciplined business function. Establish clear standards, operational accountability, and analytics-driven KPIs that enable executive leadership to make risk-informed investment decisions.

Accountability, Credibility, and Collaboration

Core Capabilities:

  • Enterprise Cybersecurity Strategy & Executive Reporting
  • Governance, Risk & Compliance (PCI-DSS, SOX, HIPAA, GDPR, CCPA, SOC 1/2)
  • NIST CSF, NIST 800-53, 800-61, 800-171, 800-190
  • MITRE ATT&CK
  • AI/ML Security & Governance
  • Zero Trust Architecture & Identity Modernization
  • Multi-Cloud Security (AWS, Azure, GCP, OCI)
  • DevSecOps, Policy-as-Code, CI/CD/CA (Continuous Assurance)
  • Security Operations, MSSP, MDR/SOAR, Incident Response
  • Mergers, Acquisitions & Divestitures Security Integration
  • OT, IoT, and SCADA Security (NIST 800-82)

Standard of performance: measurable risk reduction, sustained audit readiness, optimized security spend, and protection of revenue-critical operations.

Current Position: BISO
Business Information Security Officer, Security Architect @ Lowe's Company, Inc.
Mobile Phone:
(Text Before Calling)
Email: email me
City: Charlotte, North Carolina

Experience

Education & Experience

My Education & Certifications

Bachelor of Arts - Management and Human Relations

Trevecca Nazarene University | 2000-2002

Coursework focused on ethical leadership, HR law, talent development, and organizational behavior.

Biology & Computer Science

University of Tennessee at Martin |

Biology major explores life at the molecular level with an emphasis on cells, proteins, and DNA. Computer Science minor emphasizes the mathematical and theoretical foundations of computing.

General Studies

Volunteer State Community College

Associates in Computer Science.

CCNA

CISCO | 2014

Certified Cisco Network Associate.

CISM

ISACA | In Progress - testing May 2026

Certified Information Security Manager.

My Experience

BISO, Security Architect - GRC

Lowe's | 2025 - PRESENT

Accountable for enterprise cyber risk, security architecture, and risk governance for business domains. Aligning and mapping security and risk to overall business objectives and risk appetite.

Senior Manager Security Architecture - Global

Lowe's | 2020 - 2025

Led Security Architecture Infrastructure Team for a Fortune 30 retailer (2,000 stores; 310k associates; 250k+ endpoints). Standardized enterprise patterns, modernized identity, and drove risk-based roadmaps across data centers and multi-cloud estates.

Manager IT

31-W Insulation | 2017 - 2020

Secured and operated a hybrid environment across 35+ locations. Introduced redundant architecture, strengthened security controls, and improved service reliability for on-prem and cloud environments.

Network Administrator

Cracker Barrel Old Country Stores | 2005 - 2017

Network and security engineering for hybrid environment across 650 locations, 130K Sq Ft Distribution Center, Aviation and Hotel. Moderninzing security platforms and hardening perimeter, Core Data center, segmentation, and monitoring.

Security Analyst

Sumner Regional Health Systems | 2004 - 2005

Responsible for network and information security for regional healthcare facilities including hospitals, urgent care and related remote sites. Responsible for security policies and guidelines creation and adherence for regulatory compliance. Network security and monitoring.

Network Analyst

Sumner Regional Health Systems | 1994 - 2005

Responsible for network and infrastructure for regional healthcare facilities and remote sites.








Service

Volunteer

Member - Volunteer
LKNITP Peer Group

Member Lake Norman IT Professionals peer group—recruiting members, curating topics, and facilitating leadership dialogues that compound learning.

Read More

SIM Charlotte
Member

Member of SIM Charlotte—advancing STEM and Women-in-Tech through community events and partner engagement.

Read More

Personal

Fishing • Hockey • Golf

©chuckpewitt.com. All Rights Reserved. Designed by ME

```