Profile: Don Baham, Chief Information and Security Officer
Published On: September 15, 2026

Don Baham began his career in system administration, working across computers, servers, and networks before expanding into more client-facing positions. Over time, he moved between technical and more business focused roles, including professional services, sales engineering, and software training. That range of experience gave him an early ability to understand technology while also communicating its value to stakeholders.
“I enjoyed working with clients and being out in front, but I also enjoyed the technical side of things,” Don recalls. “I think that has helped me throughout my career.”
His path into cybersecurity came while working for a managed service provider, where a manager gave him the opportunity to take on security related responsibilities. He started with penetration testing, red teaming, and social engineering, gaining firsthand experience testing organizations from an attacker’s perspective.
From there, Don’s career increasingly moved toward security leadership and program building, setting the foundation for the work he leads today.
A Passion for Building
As Don gained experience, his career began shifting toward leadership. He started managing small teams and quickly discovered that developing people was something he genuinely enjoyed.
“The thing about leading people is that you don’t really know if you’re going to enjoy it until you do it,” he reflects. “I started doing it with small teams and found I really loved investing in the team, team culture, company culture, and the next generation.”
For approximately 15 years, people leadership has remained an important part of his career. At the same time, another pattern began to emerge. Don was repeatedly drawn to organizations undergoing transformation or acquisition, where he could help create something rather than simply maintain what was already there.
“I’m not really a maintainer,” Don explains. “I’m a builder. I like to build things. I like to mature and grow programs. I’m not really one to come in and take over and just sit on the program. So, this is an environment that suits my style.”
Building Security Across a Portfolio
Today, Don serves as Chief Information and Security Officer at Rubicon Founders, where his responsibilities extend across approximately 15 portfolio companies. With Rubicon both investing in and launching businesses, his role gives him the opportunity to build security and technology programs at very different stages of maturity.
For newly formed companies, Don is involved from the beginning, helping establish the technology architecture and security program while guiding key platform decisions. His team provides that foundation until the organization is ready to bring in its own leadership or transition day-to-day responsibilities to an outside partner.
As companies mature, Don’s role shifts from building to advising. He works with technology leaders across the portfolio, creating opportunities to share resources and learn from one another while maintaining visibility into cyber risk across the fund. This allows Rubicon to identify where a company may need additional support and where greater maturity is required.
That foundation can be particularly important within healthcare. Some of Rubicon’s companies begin with significant payer relationships, which means they may be handling sensitive information such as PHI. They do not have the luxury of waiting years for their security programs to mature.
For Don, it is a model that plays directly into one of the strengths that has defined his career. Rather than maintaining a single established program, he is able to repeatedly build, strengthen, and potentially hand off programs designed to grow alongside the businesses they support.
Connecting Security to Business Value
Despite Don’s technical background, his priorities today extend well beyond technology.
As Don’s career has evolved, so has his view of the CISO role. Technical expertise remains important, but he believes security leaders must understand how their work supports the broader organization.
He explains, “At this point in my career it is about integrating with business operations, enabling the business, and translating what we are working on back to business value.”
The fundamentals of security remain important, but Don believes a security organization becomes a strategic part of the business when it understands where the company is going and ensures its priorities support that direction.
Finding the Right Approach to AI
As Rubicon and its portfolio companies expand their use of AI, Don is focused on balancing responsible adoption with business value. As an investment firm regulated by the SEC with exposure to healthcare data, Rubicon must consider where sensitive information can go and which AI platforms are appropriate for different types of data.
For Don, that starts with governance and acceptable use policies with specific parameters around their different types of data. The goal is not to restrict adoption, Don explains, “We want to enable the business while reducing the risk that comes with broader AI use.”
Now, he sees the conversation moving beyond access and toward value. Rubicon has enabled multiple generative AI platforms, but the more important question is what organizations are accomplishing with them.
“How do we actually use it to create value for the firm or for a portfolio company or both?” he asks. With organizations spending heavily on AI, Don believes measuring that investment against real business outcomes will become increasingly important. For him, that is the next stage of AI maturity: creating enough structure to use the technology responsibly while ensuring the investment is improving the business.
Leading Through Trust
Don’s approach to leadership has evolved considerably since he first began managing people. Early on, delegation did not come naturally. He admits that his instinct was often to handle something himself if he wanted to ensure it was done correctly. A mentor eventually showed him another approach, one that continues to influence how he leads today.
“The way I approach leadership is that it all starts and ends with trust,” Don shares. “I try to empower the team to take on additional responsibilities that probably push them out of their comfort zone, and then give them the autonomy to go execute.”
There is a balance to that autonomy as sometimes a leader needs to provide more direction or accountability. But Don has found that giving people room to work through challenges often produces better outcomes while creating opportunities for growth.
“More often than not, it allows team members to grow and create something or do something in a way that you hadn’t thought of,” he explains. “And that’s fun and exciting to see how people solve problems.”
“I’m trying to encourage people to experiment and learn how to figure things out, not just rely on a Google search, asking me a question, or asking Claude a question,” he explains. “Go figure something out and come back with answers or some options. But I don’t want to be the one feeding answers.”
It is an approach built around giving people enough trust to stretch themselves, while remaining available to support them along the way.
Continuing to Grow
Don holds himself to the same expectation for continued growth. “I moved from California to Nashville thirteen years ago and didn’t know anybody. I started by getting into local associations and building my network,” he recalls. “I’m an introvert by nature, but forcing myself to just get out there has helped me build a great network.”
Today, Don participates in several national peer groups and has continued investing in formal executive education. Last year, he completed a Chief Information and Digital Officer certificate program through Carnegie Mellon and is currently preparing for another program focused on board leadership and executive development.
Today, the common thread is clear. Whether he is standing up security for a new portfolio company or evaluating how AI can create measurable value, Don continues to gravitate toward opportunities to build something better.
Subscribe
Stay up to date with cyber security trends and more
