Profile: Prem Patel, Director of Cybersecurity Operations, ACV Auctions
Published On: September 15, 2026

Premal “Prem” Patel’s path into cybersecurity began with curiosity. Growing up, he was always interested in understanding how things worked, often taking them apart and finding a way to put them back together. Yet technology was not initially where he imagined building his career.
Prem entered college on a medical pathway with plans to become a doctor. During his second year, he reconsidered that direction and turned toward an interest that felt more natural. He added computer science alongside biology for his undergraduate studies and later earned a master’s degree in cybersecurity.
“I’d rather be tinkering, breaking things, and hacking things,” he recalls of discovering cybersecurity as a career path.
Prem began gaining professional experience while still in school through a co-op at MIT Lincoln Laboratory, where he had the opportunity to work with the Department of Defense. The experience introduced him to the structure and discipline of cybersecurity within government and helped establish the technical foundation that would shape his career.
From there, he moved into consulting with Deloitte and Ernst & Young. Working across industries including healthcare, financial services, automotive, oil and gas, and aviation gave Prem exposure to organizations with very different priorities and risk environments. It also taught him to think about cybersecurity through the lens of the business it protects.
Building the Next Stage at ACV
In 2026 Prem joined ACV Auctions as Director of Cybersecurity Operations. His initial conversations with the CISO and the broader team immediately stood out.
ACV presented the kind of challenge that aligned with his experience. The organization had evolved from its startup roots following its IPO, creating an opportunity to continue maturing the security capabilities alongside the business.
Prem saw a chance to bring together lessons from his consulting and industry experience to help evolve cybersecurity operations into a more mature function. His vision includes growing a team that began with only a few people into a globally supported operation capable of providing coverage around the clock.
His responsibilities extend across incident response, security operations and threat detection and response, while also touching areas including identity and access management, third party risk management and security awareness. As AI becomes increasingly embedded within the business, AI security has emerged as another important area of focus.
Creating the Foundation for AI Security
Prem views AI as a double-edged sword, where its ability to improve productivity is significant, but the same technology is also accelerating risk.
For security leaders, he believes two areas have become particularly important: data and identity. Organizations need visibility into where data resides, where it moves, and who or what can access it. That last distinction is increasingly important as nonhuman identities and AI agents begin operating at a scale traditional identity programs were not necessarily designed to address.
At ACV, AI is beginning to influence both development and products, making those foundational controls increasingly important. Prem believes the broader security mindset must evolve with it.
“We went from security as reactive to proactive to now zero trust and assumed breach,” he explains. AI can accelerate the exploitation of vulnerabilities from days or weeks to hours or minutes, requiring organizations to rethink how quickly their defensive capabilities can respond.
That does not mean Prem believes organizations should slow innovation. Instead, he sees security’s responsibility as helping the business adopt AI responsibly while understanding its risks. “We don’t want to be a roadblock or a gatekeeper,” he says. “It’s more of the fact that we want to create guardrails for the path forward.”
Those guardrails also need to demonstrate business value. As organizations invest heavily in AI, Prem believes security leaders will increasingly need to communicate whether those investments are delivering meaningful returns while ensuring the technology is being implemented with a safe, secure, and compliant perspective.
Going Down the Rabbit Hole
Keeping pace with AI requires more than following headlines. Prem has adopted advice from one of his mentors to choose a topic and go deeply into it until he holistically understands how the technology works.
For AI, that has meant studying technologies such as Model Context Protocol and APIs rather than limiting his focus to their security implications. Prem wants to understand the underlying technology first, then translate that understanding into practical controls. “The biggest piece is, how do you take that theoretical aspect and then operationalize it?” he says.
That question becomes increasingly significant as organizations introduce AI agents capable of interacting with sensitive systems and information. Prem believes access needs clear checks and balances, particularly when agents are connected to environments such as email or corporate data. Human oversight remains an important part of that model.
“There always has to be some sort of human in the loop to make sure that there is a certain level of checks and balances for that agent,” he explains.
Translating Security Into Business Value
Prem’s consulting background has also influenced how he communicates cybersecurity. Working across industries taught him that the technical risk may change, but the most important question remains consistent: who is ultimately impacted?
Prem says that for healthcare organizations, that might mean protecting patients and their sensitive information. In another industry, the priority may look entirely different. Understanding that context allows him to connect cybersecurity decisions to what matters most to the organization and its customers.
That perspective shapes how he communicates with both technical and nontechnical audiences. “It’s an art of doing the technical to nontechnical,” Prem explains. “Keep it simple to the point where they can understand it as well. Because we can communicate as much as we want, but if they don’t understand it, then what’s the point?”
For Prem, effective communication begins by understanding the other person’s perspective rather than expecting them to adopt the language of cybersecurity. That ability has become important as security moves closer to business strategy and leaders are asked to explain emerging risks such as AI to audiences across the organization.
Learning Through Leadership
Prem approaches leadership with the same curiosity that initially drew him toward cybersecurity. While becoming a CISO or moving into another senior technology leadership role is a long-term goal, he is focused on continuing to learn before getting there.
“I value the failures much more than the successes because that’s how you grow as a leader,” he says. “That’s how you grow as a person as well.”
Much of that growth comes from the people Prem has intentionally surrounded himself with. In addition to formal leadership training and independent learning, he has developed a network of mentors he can turn to when working through difficult decisions. His core group of mentors spans leaders with experience running large organizations, building businesses, and creating cybersecurity companies.
Prem encourages emerging cybersecurity professionals to build those relationships by being willing to make the first move. “The answer will always be ‘no’ if you don’t ask,” he says. “You must put your foot forward to be able to say, ‘Hey, I genuinely want to learn.’”
That willingness to keep learning is particularly important as cybersecurity enters another period of rapid change. Prem believes the industry is still determining what mature AI security will ultimately look like. Organizations are experimenting, learning where gaps exist and beginning to establish more consistent controls. He expects greater standardization to emerge as the technology and security practices surrounding it mature.
For Prem, navigating that uncertainty comes back to the same approach that has shaped his career: understand the technology deeply, connect security to the people and business it protects, and remain willing to learn as the landscape changes.
Subscribe
Stay up to date with cyber security trends and more
