Profile: Sean Calista, Sr Director of Information Technology and Security, CloudZero
Published On: September 15, 2026

Sean Calista discovered information security earlier than most. Before graduating from high school, he was already working at a cybersecurity company, writing detection signatures and gaining firsthand experience with security technologies.
He went on to study information security and network engineering at Rochester Institute of Technology, followed by a co-op and eventual role at MIT Lincoln Laboratory. Working within a federally funded research environment focused on national defense broadened his cybersecurity experience, but Sean ultimately found himself drawn back to the fast-paced startup environments where he had started his career.
That decision set the direction for what came next. Over the next two decades, Sean would build his career across security engineering, incident response, infrastructure, and leadership, often joining growing organizations where he had the opportunity to build and mature security programs.
Building Security From the Ground Up
Sean joined athenahealth in 2013 as one of the company’s early security hires, where his responsibilities included incident response, security engineering, and implementing controls to protect sensitive customer information. He later moved to LogMeIn, initially building security capabilities across the organization’s global corporate environment before shifting toward infrastructure security for its production systems.
It was during this period that Sean learned one of the lessons that continues to influence his approach today: the strongest security control is not necessarily the most restrictive one.
Working alongside his boss and mentor, Sean gained valuable skills including the important balance of integrating business objectives and security risk.
The experience helped Sean understand that security leaders must find the controls that are appropriate for their organization and its risk appetite rather than pursuing security in isolation.
That philosophy followed him through roles at Drift, TrueMotion, and Relay Therapeutics, where he repeatedly found himself joining organizations with little or relatively small security functions and helping build them into mature programs. At TrueMotion, he established the security incident response team and information security committee while developing the metrics and objectives needed to connect security strategy with business priorities. At Relay Therapeutics, he again helped establish the security program, including its framework, budget and objectives.
Building has become what Sean describes as his “bread and butter.” Today, he brings that experience to CloudZero, where he serves as Senior Director of Information Technology and Security and has spent the past several years building out the company’s security program.
Building Teams Around Your Weaknesses
As Sean has transitioned from technical practitioner to security leader, he has also learned that leadership does not require being the strongest person in every discipline.
His background is rooted heavily in incident response, infrastructure, and security engineering. When building the team at CloudZero, he deliberately looked beyond those strengths.
“I always have the mentality of focusing on, and augmenting, your weaknesses,” he explains.
Rather than hiring first in the areas he knew best, Sean prioritized expertise in areas where others could bring deeper knowledge. His first information security hire focused on application security, while another was brought in to lead governance, risk and compliance.
For Sean, surrounding himself with people who can bring greater depth to specific areas creates a stronger security organization while also allowing those individuals to grow as leaders themselves.
It reflects a larger lesson he has learned throughout his career: growth comes from recognizing what you do not know and surrounding yourself with people who can make you better.
Learning to Think Like the Business
Sean’s technical background is extensive, but his approach to security is equally grounded in business. Some of that perspective came from his upbringing. His father and grandfather worked in sales and business roles, exposing Sean to a different way of thinking than the engineering environment in which he ultimately built his career. But he credits much of his development to learning on the job and, in particular, learning from mentors.
Three people have had an especially significant influence: Chris Harrington, who gave Sean his first opportunity in the security industry at Nitro Security and later hired him at MIT Lincoln Laboratory; Gabor Tokaji when he was at LogMeIn & TrueMotion; and CloudZero founder Erik Peterson.
Sean believes aspiring leaders should seek out people who have already reached the level they hope to achieve. That philosophy has influenced how Sean evaluates his own career opportunities. The organization matters, but he believes the person you work for can have an even greater impact on your development.
“The most important thing is who your boss is,” Sean says.
At CloudZero, working for Peterson has helped Sean continue evolving from a technical security leader into a broader business executive as he works toward his long-term goal of becoming a CISO.
Finding the Balance With AI
The same balance Sean learned earlier in his career is becoming increasingly important as organizations adopt AI.
CloudZero itself sits directly within that evolution. The company helps organizations understand AI ROI, including how AI spending can be attributed to specific features and customers. As businesses invest significant amounts into AI, understanding whether that spending is delivering value is becoming an important business question.
From Sean’s perspective as a security leader, however, AI is also fundamentally changing who can build technology.
In his 20 years in information security, Sean says he cannot remember another point when people outside traditional technical roles could easily develop their own applications. AI has changed that. Finance and HR leaders can now build tools and applications themselves, creating opportunities for innovation while introducing a new set of security considerations.
Sean sees AI agents almost like another workforce that must be governed. They need the right access and the right data, and organizations need to think about how information is made available to them.
The challenge is doing that without undermining the innovation AI makes possible. “How can I keep the business moving fast on AI without sacrificing security? It’s a delicate balance.” Sean says.
Simply shutting AI down is not a viable strategy in his view. “If you don’t adapt with AI, you’re going to lose,” he says.
Instead, Sean believes organizations must understand the associated risks and establish controls that allow the business to move forward securely.
Making It Easy to Do the Right Thing
At CloudZero, one way Sean’s team is addressing this challenge is by creating what they call a “golden path.”
As employees across the organization gain the ability to build applications, security cannot assume everyone will understand the infrastructure and controls required to deploy them safely. Rather than expecting every employee to become a security expert, Sean wants to create an approved path that makes secure deployment easier.
That may mean providing designated cloud environments and incorporating protections such as identity controls so employees can implement applications with AI while limiting risk to the business.
The philosophy behind it is straightforward. “The way to win in this industry is to make it easy and do the right thing,” Sean says. “When you make it hard to do the right thing, that’s when things never go your way.”
That mindset extends beyond technology. Sean also believes security programs cannot scale if responsibility for security remains solely within the security team. CloudZero uses a security champions program to establish advocates throughout the business who can help extend the security team’s reach. As AI enables more employees to become builders themselves, those relationships are becoming even more valuable.
Giving the Next Generation a Chance
As Sean looks toward becoming a CISO, he is also thinking about the responsibility established leaders have to those entering the profession. His own career began because someone was willing to take a chance on him, a high school student.
Years later, Sean remembers discussing that decision with Chris Harrington, the person who initially hired him. Harrington admitted he had questioned what a high school student could contribute. But he gave Sean the opportunity anyway.
“If he didn’t give me that chance, I’m not sure where I would be,” Sean says. It is a lesson Sean believes is particularly relevant as AI begins changing the entry level jobs that traditionally helped people establish themselves in cybersecurity.
Security leaders have an opportunity to actively develop the next generation, whether that means creating internships or mentoring someone earlier in their career.
Sean also encourages younger professionals not to wait for those relationships to happen organically. He recommends finding leaders they respect, including people outside cybersecurity, and asking for their time. Even a regular coffee or brief conversation can become an opportunity to develop business acumen and learn from someone who has already navigated certain challenges.
For Sean, that cycle of opportunity is central to leadership. His career began because someone gave him a chance. It grew because mentors challenged him to think differently about security. Now, as AI reshapes both cybersecurity and the paths people take into the profession, he believes today’s leaders have a responsibility to provide those same opportunities to others.
“I truly believe that what’s good for the person coming up is good for the industry,” Sean says, “and it’s just good for us as humans to help each other out.”
Subscribe
Stay up to date with cyber security trends and more
