Information security professional

Security that
moves business
forward.

I'm Charlie Reyes, CISSP—a security leader with deep experience across critical infrastructure, power and gas utilities, operational technology, and enterprise infrastructure security.

Charlie Reyes, CISSP
CR
Charlotte, NCOpen to new connections
01 / 04
“The strongest security programs don't just protect the organization—they help it move with confidence.
Charlie ReyesSecurity · Risk · Resilience

Focused on what
matters most.

Experienced across the intersection of technology, security, and business—helping organizations understand risk and make better decisions.

01

Security leadership

Translating technical risk into clear priorities that teams and leaders can act on.

02

Risk & resilience

Building practical security programs that protect operations while supporting the business.

03

Trusted partnership

Connecting people, process, and technology through calm communication and sound judgment.

Protecting the systems
that keep life moving.

My utility-sector work has spanned compliance, vulnerability management, incident response, and the development of stronger IT/OT security operations—always with reliability and safe operations at the center.

01

Utility & critical infrastructure

Nearly 13 years at Duke Energy supporting the cybersecurity needs of electric power and gas operations, from hands-on analysis through OT security leadership.

02

OT security operations

Led Duke Energy’s OT Security Operations Center and a team responsible for cyber investigation and response across operational technology environments.

03

NERC CIP compliance

Applied NERC CIP requirements in operational settings, including CIP-007 R2 patch-source reviews and mitigation plans, plus CIP-010 configuration baselines, change control, and audit-ready evidence.

04

Vulnerability & response

Directed vulnerability management supporting 4,000+ critical-infrastructure assets across three regions while strengthening IT/OT detection, response, and cross-industry information sharing.

NERC CIP focusCIP-007 · Systems Security Management
CIP-010 · Configuration Change Management

Experience includes security patch management, ports and services, malicious-code prevention, event monitoring, system access control, configuration baseline management, change impact review, annual vulnerability-assessment reporting, security-controls testing, and maintaining defensible compliance documentation.

Built on experience.
Backed by credentials.

A career grounded in information security, continual learning, and service to the professional community.

01CISSPISC2
02Security+CompTIA
03InfraGardProfessional organization
04OT Defender Fellowship2023 Fellowship member
ASU
EducationAppalachian State UniversityBachelor's · Computer Information Systems
PSU
Continuing educationPenn State World CampusPost-Baccalaureate Certificate · Information Systems Security

Let's connect, share,
and keep learning.

I'm interested in building new connections, expanding my professional network, meeting others across the industry, and learning more about security in critical infrastructure.