Chief Information Security Officer

James Hengsterman-Cash

AI security and governance for federal and regulated technology environments.

Security executive and Duke executive cybersecurity faculty member focused on turning AI governance, compliance, and customer trust into operating discipline.

Headshot of James Hengsterman-Cash
  • CurrentCISO, Unison
  • TeachingDuke Executive Cybersecurity Programs
  • RecognitionCybersecurity Executive of the Year, 2025 Cybersecurity Excellence Awards
  • Prior experienceEightfold AI · AWS Public Sector · GDIT · DoD / USAF

About

James Hengsterman-Cash is Chief Information Security Officer at Unison and a faculty member with Duke’s executive cybersecurity programs, where he teaches AI risk management, regulation, and governance to senior executives.

His work focuses on the practical execution of cybersecurity, AI governance, compliance, and technology risk in federal and regulated environments. A U.S. Air Force and Department of Defense veteran, he has held security leadership roles across AI, public sector, cloud, and defense-aligned organizations, with experience spanning enterprise security strategy, governance, risk, compliance, and customer trust.

He also serves on the regional advisory board of NPower, the national nonprofit preparing military veterans and young adults from underserved communities for careers in technology.

Focus Areas

Executive cybersecurity leadership, AI governance, and trust programs for federal and regulated environments.

  • AI Governance

    Operating models for enterprise AI adoption, including ownership, acceptable use, data boundaries, model oversight, executive reporting, and risk acceptance.

  • Cybersecurity Strategy

    Security leadership for SaaS, federal, regulated, and mission-critical technology environments where trust is a commercial and operational requirement.

  • Compliance by Design

    Using ISO/IEC 42001, NIST AI RMF, FedRAMP, SOC 2, ISO 27001, and related frameworks as operating tools rather than annual evidence exercises.

  • Federal Technology Risk

    Security and governance considerations for platforms serving government agencies, defense missions, public sector buyers, and highly regulated customers.

Speaking & Commentary

Available for executive education, board and advisory briefings, conference panels, podcasts, and media commentary. Talks draw on the focus areas above — framework-to-operating-model AI governance, security leadership in regulated environments, compliance as evidence architecture rather than audit theater, and federal technology risk.

Upcoming: Duke University Executive Education — AI & Cybersecurity Leadership, Mexico City, October 2026.

Sample formats: 20-minute keynote, 45-minute executive briefing, 60-minute panel, podcast interview, or half-day workshop.

Media Kit

For conference organizers, journalists, podcasters, and executive education teams.

Short bio

James Hengsterman-Cash is Chief Information Security Officer at Unison and a faculty member with Duke’s executive cybersecurity programs. Named Cybersecurity Executive of the Year at the 2025 Cybersecurity Excellence Awards, he focuses on AI governance, cybersecurity leadership, compliance, customer trust, and federal technology risk.

Long bio

James Hengsterman-Cash is Chief Information Security Officer at Unison and a faculty member with Duke’s executive cybersecurity programs. Named Cybersecurity Executive of the Year at the 2025 Cybersecurity Excellence Awards, he focuses on the practical execution of cybersecurity, AI governance, compliance, and customer trust in federal and regulated technology environments. A U.S. Air Force and Department of Defense veteran, he has held security leadership roles across AI, public sector, cloud, and defense-aligned organizations, including Eightfold AI, AWS Public Sector, and GDIT. He serves on the regional advisory board of NPower, the national nonprofit preparing military veterans and young adults from underserved communities for careers in technology.

Contact

For speaking, media, executive education, board briefings, conference panels, podcasts, or advisory inquiries.

Public inquiries

Include the requested format, audience, date or deadline, and whether the inquiry is on the record.

Connect on LinkedIn