AlexRobertKleiner

Senior Cyber Policy Advisor The White House
Office of Management and Budget · Office of the Federal CIO

Cybersecurity and Emerging Technology LeaderExecutive Leadership·National Policy·Deep Technical PracticeSecurity Engineer·Penetration Tester·GRC·Threat Intelligence

Protect and Enable the Mission

Lead author of 2 OMB memoranda, with a foundation of 275+ penetration tests and 550+ risk assessments.

The path here

From Hands-On-Keyboard Technical to Policy, Strategy, and Leadership

Explore

I am a senior cybersecurity and emerging technology leader with 15+ years across hands-on technical practice, program leadership, and policy.

I developed my technical security practice through penetration testing, red team engagements, and security operations center (SOC) work, learning the vulnerability lifecycle firsthand from discovery through remediation. That foundation grew into enterprise security programs, vulnerability disclosure, evaluation and risk frameworks, detection strategies, and national cybersecurity and emerging technology policy. I translate complex technical risk into clear decisions and chair interagency working groups that turn those decisions into policy agencies can implement.

Today I lead technical cyber and emerging technology portfolios at the White House, in the Office of the Federal Chief Information Officer at the Office of Management and Budget. As lead author of OMB M-26-14, I established a risk-based logging and network visibility policy that set the stage for AI-enabled cyber defense. As lead author of OMB M-26-15, I moved federal post-quantum migration from strategy into civilian agency guidance for execution. I also serve as a federal Major Incident Response Commander and advise on AI governance and acquisition, cybersecurity executive orders, federal cloud authorization (FedRAMP) modernization, and annual federal information-security (FISMA) guidance.

I develop people alongside programs, helping technical teams turn findings into mitigation priorities through clear direction and coaching. I support investment and resource decisions by connecting cyber risks with mission needs, budget requirements, and cost-saving considerations. With dual bachelor's degrees in Computer Science and Experimental Cinema and Production, I bring both technical and creative perspectives to unfamiliar problems.

More about my technical foundation

Before policy, I built a technical foundation of 275+ penetration tests and 550+ risk assessments, ran audit and compliance programs across HIPAA, PCI DSS, SOX, FedRAMP, SOC 2, and ISO 27001, and helped build continuous audit at citywide scale. Drawn to the cutting edge of cybersecurity and emerging technology, I find creative, practical solutions where no precedent exists. Where no playbook existed, I led its creation in principle and practice.

What I believe
Technology is the great equalizer.

Security must protect people, institutions, and infrastructure from harm while enabling innovation, mission objectives, and forward progress.

When security becomes overly restrictive, it slows the work it is meant to safeguard. When security is careless, it introduces unacceptable risk or enables misuse by those who would exploit humanity's new tools. The responsibility of successful cybersecurity is to design systems and policies that achieve both.

That belief has shaped a career in public service at the White House, in New York City government, and in nonprofit healthcare, alongside recognition in the United Nations Information Security Hall of Fame, intentionally built around ensuring that technological advancement protects and enables the mission of organizations that serve people and the greater good.

The work I am proudest of started where no playbook existed: first-of-kind directives, programs founded from nothing, and decisions with no settled answer.

Working at the frontier means testing assumptions, connecting disciplines, and finding a workable path before there is an established model. Meet people and the problem where they are. Ask the questions that narrow it. Name the unknowns, build a first version that addresses each stakeholder's mission, risks, and constraints, and improve it with the people who have to live with it. That is how federal logging policy went from an idea to a directive and how a closed student television station became a 200+ member studio.

At New York City Cyber Command, that meant giving leaders risk-informed dashboards, mitigation priorities, and accountability records by building the citywide cyber risk mitigation and acceptance program from the ground up and pioneering its first audit methodology for industrial control systems and operational technology (ICS/OT).

Security done this way is never a roadblock. It is an avenue to protect and enable the mission.

15+years across technical practice, security leadership, and policy
2OMB memoranda as lead author: M-26-14 (logging & visibility) and M-26-15 (post-quantum cryptography)
275+penetration tests across web, mobile, cloud, medical devices, and OT
550+independent information security risk assessments
Contact

Let's talk.

Open to conversations about cybersecurity leadership, security programs, AI security, and emerging-technology policy.