Security
& Risk

November 14 – 15, 2023  |  Washington, D.C. & Digital

Sarah Nur

Associate Chief Information Officer for Cybersecurity and Treasury Chief Information Security Officer, U.S. Department of the Treasury

Sarah Nur is a seasoned cybersecurity executive leader who serves as the Department of Treasury’s Associate Chief Information Officer for Cybersecurity (ACIO-CS) and Chief Information Security Officer (CISO).

As a member of the Senior Executive Service (SES), she has a great deal of responsibility and oversight of several Cybersecurity functions/programs across the Treasury’s $4.5B IT portfolio, $550M cyber budget, and 150K users.

Upon assuming the ACIO-CS/CISO role in 2019, Sarah’s initial focus was on improving the Enterprise Key Performance Indicators (KPI) for the Federal IT Acquisition Reform Act (FITARA) Cybersecurity grade.  She led the direction and execution of Treasury’s cybersecurity priorities and engagement, which resulted in significant improvement in raising Treasury’s FITARA Cybersecurity grade from “D” to “B.”

In addition to governing nine Bureaus, each with its own operating Bureau CISO, Sarah serves as the chairman for the Financial and Banking Information Infrastructure Committee (FBIIC) CISO Subcommittee. This forum brings together CISOs from the financial sector, including banking institutions and regulators, to exchange cybersecurity information, collaborate on best practices and common Cyber initiatives, engage in vulnerability and threat management, and discuss incident handling.

Prior to joining the Treasury in 2016, Sarah Nur held numerous leadership positions in systems engineering, IT network deployment (worldwide), and operational cybersecurity supporting public and private organizations.

She is a proud alumna of Howard University and a long-standing certified member of PMI, (ISC)2, ISACA, ITIL, and EC-Council.

Sarah is a proven leader who thrives in complex environments. She loves building teams, mentoring students, and inspiring interest in pursuing a career in IT and cybersecurity.