Leadership
Who you actually work with.
Engagements are led by senior practitioners, not handed to a delivery pool after the sale. If you want to understand how that shapes a program before you speak to anyone, read why Semper Sec exists or see how our service lines fit together. Interested in joining the team? Explore careers.
Leadership.
Our founders lead the firm and stay close to the work.

Founder and CSO
Rob Carson
CISSP, CISA, CCSK
Rob leads information-security management at Semper Sec, drawing on prior roles at InteliSecure, Cherwell Software, and Celsus Advisory Group, and on seven years as a United States Marine Corps infantry officer. His program experience spans ISO 27001, PCI, and HIPAA. He holds a BS from Texas A&M University and an MS from University of Maryland University College.

Co-Founder and CEO
Bradley Stine
CISSP
Bradley was previously Chief Technology Officer at the Colorado Attorney General’s Office, Security Assessments and Incident Response Manager at InteliSecure, Director of Security at Cherwell Software, and a Senior Manager at Deloitte. His work covers cloud transformation, continuous-integration automation, identity and access management, incident and vulnerability management, ISO 27001, and enterprise architecture.
Directors.
Delivery, service, and client engagement are led by directors with deep program experience.

Director of Service Delivery
Ron Terrell
GISP
Ron leads service delivery, combining project management and cybersecurity experience with a background in international contracting. He focuses on the coordination and collaboration that keep multi-workstream programs moving.

Director of Sales
Chris Modlin
Chris brings more than seven years in cyber risk services and over a decade of B2B consultative selling. He works with ISO 27001, NIST CSF, CIS, and SANS 20, alongside cloud security, privacy, and managed security services.

Director of Implementation Services
Javan DeGraff
GISP
Javan works across offensive and defensive security and has managed ISO and wider security programs, bringing both the attacker’s perspective and the operator’s discipline to client work.
The practitioners behind the program.
Semper Sec was founded by security and compliance practitioners who had run these programs from the inside. That is still how engagements are led: by people senior enough to be useful in the first conversation.