Before Andrew Park led security for UltraViolet Cyber, he was one of our customers. That relationship — and the moment it started — says more about how he leads than any line on his resume.
We're glad to introduce Andrew Park as UltraViolet Cyber's new Chief Information Security Officer.
"I'm a nerd at the end of the day — an engineer, a solution builder," Andrew says of himself. That's the throughline of a career that started as a Unix systems administrator in the mid-1990s, before spam was even a problem and long before cloud was a category. He spent close to two decades in Unix administration and automation before adding scripting, programming, DevOps, and cloud skills, then spent four years at Amazon Web Services as a cloud infrastructure architect, solutions architect, and cloud security consultant, advising enterprise customers on secure cloud adoption. From there, Andrew spent five years as CISO of a Canadian crypto exchange, one of the highest-pressure environments in tech, before joining UltraViolet. He holds a CISSP, an AWS Certified Security Specialty certification, and a Bachelor of Science in Computer Science from the University of Toronto. That foundation shapes how he thinks about defense today: start with the fundamentals, then build up.
Andrew's path to UltraViolet started as a client engagement, not a traditional job search.
As CISO at the crypto exchange, one aspect that Andrew managed was SOC 1 and SOC 2 pen testing requirements. As he was soliciting his network for potential pen-testing vendors, a board member introduced him to UltraViolet's CEO.
The first engagement included a week-long phishing campaign. In the final hours of that test, UltraViolet’s team stole the session of one of the employees. From there, the "attacker" moved through that employees entitled system accesses undetected. For Andrew, it was the first time he saw, firsthand, what a real account compromise looks and feels like from the inside: the gap between a control that passes a test and one that holds up once someone is actually in your systems.
Andrew ran five or six more engagements with us before his final year at the exchange. When UltraViolet needed a CISO, he already understood how we work, because he had sat on the other side of the table.
Security is a team sport, and it's everybody's responsibility — a principle Andrew repeats often. When he assessed UltraViolet's security posture on arrival, he found a culture that was, in his words, "a little bit shy": people were hesitant to volunteer what they saw, worried about being wrong or embarrassed. "It's unbelievable how much security you can achieve just by talking at the right level," he says. The fix isn't a mandate — it's making security approachable enough that people want to engage with it, not avoid it. He posts routine updates himself, even the unglamorous ones, in the leadership channel, and rather than asking open-ended questions like "what do you think?", he proposes a direction first. Security that lives in a silo can't see far enough; real threat visibility depends on everyone paying attention, not just the security team.
A few of the initiatives Andrew has already launched:
Andrew's priorities for the next twelve months:
Outside UltraViolet, Andrew is three years into an adjunct role teaching Cloud Computing and Cloud Security at Humber College in Toronto. He’s inspiring the next generation of security practitioners ensuring a deep foundation in operating systems, applications, programming, and cloud. In his words, you need to simmer in the IT industry for a long time. When he reviewed 500 resumes for two junior openings, the signal that mattered most wasn't coursework — it was whether someone had built something on their own, visible in a personal GitHub repo.
Welcome, Andrew!
Andrew Park brings a rare vantage point to this role: he's sat on both sides of the security relationship, first as a customer buying validation, now as the executive responsible for delivering it. Join us in welcoming him to UltraViolet Cyber — and connect with him on LinkedIn.