Bio

I’m Victoria Mosby, a cybersecurity strategist, advisor, and storyteller with more than 16 years of experience navigating the worlds of governance, risk, compliance, and cybersecurity SaaS. My journey didn’t start with a love of policy checklists, but with a fascination for how technology and people intersect, and how the right decisions can protect organizations, empower teams, and build trust where it matters most.

Over the years, I’ve worked in roles that demand both technical depth and business fluency. Today, I’m a Senior Sales Engineer, partnering with organizations to strengthen their security programs by designing the right workflows, aligning software to real operational needs, and helping teams respond to auditor and board pressure with clarity and confidence. Along the way, I’ve built a reputation as a trusted advisor, someone who can translate technical jargon into executive priorities and turn strategic visions into practical next steps.

I also believe security doesn’t have to be dull or inaccessible.

That belief led me to create the Cyber Lorekeeper, a creative platform where I blend cybersecurity with storytelling, gamification, and worldbuilding. Through projects like the Compliance Dungeon, the Storytelling Framework, and Tales from the Digital Realm, I explore new ways to make governance, compliance, and incident response not only understandable, but memorable and even enjoyable. It’s part passion project, part experiment, and part love letter to a field that thrives on innovation.

Looking ahead, I’m focused on expanding my impact as both a practitioner and a creator. I’m building toward a future in security evangelism and Field CTO style roles where I can shape product strategy, influence industry practice, and continue developing tools that help teams move from findings to fixes. At the same time, I’m committed to writing, teaching, and speaking, sharing ideas that bridge the gap between the boardroom, the security team, and the wider community.

Outside of work, you’ll usually find me crocheting, chasing good stories, or buried in a fantasy novel. Like many people in cybersecurity, I thrive at the intersection of logic and creativity, and I try to bring that same energy into everything I build.

What I Focus On Now

Right now, my work centers on a few core themes:

• Turning pentest and vulnerability data into real remediation programs
• Designing workflows that help security teams move from findings to fixes
• Acting as the voice of the customer in product and platform strategy
• Teaching security teams and executives how to communicate risk clearly
• Exploring creative ways to make security more human and more memorable

Career Direction

I’m building toward a future in Field CTO and security evangelism roles focused on product strategy, customer advocacy, and industry education. My goal is to help shape how security tools are built, how risk is communicated, and how teams design programs that scale beyond compliance.

Resume

  • Strategic field engineer working across enterprise pre sales, customer adoption, churn recovery, and product strategy.

    • Lead complex enterprise demos, POVs, and executive technical sessions across vulnerability management, pentesting, and exposure management programs

    • Serve as technical owner for strategic and at risk accounts, stabilizing relationships through workflow redesign, retraining programs, and executive advisory sessions

    • Recover and retain churn risk customers by diagnosing adoption failures and rebuilding remediation and reporting workflows aligned to operating models

    • Partner closely with Product and Engineering to influence roadmap features in remediation, reporting, CTEM workflows, and platform usability

    • Design and deliver customer success webinars, bootcamps, platform training videos, and enablement programs used across customers and GTM teams

    • Author technical blogs, competitor analysis, and sales battlecards supporting product positioning and market education

  • Supported commercial and federal accounts at a high growth cybersecurity startup. Led technical demonstrations, POV deployments, RFI submissions, and customer workflow alignment across DoD and civilian agencies.

  • Primary federal and DoD field engineer covering mobile threat defense, federal financials, and systems integrators.

    • Led pre sales and post sales technical strategy across multiple federal territories

    • Presented at major DoD cyber conferences including AFITC, Fort Detrick Cyber Day, and AFCEA West Indo Pacific

    • Served as board representative for the Lookout Foundation and program lead for the Day of Shecurity virtual conference

  • Founder and lead consultant providing governance, risk, and compliance advisory services to federal and commercial clients.

    • Delivered executive advisory, policy development, and risk program design for large scale federal security programs

    • Advised the United States Air Force FIAR CISO Program on POA&M modernization, risk tolerance strategies, and enterprise risk governance

    • Built executive dashboards and reporting programs for multi tier risk visibility

  • Supported vulnerability remediation, POA&M lifecycle management, and compliance operations for United States Coast Guard Cyber Command programs.

  • Focus: Governance, risk, and compliance management, policy management, executive engagement, and audit support

    • Progressed from intern to senior analyst within the corporate information security team

    • Led corporate POA&M executive briefing program and delivered regular updates to CISO, CIO, and senior leadership

    • Supported OIG and GAO audits, security control assessments, and enterprise policy governance

    • Built security awareness training and executive level reporting programs

Education

MS, Cyber Forensics - Stevenson University (2021)

BS, Cyber Security - University of Maryland, University College (2013)

BS, Computer Network & Security - University of Maryland, University College (2013)

Patent

Device-based Security Scoring

US-11537721-B2 · Issued Dec 27, 2022

Writing, Speaking, and Media

I regularly write and speak on topics including exposure management, remediation workflows, pentest reporting, product strategy, and security storytelling. My work includes technical blogs, customer success webinars, bootcamps, podcasts, and conference presentations focused on helping teams bridge the gap between findings and fixes.