Today we’d like to introduce you to Maria Thompson.
Hi Maria, can you start by introducing yourself? We’d love to learn more about how you got to where you are today?
My journey into cybersecurity began during my time in the Marine Corps. In the early 2000s the Marine Corps created a new military occupational specialty (MOS) called Information Assurance Technician/Chief. This MOS was responsible for computer network defense of the Marine Corps networks both in garrison and tactical. I was selected as one of the first 30 Marines to become part of this effort. Fast forward 7 years, and I retired as a Master Gunnery Sergeant (MGySgt), and the Information Assurance Chief for the Marine Corps. A role that came with the responsibility of the health, training and policies for the cybersecurity and protections of Marine Corps networks. Upon retiring, I took a role as the Certifying Authority (CA), conducting assessments and Certification and Accreditation (C&A) for Multi-National Forces in Iraq. My responsibility included ensuring that security was baked into any systems connected to the Iraq mission networks, which included secure, non-secure and coalition networks.
Following my stint as the CA in Iraq, I held a few other cyber roles which included Security Engineer in a software integration lab that developed software supporting joint missions in Iraq and Afghanistan, and as a contractor project lead for SOC at the Environment Protection Agency (EPA) National Data Center.
After 3.5 years at the EPA, I joined the North Carolina Department of Information Technology as the state’s first Chief Risk and Security Officer. I held this role for 6.5 years. The position of State Chief Risk and Security Officer was by far one of the most impactful professions I have held in my career, second to only my 20 years in the Marine Corps. My new battlefield now became the entire state. In this role I was able to build bridges and mend relationships. My teammates were stakeholders from private industry partners to state, local, academic, and federal agencies. It was here that I helped pioneer the “Whole of State” approach to cybersecurity. We built the Joint Cyber Task Force (JCTF), bringing with support from key stakeholders to include the North Carolina National Guard Cyber Team.
The next chapter took me to Amazon Web Services (AWS), where I spent close to 5 years as an Executive Cybersecurity Advisor. Transitioning to the cloud meant evolving my perspective on risk. While my title changed, my responsibilities to the states did not. A part of this role was to continue to evangelize the need for cybersecurity best practices and to help state and academic entities transform their cyber practices from reactive to proactive measures.
Today, as a Public Sector Executive Strategist at Wiz, my mission is to act as a bridge between the complex world of cyber risk and the critical needs of our public sector customers. Whether it’s navigating FedRAMP, GovRAMP, or CMMC, my focus is on earning trust and delivering value. I’ve found that the best way to secure our public services—our citizen data, our infrastructure, and our national security—is to treat every engagement as a partnership.
Can you talk to us a bit about the challenges and lessons you’ve learned along the way. Looking back would you say it’s been easy or smooth in retrospect?
As you can imagine, being the first female MGySgt Information Assurance Chief for the Marine Corps came with its own struggles. Often enough I had to deal with Imposter Syndrome and occasional misogyny as can be expected in a male dominant environment. I was able to succeed due to perseverance, dedication and outstanding leadership.
In my role at the state, some of the challenges were understanding the complexities of state and local government, and navigating political landmines while building relationships that are mutually beneficial for a whole of state cybersecurity mission.
Thanks for sharing that. So, maybe next you can tell us a bit more about your business?
At Wiz, our mission is to help organizations protect everything they build and run in the cloud. We are the industry-leading Cloud-Native Application Protection Platform (CNAPP), but we prefer to think of ourselves as the operating system for modern cloud security, including our protections for AI workloads through our Artificial Intelligence – Application Protection Platform (AI-APP)
We specialize in full-stack visibility. Rather than forcing teams to jump between siloed tools to secure infrastructure, code, or runtime, we unify these signals on a single platform. We are known for our “Security Graph,” which allows us to model an organization’s entire cloud environment as a digital twin. This enables us to turn the noise of thousands of disconnected alerts into actionable intelligence, helping teams focus only on the risks that truly matter.
What sets us apart
There are three main areas that really resonates with customers and sets us apart.
Agentless Visibility: We don’t rely on cumbersome agents that slow down deployment or cause performance friction. Most CISOs and security professionals have gotten tired of the endless agent deployments that can tax systems, as well as create blind spots due to gaps in coverage. Our API-based approach means organizations can achieve 100% visibility across their entire cloud environment in minutes, not months.
The Power of Context (Toxic Combinations): Most tools list vulnerabilities; we identify attack paths. We look for “toxic combinations”—the intersection of misconfiguration, vulnerability, and exposure—that actually create a path for an attacker to reach sensitive data. We don’t just tell you what is broken; we tell you why it’s critical.
Democratization: We’ve fundamentally changed who owns security. By providing intuitive, context-rich insights, we empower non-security teams—developers, DevOps, and engineers—to take ownership of their own security posture. At Wiz, we say, “context is queen”. This means that in a sea of alerts and alarms, we are able to help customers reduce risks by only surfacing the most impactful and critical risks, across cloud environments in a shared risk, shared responsible way. This shifts the burden off of a single, bottlenecked security team and integrates security into the natural flow of development.
What we are most proud of brand-wise
We are most proud of our results-oriented approach to customer success. We don’t just measure success by the software we deploy, but by the tangible risk reduction we drive. It is a major badge of honor for us that 50% of our customers achieve “Zero Criticals” within their environments after adopting the Wiz platform. Being trusted by over 40% of the Fortune 100—ranging from highly regulated global banks to rapid-growth tech companies—is a testament to the fact that we have evolved from being a “point solution” to becoming a core strategic partner in digital transformation.
What we want readers to know
I want readers to understand that Wiz is not just another security tool. My decision to join the Wiz team was largely based on the value and gap that I saw this capability filling. As I mentioned earlier, in addition to traditional security visibility and protection, Wiz is also built for the complexity of the AI era. As organizations accelerate their AI adoption, they are facing a fragmented security landscape. Wiz provides the governance and visibility needed to secure AI pipelines, models, and agents end-to-end. Whether you are building from scratch or managing a massive, hybrid environment, Wiz enables you to ship secure software, including vibe coded software, with confidence, rather than letting security stifle innovation.
My Role at Wiz
As a Public Sector Principal Strategist, my focus is on helping large organizations navigate the transition to a modern cloud-security operating model. I have “sat in the seat” as a former CISO for the State of North Carolina, so I understand the friction between needing to move fast and the mandate to stay secure.
My role isn’t just about evangelizing the platform; it’s about consulting with IT leaders on how to break down the silos between their developers and their security teams. I spend my time helping agencies and educational institutions modernize their infrastructure, consolidate their sprawl of legacy tools, and adopt a “code-to-cloud” mindset. I bridge the gap between technical teams and leadership to ensure that security is “baked in” to the infrastructure from day one—making it an accelerant for business outcomes, not a drag on velocity.
Any advice for finding a mentor or networking in general?
Be open to who can be a mentor. Do not restrict your selection to same gender or apply other filters. There are a lot of folks open to mentoring, you just have to ask. I have also had silent mentors in my past who I have learned many valuable lessons and career moves from. Do not limit yourself to how you leverage mentorship.
I have found networking to be invaluable in building my personal brand as well as opening options for career changes. It is important to be seen, be heard and be part of positive changes in your environment.
Contact Info:

