Securing the Human: Anahi Santiago on Leadership, Growth, and Giving Back

There are leaders whose careers impress you, and then there are leaders whose way of showing up stays with you.

Anahi Santiago has always been both for me.

I’ve had the opportunity to interact with Anahi several times over the years, and she is someone I have genuinely looked up to for a long time. Of course, her career is incredibly impactful, but what has always inspired me just as much is how she chooses to use that experience. She shares what she knows. She makes time for the community. She invests in people. And she does it with this sense that none of us grow by keeping what we have learned to ourselves.

That came through so clearly in our conversation. Whether we were talking about taking a chance on herself before she felt fully qualified, building teams by looking beyond the traditional cybersecurity résumé, being “only two hands away from the patient,” or her belief that when you love what you do, you share it, there was a consistent thread: people matter.

And maybe that is what I admire most about Anahi. For someone who has accomplished so much, she still seems deeply invested in helping others learn, grow, and find their own way forward.

I have wanted to have this conversation for a while, and I am so excited to finally share it with the Tech She Secures community.

Meet Anahi Santiago.

Origins & Career Journey

You’ve had such a dynamic journey, from early roles in IT and project management to becoming a long-standing CISO in healthcare. What initially drew you into security and privacy, and what has kept you committed to this path over time?

I started my career as an engineer, taking off-the-shelf software and reverse engineering it into the security architecture, which was pretty ahead of its time. From there, I moved into project management and eventually began running large international infrastructure projects.

Because I came from such a technical background, I was a very hands-on project manager. I was exposed to infrastructure, networking, applications, databases, web, e-commerce, and all of it had an information security component. I just started gravitating toward security. During those years, I was like a sponge. I wanted to learn and grow, and I got to work with some really smart people. I looked at it as free education.

Unfortunately, free education doesn’t pay the bills. I was woefully underpaid and actually bartending at night to supplement my full-time job. One evening, I was telling the owner’s son-in-law that it was time for me to move on. I had found my passion in information security and knew that was what I wanted to pursue.

He happened to work at Einstein Healthcare Network and told me they were hiring for a security officer. My immediate reaction was, “I’m a project manager. I can’t just take an information security officer job. I’m not qualified.” He said, “Just give me your resume.”

This was in 2005, when the HIPAA Security Rule was coming into effect. Einstein had no information security program or dedicated security function. I interviewed, got the job, and became not only the information security officer, but the only information security person for the entire organization. I spent the next ten and a half years building the program from the ground up.

I think being that sponge early in my career, learning as much as I could and valuing how rich and powerful knowledge can be, gave me the confidence to believe I could do it. And I did.

Eventually, ChristianaCare called about the CISO role. The opportunity to focus fully on security and join an organization with a culture where I felt I could really thrive was incredibly attractive.

And here I am, eleven years later, still having a great time leading this organization.

Leadership & Influence

You’ve been in the CISO seat for over a decade, which speaks to both trust and impact. What has been one of the most defining leadership challenges you’ve faced at that level, and how did it shape the way you lead today?

At the end of the day, I’m in healthcare very intentionally. I love this industry, and I don’t know that I would ever intentionally leave it.

For me, the biggest challenge is showing up every day knowing that if I’m not doing the best for my organization, I’m not doing the best for our patients, and I could ultimately be impacting their health. That is my North Star. It’s incredibly rewarding, but it can also be challenging and, on certain days, a little terrifying.

At the same time, I work for a highly innovative organization that wants to use technology to solve problems that haven’t been solved before. The challenge is that if the technology problem hasn’t been solved before, chances are the cybersecurity challenges associated with it haven’t either.

Hospital at Home is a great example. There aren’t established cybersecurity frameworks for how you protect data and systems that are now sitting in someone’s home, but I still have a responsibility to protect them. As that program grows, my team and I have to move at that same pace.

We saw something similar with virtual care. Years before COVID-19, our leaders asked us to create a secure architecture that would allow access from anywhere, at any time, on any device. So, when COVID-19 hit and many organizations were scrambling to deploy remote access, our team was able to say, “All right, cool. Where else can we help? We’re all set.”

That experience reinforced something for me as a leader: in healthcare, security has to be able to move with innovation. You can’t always wait for the perfect framework or for someone else to solve the problem first. Sometimes you have to help figure out what secure looks like while the organization is moving forward.

Healthcare, Risk & the Human Impact

Having spent so many years in healthcare, how has that environment shaped your perspective on risk, especially when balancing innovation with patient safety and trust?

Whenever I get this question, I think about how much healthcare cybersecurity has evolved over the course of my career. Back in the day, we worried about protecting data in the data center. Then we worried about protecting data in the cloud. Now we’re protecting data and technology in people’s homes.

At one point, the focus was largely on protecting the data itself. Then ransomware changed the conversation, and availability became just as critical. Today, we’re thinking about human beings walking around with implantable devices, receiving care through connected technology, and relying on devices in their homes. I call that “securing the human.”

That creates a very unique cybersecurity challenge because you can’t wrap a human in a firewall. But you still have to protect them, whether it’s the cardiac device inside someone, an infusion pump supporting care in the home, or any of the connected technologies sending information back to clinicians who are using it to make decisions about a patient’s care.

When I started in this field, I worried about things like viruses that were mostly annoying, and medical devices weren’t connected to anything. Today, we have ambulances transmitting information to emergency rooms before a patient even arrives so the care team can be ready with the right technology at the bedside.

It’s wild when you think about how far we’ve come, but it’s also incredibly important. Healthcare cybersecurity is no longer just about securing data or systems. It’s about securing the human. I’ve been living that for more than two decades, and it absolutely requires a different mindset.

Team Building & Culture

You’ve built and led highly visible, high-performing teams. What do you prioritize when creating a security organization that is not only effective, but also trusted and respected across the enterprise?

Another North Star I share often with my team is that “we are only two hands away from the patient.” Every decision we make, whether in the name of security or in spite of security, has an impact on our organization’s ability to deliver care.

If you block something on the internet, you might prevent a clinician from getting what they need to care for a patient. If you leave a hole in the firewall open, that could also impact their ability to provide care. So, we can’t just do something because we think it is the best thing for security. We have to understand how that decision affects the organization and, ultimately, the patient.

When it comes to building the team itself, we prioritize soft skills over technical acumen. We believe you can teach information security to anyone, but you can’t necessarily teach passion, hunger to learn, collaboration, or the understanding that, at the end of the day, patient care is more important than security. We might all think security is the most important thing, but we can’t operate that way.

For senior-level hires, I look for people who want to teach, build, grow, and contribute. That creates the capacity for us to bring in people at the entry level and help them become high performers. My team includes people who came from radiology, the help desk, the SOC, business relationship management, and even an executive assistant role.

One of my favorite examples is someone I came across on social media who posted that he was trying to break into cybersecurity and couldn’t get anyone to give him a shot. I told my number two, “Give this guy five minutes.”

We ended up hiring him. He started as a contractor, became an analyst, and today he leads vulnerability management efforts, coordinating across security, applications, infrastructure, and networking. To me, that demonstrates what can happen when you’re willing to teach, grow, and invest in people.

We’re also very intentional about psychological safety. I want people to know they can speak up. I want to know if they’re overworked or stressed, whether they’re working on things that help them grow, and whether the work is actually interesting to them. If it isn’t, let’s create opportunities.

And family first is something we say all the time. If you need to step away in the middle of the day to take care of something, go do it. I trust that the time will come back somewhere.

I think creating that kind of culture, one where people feel supported, challenged, trusted, and given room to grow, has helped us attract and keep the right talent.

Representation & Mentorship

You’ve been a strong advocate for mentorship and representation. What has that meant to you personally, and how has it influenced the way you show up as a leader?

It’s a passion of mine. I’m not just here to punch the clock. I’m here to contribute to my organization, but I also find a lot of joy in contributing to the industry as a whole.

That can take a lot of different forms, whether it’s serving on the Health-ISAC Board of Directors, being part of the Healthcare Sector Coordinating Council, helping stand up a local Women in Cybersecurity chapter, or speaking with students at middle schools, high schools, and colleges.

We work in an industry that doesn’t have enough talent. We can sit around and complain about it, or we can be part of the solution by helping build the future cybersecurity leaders and talent our industry so desperately needs.

For me, that work is fun. It’s part of my passion. My husband is always telling me that I need to figure out how to say no, but it’s hard to say no to something you genuinely enjoy.

I’m also fortunate to be surrounded by other leaders who have made it part of their mission to have an impact in their communities and across the industry. I’m in really good company, and that makes it easier to keep showing up and doing the work.

BADdest Moment

Tell us about the “BADdest” challenge you’ve taken on in your career, the boldest, most authentic, and driven moment you’re most proud of, and how it shaped you.

I think we started with this one. Five years after graduating from college, I threw my hat in for an information security officer role with absolutely no information security titles anywhere on my resume. I don’t know that you can get much bolder than that, especially walking into an organization that had nothing in place.

I had to start completely from the ground up. I spent the next ten and a half years building the program, building the team, and building the culture. At the time, people didn’t really know what cybersecurity was. My first year and a half was spent doing roadshows just explaining information security, what the HIPAA Security Rule meant, and why any of it mattered.

I remember going to speak with the physicians and residents. The chair of the department immediately pushed back. His perspective was, “You’re not coming in here and stopping me from doing my work. Patient care comes first.” He pelted me with questions, and I answered every single one calmly and from his perspective.

I walked out of that room thinking, “Can I pull this off? Because I think I just got whooped.”

But from that day forward, that physician became one of my biggest allies, and he happened to be one of the most vocal influencers across the organization.

That experience taught me something I still carry with me today: you can’t walk into a room simply in the name of cybersecurity and expect people to follow your agenda. You have to understand who your audience is, what matters to them, and meet them where they are. Otherwise, you’re going to lose the room.

The bold part was believing I could take on that role in the first place. The authentic part was being willing to show up as myself, learn, and listen. And the driven part goes back to those first five years of being a sponge, learning everything I could so that when the opportunity came, I was willing to take the chance.

Twenty-two years later, I’m still in healthcare and still carrying those lessons with me.

Knowledge Sharing & Giving Back

You’re incredibly active in the industry and consistently share insights and lessons. What drives you to give back in that way, and how do you think knowledge-sharing shapes the future of our field?

It starts with loving what you do. I think when you love something, you share it because you want other people to love it too.

For me, I enjoy sharing, but I also want to keep growing, and so much of how I grow comes from other people. If we want our industry to grow and thrive, we have to share. If we all live in our own silos, none of us will be successful.

My passion for growing really turned into a passion for sharing.

I also believe in building a strong personal brand, and I don’t mean what you look like or how you’re perceived. I mean building a reputation where people want to work with you, work for you, and collaborate with you. That creates opportunities to be exposed to new ideas, people, and experiences that help you continue to thrive.

A mentor once told me that job security has nothing to do with keeping your current job. It has everything to do with being able to thrive in your current role and, if you choose, continue to thrive in whatever comes next. That has always stuck with me.

Sometimes people hold tightly to what they know because they think that knowledge is what makes them valuable. But if that knowledge is no longer needed, you can be left with an empty bag. Sharing what I know and helping others grow doesn’t empty the bag. It gives me opportunities to keep learning too.

We’re all learning in this field. If you’re not learning, you’re not growing, and you’re not thriving.

Innovation, AI & the Future

As healthcare continues to evolve with AI and emerging technologies, what excites you the most, and where do you think leaders need to be more intentional or cautious?

What excites me about AI is the transformative impact it can have on healthcare and our ability to deliver better care. We’ve already seen examples of AI helping detect tumors faster than the naked eye, improving efficiencies, helping with things like OR scheduling and claims reimbursement, and reducing waste and cost.

I also think AI can make all of us better, professionally and personally, by augmenting the way we work. To me, that’s incredibly exciting. AI isn’t necessarily going to take our jobs, but we do need to learn how to use it to become more productive and continue to thrive.

Where I think we need to be much more intentional is around the risks, because in healthcare those risks go far beyond cybersecurity.

When leaders first started coming to me asking, “What do we do about AI?” my response was, “This isn’t a cybersecurity-driven issue. It’s going to take a village.”

We have to think about the clinical risks of using AI to make decisions, the financial risks of investing in technology that may not deliver the outcomes we expect, and the ethical risks, particularly around bias in how models are trained. If we use AI in areas like hiring, for example, and the data reflects an industry that has historically lacked representation, that bias can carry forward into the model.

There are so many factors to consider, including ethnicity, geography, socioeconomic differences, and the populations represented in the data. It’s really hard to get right.

That’s why AI governance has to be multidisciplinary. Cybersecurity absolutely needs to be at the table, but we shouldn’t be the only ones at the table, and we shouldn’t necessarily be the ones leading it. It takes clinical, business, legal, ethical, technology, and security perspectives working together.

There are certainly cybersecurity risks with AI, but in healthcare, I think the clinical, business, and ethical risks deserve an equally bright light.

Wellbeing & Staying Grounded

With everything you carry as a CISO, industry leader, mentor, and advocate, what does taking care of yourself look like? Do you have any self-care rituals or non-negotiables that help you reset and stay grounded?

I’m an avid sports fan, so I spend a lot of time going to sporting events. I have season tickets to the Phillies, the Eagles, and the Sixers, so that definitely takes up a big chunk of my time.

I’m also a long-distance runner. I run marathons and half marathons, and that time is really my alone time. I don’t like to run with other people. I want to think my thoughts or escape from my thoughts, whatever the flavor is for the day. That’s my therapy.

I also love to travel. My husband and I enjoy traveling, spending time with family, going out to dinner, and just being social. My plate is full, but both plates are full, and that’s important to me.

One of my biggest non-negotiables is that I will not work for an organization that doesn’t value that kind of harmony or restricts my ability to have it.

Earlier in my career, I would work 14- or 16-hour days, and the work never disappeared. The plate never emptied. Then I started my Executive MBA and suddenly I couldn’t work that way anymore. I had to shut the computer down, go to class, and work with my study group.

I did that for 20 months, and nobody noticed. I didn’t get a bad performance review. Nobody told me I wasn’t productive anymore. And I remember thinking, “Why did I put myself through that if no one other than me was expecting it?”

That was my aha moment. I decided I wasn’t going to do that anymore.

There will always be exceptions. If there’s a major cyberattack, I might be pulling an all-nighter or working through the weekend. I signed up for that. But those moments should be the exception, not the rule.

For me, having the freedom to live my life, enjoy the things that matter to me, and still show up fully for my work is non-negotiable.

Advice for the Community

For the Tech She Secures community and others looking to grow in cybersecurity and leadership, what advice would you share with them as they navigate their journeys?

Build your network. I really believe having a strong network matters, whatever that looks like for you. For some people, it may be a strong personal network. For others, it may be professional. The important thing is having people you can learn from, lean on, and grow with.

We can’t do this in silos. If you try to go at everything alone, you’re much more likely to burn out and miss out on the perspective and support that help you thrive.

I would also say: invest in yourself, value yourself, and take chances. Believe that you can do anything you set your mind to, but remember that setting your mind to something doesn’t just mean thinking about it. You have to put in the work. You have to invest in whatever that thing is.

If you stay focused, put in the effort, and surround yourself with the right people, you can accomplish great things.

Looking Ahead

You’ve had a deeply impactful career spanning leadership, governance, and industry influence. What’s next for you?

Honestly, I’m having fun. I’m not really thinking too much about what’s next because I don’t want to look past what I’m experiencing now. I’m thriving, I’m enjoying the work, and I’m still very connected to the mission.

If I had to think about a next chapter, I would probably still want to stay in information security. I don’t necessarily see myself becoming a CIO or moving into some other executive role. I really enjoy being tied to this mission. What may change over time is the scale of the impact, whether that means working with a larger organization or eventually serving in more of a strategic advisory capacity.

And at some point, of course, I’m going to retire. When that time comes, I would love to serve on a few public boards where I can continue to contribute, share what I’ve learned, and have an impact without necessarily working a full-time job.

So, I don’t think my trajectory is toward dramatically changing careers. It’s more about continuing to do work I love, finding ways to have greater impact, and eventually carrying that passion into whatever the next phase looks like.

Closing Reflections

What stayed with me most from this conversation was Anahi’s belief in growth, not just for herself, but for the people and communities around her.

Her journey is such a powerful reminder that leadership is not only about what we build or accomplish. It is also about the chances we are willing to take, the people we choose to invest in, the knowledge we are willing to share, and the space we create for others to grow alongside us.

I also loved hearing someone with such an accomplished career talk about protecting joy, making room for life, and still being able to say, after all these years, “I’m having fun.

Anahi, thank you for sharing your time, your wisdom, and your experiences so generously with the Tech She Secures community. I have admired your leadership for a long time, and this conversation only left me more inspired by the leader and person you are.

Maliha



























Disclaimer: The content on this blog and website reflects a combination of my personal experiences, perspectives, and insights, as well as interviews and contributions from other individuals. It does not represent the opinions, policies, or strategies of any organization I am currently affiliated with or have been affiliated with in the past. This platform serves as a personal space for sharing ideas, lessons learned, and meaningful reflections.

Next
Next

Built to Evolve: Mushyada Ali on Growth, Motherhood, and a Life of Learning