About Us
The United States Insider Risk Management Center of Excellence (USInRM CoE) is a dedicated nonprofit organization committed to enhancing the understanding and management of insider risk. By fostering collaboration among private, public, and academic sectors, we aim to share knowledge and resources that mitigate insider threats, ensuring a safer environment for U.S. and international corporations. Our initiatives are designed to create awareness and promote best practices in insider risk management.
Our vision is to raise the proverbial tide to lift all insider risk/threat practitioners.

Our Mission

At the USInRM CoE, we are dedicated to fostering collaboration and knowledge-sharing among private, public, and academic sectors. Our mission is to empower organizations to proactively address insider risks and ensure a secure operational environment.
We support organizations' insider risk management by equipping them with the essential tools and insights needed to identify, manage, and mitigate insider threats. We strive to create a supportive network that empowers stakeholders to safeguard their assets and cultivate trust within their organizations. Together, we can create a resilient ecosystem that protects both businesses and employees.
Meet Our Team
Our dedicated team at USInRM CoE comprises experts from various fields, all united in their commitment to enhancing insider risk management practices. We work collaboratively to provide valuable insights and resources to our partners and the community.

Executive Director
Dawn Haley
Dawn Haley is the Senior Manager for Threat Management at Duke Energy Corporation, where she heads the Digital Forensics Investigations and Insider Threat teams.
In her role, Dawn collaborates closely with Human Resources, Legal, Ethics, and Data Privacy to protect Duke Energy’s people, assets, operations, and brand across its seven-state footprint.
Prior to joining Duke Energy, Dawn served in the United States Army during Operation Iraqi Freedom and Operation Enduring Freedom as a Human Intelligence Collector and Korean linguist.
Dawn holds a bachelor’s degree in Intelligence Studies from American Military University, with a minor in Digital Forensics, and a Master of Business Administration from the University of Maryland Global Campus. She also possesses several technical certifications from SANS, as well as the Global Counter Insider Threat Certified Professional certification from the University of Maryland Applied Research Lab.

Deputy Director
Mark Handy
Mark Handy is a Managing Director of Morgan Stanley in the Cyber, Data, Risk and Resilience Division. Mark joined the Firm in 1998 and worked in London, New York and Tokyo, prior to moving to Alpharetta, GA in mid-2021.
Mark currently serves as Global Head of Insider Risk Management in addition to managing Global eDiscovery & Investigations and Insider Threat functions.
Mark works extensively with Legal and Compliance, Human Resources and Business leaders to ensure that jurisdictional requirements are met, monitoring and response is privacy focused, and that control implementation occurs in such a way as to support, rather than impact, business activities.
Mark is an active leader across the financial services sector with a passion for information sharing and enhancing capabilities across the sector. Mark serves on the FS-ISAC Insider Threat Steering Committee, is co-chair of the SIFMA Insider Threat Working Group and sits on the steering group for the Carnegie Mellon OSIT FinSIG.
Mark has a B.Sc. Mathematics and Finance from the University of Portsmouth, holds CISM, CRISC, GCITP, and ITPM Certifications and has recently completed a Graduate Certificate in Insider Risk Management and Mitigation from the University of Maryland.

Chief Researcher
Stephanie Jaros
Stephanie Jaros is an award-winning insider risk professional with 15 years of experience in program design, implementation, assessment, and research across government and industry.
Currently, she is a Research Scientist at the University of Maryland’s Applied Research Laboratory for Intelligence & Security (ARLIS). Previously, Stephanie served as the Director of Research for the Department of Defense’s (DoD) Counter-Insider Threat Program, during which time she founded and built The Threat Lab, a multi-disciplinary program dedicated to integrating the social and behavioral sciences into DoD’s counter-insider threat mission space. In addition to her work for DoD, Stephanie served as the Senior Security Manager for Strategy for Zoom’s Insider Risk Mitigation Program and as the Insider Threat Program Coordinator for US Customs and Border Protection.
.jpg)
Advisor
John "J.T." Mendoza
John “JT” Mendoza has over 25 years of service in positions of progressive responsibility spanning the public and private sectors. In his current role, J.T. Mendoza serves as Head of Global Insider Risk Management for Marriott International. He is also the Founder and former Executive Director, US Insider Risk Management Center of Excellence – a national non-profit focused on equipping and enabling insider risk practitioners.
Prior to joining the private sector, JT served as Deputy Director, US Air Force Insider Threat. In this role, he was responsible for strategy, outreach, and integration efforts. Before re-joining the USAF, he served as a senior leader within Defense Intelligence Agency’s Counterespionage Division. In addition to overseeing numerous joint cases with the FBI, which led to successful prosecutions, he led DIA’s efforts to revamp and increase the ability to protect and defend the agency against insider threat and foreign intelligence entity penetration attempts.
Industry Sector Liaisons
Our Industry Sector Liaisons bring together experienced leaders from across government, industry, and academia, united by a shared commitment to advancing insider risk management. Through strategic guidance and collaborative leadership, our liaisons support the development of initiatives, partnerships, and resources that strengthen the broader community.

Melissa Cardiello
Accomplished senior leader with decades of successful strategic and tactical leadership in Cybersecurity and governance oversight. Autonomous and empowering management style with a solutions-oriented approach to problem-solving.
Subject matter experience and hands on knowledge with 24*7 Security Operations Center (SOC), Insider Threat Operations (ITO) & Data Loss Prevention (DLP), Incident Management, Digital forensics and Incident Response (DFIR), Threat Hunting, Offensive Security, and Cyber Exercise and Resilience.

David Helfen
Service-oriented, trustworthy, and forward-thinking leader, offering progressive career in the field of Cybersecurity protection. Equipped with proven success in directing and implementing in-depth investigations, introducing and deploying new security programs, systems, and policies, as well as preventing and reducing security breaches through incident response.
Experienced in building relationships with business leadership in addition to the technical security teams that help bridge knowledge gaps. Expert at analyzing accumulated data and evidence and developing tactical security plans within controlled access environments. Highly commended for consistent success in delivering assignment to completion with impressive results.

Todd Masse
Todd Masse is a member of the Senior Security Leadership Team and a Program Manager for Security,
Counterintelligence (CI), and Insider Threat (IT) within the Security Services Department (SECD) at The Johns Hopkins University Applied Physics Laboratory (APL).
Todd partners with Laboratory leadership, Department and Sector Security Representatives (DSRs), various
stakeholders across the Laboratory, and with external law enforcement, national defense, and intelligence
community partners to protect technologies, programs, and information at APL; keep Staff informed of
threats; and to support the APL security culture.
Todd earned a BA from The University of Massachusetts (Economics and Political Science), an MA from The American University (International Affairs – Defense and International Economic Policy), and an MBA from the University of Maryland (Finance).
He has worked for the Federal Bureau of Investigation (FBI), the U.S. Department of Energy, the U.S.
Congress, and the U.S. Nuclear Regulatory Commission.
He has testified before Congress numerous times as an expert witness on intelligence and homeland security
issues and published a book on nuclear terrorism (Nuclear Jihad: A Clear and Present Danger 2011,
Potomac Books).

Josh Massey
Joshua W. Massey is the Services Director, Global Security at MITRE, bringing expertise in security and global operations. Their background reflects a strong focus on public service and security, with experience in both government and technical consulting roles.
At MITRE, Joshua oversees service delivery and directs strategic initiatives related to global security. They provide engineering and technical guidance, applying their knowledge to support federal government projects. Their work history includes service as a Special Agent with the U.S. Department of Commerce, where they contributed to economic growth initiatives through regulatory compliance and security protocols. Earlier in their career, Joshua served as an Intelligence Research Specialist at ATF, focusing on intelligence gathering and risk assessment.