Bron Torres is an enterprise cybersecurity executive and a co-founder and co-CEO of UnKAnscious, an AI-native software company in North Carolina. He spent two decades running security for organizations where the consequences were real — a Fortune 100 environment of roughly 300,000 nodes, a multi-billion-dollar insurer’s 24x7 security operations, and the government cloud environments of a global payroll platform — most recently as Vice President of Cybersecurity at Dayforce.
He now builds AI. UnKAnscious makes GoalRunner, an AI Chief of Staff in private alpha with live users and real workloads. The company’s design principle comes straight out of the security career that preceded it: maximum useful understanding, minimum necessary authority. An AI system may be allowed to know a great deal about the world it serves; its power to act on that world is a separate grant, constrained by default and given explicitly, one capability at a time.
That is the intersection Bron works at — AI, cybersecurity, and human decision authority. Not AI safety as an abstraction, and not security as paperwork. The engineering question of what an autonomous agent is permitted to do, how that permission is enforced, and what evidence it must show for the conclusions it reaches.
What he is building now
UnKAnscious · Co-Founder & Co-CEO · July 2025 – present
UnKAnscious LLC builds trustworthy AI designed to increase human agency. Bron co-founded the company and co-leads it as Co-Founder & Co-CEO, and designed and built its systems end to end — AI orchestration, agentic automation, and the governance controls around them.
GoalRunner, the company’s first product, tells a founder what they owe, what they are owed, and the moment they are finished with everything it watches — and shows the evidence behind every word. It reads the sources the user chooses to connect, and it recommends rather than acts: every message it sends is a draft the user confirms. It is in private alpha with live users and live workloads.
The architecture applies security-executive discipline to modern AI: least privilege, human-in-the-loop authority models, and a verifiable evidence trail behind every conclusion the system reaches.
Where AI and security meet
Most of the current conversation about AI security is about protecting models. The harder problem, and the one Bron works on, is authority: an agent’s risk comes less from what it says than from what it is permitted to do — the systems it reaches, the messages it sends, the money it moves.
The essay The AI That Knows You Best Should Have the Least Power Over You sets out the position: understanding and authority are different grants, and conflating them is the design error underneath most of the anxiety about personal AI.
Working topics: securing AI agents · authority boundaries for autonomous systems · trustworthy agentic AI · AI governance for CISOs and boards · AI-native security architecture · human decision authority in agentic systems · enterprise AI adoption and its security consequences.
Twenty years of security leadership
Dayforce · Vice President of Cybersecurity · September 2022 – July 2026
Senior security executive with CISO-scope security accountability for Dayforce’s government cloud environments — responsible for taking a commercial SaaS payroll and human capital management platform into regulated national-government and U.S. federal environments. Led a roughly 15-person cybersecurity organization with seven direct reports, extended through managed-service providers.
• Led security design and implementation for a government cloud environment serving a major national government customer, aligned to PBMM — security architecture, security engineering leadership, SIEM design and implementation, and vulnerability-management governance.
• Took that environment through the applicable government security approval, with the customer actively testing and working in it, then began a follow-on build extending the platform to an additional national-government customer.
• Architected, built and operationalized a FedRAMP environment for mission-critical federal payroll, with a major U.S. federal customer live and running on it.
• Engineered an automated vulnerability-management program integrating identification, governance and remediation workflows with Jira and ServiceNow.
Autodesk · Director of Security Assurance · January 2019 – August 2022
Owned the security organization’s internal and external relationships — reporting security posture to the Board of Directors, CEO staff, legal and customers — while leading global security governance, risk, compliance, privacy and third-party management.
• Built Autodesk’s M&A security practice: the operating model for pre-close security due diligence and post-close integration, made repeatable rather than run deal by deal.
• Led Autodesk for Government from ideation through implementation — created and operationalized the government/FedRAMP platform that let Autodesk serve a live U.S. government customer. A $12M program spanning 200+ internal and external services, the largest technology-modernization effort in company history at the time.
• Led the global compliance program: SOC 2 and ISO across 70+ cloud and datacenter products and services, plus enterprise PCI and SOX.
• Ran CEO-staff cyber simulations testing the company’s response to large-scale incidents.
Independent consulting practice · Advisory CISO · January 2017 – January 2019
• Designed and led a global vulnerability-management program spanning 300,000+ nodes across multiple business units of a global technology company — on-premise, AWS and SaaS assets — with a 125+ procedure assessment methodology and a three-year roadmap.
• Served as Advisory CISO and head of information security for an AWS-based technology startup, leading its security and PCI compliance program.
CSAA Insurance Group (AAA) · Director of Information Security and Privacy · November 2013 – December 2016
Served in the Deputy CISO capacity, leading the breadth of the enterprise security organization: GRC and IT compliance, 24x7 security operations and incident response (a 35-person onshore and offshore team), identity and access management, threat and vulnerability management including penetration testing, and security awareness.
• Cut enterprise patch age from 200+ days to 90 and delivered a clean PCI Report on Compliance every year.
• Transformed IT compliance from 15 FTE to 5 while improving compliance outcomes and risk reporting; implemented the Archer GRC platform.
• Created a cyber resilience team and ran cyber war games with executive leadership.
Deloitte & Touche LLP · Manager, Cyber Security & Privacy · January 2011 – November 2013
Acting CISO for two client organizations, including a Fortune 100 technology company. Principal advisor to the security and privacy counsel of a multi-billion-dollar healthcare organization. Led FFIEC gap assessments for large financial-services firms and conducted 120+ application security architecture reviews.
Kaiser Permanente · Management Consultant, Information Security · March 2009 – January 2011
Key advisor to the CISO of a 170,000+-employee healthcare enterprise; guidance across a $21M OPEX and $35M CAPEX security budget, and co-developer of the long-term identity and access management strategy.
Earlier
Progressive information security and technology roles at Washington Mutual, NBC Universal, Expedia and GSS Group, and a period as a financial advisor at UBS Financial Services — the hands-on engineering and operations foundation beneath the executive roles above.
Speaking and writing
OpenSSL Conference 2025 · Prague · 9 October 2025
Leveraging FedRAMP as a Transformative Tool for Organizations: From Checkbox to Culture — with Bernie Leung and Sapna Paul, on the Security, Compliance & the Law track at the inaugural OpenSSL Conference (400+ participants, 30+ countries).
Essay · August 2026
The AI That Knows You Best Should Have the Least Power Over You — on why understanding and authority are separate grants in personal AI.
Advisory and consulting
Bron advises on the problems his own career sits on top of. Typical engagements:
• Securing AI agents. Authority models, least-privilege design, human-in-the-loop checkpoints, and evidence requirements for systems that act on a business’s behalf.
• AI governance for executives and boards. Turning AI risk into decisions a board can actually take, with the same discipline used for security risk reporting.
• Regulated-market entry. Taking a commercial SaaS platform into government and federal environments — FedRAMP, PBMM, NIST — as an engineered program rather than a document exercise.
• Security transformation. Rebuilding vulnerability management, security operations, compliance and third-party risk into operational systems with engineering accountability.
• M&A security. Pre-close diligence and post-close integration as a repeatable capability.
To start a conversation: bt@unkanscious.com
Education
Master of Business Administration — Chapman University
B.S., Business Administration — California State University, Monterey Bay
Elsewhere
Based in North Carolina, United States.