John Moulton is the U.S. Census Bureau’s Acting Chief Information Security Officer (CISO), leading enterprise cybersecurity strategy, security modernization, threat intelligence, threat mitigation, and risk management.
A veteran cybersecurity executive with more than 25 years of federal experience, John has overseen major modernization initiatives across three decennial censuses and the Census Bureau enterprise, advancing Zero Trust architecture, secure cloud adoption, phishing-resistant multi-factor authorization (MFA), security operations center (SOC) modernization, active cyber defense and emerging AI-driven cybersecurity capabilities.
John also serves as Director of the Census Insider and Cyber Threats Program, for which he established the Census Bureau’s first enterprise-wide insider and cyber threat capability. In this role, he provides senior intelligence and national-security guidance to Census Bureau leadership and represents the agency in high-level engagements with the Department of Homeland Security (DHS)/Cybersecurity and Infrastructure Security Agency (inside the DHS), the Department of Commerce, the intelligence community and other federal partners.
Previously, John was the senior cybersecurity executive supporting the 2020 Census Technical Integrator Contract, leading cybersecurity operations for all systems supporting the 2020 Census—including cloud infrastructure, continuous monitoring, Security Operations Center, cyberthreat intelligence and active cyberdefense. In 2015, he served as the Information Owner in the Center for Administrative Records Research and Applications (CARRA), where he ensured all data used in approved research projects met strict guidelines for Census Bureau policy usage and adherence to inter-agency agreements and contractual obligations.
John rose through the ranks in the Census Bureau’s mission‑critical operations, including key leadership responsibilities during the 2000 and 2010 Censuses. In each role, he strengthened the agency’s cybersecurity posture, elevated organizational readiness and advanced enterprise‑wide resilience by applying deep expertise in IT systems, network architecture, data protection, risk management, incident response, digital forensics, compliance, continuous diagnostics and mitigation, and complex cybersecurity operations.
John previously served as a Marine security guard/embassy duty in the U.S. Marine Corps, providing security for diplomats, embassies, VIPs and classified materials. He holds a master’s certificate in IT project management from The George Washington University School of Business and maintains several cybersecurity industry certifications.