enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Thrasio

Scaling Security and It For High-growth Enterprises

Mark McNamara, Global Chief Information Security Officer and Head of Technology, Thrasio

Mark McNamara is a seasoned technology executive with over 20 years of experience in enterprise IT and security across Fortune 1000 companies and startups. As head of technology at Thrasio, he played a key role in scaling operations from 200 employees to more than 2,500 employees and $1.5 billion in revenue. He built resilient technology frameworks, optimized IT operations, and led a team of more than 150 experts in across technology.

He integrated finance and inventory systems while driving operational efficiency with a strong focus on security and innovation. McNamara specializes in balancing security with scalability in fast-growing environments, preparing businesses for pre-IPO success. His expertise lies in mitigating risk, disconnecting cost from growth, while strengthening cybersecurity. He has a unique skillset of combining business acumen, financial rigor, automation and leveraging technology to accelerate business growth.

A Strategic Security Leader with Extensive Experience

With over two decades in IT and security leadership, I bring a strategic, principles, and adaptable approach to enterprise security. At Thrasio, I was instrumental in scaling operations, building resilient technology frameworks, and supporting a rapidly expanding business on amazon, and a consumer goods business.

Leading a team of over 150 experts, I optimize and automating IT operations, Security, Enterprise Applications, and DevOps/DevSecOps automation while integrating finance and inventory systems for peak efficiency. My focus on innovation and security ensures operational excellence and positions technology as a driver of business growth.

Building Security from the Ground Up at Thrasio

As head of technology at Thrasio, the world’s largest Amazon aggregator, I had the unique opportunity to design security infrastructure from the ground up. Unlike legacy enterprises burdened by outdated systems, Thrasio’s clean slate allowed for implementing cutting-edge security solutions tailored to a rapidly evolving industry. The challenge was creating next generation capabilities rather than relying on old “best practices”.

“Social Engineering Remains A Persistent And Evolving Threat, Underscoring The Need To Move From Point-In-Time Assessments To Real-Time, Continuous Security Posture Management. Today’s Security Teams Must Maintain Constant Vigilance, Leveraging Adaptive Strategies And Live Insights To Stay Ahead Of Ever-Changing Attack Tactics.”

Joining the company during its startup phase presented complex security challenges. Building foundational security framework, aligning technology with business growth while ensuring security evolved alongside Thrasio’s rapid expansion.

Balancing Security and Scalability in a High-Growth Environment

Scaling security in a fast-growing company requires careful prioritization with a basic philosophy “automated continuous security is the only way to manage hyper growth.” . With limited resources, automating security and building a high performing team was the only way to maximize security to resource ratios. I focused on identifying key risks—mapping potential revenue loss, operational disruptions, and emerging threats—and aligning security strategies accordingly.

My team ensured security remained a strategic enabler rather than a bottleneck by emphasizing risk-based prioritization. This approach helped Thrasio scale efficiently while maintaining robust security measures.

Integrating IT Infrastructure for Security and Efficiency

During Thrasio’s rapid expansion, we acquired around 250 businesses, each with unique infrastructure complexities. Some operated exclusively on Amazon, making integration seamless, while others required tailored solutions.

My team developed a flexible Mergers & Acquisition strategy based on each business model, whether direct-to-consumer, e-commerce, or multi-channel. Identity management was a primary focus, ensuring secure user access across devices and environments. While consolidating infrastructure enhanced security and scalability, some systems remained independent due to compatibility constraints, requiring a case-by-case approach.

This strategic balance ensured security, operational efficiency, and business continuity while aligning acquisitions with Thrasio’s objectives.

Key Advice for CSOs and IT Leaders in High-Growth Companies

Social engineering remains a persistent threat, demanding continuous assessment and adaptation. Security teams must move from “point in time” view of security to “continuous” with the ability to manage a continuously moving risk landscape. This means staying vigilant and refining strategies to counter evolving attack tactics. Prioritizing identity security is crucial, it is the 1st control. With a strong push toward password-less authentication or passkeys to mitigate credential-based risks.

Leveraging AI in security is increasingly vital as a defensive tool and as a proactive measure to enhance threat intelligence, provide dynamic protection, and improve overall security posture. Organizations should actively explore AI-powered security innovations to stay ahead in an evolving landscape.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.