Sonu Shankar appointed as Pentagon principal deputy CIO
Sonu Shankar, a cybersecurity industry veteran who recently served as an advisor to Pentagon leadership, has been named principal deputy CIO at the Defense Department.
Shankar was appointed to the role by President Donald Trump, according to a DOD news release. He was officially sworn-in Aug. 24.
Prior to taking on his new job in the CIO’s office, Shankar served as a “strategic advisor” to Pentagon leadership via the Business Operators for National Defense program, per the release.
The BOND initiative was launched less than a year ago by Deputy Secretary of Defense Steve Feinberg with the aim of harnessing the expertise of industry executives as the Pentagon moves to improve its acquisition system. The program influenced Feinberg’s recent “Funding Palantir” memo, according to sources.
According to his LinkedIn profile, Shankar began serving in a strategic advisory role to the department in June before taking on his new position in the Office of the CIO. Prior to that, he spent nearly two decades in industry at cyber and IT-focused companies, including Phosphorus Cybersecurity, Arctic Wolf, Box and Cisco.
In his new capacity, he’ll be tasked with advancing the Defense Department’s IT, cybersecurity and digital modernization initiatives.
“The addition of Mr. Shankar to our team will add additional firepower to our transformation work and the OCIO team. His decades of experience in cybersecurity and technology, especially his industry experience at the intersection of product innovation, executive leadership, and international business development, will be a tremendous asset to the mission,” Pentagon CIO Kirsten Davies said in a statement.
Shankar said in a statement that the “ambitious transformation of the Department’s digital ecosystem is a bold and necessary effort to empower our warfighters and maintain a technological edge over our adversaries.”
He’s stepping into the principal deputy CIO role at a pivotal time. Last month, Davies announced the suspension of the implementation of Phase 2 requirements for the Pentagon’s hotly debated Cybersecurity Maturity Model Certification (CMMC) program. The move was prompted by concerns that the rules would drive many companies out of the defense industrial base at a time when the U.S. military urgently needs their technologies and products.
A new CMMC Reform Task Force was created in July and tasked with conducting a review of the entire program and submitting a report of its findings and recommendations within 60 days. To inform those efforts, the Pentagon released a request for information to get industry’s feedback on CMMC and the path forward. The RFI garnered more than 1,110 responses, according to the CIO’s office.