CISO · Professor · Investor
Anthony Candeias.
Chief Information Security Officer at a major global investment firm. Cybersecurity lecturer at Columbia, NYU, and Fordham. Early-stage investor in cybersecurity and AI startups.
01 About
Anthony Candeias is a Chief Information Security Officer and an active angel investor in cybersecurity and AI startups.
Previously, Anthony served as CISO and VP of IT at WeightWatchers, where he built and led the company’s security program. Before that, he was Director of Cybersecurity at Columbia University. He began his career at Goldman Sachs and the Ford Foundation.
Throughout his career, Anthony has developed deep experience investigating and building defenses against nation-state APTs.
Anthony has taught graduate-level cybersecurity courses at Columbia, NYU, and Fordham for over a decade. He holds master’s degrees from Columbia University and Fordham University, where he also earned his bachelor’s degree in Computer Systems.
02 Current role
Chief Information Security Officer
Since 2025, at a major global investment firm — leading enterprise cybersecurity strategy spanning four disciplines:
- Detection & response Finding and neutralizing threats against the firm in real time.
- Offensive security Testing defenses the way an adversary would.
- Security engineering Building the tooling and automation the program runs on.
- Security architecture Designing systems that are defensible from the start.
03 Teaching
Faculty appointments.
- Columbia University Lecturer · 2025 — Present
- New York University Adjunct Instructor · 2017 — 2025
- Fordham University Adjunct Faculty · 2014 — 2025
Over a decade of graduate-level cybersecurity instruction at top-tier New York institutions — curriculum spanning enterprise risk, threat management, secure architecture, and cybersecurity engineering and management, bridging academic theory with industry practice.
04 Investing & advising
Investments & advisory.
Partnering with founders building the next generation of cybersecurity, AI, and infrastructure companies.
- CalypsoAI Exit — acquired by F5 · $180M
-
OptiAdvisory
AI-native identity and access management automating operations across human, non-human, and agentic identities.
-
ClarityExit — acquired by Deel
AI security platform that detects deepfakes and AI-driven social engineering with patent-pending media authentication technology.
-
Mate SecurityInvestment
AI-native SOC platform that adapts in real time using organizational context to eliminate alert fatigue and automate investigation.
-
Dune SecurityAdvisory
AI-powered adaptive risk management — simulates multi-channel attacks and automatically tailors security controls to each user’s risk profile.
-
FIG SecurityInvestment
Finds and fixes broken security flows across the entire SecOps stack, enabling teams to simulate and deploy changes with confidence.
-
ArmsCyberAdvisory
Automated Moving Target Defense anti-ransomware — detects, blocks, and recovers from ransomware using deceptive tripwires and stealth archival.
-
NovaNavAdvisory
AI-powered surgical recovery platform — automated pre-op reminders, real-time patient check-ins, and CMS PROMs compliance.
-
AutohealInvestment
AI platform for SRE and support engineering — a Production Context Graph powers multi-agent incident triage, investigation, and resolution to reduce MTTR.
-
Glow SecurityInvestment
Next-generation cybersecurity platform securing enterprise environments.
-
VividInvestment
Stealth-stage technology company building intelligent enterprise solutions.
-
Generate SecurityAdvisory
Stealth-stage cybersecurity company building next-generation security tooling.
05 Speaking & open source
In public, and in the open.
I speak at industry conferences on AI security and enterprise defense — recently CrowdStrike Fal.Con, Cyera’s DataSec NYC Summit, the ISMG Healthcare Security Summit, and HMG Strategy’s New York CISO & Technology Leadership Summit — and write on AI security for CalypsoAI and F5. The tooling side of that thinking is open source, under ACandeias on GitHub.
-
AI-Forensicator
macOS forensic analysis tool that collects artifacts from AI applications like Claude, ChatGPT, Cursor, and browsers — built for incident response and AI auditing.
-
injection-detection
Prompt injection scanner for web pages — detects hidden instructions, data exfiltration attempts, and obfuscated payloads targeting LLMs.