August 26, 2026

Career Spotlight: Rona Michele Spiegel

Meet Rona Michele Spiegel, Senior Manager of Security and Trust, Mergers and Acquisitions at Autodesk. Autodesk develops software that helps people design and create everything from buildings and products to manufacturing solutions and entertainment.

Rona Spiegel is a cybersecurity and technology leader with more than 20 years of experience helping organizations securely adopt and scale technology. She leads Trust for Mergers and Acquisitions at Autodesk, bringing security, privacy, resilience, Governance, Risk and Compliance (GRC), and Trusted AI together to help organizations become stronger than the sum of their parts.

Prior to Autodesk, Rona led Cloud Governance and Operations at Cisco and Wells Fargo and advised organizations on Technology Strategy, User Experience, and Compliance, both independently as a vCISO and as a management consultant at Deloitte. Her work today focuses on cloud security, cybersecurity strategy, and Trusted AI. Rona holds a CISSP and a Master’s in Information and Cybersecurity from UC Berkeley and is passionate about mentoring the next generation of cybersecurity leaders, particularly women entering the field.

1. Can you share how your career evolved into cybersecurity leadership and your current work integrating security, privacy, resilience, and AI governance into mergers and acquisitions?

My path into cybersecurity was not traditional, but that is common in this field. Cybersecurity professionals once came mainly from areas such as law, IT, and government. Today, people enter the field from many different backgrounds.

I began my career in design and user experience, studying how people interact with technology and how organizations adapt to new digital tools. I later moved into management consulting, where I learned to solve problems by considering three things: people, processes, and technology.

At Deloitte, I gained experience in change management, mergers and acquisitions, and risk. I also learned how to communicate with different audiences, from technical architects to business executives. That experience prepared me for leadership roles where I needed to explain complex topics in ways that made sense to different groups.

At Autodesk, I bring all these skills together. When we introduce a new process or tool, we consider how it will affect employees and the business. When Autodesk acquires another company, we also need to understand how that company manages security, privacy, business continuity, and artificial intelligence.

We identify possible risks and determine how to safely connect the new company’s technology and practices with Autodesk’s. The goal is not simply to check a security box. It is to manage risk while helping the two companies successfully come together.

2. How do security, privacy, resilience, and AI governance come together under the broader concept of “Trust”?

Many technology products are now delivered as online services, also known as Software as a Service, or SaaS. When customers use these products, they trust another company with their personal information, creative work, and sometimes important parts of their business.

Security is one part of earning that trust, but it is not the only part.

Privacy means using and protecting people’s information responsibly and following legal and ethical requirements. Resilience means making sure systems remain available or can recover quickly when something goes wrong. AI governance provides rules for using artificial intelligence responsibly, safely, and ethically. This includes considering how AI is trained and how it uses personal information and intellectual property.

Governance, Risk, and Compliance - often called GRC - helps connect all these areas. Together, they give customers confidence that their information is secure and that the technology they depend on is being managed responsibly, reliably, and ethically.

3. For readers who are unfamiliar with the field, how would you explain cloud security and why it has become so important?

Many websites and mobile apps store information and run their services through cloud providers such as Amazon Web Services, Google Cloud, and Microsoft Azure. The cloud allows organizations to access computing resources through the internet instead of managing everything on their own physical computers and servers. Whenever you enter a username, password, address, birthdate, or payment information online, that data may travel through several systems and networks before reaching its destination. If those systems are not properly protected, the information could be stolen, exposed, or misused.

Cloud security focuses on protecting these systems and the information stored within them. Important areas include controlling who can access information, encrypting data, securely configuring systems, finding vulnerabilities, monitoring for suspicious activity, and responding to security incidents. Cloud security is also a great field for students to explore. Major cloud providers offer free beginner training that can help you start building practical skills.

4. As cybersecurity tools become automated and AI-enabled, which decisions do you believe will always require human judgment?

There is still a lot of debate about which decisions should be made by people and which can safely be automated. For important situations, humans should ultimately decide how AI is used rather than depending entirely on the technology. However, people are not perfect either. We make mistakes, miss important details, and can be manipulated through social engineering. Even well-designed automated systems can fail if there are problems in the process or if people begin approving alerts without carefully reviewing them. Instead of simply placing a person somewhere in an automated process, organizations should examine every important decision. They should identify the risks and determine where human judgment is most valuable. AI can analyze large amounts of information and help people make decisions. However, humans should remain responsible when a decision requires an understanding of the situation, involves serious consequences, or affects people’s safety, privacy, or rights.

5. Do students need to specialize early, or is it better to build broad experience across areas such as cloud, risk, privacy, and incident response?

The answer is both. Cybersecurity has many entry points, and students benefit from understanding the field broadly while gaining deeper experience in an area that interests them. Start by exploring a topic that excites you, such as cloud security, risk, privacy, ethical hacking, or incident response. Even if you later decide it is not the right specialty for you, the experience will still help you build a strong foundation. Employers often look for practical experience, even for entry-level positions. You can begin building that experience through online courses, certifications, competitions, conferences, student organizations, volunteer opportunities, and local cybersecurity groups. Technical knowledge is important, but communication, curiosity, teamwork, and problem-solving matter just as much. These skills can be learned and strengthened over time.

Most cybersecurity leaders began in one area that interested them and gradually expanded their knowledge. Because technology and security constantly change, you will always have opportunities to learn, grow, and try something new.