Profile
Kevin Donovan serves as the Deputy Branch Chief for the Vulnerability Response and Coordination (VRC) Branch at the Cybersecurity and Infrastructure Security Agency (CISA). In this role, Kevin leads national efforts to coordinate the disclosure of technical vulnerabilities that pose significant risks to critical infrastructure and government systems, and to analyze and prioritize all newly disclosed vulnerabilities, including determining appropriate response actions. He and the VRC team execute the agency’s Coordinated Vulnerability Disclosure (CVD) program, manage CISA’s participation in the Common Vulnerabilities and Exposures (CVE) program as both a CVE Numbering Authority (CNA) and a Root CNA, provide data enrichment for every newly published CVE through CISA’s Vulnrichment initiative, and make determinations for new entries to the Known Exploited Vulnerabilities (KEV) catalog. Kevin also supports CISA’s involvement in the CVE Program by providing programmatic oversight and strategic guidance.
Prior to joining CISA, Kevin worked at the Department of Homeland Security Headquarters, the General Services Administration Office of Inspector General, the Department of Veterans Affairs, and the Department of Defense. Before entering federal service, Kevin spent nine years in the private sector as an IT consultant.
Sessions