"Developed and implemented X meaningful control at Google" is close to auto-investable, IMO.
There are some pharma (drug discovery) and prop-trading firms I'd respect highly, too. Not high street banks but smaller or more focused entities. Knowing which is hard.
For big companies which are "obviously" good: Apple's not bad internally. FB, Amazon, Microsoft aren't bad. The hard part is identifying who is good internally out of large teams. (Yahoo! has also traditionally had good infosec relative to everything else, although perhaps sacrificed business to it.)
LV casinos as a sector seem to be ok.
For harder bets: There are few tougher environments today than the bitcoin ecosystem. A lot of those companies are shitshows staffed by people with zero infosec background, but there are exceptions.
Also of course some of the most elite consultancies (iSEC, IOActive, Cylance, etc.) have great people. There are individual good people in large big-N consultancies too, but as a blanket statement, not as good to recruit from.
(For offense: Israel/8200/etc. are probably the best recruiting pool, due to cost relative to skill. There are good people in the NSA ecosystem as well, for offense, although largely contractors, and expensive. I don't buy that extreme competence at actually implementing widely-known-but-we-didnt-think-people-would-actually-go-that-far vulnerabilities makes you a stronger defensive player, though; developing fundamentally new attacks, or finding vulnerabilities, sure, but spending $5b to do the attack everyone had identified as a possibility is just an engineering and economic exercise.)
(In SV today, startups in security are probably the best pool of talent, hence acquihire. I probably know a pool of ~200 good to great people in the general security ecosystem at any given time from a bunch of companies who are recruitable or buyable.)
http://www.thewire.com/technology/2013/06/facebooks-former-s...
Old -- but there are other articles about it as well...
It would be hard to imagine more prominently anti-NSA security executive than Alex Stamos, their current CSO.
And the ones listed by @rdl.
They're a pretty good case study for how the right senior hires at the right time can set the tone for a security organization for many years after those people leave.