Security as an operating model
Security programs should create accountable ownership, visible risk treatment, and repeatable decision-making—not just policy binders.
Cybersecurity executive with 25+ years across enterprise, federal, regulated, and classified environments, including 11 years leading an enterprise security function with CISO-equivalent scope. Focused on cyber risk, Zero Trust, cloud and SaaS security, AI governance, incident readiness, data protection, resilience, and turning security strategy into accountable operating practice.
I operate at the intersection of security strategy, business risk, architecture, resilience, and execution. My work has included building security governance, strengthening identity and access controls, improving audit readiness, leading incident preparedness, modernizing physical and technical security, and translating complex cyber risk into decisions senior leaders can act on.
Security programs should create accountable ownership, visible risk treatment, and repeatable decision-making—not just policy binders.
Experienced across IAM, Microsoft security, vulnerability management, SIEM, endpoint protection, vendor risk, incident response, and resilience.
Translate technical findings into business priorities, remediation ownership, accepted-risk decisions, and clear leadership action.
A representative set of security leadership outcomes. These will become deeper case studies as the evidence portfolio is developed.
Owned security strategy, governance, operational security, policy, risk management, resilience, and executive reporting.
Strengthened identity controls and reduced reliance on weak access patterns.
Strengthened resilience through incident-response planning, tabletop exercises, business continuity, and recovery discipline.
Combined security awareness and process improvements to address real-world fraud risk.
Supported modernization of physical-security capabilities and operational readiness.
Advised professional and leadership audiences on secure AI adoption, model/vendor risk, data protection, access control, and responsible use.
Effective security leadership is not about maximizing the number of controls. It is about building organizations that can continue operating when controls fail, suppliers fail, systems fail, or attackers succeed.
Efficiency matters. Resilience matters more when the environment is uncertain. Security should test assumptions before adversaries do.
Identity should increasingly rely on stronger combinations of what a person is and what they possess, reducing dependence on reusable secrets.
Policies are useful only when they lead to ownership, measurable action, evidence, escalation, and better decisions.
A CISO-level capability map spanning governance, technical risk, operating resilience, and executive leadership.
Public summaries of deeper evidence-backed work. Over time, each can become a dedicated case-study page.
Security governance, risk register, remediation accountability, audit readiness, incident preparedness, vendor risk, and executive reporting.
Led a 493-user MFA, SSO, identity-governance, and access-lifecycle transformation using Okta and Duo, with phased deployment, user training, role-based application access, privileged-account separation, quarterly reviews, and NIST 800-53 evidence.
Designed a right-sized security and business-continuity approach for a small music studio, expanding cloud protection from temporary file sharing measured in tens of megabytes to automated backup of nearly the full dataset—just under 1 TB—while strengthening identity, network segmentation, recovery readiness, and protection of customer data.
Executive tabletop exercises, incident-response planning, continuity, recovery, escalation, lessons learned, and corrective action.
Completed professional certifications supporting cybersecurity leadership, cloud security, governance, AI security, and execution.
Certified Information Systems Security Professional
Certified Information Security Manager
Certified Cloud Security Professional
Project Management Professional
Security certification focused on AI-era cybersecurity risks and controls
St. Mary’s College of Maryland
A career spanning national-security environments, enterprise cybersecurity leadership, advisory work, and emerging AI-security governance.
Led enterprise security strategy, governance, operations, incident readiness, risk management, resilience, and executive reporting.
Supported classified mission environments and security programs across national-security contexts.
Advised professional and leadership audiences on secure AI adoption, model/vendor risk, data protection, access controls, and governance.
Open to conversations around CISO, vCISO, cybersecurity leadership, enterprise risk, cloud security, AI governance, and resilient security programs.