Security Executive · CISO · Advisor
Head of Security, IT & DevOps
Enterprise Security & Technology Executive with 15+ years leading Information Security, IT, and DevOps across Finance, Payments, Healthcare, Retail, and Analytics. Zero major audit findings across SOC 2 and PCI. Trusted advisor to executive leadership and boards — translating cyber risk into business impact.
Measurable Outcomes
Sectors
Security leadership across regulated and high-growth environments — building programs that meet the specific risk profile of each sector.
Core Competencies
From boardroom risk conversations to hands-on cloud controls — leading security, IT, and DevOps as a unified function that protects revenue and enables growth.
Building enterprise security programs aligned to NIST CSF, ISO 27001, and CIS Controls. Risk governance, GRC frameworks, board-level KPI reporting, and security roadmap ownership — delivered with measurable maturity gains.
Zero major findings across SOC 2 Type II and PCI DSS programs. Deep practitioner across ISO 27001, NIST CSF, CCPA/CPRA, GDPR, and HIPAA — owning the full lifecycle from control design through external auditor management.
Securing AWS and Azure environments with Zero Trust architecture, CIS-hardened systems, and SAST/DAST/SCA embedded into CI/CD — a 45% reduction in cloud misconfigurations. IAM transformation via Okta and Azure AD.
Career
15+ years of progressive security leadership across Finance, Payments, Healthcare, Retail, Semiconductor, Manufacturing, and Analytics — always owning more than just security.
Full executive ownership of Security, IT Operations, and DevOps for a high-growth payment analytics platform.
Led enterprise security strategy, roadmap, and compliance programs at one of the world's largest fintech firms.
Led security engineering and operations initiatives across enterprise systems, strengthening threat detection and response.
Led enterprise security programs for fintech and payment platforms, designing security architecture and controls from the ground up.
Implemented enterprise security controls, monitoring, and risk assessments — building the foundational practitioner depth that underpins all subsequent leadership.
The CISO Case
Most security leaders own one dimension. I've been running three simultaneously — and delivering measurable outcomes in each.
50%+ reduction in critical vulnerabilities. 40% improvement in MTTD/MTTR. 45% fewer cloud misconfigurations. Zero major audit findings across SOC 2 and PCI. These are the metrics boards care about — and I deliver them.
Most CISO candidates own security in isolation. I own the full technology operating layer — infrastructure, pipelines, and security controls — which means I speak the language of every stakeholder and eliminate the silos that create risk.
Regulated industries demand more than checkboxes. With hands-on depth across SOC 2, PCI DSS, ISO 27001, NIST CSF, GDPR, CCPA, and HIPAA — and 8 active certifications — I bring the rigor complex environments require without slowing the business down.
M&A is where security programs get exposed. I've led security diligence, post-merger integration, and IAM consolidation at both Fiserv (Ondot acquisition) and in a current confidential transaction — providing boards with real risk visibility at the most critical moment.
Tools & Platforms
Hands-on depth across the full security and infrastructure toolchain — from SIEM to DevSecOps pipelines.
Credentials
Eight active credentials spanning security leadership, audit, ethical hacking, cloud, and governance.
Education
Continuing Education
Engagements
Available for fractional advisory, audit readiness, and framework gap-assessment engagements alongside full-time opportunities — the same rigor that delivered zero major findings across SOC 2 and PCI DSS, brought to your program on a retainer or fixed-scope basis.
Ongoing part-time security leadership for organizations not yet ready for a full-time CISO — board and executive reporting, risk governance, security roadmap ownership, and vendor/tooling strategy.
End-to-end readiness for SOC 2 Type II, PCI DSS, ISO/IEC 27001, HIPAA, GDPR, and CCPA/CPRA — control design, evidence collection, gap remediation, and direct auditor liaison through to report issuance.
Structured gap assessments against NIST CSF, NIST SP 800-53, CIS Controls v8, and COBIT 2019 — cross-mapped so evidence gathered once satisfies multiple frameworks instead of separate, duplicative audits.
Architecture and configuration review of AWS/Azure environments — IAM and Zero Trust design, CIS-hardened baselines, and DevSecOps pipeline security (SAST/DAST/SCA), targeting measurable reductions in misconfiguration risk.
Security risk assessment and control evaluation for buy-side or sell-side transactions, plus post-merger integration planning — IAM consolidation, tooling rationalization, and compliance alignment across merged environments.
Design or uplift of detection and response capability — SIEM/EDR deployment, incident response playbooks, tabletop exercises, and MTTD/MTTR improvement grounded in live production experience.
Full lifecycle delivery for Model Context Protocol integrations and enterprise AI chatbots — architecture and tool/resource design, an access-authorization framework governing what each AI-connected system can see and do, secure production deployment, and long-term support: model/tool governance, permission audits, and ongoing maintenance as the AI ecosystem evolves.
Engagements are scoped individually — retainer, fixed-fee, or project-based — depending on the framework(s) in scope and current program maturity.
What I'm Pursuing
Actively exploring Chief Information Security Officer roles, fractional CISO engagements, board-level security advisory positions, and strategic consulting. Fintech, payments, SaaS, and high-growth companies are a natural fit. GitHub is the source of truth for the hands-on work — compliance frameworks, MCP integrations, and tooling — referenced throughout this site.
Send a Message