Selected impact

Highlights

Security governance made operational.

Examples of the scale, systems thinking, and measurable progress I bring to complex security, compliance, and risk environments.

See the full career progression

The through line

Turn requirements into systems teams can run—and leaders can trust.

Across two decades in information technology and more than fifteen years in cybersecurity, my work has centered on making security expectations concrete: define the standard, automate the check, enable the fix, and make the result visible.

01Enterprise scale

Governed 120+ security configuration baselines

Led security configuration governance across cloud, hybrid, and on-premises environments in a highly regulated financial institution.

Security governanceCloud and hybridFinancial services
02Automation

Operationalized 80+ automated compliance policies

Replaced fragmented, point-in-time validation with repeatable policy automation and reporting that made control posture easier to measure and manage.

Policy as codeContinuous validationReporting
03Measurable improvement

Helped move enterprise configuration compliance from ~73% to ~92%

Connected findings to actionable remediation guidance, accountable owners, and risk-based priorities to improve sustained compliance outcomes.

Remediation enablementRisk-based prioritizationOutcomes
04Regulated environments

Supported audit and regulatory readiness

Applied security engineering and governance discipline in support of FFIEC and NYDFS expectations, while building evidence leaders and auditors could use.

FFIECNYDFSAudit readiness
05Technical foundation

Built security depth from mission-critical operations

Progressed from systems administration and DISA STIG compliance into cybersecurity engineering, cloud governance, automation, and enterprise security leadership.

DISA STIGsDoD systemsSecurity engineering
06Forward-looking practice

Designed practical models for the next stage of governance

Developing frameworks for security governance, enterprise cybersecurity capabilities, AI risk management, and AI-assisted security workflows.

Security Governance FrameworkECSRMNIST AI RMF

Representative outcomes from enterprise security configuration governance work; values are approximate where indicated.

Let's connect

Looking for security that works in the real world?

Open to conversations with recruiters, hiring managers, security leaders, and peers working through complex governance and compliance challenges.