Governed 120+ security configuration baselines
Led security configuration governance across cloud, hybrid, and on-premises environments in a highly regulated financial institution.
Selected impact
Security governance made operational.
Examples of the scale, systems thinking, and measurable progress I bring to complex security, compliance, and risk environments.
See the full career progressionThe through line
Across two decades in information technology and more than fifteen years in cybersecurity, my work has centered on making security expectations concrete: define the standard, automate the check, enable the fix, and make the result visible.
Led security configuration governance across cloud, hybrid, and on-premises environments in a highly regulated financial institution.
Replaced fragmented, point-in-time validation with repeatable policy automation and reporting that made control posture easier to measure and manage.
Connected findings to actionable remediation guidance, accountable owners, and risk-based priorities to improve sustained compliance outcomes.
Applied security engineering and governance discipline in support of FFIEC and NYDFS expectations, while building evidence leaders and auditors could use.
Progressed from systems administration and DISA STIG compliance into cybersecurity engineering, cloud governance, automation, and enterprise security leadership.
Developing frameworks for security governance, enterprise cybersecurity capabilities, AI risk management, and AI-assisted security workflows.
Representative outcomes from enterprise security configuration governance work; values are approximate where indicated.
Let's connect
Open to conversations with recruiters, hiring managers, security leaders, and peers working through complex governance and compliance challenges.