Virtual CISO (vCISO)
Aug 2025 - Current (1 year 3 months)
As a Virtual Chief Information Security Officer (vCISO), I partner with organizations to design, implement, and mature their cybersecurity programs. My work spans conducting comprehensive risk assessments, aligning controls with frameworks such as NIST CSF, ISO 27001, SOC 2, HIPAA, and PCI DSS, and building governance structures that enable executive oversight and board reporting. I guide incident response readiness, third-party risk management, vulnerability management, and policy development while ensuring compliance with regulatory and contractual obligations. Acting as both strategist and hands-on advisor, I help organizations balance security and business priorities, strengthen resilience, and reduce enterprise risk.