I enjoy building teams and solving problems at the intersection of business and technology. I am passionate about aligning security risks with business objectives, implementing automated security controls to reduce the cost of compliance, and building partnerships with Infrastructure & Product Engineering teams to achieve shared objectives.
I've led successful Security and Engineering teams at small startups, hypergrowth unicorns, and Fortune 500 enterprises. I'm at my best working in high-performing environments where teams are empowered to experiment, fail fast, and challenge the status quo.
Building a secure and compliant technology ecosystem requires not only technical problem-solving skills but also strong communication and the ability to influence. I enjoy the challenges inherent in securing cloud-first architectures and evolving technology practices like microservices, container orchestration, devsecops, CI/CD continuous validation, and compliance as code.
I strive to make security compliance a no-brainer by building consensus among stakeholders, evangelizing creative solutions that exploit automation, and translating vision into a practical, tactical plan.
SOX | SOC2 | HIPAA | HITRUST | PCI-DSS | ISO | NIST | CIS18 | OWASP | ATT&CK | FAIR