About
I work where security, risk, and execution meet.
Over the last 12 years I've moved from building technology to governing the risk in it. I did that first through cybersecurity project management, and then as a Business Information Security Officer owning GRC for around 150 applications.
Most of what I do comes down to getting security findings fixed. As a BISO I took vulnerability-remediation SLA compliance from about 65% to 99%. That came from giving every risk an owner, a deadline, and a clear path to a decision, rather than from chasing teams harder. More recently I've worked on statewide data-modernization efforts, where the job is to catch privacy and security gaps in sensitive public-sector data flows before they get built.
I'm comfortable in the technical weeds, but the part I'm best at is the handoff: turning a control gap, a pen-test finding, or a regulatory requirement into something a director or an auditor can understand, own, and sign off on. Security that no one understands does not get prioritized, and security that is not prioritized does not get done.
Where assessment and governance turn into action.
Away from work, I enjoy tinkering with technology, playing electric guitar, growing produce in my garden, strategy games like Factorio, and Magic: The Gathering with friends.