About

Security is a business problem that happens to be technical

Fifteen years leading enterprise security across global manufacturing, academic healthcare, national retail, and financial services — with an MBA and a finance degree behind the technical work.

What I do now

I am Director of Cybersecurity and Deputy CISO at a global food production and manufacturing company, where I own enterprise security strategy, governance, risk, architecture direction, vendor strategy, and a $24M annual security budget for a $14B business with more than 50,000 employees worldwide. I report to the CISO, lead a 12-person team across cyber risk, governance, architecture, and operations, and present quarterly to the Executive Cybersecurity Committee and the board.

When I arrived, the enterprise security governance program did not exist. I built it — the policy set, the control environment, the risk register, the reporting cadence, the third-party risk process, and the KPIs and SLAs that now measure how the program is actually performing. That program is what carried the company through IPO readiness, external audit, and cyber-insurance underwriting.

Enterprise security program scope Enterprise security strategy and accountability at the centre, connected to board and executive reporting, governance and risk, security operations, architecture, identity and Zero Trust, third-party risk, AI and agent governance, and budget and vendor strategy. Enterprise security strategy & accountability Board & exec reporting Governance & risk Security operations Architecture IAM & Zero Trust Third-party risk AI & agent governance Budget & vendor strategy

Every function shown is one I own or direct in the current role.

How I got here

I started on the audit side. For seven years at a national IT audit and risk advisory firm I led IT, cybersecurity, and compliance assessments for more than 500 banks and credit unions — governance, access, data protection, business continuity, vendor management, resilience. That work teaches you two things quickly. First, how to find the gap between what a control document claims and what the organization actually does. Second, how to tell an audit committee something they do not want to hear in a way that produces a decision instead of an argument.

From there I went operational. At a major sporting goods and outdoor retailer I was the company’s first enterprise information security leader — $6.5B in revenue, 40,000 employees, stores, e-commerce, payment, and corporate environments, and no existing security function. I built it, led ten engineers, modernized identity, moved the company toward Zero Trust, and took it through PCI DSS compliance and the audits behind it.

At a leading global healthcare organization I moved from building a function to running one at scale: a 100-person information security organization for a 76,000-employee academic medical system with more than $16B in revenue, spanning security operations, threat management, IAM, GRC, engineering, architecture, cloud security, and review. I set multi-year strategy across on-premises, private cloud, AWS, Azure, and SaaS; built a 24x7 SOC on a hybrid MSSP model; guided HITRUST CSF certification; and served as executive incident commander for major security events — owning the technical resolution alongside executive communications, legal, and regulator coordination.

Then global food manufacturing, and a different problem again: a worldwide production and consumer-goods footprint, an IPO on the horizon, and a governance program that had to be built from nothing and be credible to outside auditors within a fixed window.

The finance part matters

I have a Bachelor of Science in Finance and an MBA from Missouri State University, alongside a graduate certificate in cybersecurity. That is not decoration on the resume — it is why the risk conversations go differently.

Most security programs fail their executives not on competence but on translation. A CFO cannot act on “we have 4,200 critical vulnerabilities.” They can act on “this specific set of exposures represents roughly $46M of annualized loss expectancy, here is what it costs to remove most of it, and here is the sequence.” Being able to build that second sentence honestly — and defend the model behind it to an auditor, an underwriter, or a board member who used to run a P&L — is most of what makes a security program fundable.

The through-line

Every one of these roles involved building or rebuilding a security function under external pressure — an audit, a certification, an IPO, a regulator, or an incident already in progress. That is the work I am good at and the work I look for.

What I am looking for

Senior security leadership — CISO, Deputy CISO, or a Director/Senior Director role with real program ownership — at an organization where security has a genuine business consequence: regulated, customer-trust-dependent, going through a transaction, or scaling faster than its control environment.

I am most useful where the program needs to be built or turned around rather than maintained, and where the executive team actually wants to understand the risk rather than receive a status color. If that sounds like your situation, get in touch.

Education & credentials

Missouri State University

  • Master of Business Administration
  • Graduate Certificate in Cybersecurity
  • Bachelor of Science in Finance

Certifications

  • CISSP — Certified Information Systems Security Professional
  • CISM — Certified Information Security Manager
  • CISA — Certified Information Systems Auditor
  • CRISC — Certified in Risk and Information Systems Control
  • CDPSE — Certified Data Privacy Solutions Engineer
  • CRMA — Certification in Risk Management Assurance

Frameworks & standards I work in

  • NIST CSF 2.0
  • NIST SP 800-53
  • NIST AI RMF
  • ISO/IEC 27001
  • SOC 2
  • PCI DSS
  • HITRUST CSF
  • HIPAA
  • GDPR
  • CCPA
  • CIS Controls
  • OWASP