Experience

Twenty years, four industries, one job

Manufacturing, academic healthcare, national retail, and financial services. Different regulators, different threat models, same underlying task: make the risk visible, then make it smaller.

Career timeline, 2005 to present Four roles in sequence: Senior Director of Audit and Technology at a national IT audit and risk advisory firm from 2005 to 2012; Head of Information Security at a sporting goods retailer from 2012 to 2015; Director of Information Security at a global healthcare organization from 2015 to 2022; and Director of Cybersecurity and Deputy CISO at a global food manufacturer from 2022 to the present. Senior Director, Audit & Technology National IT audit & risk advisory firm · 500+ clients Head of Information Security (CISO) Sporting goods retailer · $6.5B · 40,000 employees Director of Information Security Global healthcare organization · $16B+ · 100-person org Director of Cybersecurity (Deputy CISO) Global food manufacturer · $14B · 50,000+ employees 2005 2012 2015 2022 Now

Bar shade deepens with seniority; the current role is picked out in gold.

2022 – Present

Global Food Production & Manufacturing Company
$14B revenue · 50,000+ employees

Director of Cybersecurity (Deputy CISO)

Own enterprise security strategy, governance, risk, architecture direction, vendor strategy, and a $24M annual security budget for a global food production and manufacturing company. Report to the CISO; present to the Executive Cybersecurity Committee and the board.

  • Built the enterprise security governance program from the ground up and now lead a 12-person team across cyber risk, governance, architecture, and operations.
  • Reduced annual quantified cyber risk exposure by approximately $46M by sequencing remediation according to business impact rather than raw vulnerability counts. Case study →
  • Delivered an IPO-ready security program one year ahead of schedule, producing policies, control evidence, audit documentation, and executive reporting accepted by auditors, cyber-insurance underwriters, and regulators. Case study →
  • Reduced cybersecurity spend 27% year over year by rationalizing overlapping tools, reshaping vendor strategy, and eliminating duplicated effort between IT and security. Case study →
  • Operate the ISMS and control environment against NIST CSF 2.0, ISO 27001, and CIS Controls; set the KPIs and SLAs used to measure risk, spend, and program performance.
  • Established governance for enterprise AI platforms and agentic tooling, including acceptable-use standards and machine and agent identities within access management.
  • Rebuilt third-party and supply-chain cyber risk around tiered due diligence, continuous monitoring, contractual requirements, and customer and partner security assessments.

2015 – 2022

Leading Global Healthcare Organization
$16B+ revenue · 76,000 employees

Director of Information Security

Led information security for a global healthcare organization. Directed a 100-person organization spanning security operations, threat management, IAM, GRC, engineering, architecture, cloud security, and review.

  • Set multi-year security strategy across on-premises, private cloud, AWS, Azure, and SaaS, embedding security review into system design, approval, and release.
  • Built a 24x7 SOC on a hybrid MSSP model — outsourced Tier 1 monitoring and triage while retaining escalation, detection engineering, and incident response in-house. Case study →
  • Served as executive incident commander for major security events, owning technical resolution, executive and legal communications, regulator coordination, and post-incident improvement.
  • Guided HITRUST CSF certification and aligned the broader program to ISO 27001, NIST CSF, and CIS Controls while maintaining HIPAA, GDPR, and CCPA obligations.
  • Directed IAM, vulnerability management, penetration testing, threat intelligence, endpoint protection, security engineering, architecture, and GRC outcomes.
  • Implemented secure SDLC and DevSecOps practices with OWASP-aligned review, WAF, DDoS protection, and practical partnership with engineering teams.

2012 – 2015

Major Sporting Goods & Outdoor Retailer
$6.5B revenue · 40,000 employees

Head of Information Security (CISO)

First enterprise information security leader for a national retailer, covering stores, e-commerce, payment, and corporate environments. Built the function and led 10 engineers.

  • Moved the company toward Zero Trust and modernized IAM to protect customer and employee data across card-present, online, and corporate environments. Case study →
  • Achieved PCI DSS compliance and managed the internal and external audits supporting millions of transactions annually.
  • Deployed EDR, reduced attack surface through testing and assessments, and delivered security awareness to the full workforce.
  • Partnered with Sales, IT, Engineering, and Customer Support to keep the roadmap funded, pragmatic, and aligned with growth and customer trust.

2005 – 2012

National IT Audit & Risk Advisory Firm
Remote
500+ banking & credit-union clients

Senior Director of Audit & Technology

Led IT, cybersecurity, and compliance assessments across governance, access, data protection, business continuity, vendor management, and resilience.

  • Translated findings into prioritized remediation for executives, audit committees, and boards.
  • Managed concurrent engagements against examination deadlines and client budgets.
  • Built the habit that still drives how I report risk: an assessment is only useful if it ends in a decision someone is willing to fund.

Earlier

United States

Earlier career

  • Lead Information Security Auditor — regional technology advisory firm
  • Network Administrator — community bank

The detail behind the bullets

Five of these engagements are written up properly — situation, decision, outcome, and what actually transfers to another organization.