Manufacturing, academic healthcare, national retail, and financial services. Different regulators, different threat models, same underlying task: make the risk visible, then make it smaller.
Bar shade deepens with seniority; the current role is picked out in gold.
2022 – Present
Global Food Production & Manufacturing Company $14B revenue · 50,000+ employees
Director of Cybersecurity (Deputy CISO)
Own enterprise security strategy, governance, risk, architecture direction, vendor strategy, and a $24M annual security budget for a global food production and manufacturing company. Report to the CISO; present to the Executive Cybersecurity Committee and the board.
Built the enterprise security governance program from the ground up and now lead a 12-person team across cyber risk, governance, architecture, and operations.
Reduced annual quantified cyber risk exposure by approximately $46M by sequencing remediation according to business impact rather than raw vulnerability counts. Case study →
Delivered an IPO-ready security program one year ahead of schedule, producing policies, control evidence, audit documentation, and executive reporting accepted by auditors, cyber-insurance underwriters, and regulators. Case study →
Reduced cybersecurity spend 27% year over year by rationalizing overlapping tools, reshaping vendor strategy, and eliminating duplicated effort between IT and security. Case study →
Operate the ISMS and control environment against NIST CSF 2.0, ISO 27001, and CIS Controls; set the KPIs and SLAs used to measure risk, spend, and program performance.
Established governance for enterprise AI platforms and agentic tooling, including acceptable-use standards and machine and agent identities within access management.
Rebuilt third-party and supply-chain cyber risk around tiered due diligence, continuous monitoring, contractual requirements, and customer and partner security assessments.
2015 – 2022
Leading Global Healthcare Organization $16B+ revenue · 76,000 employees
Director of Information Security
Led information security for a global healthcare organization. Directed a 100-person organization spanning security operations, threat management, IAM, GRC, engineering, architecture, cloud security, and review.
Set multi-year security strategy across on-premises, private cloud, AWS, Azure, and SaaS, embedding security review into system design, approval, and release.
Built a 24x7 SOC on a hybrid MSSP model — outsourced Tier 1 monitoring and triage while retaining escalation, detection engineering, and incident response in-house. Case study →
Served as executive incident commander for major security events, owning technical resolution, executive and legal communications, regulator coordination, and post-incident improvement.
Guided HITRUST CSF certification and aligned the broader program to ISO 27001, NIST CSF, and CIS Controls while maintaining HIPAA, GDPR, and CCPA obligations.
First enterprise information security leader for a national retailer, covering stores, e-commerce, payment, and corporate environments. Built the function and led 10 engineers.
Moved the company toward Zero Trust and modernized IAM to protect customer and employee data across card-present, online, and corporate environments. Case study →
Achieved PCI DSS compliance and managed the internal and external audits supporting millions of transactions annually.
Deployed EDR, reduced attack surface through testing and assessments, and delivered security awareness to the full workforce.
Partnered with Sales, IT, Engineering, and Customer Support to keep the roadmap funded, pragmatic, and aligned with growth and customer trust.
2005 – 2012
National IT Audit & Risk Advisory Firm Remote 500+ banking & credit-union clients
Senior Director of Audit & Technology
Led IT, cybersecurity, and compliance assessments across governance, access, data protection, business continuity, vendor management, and resilience.
Translated findings into prioritized remediation for executives, audit committees, and boards.
Managed concurrent engagements against examination deadlines and client budgets.
Built the habit that still drives how I report risk: an assessment is only useful if it ends in a decision someone is willing to fund.
Earlier
United States
Earlier career
Lead Information Security Auditor — regional technology advisory firm
Network Administrator — community bank
The detail behind the bullets
Five of these engagements are written up properly — situation, decision, outcome, and what actually transfers to another organization.