Directed a ground-up SOC 2 program from first pitch through external audit engagement: policy framework, gap assessments, Secureframe implementation, penetration testing, tabletop exercises, and the auditor relationship. Evidence collection runs on automation, not spreadsheets.
SOC 2
Secureframe
Audit
GRC
AI Governance & Rollout
AI Governance
Wrote the AI acceptable-use policy and led the phased rollout of Gemini, Claude, Claude Code, and Cursor with controls built in from the start: risk assessments, OpenTelemetry usage monitoring, spend caps, and Okta-governed provisioning. Extended governance to MCP servers with an SOP, inventory tooling, and a request intake process.
Claude Code
Cursor
Gemini
Policy
OpenTelemetry
AI Usage & Adoption Dashboard
AI Governance
Built the dashboard leadership uses to steer AI investment, covering per-user adoption, usage depth, and spend across Claude, Cursor, and Gemini. Data collection is automated, including a PowerShell exporter written against Cursor's analytics API.
Analytics
PowerShell
BigQuery
Reporting
Ran the cloud security platform selection, choosing Orca while retiring native AWS and GCP security tooling. Baselined cloud-native Kubernetes container CVE exposure in production, including VM instances in EC2 and Azure, and stood up malicious-package alerting. Utilized DSPM capabilities and secrets detection.
Orca
AWS
GCP
CNAPP
Vulnerability Management
Security Policy Library
Compliance
Built the company's information security policy framework from zero into a versioned library of 20+ documents, each carried through legal, HR, and executive approval with employee attestation. Every policy is backed by a working control, so the framework holds up under audit.
Policy
Governance
SOC 2
Risk
Led evaluation, procurement, and rollout of managed detection and response, integrated across the SaaS estate, cloud infrastructure, and every endpoint. Vulnerability counts have trended down since deployment, reported quarterly to leadership.
Arctic Wolf
MDR
SOC 2
Monitoring
Supply Chain Threat Mitigation
Detection & Response
Built and led supply chain threat mitigation across the engineering estate: scripted GitLab exposure sweeps, malicious-package alerting, post-event analysis for leadership, and automation that shortens detection and response when upstream threats appear.
Supply Chain
GitLab
Threat Mitigation
Automation
Incident Response & Tabletop Program
Resilience
Established tabletop exercises as standing controls: incident response scenarios with DevOps, legal, compliance, and executives, plus annual business continuity and disaster recovery testing. Designed and ran a company-wide security tabletop at the product and technology summit.
Incident Response
BC/DR
SOC 2
Training
Built the CCPA and data-subject request process with defined SLAs and automated intake, drove privacy policy and MSA updates with legal, implemented consent management on the website, and managed the Privacy Impact Assessment for the company's Canadian market launch with external privacy counsel.
CCPA
CPRA
PIPEDA
Privacy
Consent
Selected and led the Jamf and Jamf Connect deployment for the macOS fleet: zero-touch enrollment, policy and script architecture, local admin removal, and Okta-connected login. Closed the MDM gap alongside Intune on Windows.
Jamf
macOS
MDM
Okta
Built automated identity management with Okta as definitive source of truth, integrating Rippling HRIS, SCIM, SAML, and BetterCloud API automations.
Okta
BetterCloud
Rippling
SCIM
API
Engineered automated user lifecycle management using APIs, SCIM, webhooks, and custom JavaScript BetterCloud extensions.
BetterCloud
JavaScript
SCIM
Webhooks
Delivered Endpoint Detection and Response across all end-user devices to meet SOC 2 security controls and strengthen incident response.
SentinelOne
EDR
SOC 2
Endpoint
Deployed Intune MDM for centralized device management, compliance policies, and remote wipe across the mobile fleet.
Intune
MDM
Compliance
SOC 2
Migrated all passwords from shared spreadsheets to 1Password with employee training for secure password management.
1Password
Training
Password Management
Upgraded network infrastructure with FortiGate firewalls, FortiAP access points, FortiSwitch managed switches, and FortiManager across all offices.
FortiGate
FortiAP
FortiManager
Network Security
Audited email-enabled systems and implemented DMARC to improve deliverability and mitigate spoofing and spam.
DMARC
Email
Security
Architected and deployed Okta as a foundational security platform, migrating all applications to centralized SSO and MFA.
Okta
SSO
MFA
SAML
SCIM
Developed vessel cyber security plan per IMO MSC-FAL.1/Circ.3 using the NIST Cybersecurity Framework for process control and safety systems.
IMO
NIST CSF
Maritime
Risk Assessment
Document Management System
Development
Built a PHP/LAMP document management system with SMB replication via FTP to remote sites and intranet integration.
PHP
LAMP
FTP
WordPress