Directed a ground-up SOC 2 program from first pitch through external audit engagement: policy framework, gap assessments, GRC platform implementation, penetration testing, tabletop exercises, and the auditor relationship. Evidence collection runs on automation, not spreadsheets.
SOC 2
GRC
Compliance Automation
Audit
AI Governance & Rollout
AI Governance
Wrote the AI acceptable-use policy and led the phased rollout of Gemini, Claude, Claude Code, and Cursor with controls built in from the start: risk assessments, OpenTelemetry usage monitoring, spend caps, and IdP-governed provisioning. Extended governance to MCP servers with an SOP, inventory tooling, and a request intake process.
Claude Code
Cursor
Gemini
AI Policy
MCP
AI Usage & Adoption Dashboard
AI Governance
Built the dashboard leadership uses to steer AI investment, covering per-user adoption, usage depth, and spend across Claude, Cursor, and Gemini. Data collection is automated, including a PowerShell exporter written against a vendor analytics API.
Analytics
PowerShell
BigQuery
Reporting
Cloud Security Platform (CNAPP)
Cloud Security
Ran the cloud security platform selection, choosing a CNAPP while retiring native AWS and GCP security tooling. Baselined cloud-native Kubernetes container CVE exposure in production, including VM instances in EC2 and Azure, and stood up malicious-package alerting. Utilized DSPM capabilities and secrets detection.
CNAPP
CSPM
AWS
GCP
Vulnerability Management
Security Policy Library
Compliance
Built the company's information security policy framework from zero into a versioned library of 20+ documents, each carried through legal, HR, and executive approval with employee attestation. Every policy is backed by a working control, so the framework holds up under audit.
Policy
Governance
SOC 2
Risk
Managed Detection & Response
Detection & Response
Led evaluation, procurement, and rollout of an MDR service integrated across the SaaS estate, cloud infrastructure, and every endpoint. Vulnerability counts have trended down since deployment, reported quarterly to leadership.
MDR
SIEM
SOC 2
Monitoring
Supply Chain Threat Mitigation
Detection & Response
Built and led supply chain threat mitigation across the engineering estate: scripted exposure sweeps of the source control estate, malicious-package alerting, post-event analysis for leadership, and automation that shortens detection and response when upstream threats appear.
Supply Chain Security
Incident Response
CI/CD
Automation
Incident Response & Tabletop Program
Resilience
Established tabletop exercises as standing controls: incident response scenarios with DevOps, legal, compliance, and executives, plus annual business continuity and disaster recovery testing. Designed and ran a company-wide security tabletop at the product and technology summit.
Incident Response
BC/DR
SOC 2
Training
Built the CCPA and data-subject request process with defined SLAs and automated intake, drove privacy policy and MSA updates with legal, implemented consent management on the website, and managed the Privacy Impact Assessment for the company's Canadian market launch with external privacy counsel.
CCPA
CPRA
PIPEDA
Privacy
Consent
Cross-Platform Device Management (UEM)
Endpoint Management
Selected and led UEM/MDM deployments for both Windows and macOS fleets: zero-touch enrollment, policy and script architecture, application whitelisting, local admin removal, and identity-connected login. Closed the MDM gap across both operating systems.
UEM
MDM
macOS
Windows
Zero Touch
Identity Platform & SSO
Identity
Architected and deployed the company's identity provider as the foundational security platform, migrating the full SaaS estate to centralized SSO, MFA, SAML, and OIDC, including modifying an internally hosted application to authenticate over OIDC.
IAM
SSO
MFA
SAML
OIDC
HRIS as Source of Truth
Automation
Built automated identity management with the HRIS as the source of truth, pushing employee metadata through the identity provider to every connected application over SCIM and SAML, so job changes and terminations propagate without manual work.
SCIM
Lifecycle Management
HRIS
API
User Lifecycle Automation
Automation
Engineered joiner-mover-leaver workflows using APIs, SCIM, webhooks, and a SaaS management platform, consolidating roughly twenty workflows into five with conditional logic. Ten simultaneous onboardings became a routine morning.
Lifecycle Management
Automation
SCIM
Webhooks
EDR Deployment
Endpoint Security
Evaluated competing EDR platforms, selected one, and deployed it silently to the full Windows fleet with zero support tickets, followed by macOS. Detections route to chat and ticketing for triage; the deployment satisfied cyber insurance requirements and SOC 2 endpoint controls.
EDR
XDR
Endpoint Security
SOC 2
RMM & Patch Management
Endpoint Management
Built the business case for an RMM platform twice (first deferred, then approved on quantified cost of manual work), rolled it out to 95%+ of the fleet, and wrote a PowerShell automation library including a two-ring patching model with an expedited path for critical CVEs.
RMM
Patch Management
PowerShell
Vulnerability Management
Enterprise Password Management
Security
Replaced spreadsheet credential storage with an enterprise password manager: IdP-integrated SSO and SCIM provisioning, agents pushed through RMM, shared vault architecture, and admin training sessions.
Password Management
IAM
SCIM
Training
Network Security Across Six Offices
Networking
Deployed next-generation firewalls and access points across all offices with centralized, declarative management, site-to-cloud VPN with segmented zones, and complete IT builds for office moves in five cities.
NGFW
VPN
Network Security
Office Buildouts
Audited email-enabled systems and implemented DMARC to improve deliverability and mitigate spoofing and spam.
DMARC
Email
Security
Developed vessel cyber security plan per IMO MSC-FAL.1/Circ.3 using the NIST Cybersecurity Framework for process control and safety systems.
IMO
NIST CSF
Maritime
Risk Assessment
Document Management System
Development
Built a PHP/LAMP document management system with SMB replication via FTP to remote sites and intranet integration.
PHP
LAMP
FTP
WordPress