// full_stack_grc

I build security programs
and the tools to run them.

GRC leader with 12+ years building compliance, risk, and security programs at high-growth tech companies and public-sector orgs. I don't just manage audits. I write the code that automates them.

12+
Years in Security & GRC
10+
Audits Conducted (SOC 2, PCI, ISO)
3
Internal Apps Shipped
75%
Manual Work Eliminated
The Arc

I started in the trenches: racking servers, writing PowerShell scripts, managing VMware clusters. That sysadmin foundation taught me how infrastructure actually works, which turned out to be the thing most GRC people are missing.

From there I moved into security operations and eventually into GRC program management, leading risk programs and building a vendor assessment process covering 2,000+ vendors for the City of San Francisco (55 departments, 30,000 employees) before shifting to high-growth startups.

At Amplitude and Handshake, I found my groove building compliance programs that actually work (SOC 2, ISO 27001, PCI) while simultaneously building the internal tooling to automate the boring parts. This is also where I learned firsthand how painful customer trust workflows are and became convinced that no human should ever manually fill out a security questionnaire again.

AI has been part of my toolkit since the early GPT-3.5 days, when I started using it to accelerate GRC workflows like policy drafting, risk analysis, and evidence mapping. That evolved into writing Python scripts with Copilot, then building full production applications with Claude. Today I use AI-assisted development to ship internal security tools on GCP, going from idea to deployed Cloud Run service in days, building tools that would otherwise never exist.

The throughline: I make security programs that don't depend on me being in the room. Automated evidence collection, self-service vendor reviews, codified risk processes. Programs that outlast the audit cycle.

Current Role
Technical Lead Manager, GRC, Handshake
Location
San Francisco, CA
Education
M.S. CIS, Boston University
Certifications
CISSP · CISM · OPEN FAIR
What I Do
The intersection of program management, security engineering, and software development.
🛡

Compliance

End-to-end ownership of audit programs from scoping through delivery. Zero-exception track record across SOC 2, ISO 27001, and PCI DSS. Built automated evidence collection pipelines that cut audit prep time by 80%.

SOC 2 ISO 27001 PCI DSS Anecdotes

Governance & Risk

Build governance and risk programs from scratch: policy frameworks, risk registers, risk councils, and assessment methodologies. Experienced with FAIR quantitative risk and ISO 27005 qualitative approaches.

FAIR ISO 27005 Policy Frameworks Risk Registers
💻

AI-Assisted Development

Design, build, and deploy production security applications using Claude Cowork. Full-stack apps on GCP Cloud Run that automate vendor risk, customer trust, and compliance workflows, shipping tools in days that would otherwise never exist.

Claude Cowork GCP Cloud Run FastAPI React
👥

Customer Trust & Third-Party Risk

Deployed self-service customer trust portals and AI-powered questionnaire response, reducing time spent on security questionnaires by 90%+. Built vendor risk programs assessing 2,000+ vendors with risk-based tiering and SLA-driven review processes.

SafeBase Sudozi SecurityScorecard Wolfia
🔐

Security Culture & Awareness

Enterprise-scale security awareness and training programs with onboarding controls, phishing simulations, and completion enforcement. Build security culture through education, not just policy.

KnowBe4 Phishing Simulations Training Programs

Infrastructure & Operations

Deep infrastructure roots: VMware, Active Directory, Linux/Windows ops. PowerShell and Ansible automation. The foundation that makes everything else possible.

PowerShell Ansible VMware Linux
Career Timeline
From sysadmin to security leader, each role built on the last.
Technical Lead Manager, GRC | Handshake
Jun 2025 – Present
  • Led the company's first SOC 2 Type I audit for Handshake's AI product, leveraging existing core controls to deliver a streamlined audit with zero exceptions
  • Managed vulnerability management and the security exception program, achieving 95%+ SLA compliance and 100% exception coverage across all open findings
  • Reduced manual effort on customer security questionnaires by 90%+ by deploying Wolfia and standardizing AI-assisted response workflows
  • Built and deployed 3 production internal security applications using AI-assisted development, replacing multi-day manual workflows with automated tooling on GCP Cloud Run
  • Stood up the insider threat program, deploying DLP controls to surface risk indicators and deliver data-driven briefings that inform leadership decision-making
Senior Security Technical Program Manager, GRC | Handshake
Feb 2024 – May 2025
  • Delivered SOC 2 with zero exceptions within 90 days of hire; reduced subsequent audit timeline by 33% through self-service evidence collection via GCP, GitHub, and Anecdotes
  • Reduced vendor security review SLA from 8 days to 2 business days by building risk-based vendor tiering workflows, achieving 100% review coverage
  • Deployed SafeBase to establish a customer trust program, enabling self-service access to security documentation for internal and external stakeholders
  • Developed the governance and risk management program from scratch: rewrote 22 policies, conducted risk assessments, built a risk register, and stood up a cross-functional risk council
  • Deployed KnowBe4 for security and privacy training with onboarding controls requiring completion within 30 days for all employees and contractors
Senior Associate (Freelance) | Atlas One Security
Jan 2024 – Present
  • Led end-to-end SOC 2 Type I program from scratch for a subsidiary of a publicly traded company, establishing governance, controls, and audit readiness
  • Supported ISO 27001 and PCI DSS initiatives across multiple clients, providing audit preparation, control design, and evidence support
  • Served as subject matter expert on AI-assisted GRC tooling, advising clients on automation strategies for evidence collection and policy management
Senior Security Engineer, Risk & Assurance | Amplitude
Feb 2022 – Feb 2024
  • Led SOC 2 and ISO audit programs end-to-end, including auditor relationships, control owner coordination, evidence collection, and program management
  • Implemented Anecdotes to automate compliance workflows, cutting manual compliance effort by 80%
  • Deployed SafeBase customer trust program, reducing inbound questionnaires by 95% with a 99.5% response SLA
  • Built Python scripts leveraging API integrations to streamline evidence and data collection, providing control owners with actionable, real-time insights
  • Implemented a risk management program aligned with ISO 27005
Cybersecurity GRC Program Manager | City & County of San Francisco, DT
Sep 2019 – Feb 2022
  • Led the City's cybersecurity risk management program using FAIR methodology, guiding 55 departments through risk assessments, gap analysis, treatment plans, and continuous monitoring
  • Established and managed the City's vendor risk management program, overseeing risk assessments for 2,000+ qualifying vendors
  • Automated risk management workflows in LogicGate, improving consistency and reducing manual effort across the GRC program
  • Implemented an enterprise cybersecurity awareness program for 30,000 employees and contractors
Security Program Manager | Superior Court of California, SF
Apr 2016 – Sep 2019
  • Implemented CIS 20 security controls, conducting risk assessments and engaging executive stakeholders to prioritize cybersecurity investment
  • Managed the corporate security program using FireEye EDR, Tanium, Trend Deep Security, and PAN Traps across VMware infrastructure
  • Designed RBAC with need-to-know access principles; leveraged PowerShell and Ansible to automate operations
Senior System Administrator | Pravis LLC
Nov 2012 – Apr 2016
  • Designed and maintained VMware clusters and Citrix XenApp farms supporting 200+ Windows and 50+ Linux servers
  • Automated identity and infrastructure workflows using PowerShell across Active Directory, Exchange, and VMware; led team of 5
Things I've Built
Production applications and automation, not proofs of concept.
1 2 3 4 Customer Security Intake Submit a customer or prospect security request Why this process? Trust Portal answers the majority of security questions automatically...
Production

Customer Security Intake

Fully automated security request intake system, from GTM to Linear to Wolfia. 14 systems integrated, zero manual steps. Reduced time spent on customer security questionnaires by 90%+.

→ 90%+ time reduction on questionnaires
Next.js Cloud Run Linear Wolfia IAP
View case study →
TPRM Dashboard Vendors Total Vendors 162 Critical 48 Pending 55 Non-Critical 59 VENDOR DECISION PII INTEGRATION AuthProvider Co Critical DataViz Platform Not Critical LLM Provider Critical Monitoring SaaS Pending
Production

TPRM | Third-Party Risk Management

Automated vendor risk platform that syncs with procurement (Ramp) and project tracking (Linear). Tracks 162 vendors with automated risk evaluation, daily syncs, and Slack alerts.

→ 162 vendors, 100% audit coverage
FastAPI React Cloud Run Ramp API Linear
View case study →
company-grc-security-policies Private Name Last commit .github/workflows Update sync workflow access-control-policy.md Annual policy review acceptable-use-policy.md Clarify BYOD section asset-management-policy.md Add cloud asset tagging data-classification-policy.md Initial commit incident-response-policy.md Update escalation path
Production

Security Policies as Code

22 security policies managed as markdown in GitHub with automated publishing to Notion via GitHub Actions. Every change is version-controlled, peer-reviewed, and audit-ready.

→ 22 policies, 0 manual publishing steps
Markdown GitHub Actions Notion API Claude
View case study →
Production

Automated Evidence Collection

Self-service SOC 2 evidence collection through GCP and GitHub integrations with Anecdotes. Achieved 100% evidence coverage and 80% auditor acceptance of automated evidence.

→ 80% compliance effort reduction
GCP GitHub Anecdotes Python
Shipped

Vendor Risk Tiering System

Risk-based vendor tiering workflows in Sudozi. Cut vendor security review SLA from 8 days to 2 business days with 100% review coverage for all in-scope vendors.

→ 8-day SLA → 2-day SLA
Sudozi Risk Tiering Workflow Design
Shipped

City-Scale Risk Management Engine

Built the City of San Francisco's cybersecurity risk management program using FAIR methodology. Guided 55 departments through risk assessments, gap analysis, and treatment plans.

→ 55 departments, 2,000 vendors assessed
FAIR LogicGate CAIQ-Lite SecurityScorecard
Skills
Reusable skill files for Claude Code and Cowork. Drop them into your .claude/skills folder and they work immediately. Built from real production workflows, anonymized for public use.
Writing
Reflections on building, shipping, and figuring it out as I go.
Education & Certifications

Education

  • M.S. Computer Information Systems
    Boston University
    2013
  • A.S. Computer Networking & IT
    City College of San Francisco
    2010
  • B.A. International Relations / Russian
    UC Davis
    2007

Certifications

  • CISM
    Certified Information Security Manager
    Active
  • CISSP
    Certified Information Systems Security Professional
    Active
  • Security+
    CompTIA
    2020
  • OPEN FAIR Certified
    The Open Group
    2019