// Experience
Career Timeline
From sysadmin to security leader, each role built on the last.
Technical Lead Manager, GRC | Handshake AI
Jun 2025 – Present
  • Led the company's first SOC 2 Type I audit for Handshake's AI product, leveraging existing core controls to deliver a streamlined audit with zero exceptions
  • Managed vulnerability management and the security exception program, achieving 95%+ SLA compliance and 100% exception coverage across all open findings
  • Reduced manual effort on customer security questionnaires by 90%+ by deploying Wolfia and standardizing AI-assisted response workflows
  • Built and deployed 6 production internal security applications using AI-assisted development, replacing multi-day manual workflows with automated tooling on GCP Cloud Run
  • Stood up the insider threat program, deploying DLP controls to surface risk indicators and deliver data-driven briefings that inform leadership decision-making
Senior Security Technical Program Manager, GRC | Handshake AI
Feb 2024 – May 2025
  • Delivered SOC 2 with zero exceptions within 90 days of hire; reduced subsequent audit timeline by 33% through self-service evidence collection via GCP, GitHub, and Anecdotes
  • Reduced vendor security review SLA from 8 days to 2 business days by building risk-based vendor tiering workflows, achieving 100% review coverage
  • Deployed SafeBase to establish a customer trust program, enabling self-service access to security documentation for internal and external stakeholders
  • Developed the governance and risk management program from scratch: rewrote 22 policies, conducted risk assessments, built a risk register, and stood up a cross-functional risk council
  • Deployed KnowBe4 for security and privacy training with onboarding controls requiring completion within 30 days for all employees and contractors
Senior Associate (Freelance) | Atlas One Security
Jan 2024 – Present
  • Led end-to-end SOC 2 Type I program from scratch for a subsidiary of a publicly traded company, establishing governance, controls, and audit readiness
  • Supported ISO 27001 and PCI DSS initiatives across multiple clients, providing audit preparation, control design, and evidence support
  • Served as subject matter expert on AI-assisted GRC tooling, advising clients on automation strategies for evidence collection and policy management
Senior Security Engineer, Risk & Assurance | Amplitude
Feb 2022 – Feb 2024
  • Led SOC 2 and ISO audit programs end-to-end, including auditor relationships, control owner coordination, evidence collection, and program management
  • Implemented Anecdotes to automate compliance workflows, cutting manual compliance effort by 80%
  • Deployed SafeBase customer trust program, reducing inbound questionnaires by 95% with a 99.5% response SLA
  • Built Python scripts leveraging API integrations to streamline evidence and data collection, providing control owners with actionable, real-time insights
  • Implemented a risk management program aligned with ISO 27005
Cybersecurity GRC Program Manager | City & County of San Francisco, DT
Sep 2019 – Feb 2022
  • Led the City's cybersecurity risk management program using FAIR methodology, guiding 55 departments through risk assessments, gap analysis, treatment plans, and continuous monitoring
  • Established and managed the City's vendor risk management program, overseeing risk assessments for 2,000+ qualifying vendors
  • Automated risk management workflows in LogicGate, improving consistency and reducing manual effort across the GRC program
  • Implemented an enterprise cybersecurity awareness program for 30,000 employees and contractors
Security Program Manager | Superior Court of California, SF
Apr 2016 – Sep 2019
  • Implemented CIS 20 security controls, conducting risk assessments and engaging executive stakeholders to prioritize cybersecurity investment
  • Managed the corporate security program using FireEye EDR, Tanium, Trend Deep Security, and PAN Traps across VMware infrastructure
  • Designed RBAC with need-to-know access principles; leveraged PowerShell and Ansible to automate operations
Senior System Administrator | Pravis LLC
Nov 2012 – Apr 2016
  • Designed and maintained VMware clusters and Citrix XenApp farms supporting 200+ Windows and 50+ Linux servers
  • Automated identity and infrastructure workflows using PowerShell across Active Directory, Exchange, and VMware; led team of 5