// Experience
Career Timeline
From sysadmin to security leader, each role built on the last.
- Led the company's first SOC 2 Type I audit for Handshake's AI product, leveraging existing core controls to deliver a streamlined audit with zero exceptions
- Managed vulnerability management and the security exception program, achieving 95%+ SLA compliance and 100% exception coverage across all open findings
- Reduced manual effort on customer security questionnaires by 90%+ by deploying Wolfia and standardizing AI-assisted response workflows
- Built and deployed 6 production internal security applications using AI-assisted development, replacing multi-day manual workflows with automated tooling on GCP Cloud Run
- Stood up the insider threat program, deploying DLP controls to surface risk indicators and deliver data-driven briefings that inform leadership decision-making
- Delivered SOC 2 with zero exceptions within 90 days of hire; reduced subsequent audit timeline by 33% through self-service evidence collection via GCP, GitHub, and Anecdotes
- Reduced vendor security review SLA from 8 days to 2 business days by building risk-based vendor tiering workflows, achieving 100% review coverage
- Deployed SafeBase to establish a customer trust program, enabling self-service access to security documentation for internal and external stakeholders
- Developed the governance and risk management program from scratch: rewrote 22 policies, conducted risk assessments, built a risk register, and stood up a cross-functional risk council
- Deployed KnowBe4 for security and privacy training with onboarding controls requiring completion within 30 days for all employees and contractors
- Led end-to-end SOC 2 Type I program from scratch for a subsidiary of a publicly traded company, establishing governance, controls, and audit readiness
- Supported ISO 27001 and PCI DSS initiatives across multiple clients, providing audit preparation, control design, and evidence support
- Served as subject matter expert on AI-assisted GRC tooling, advising clients on automation strategies for evidence collection and policy management
- Led SOC 2 and ISO audit programs end-to-end, including auditor relationships, control owner coordination, evidence collection, and program management
- Implemented Anecdotes to automate compliance workflows, cutting manual compliance effort by 80%
- Deployed SafeBase customer trust program, reducing inbound questionnaires by 95% with a 99.5% response SLA
- Built Python scripts leveraging API integrations to streamline evidence and data collection, providing control owners with actionable, real-time insights
- Implemented a risk management program aligned with ISO 27005
- Led the City's cybersecurity risk management program using FAIR methodology, guiding 55 departments through risk assessments, gap analysis, treatment plans, and continuous monitoring
- Established and managed the City's vendor risk management program, overseeing risk assessments for 2,000+ qualifying vendors
- Automated risk management workflows in LogicGate, improving consistency and reducing manual effort across the GRC program
- Implemented an enterprise cybersecurity awareness program for 30,000 employees and contractors
- Implemented CIS 20 security controls, conducting risk assessments and engaging executive stakeholders to prioritize cybersecurity investment
- Managed the corporate security program using FireEye EDR, Tanium, Trend Deep Security, and PAN Traps across VMware infrastructure
- Designed RBAC with need-to-know access principles; leveraged PowerShell and Ansible to automate operations
- Designed and maintained VMware clusters and Citrix XenApp farms supporting 200+ Windows and 50+ Linux servers
- Automated identity and infrastructure workflows using PowerShell across Active Directory, Exchange, and VMware; led team of 5