I bridge the gap between technical security operations and business risk strategy. With over 10 years driving GRC initiatives, I specialize in building audit-ready security programs and turning compliance into a competitive advantage.
Focus: scalable governance, AI security, and operational resilience.
Security programs that hold up under auditor scrutiny, close enterprise deals in regulated markets, and give leadership a clear view of risk — without requiring them to be technical.
I direct end-to-end compliance lifecycles for high-assurance frameworks. My approach builds continuous, audit-ready governance models — not point-in-time checkbox exercises.
Innovation requires guardrails. I lead the safe adoption of Generative AI by establishing Acceptable Use Policies and AI Risk Assessment frameworks — balancing speed with data privacy and IP protection.
From Third-Party Risk Management to Incident Response, I build systems that quantify risk for leadership. Security operations as a business enabler — accelerating sales velocity, not slowing it down.
Practical writing on GRC, AI governance, career development, and the realities of running a security program at a growing company. No vendor pitches, no recycled frameworks — just direct perspective from the field.
Practical resources for security professionals and families — written from experience, not theory.
Protecting families in the digital age. A comprehensive guide to keeping children safe online.
View on AmazonThe essential travel companion for the gold-standard exam. Concise, exam-focused, and field-tested.
View on AmazonA strategic guide to Information Security Management. Built for practitioners preparing for the CISM exam.
View on Amazon