Business and people savvy CISO with 20+ years’ experience in technology and cyber security; 15+ years as a leader, managing teams of up to 20. Demonstrated track record of delivering business-enabling security programs in a variety of industries including healthcare, SaaS startups, Defense, and Federal Government. I foster a collaborative culture that empowers individuals with ownership and autonomy in their work. Security Programs: Board Reporting, Enterprise Security, Application/Product Security, Security Operations, Data Privacy, Identity & Access Management, Security M&A Due Diligence, Cloud Security, Threat Intelligence, ZeroTrust, Data Loss Prevention, Detection Engineering and Response, Vulnerability Management, GRC, Data Governance, Employee Education, Enterprise Risk Management, Incident Response, Insider Threat, and policy development.Compliance: Security: HITRUST, NIST CSF, SOC2 (Type I & Type II), CIS 8.0 | Privacy: CPRA, HIPAA | Financial: NYDFS, PCITechnology: On prem, hybrid, multi-cloud, cloud native | SaaS, PaaS, IaaS | AWS, GCP | Linux, Mac OS, Windows | Firewalls, CSPM, SIEM, SOAR, EDR, IAM, DLP, ZTNA, CASB, PAM, Generative AICertifications: ISC2 CISSP, CSSLP, CCSP | ISACA CRISC, CISM
Listed skills include Information Assurance, Dod, Information Security, Network Security, and 36 others.