New York City Metropolitan Area
I've spent 20+ years keeping critical systems running and secure, starting in places where failure got people killed. I came up in the U.S. Air Force, working in avionics and then network systems, including a combat deployment running network operations under fire. That's where I learned to rebuild complex systems under real pressure, with a sense of urgency and with whatever I had. It's still how I work. Since then, my security career has run through healthcare, medical devices, insurance, and clinical research: building and scaling security operations, risk, and governance programs, and leading teams through acquisitions and transformation. At Worldwide Clinical Trials I was hired to build and lead the information security program as the company scaled for growth. I took a small, operations-focused team and matured it into a structured program across security operations, risk and governance, and awareness. I also extended security oversight into areas I didn't directly own and built the cross-functional relationships that make governance work in a regulated, validated clinical-systems environment. That program has since grown into a multi-tower security organization. The thing I push hardest: security has to move at the speed of the business. The real work is holding the line on critical risk and everyday hygiene while keeping process light enough that the business moves faster, not slower. Done right, security is the reason the business can move, not the reason it can't.
Hired to build and lead the information security program for a growing global CRO that needed to scale, mature, and reduce risk. Inherited a two-person team focused on incident response fundamentals and built it into a structured program. • Formalized a hybrid Security Operations Center and incident response program, integrating managed detection and response, standardized playbooks, and regulatory-aligned coordination with QA, Legal, and Privacy. • Stood up the cyber risk and governance function, including a formal enterprise risk register and a recurring risk-assessment program, and drove ISMS and policy development toward ISO 27001. • Built enterprise security awareness from the ground up, cutting phishing click-through by roughly 75%. • Extended security governance into capabilities outside direct ownership by establishing oversight relationships with leaders across the business. • Advanced zero-trust architecture modernization and strengthened reporting frameworks that informed leadership decision-making.
Recruited during a period of expanded security investment to rebuild and mature security operations for a national managed-healthcare company. • Designed and stood up a 24/7 Security Operations Center, integrating existing staff and systems into a functioning operation. • Cut a critical vulnerability backlog by roughly 80% through risk-based prioritization with senior business and IT leaders. • Partnered with the Business Information Security Officer team to develop customer-facing security services and deliverables, helping rebuild client trust.
Owned information security strategy for BD's R&D business units and embedded security into how product teams worked. • Built a functional risk profile from NIST requirements, security event history, and threat reporting, and used it to establish a governance model with R&D executive leadership. • Partnered with IT and security leaders to creating transparency into security deliverables across the system lifecycle. • Established a security champions program, embedding security expertise inside agile development teams.
Led BD's security operations function (continuous monitoring, cyber threat intelligence, vulnerability management) through a security transformation. • Aligned and matured capabilities to the NIST Cybersecurity Framework and ISO 27002, exceeding maturity targets in the first year. • Met a strategic partner's third-party security requirements under their supply-chain risk program, leading the remediation that lifted BD's rating to the highest tier within three months and protected the partnership. • Led security integration for mergers, acquisitions, and divestitures, and identified managed services consolidation opportunities that reduced operating expense by roughly 10% without increasing risk.
Ran risk analysis across a portfolio of information-system projects and managed BD's information security program initiatives, including the rollout of its governance, risk, and compliance platform.
Advised on cybersecurity program direction and industry alignment.
Led information protection and network operations across communications and security roles, including a combat deployment to Iraq. • Served as the designated Information Systems Security Officer for the wing's networks, leading a small team and owning information assurance. • Turned around an under-performing information-protection office, raising vulnerability compliance to 99% from one of the lowest rates in the command. • Deployed to Kirkuk, Iraq, running network operations under sustained fire, including a wartime Active Directory migration and a denial-of-service response that kept joint forces connected.
Maintained C-130 flight-control and guidance avionics across home-station and deployed operations, sustaining mission readiness in combat-airlift environments.