Career Profile
Information Security executive with more than a decade of experience leading enterprise cybersecurity strategy, governance, cloud security, compliance, and risk management for high-growth SaaS organizations. Proven success building security programs from the ground up, leading SOC 2 Type II and PCI DSS compliance initiatives, directing incident response, partnering with engineering to implement secure-by-design principles, and serving as a trusted advisor to executive leadership and enterprise customers.
Today I lead IT and DevSecOps at Zonos, where I built the information security program from the ground up and took our API platform through PCI-DSS and SOC 2, with controls mapped to NIST CSF, NIST 800-53, and CIS. I own incident response, drive Zero Trust across the environment, and report security risk to executive leadership. Previously I architected hybrid cloud infrastructure at SkyWest Airlines and led a full-stack IT team at Wilson Connectivity.
Most recently I’ve been bringing AI — generative tools, agentic workflows, and the governance that should sit underneath them — into the security program and into how the team actually ships work.
Selected Achievements
Core Competencies
Security Leadership & Governance
Compliance & Assurance
Cloud, Architecture & Engineering
Experience
- Established and lead the enterprise information security program from inception — governance framework, policies, risk-management processes, and technical controls mapped to NIST CSF, NIST 800-53, and CIS Controls — enabling successful SOC 2 Type II and PCI DSS audits and materially raising security maturity.
- Serve as senior security advisor to executive leadership; operate the security steering committee, enterprise risk register, security metrics, and executive risk reporting.
- Own security operations and incident response and the business continuity and disaster recovery program; run vulnerability management, penetration testing, and threat intelligence.
- Lead customer security assurance — enterprise customer security reviews, security questionnaires, and RFP/RFI responses with audit support — and manage vendor and third-party risk.
- Drive security-by-design with engineering and DevOps: Zero Trust access and identity/access management, data classification, infrastructure as code in Terraform, and automated security testing across CI/CD pipelines in GitHub Actions.
- Established enterprise AI governance — acceptable-use, data-handling, and vendor-risk policy for generative and agentic AI — folded AI risk into the SOC 2 evidence trail, and standardized the team on agentic tooling (Claude Code, MCP).
- Operated a hybrid Azure and on-premises VMware/NetApp environment across multiple datacenters for a regional airline.
- Played a lead role in Office 365 and Azure migration, integrating SaaS, PaaS, and IaaS into enterprise workflows.
- Administered Oracle, RHEL, and CentOS Linux fleets, F5 load balancers, and Cohesity backup infrastructure.
- Led a team of 7 across networking, systems, support, database, DevOps, and security for a 250+ employee manufacturer.
- Drove migration to Google Workspace, Microsoft 365, and Azure while modernizing on-premises architecture.
- Ran eDiscovery, penetration testing, network analysis, and file recovery using digital forensics skills; headed security initiatives protecting company IP and customer data.
- Hardened campus systems and migrated SharePoint and Exchange workloads to the cloud.
- Collaborated with a security audit team on ongoing penetration testing to identify and remediate vulnerabilities.
AI & Emerging Tech
I treat AI tooling the way I treat any other system that touches our data: useful, accountable, and in scope for the security program. That means policy and tenant controls on the governance side, and hands-on adoption inside the engineering and operations workflows I own.
- AI security & governance at Zonos. Authored acceptable-use, data-handling, and vendor-review guidance for generative AI tools used across engineering and operations; folded AI vendor risk into the existing SOC 2 evidence trail.
- Certified AI Agent Security Specialist (Proofpoint, 2026). Coursework on prompt injection, agent tool-use abuse, supply-chain risk for model and plugin sources, and identity boundaries for autonomous agents.
- Agentic tooling in daily practice. Operate Claude Code with MCP server integrations (GitHub, Atlassian, Linear, Datadog) as part of the infra, security, and IT workload — including authoring Terraform, runbooks, and policy that ship to production.
- AI in the SDLC. AI-assisted code review on pull requests against cloud and CI/CD repos; AI-assisted log and alert triage to shorten the path from signal to root cause.
Skills & Proficiency
Build
How I provision infrastructure and ship code.
Defend
What I do to keep the system trustworthy.
Operate
What I run, monitor, and harden in production.
Ship with AI
How I and my team move faster without losing the plot.






