Career Profile

Information Security executive with more than a decade of experience leading enterprise cybersecurity strategy, governance, cloud security, compliance, and risk management for high-growth SaaS organizations. Proven success building security programs from the ground up, leading SOC 2 Type II and PCI DSS compliance initiatives, directing incident response, partnering with engineering to implement secure-by-design principles, and serving as a trusted advisor to executive leadership and enterprise customers.

Today I lead IT and DevSecOps at Zonos, where I built the information security program from the ground up and took our API platform through PCI-DSS and SOC 2, with controls mapped to NIST CSF, NIST 800-53, and CIS. I own incident response, drive Zero Trust across the environment, and report security risk to executive leadership. Previously I architected hybrid cloud infrastructure at SkyWest Airlines and led a full-stack IT team at Wilson Connectivity.

Most recently I’ve been bringing AI — generative tools, agentic workflows, and the governance that should sit underneath them — into the security program and into how the team actually ships work.

Selected Achievements

Built a security program from inception — stood up Zonos' enterprise information security program end to end (governance, policy, risk management, technical controls), carrying the API platform through SOC 2 Type II and PCI DSS.
Established governance & enterprise risk management — security steering committee, risk register, security metrics, and executive reporting across the organization.
Directed incident response & security operations — coordinated technical, legal, executive, and customer communications, driving post-incident improvements to organizational resilience.
Own customer security assurance — lead enterprise customer security reviews, questionnaires, RFP/RFI responses, and audit support that unblock enterprise deals.
Set enterprise AI governance — acceptable-use, data-handling, and vendor-risk policy for generative and agentic AI, folded into the SOC 2 evidence trail.
Embedded security across the SDLC — partnered with engineering on security-by-design, infrastructure as code, and automated security testing in CI/CD.

Core Competencies

Security Leadership & Governance

  • Information Security Strategy
  • Cybersecurity Governance
  • Enterprise Risk Management
  • Security Program Development
  • Executive & Board Reporting
  • Incident Response Leadership
  • Security Operations
  • Security Awareness & Training
  • Business Continuity & DR
  • Vendor & Third-Party Risk
  • Threat Intelligence

Compliance & Assurance

  • SOC 2 Type II
  • PCI DSS
  • NIST CSF & 800-53
  • CIS Controls
  • Risk Assessments
  • Security Policy Governance
  • Privacy & Data Protection
  • Customer Security Assurance

Cloud, Architecture & Engineering

  • AWS & Cloud Security
  • Zero Trust Architecture
  • Security Architecture
  • Identity & Access Management
  • DevSecOps & Secure SDLC
  • Application Security
  • Vulnerability Management
  • Data Classification
  • AI Governance

Experience

Head of Information Systems and Security

2021 — Present
Zonos · St. George, Utah
  • Established and lead the enterprise information security program from inception — governance framework, policies, risk-management processes, and technical controls mapped to NIST CSF, NIST 800-53, and CIS Controls — enabling successful SOC 2 Type II and PCI DSS audits and materially raising security maturity.
  • Serve as senior security advisor to executive leadership; operate the security steering committee, enterprise risk register, security metrics, and executive risk reporting.
  • Own security operations and incident response and the business continuity and disaster recovery program; run vulnerability management, penetration testing, and threat intelligence.
  • Lead customer security assurance — enterprise customer security reviews, security questionnaires, and RFP/RFI responses with audit support — and manage vendor and third-party risk.
  • Drive security-by-design with engineering and DevOps: Zero Trust access and identity/access management, data classification, infrastructure as code in Terraform, and automated security testing across CI/CD pipelines in GitHub Actions.
  • Established enterprise AI governance — acceptable-use, data-handling, and vendor-risk policy for generative and agentic AI — folded AI risk into the SOC 2 evidence trail, and standardized the team on agentic tooling (Claude Code, MCP).

Systems Engineer

2018 — 2021
SkyWest Airlines · St. George, Utah
  • Operated a hybrid Azure and on-premises VMware/NetApp environment across multiple datacenters for a regional airline.
  • Played a lead role in Office 365 and Azure migration, integrating SaaS, PaaS, and IaaS into enterprise workflows.
  • Administered Oracle, RHEL, and CentOS Linux fleets, F5 load balancers, and Cohesity backup infrastructure.

I.T. Supervisor / Project Manager

2013 — 2018
Wilson Connectivity · St. George, Utah
  • Led a team of 7 across networking, systems, support, database, DevOps, and security for a 250+ employee manufacturer.
  • Drove migration to Google Workspace, Microsoft 365, and Azure while modernizing on-premises architecture.
  • Ran eDiscovery, penetration testing, network analysis, and file recovery using digital forensics skills; headed security initiatives protecting company IP and customer data.

Systems Administrator

2015 — 2016
Utah Tech University · St. George, Utah
  • Hardened campus systems and migrated SharePoint and Exchange workloads to the cloud.
  • Collaborated with a security audit team on ongoing penetration testing to identify and remediate vulnerabilities.

AI & Emerging Tech

I treat AI tooling the way I treat any other system that touches our data: useful, accountable, and in scope for the security program. That means policy and tenant controls on the governance side, and hands-on adoption inside the engineering and operations workflows I own.

  • AI security & governance at Zonos. Authored acceptable-use, data-handling, and vendor-review guidance for generative AI tools used across engineering and operations; folded AI vendor risk into the existing SOC 2 evidence trail.
  • Certified AI Agent Security Specialist (Proofpoint, 2026). Coursework on prompt injection, agent tool-use abuse, supply-chain risk for model and plugin sources, and identity boundaries for autonomous agents.
  • Agentic tooling in daily practice. Operate Claude Code with MCP server integrations (GitHub, Atlassian, Linear, Datadog) as part of the infra, security, and IT workload — including authoring Terraform, runbooks, and policy that ship to production.
  • AI in the SDLC. AI-assisted code review on pull requests against cloud and CI/CD repos; AI-assisted log and alert triage to shorten the path from signal to root cause.

Skills & Proficiency

Build

How I provision infrastructure and ship code.

  • Terraform
  • GitHub Actions
  • Azure DevOps
  • Docker / Podman
  • Kubernetes (k8s, k3s, Rancher)
  • NGINX
  • Apache
  • PowerShell
  • Bash
  • Python
  • Node.js
  • JavaScript
  • HTML & CSS

Defend

What I do to keep the system trustworthy.

  • Firewalls (Palo Alto, SonicWall, pfSense)
  • VPN (IPSec, OpenVPN, Site-to-Site)
  • SSO / SAML / OIDC / ADFS
  • WAF
  • IDS / IPS / UTM
  • SSL/TLS & PKI
  • Security Monitoring & Logging
  • Endpoint / MDM
  • Penetration Testing
  • Digital Forensics
  • LLM Threat Modeling

Operate

What I run, monitor, and harden in production.

  • AWS
  • Microsoft Azure
  • Google Cloud
  • Microsoft 365
  • Windows Server
  • Linux (RHEL, Ubuntu, Kali, Arch)
  • VMware
  • NetApp
  • F5 Load Balancing
  • LAN/WAN TCP/IP

Ship with AI

How I and my team move faster without losing the plot.

  • Claude Code
  • MCP Servers
  • Cursor
  • GitHub Copilot
  • Prompt Engineering
  • AI-Assisted Code Review