MS, CISM
Director of IT & Cybersecurity
SOC 2 · PCI-DSS · HIPAA · Cloud Infrastructure · Compliance · Endpoint Management · GRC
IT and cybersecurity leader with 10+ years of experience spanning IT operations, security, and compliance in high-growth SaaS and cloud-native environments. Established and leads an enterprise security program from the ground up as sole function owner and designated Security Officer — driving SOC 2 Type I, PCI-DSS 4.0.1 compliance, IAM governance, endpoint security, and cloud security monitoring. Background includes HIPAA-regulated and critical infrastructure environments.
Greater Tucson, AZ · Remote-Friendly
Core Expertise
End-to-end security program design aligned to PCI-DSS 4.0.1, SOC 2, NIST, CIS, and HIPAA — from gap analysis through audit readiness and executive reporting.
Securing cloud infrastructure across AWS and GCP, managing distributed endpoint environments, and maintaining operational cost control and security posture at scale.
Architecting least-privilege IAM environments across Okta, Microsoft Entra, Google Workspace, and Active Directory — securing SaaS and cloud ecosystems across the enterprise.
Leading end-to-end incident response, conducting risk assessments, and coordinating cross-functional teams during active security events with full post-incident documentation.
Managing security assessments for vendors and MSSPs, cyber insurance partnerships, and supply chain compliance programs — partnering closely with Legal and Procurement.
Building high-performance security teams through organizational change, developing risk-based roadmaps, and translating technical vulnerabilities into executive-level strategy.
Career History
Director of Cybersecurity & IT Operations
Network Support Engineer
Support Lead
Get in Touch
I'm actively exploring leadership opportunities in IT and Cybersecurity — as well as consulting engagements, board memberships, and pro-bono work with non-profits. If any of those fit, I'd love to connect.