Skip to content
Open to board advisory and board seats — 2H 2026, then CY 2027–2028.
See details →
Advisory

Advisory & fractional engagements

Fractional CIO/CISO, AI-governance advisory, and board interest — the engagement shapes I'm open to, what each covers, and how to start.

VP, Information Security & DevOps at SavvyMoney — owning both the build (DevOps and platform) and protect (information security) sides for a fintech platform serving 1,500+ financial institutions. This page describes how I engage outside that role: the models below are the ones I'm genuinely open to — method and scope, no fabricated client roster.

01

Fractional CIO / CISO

For growth-stage companies scaling regulated workloads that need executive-level security and platform leadership before a full-time hire makes sense. The mandate is the same dual build-and-protect scope I run today: DevOps and platform on one side, information security on the other, under one accountable leader.

  • First 30–90 days: assess the estate, write the narrative, rank the risks, and leave an operating cadence behind.
  • Security programs built to an auditable bar — SOC 2, PCI, NIST CSF — without stalling delivery.
  • Platform and cloud architecture reviewed for cost, resilience, and small-team leverage.
02

AI-governance advisory

For teams putting AI into regulated products who need governance that engineers can actually implement. I stood up AI governance for a fintech platform: a design-time 'act vs interpret' boundary for automated decisions, mapped to NIST AI RMF, ISO 42001, and the incoming CCPA automated-decision rules.

  • Governance as an engineering discipline — controls in the pipeline, not a policy PDF.
  • Model and agent risk framed for boards, regulators, and auditors in their language.
  • Scoped engagements: a governance baseline, a framework mapping, or a design review.
03

Board service & board advisory

Forward-looking interest, stated plainly: I am not a current board director. I'm open to independent board seats and board-advisory roles — cyber and AI oversight for pre-IPO or public fintech and healthtech — for the second half of 2026, then calendar years 2027 through 2028.

  • CISSP, CISA, CISM, and CRISC; UC Berkeley MICS.
  • Operator's view of audit and risk committees: SOC 2 Type II and CSA STAR Level II posture run first-hand.
  • Cyber and AI oversight framed as business risk, not technology theater.
04

How these engagements run

  • Lead with a written narrative; meetings are for decisions, not status.
  • Hire for trajectory and judgment; coach for ownership.
  • Treat security and platform as enablers of GTM velocity, not gates.
  • Default to blameless retros, public action items, and visible dashboards.
05

Timing, location & logistics

Open to board advisory and board seats — 2H 2026, then CY 2027–2028. San Francisco Bay Area · Remote (US) · Open to occasional travel. Full detail — decision speed, travel cadence, and what slows a conversation down — is on the availability page.

Go deeper

Start the conversation

A short intro call is the fastest way to find out whether one of these shapes fits. I reply within 24 hours on weekdays.