VP, Information Security & DevOps at SavvyMoney — owning both the build (DevOps and platform) and protect (information security) sides for a fintech platform serving 1,500+ financial institutions. This page describes how I engage outside that role: the models below are the ones I'm genuinely open to — method and scope, no fabricated client roster.
Fractional CIO / CISO
For growth-stage companies scaling regulated workloads that need executive-level security and platform leadership before a full-time hire makes sense. The mandate is the same dual build-and-protect scope I run today: DevOps and platform on one side, information security on the other, under one accountable leader.
- First 30–90 days: assess the estate, write the narrative, rank the risks, and leave an operating cadence behind.
- Security programs built to an auditable bar — SOC 2, PCI, NIST CSF — without stalling delivery.
- Platform and cloud architecture reviewed for cost, resilience, and small-team leverage.
AI-governance advisory
For teams putting AI into regulated products who need governance that engineers can actually implement. I stood up AI governance for a fintech platform: a design-time 'act vs interpret' boundary for automated decisions, mapped to NIST AI RMF, ISO 42001, and the incoming CCPA automated-decision rules.
- Governance as an engineering discipline — controls in the pipeline, not a policy PDF.
- Model and agent risk framed for boards, regulators, and auditors in their language.
- Scoped engagements: a governance baseline, a framework mapping, or a design review.
Board service & board advisory
Forward-looking interest, stated plainly: I am not a current board director. I'm open to independent board seats and board-advisory roles — cyber and AI oversight for pre-IPO or public fintech and healthtech — for the second half of 2026, then calendar years 2027 through 2028.
- CISSP, CISA, CISM, and CRISC; UC Berkeley MICS.
- Operator's view of audit and risk committees: SOC 2 Type II and CSA STAR Level II posture run first-hand.
- Cyber and AI oversight framed as business risk, not technology theater.
How these engagements run
- Lead with a written narrative; meetings are for decisions, not status.
- Hire for trajectory and judgment; coach for ownership.
- Treat security and platform as enablers of GTM velocity, not gates.
- Default to blameless retros, public action items, and visible dashboards.
Timing, location & logistics
Open to board advisory and board seats — 2H 2026, then CY 2027–2028. San Francisco Bay Area · Remote (US) · Open to occasional travel. Full detail — decision speed, travel cadence, and what slows a conversation down — is on the availability page.
Go deeper
Start the conversation
A short intro call is the fastest way to find out whether one of these shapes fits. I reply within 24 hours on weekdays.