Skip to content
Open to board advisory and board seats: 2H 2026, then CY 2027-2028.
See details →
Practice

Work & case studies

Roles, scope, and outcomes from 30 years in technology building security and platform programs in regulated, high-growth environments.

Experience

2022 - Present

VP, Information Security & DevOps

SavvyMoney

fintech · 1,500+ financial institutions

Full-time · San Francisco Bay Area

Lead the information security and DevOps functions for SavvyMoney, a fintech platform serving 1,500+ financial institutions as they deliver credit and financial-wellness products. A dual mandate: owning both the pipelines and cloud architecture that ship the product and the controls that protect it.

  • Built and matured a program scoring above the industry average on the NIST Cybersecurity Framework, sustained through SOC 2 Type II attestation and a CSA STAR Level II continuous-audit posture.
  • Designed a multi-region AWS architecture with warm-standby failover for business continuity.
  • Drove security-operations automation to reallocate the team toward higher-judgment work.
  • Established a recurring threat-intelligence program that turned security into a relationship and sales asset.
  • Building AI governance frameworks for financial services: the controls layer for automated decision-making, from audit trails to the boundary between outputs a system can act on and those that need a human first.

2020 - 2022

Head of Technology & Information Security

Altais

a Blue Shield of California company · healthcare

Full-time · Oakland, CA

Dual leadership role with enterprise-wide responsibility for platform operations, cloud security, corporate infrastructure, and IT governance, progressing from Head of Platform Operations & Information Security. Reported into the executive leadership team and engaged the board and compliance stakeholders on risk posture, technology strategy, and regulatory readiness.

  • Led the cross-functional effort to achieve HITRUST certification, implementing controls aligned with healthcare compliance and securing PHI workflows.
  • Built and scaled a cloud-native AWS platform anchored by Kubernetes, improving uptime and deployment velocity while reducing overhead.
  • Presented directly to executive leadership and the board on cyber risk, mitigation plans, audit findings, and resilience strategy.
  • Formalized the incident-response program (playbooks, drills, and escalation protocols) to minimize downtime.
  • Aligned the security stack (identity, access, cloud configuration, logging, threat detection) to HIPAA, NIST, and enterprise risk frameworks.
  • Modernized corporate IT and endpoint security: network design, workstation lifecycle, asset management, and helpdesk.

2019 - 2020

VP, Information Security & Infrastructure

Xolv Technology Solutions

healthcare services · cloud-first

Full-time · San Francisco Bay Area

Brought in on the leadership team to modernize IT strategy, scale infrastructure for aggressive growth, and build a secure, compliant cloud-first foundation for a fast-evolving healthcare services organization.

  • Designed a risk-based security governance model tailored to the organization's regulatory obligations (HIPAA, SOC 2) and aligned to board-level objectives.
  • Led infrastructure, security, and DevOps to >99.95% uptime while cutting operational spend ~10% YoY through automation and resource reallocation.
  • Architected the move from legacy infrastructure to a containerized, serverless environment (Docker, Kubernetes) without compromising clinical-data compliance.
  • Built and mentored technical teams with agile practices and measurable SLAs.

2017 - 2019

VP, Information Security & Infrastructure

Easterseals Northern California

nonprofit · disability & community services

Full-time · Dublin, CA

Grew from running cloud operations into leading the information-security and infrastructure functions, owning the security program and the systems and cloud environment behind the organization, and advancing from Director, Cloud Operations to VP.

  • Owned the compliance program across SOC 2 Type II, CSA STAR, and HITRUST.
  • Ran the cloud environment and core infrastructure across a multi-site nonprofit.

2016 - 2017

Head of Information Security

Captricity

ML/AI data-as-a-service · reported to the CEO

Full-time · Oakland, CA

Recruited to lead security and DevOps transformation for a cloud-native, data-as-a-service company using ML/AI to convert handwritten forms into structured data. Reported to the CEO with full accountability for cybersecurity, compliance, DevOps, infrastructure, and IT operations.

  • Delivered a full FedRAMP ATO. Took over a project four months behind schedule and brought it to authorization on time and on budget.
  • Spearheaded SOC 2, HIPAA, EU-privacy, and FedRAMP readiness under a unified risk-management framework, across a regulatory surface that also spanned DoD SRG, CJIS, CMMC, ITAR, and ISO 27001.
  • Built the SecDevOps function, embedding security into the CI/CD pipeline and product lifecycle.
  • Cut annual AWS infrastructure cost ~40% through architectural redesign and vendor rationalization, reinvesting in ML initiatives.
  • Automated a geo-distributed AWS estate (Ansible, Chef, Puppet) across hundreds of instances with continuous deployment.
  • Owned enterprise incident-response planning and standardized Secure SDLC and cross-team workflows on JIRA.

2014 - 2016

Head of Infrastructure & Security

Starwood Waypoint Residential Trust

NYSE: SWAY · publicly-traded REIT

Full-time · Oakland, CA / Scottsdale, AZ

Led infrastructure, cybersecurity, and IT operations for a publicly-traded real estate investment trust ($2B+ in assets and 600+ employees across 27 locations) with end-to-end accountability for IT strategy and an eight-figure operating and capital budget.

  • Led the IT and security workstreams through the company's IPO and subsequent acquisition: operational readiness, auditability, and cybersecurity maturity during financial and regulatory due diligence.
  • Built a four-team security organization, spanning Red (offensive), Blue (defensive), Security Engineering, and Trust & Compliance, for visibility, separation of duties, and faster response.
  • Managed a nationwide fleet of 10,000+ devices spanning end-user systems, servers, networks, telecom, and branch IT buildouts.
  • Introduced KPI-based security measurement (vulnerability trends, patch SLAs, incident frequency, remediation timelines) tied to board-level reporting.
  • Drove IT governance and vendor consolidation to $1.2M one-time and $300K recurring annual savings.

Case Studies

SavvyMoney ·

Continuous, Provable SOC 2 Compliance

Moved from point-in-time certification to continuous assurance: SOC 2 Type II, CSA STAR Level II, and NIST CSF maturity above the industry average.

Attestation
SOC 2 Type II
Continuous audit
CSA STAR Level II
NIST CSF maturity
Above industry avg
ComplianceSOC 2NIST CSF
Read the full case study
Captricity · 2016 to 2017

Delivering a FedRAMP Moderate ATO on Time

Took over a FedRAMP Moderate authorization four months behind schedule and delivered the ATO on time and on budget. Also cut AWS cost by about 40%.

Schedule at takeover
4 months behind
ATO
On time, on budget
AWS cost
About 40% lower
FedRAMPComplianceAWS
Read the full case study
Altais · 2020 to 2022

HITRUST Certification and IT Modernization

Led the cross-functional effort to achieve HITRUST certification at a Blue Shield of California company, and modernized corporate IT and endpoint security.

Certification
HITRUST
Modernized
Corporate IT and endpoints
Cyber risk reporting
Executives and board
HITRUSTHealthcareIT Modernization
Read the full case study
Starwood Waypoint Residential Trust · 2014 to 2016

IT and Security for a 27-Location Public REIT

Ran infrastructure and security for a 27-location public REIT with 10,000+ devices, and led the IT and security workstreams through its IPO and acquisition.

Locations
27
Devices
10,000+
Savings
$1.2M one-time + $300K/yr
InfrastructureSecurity Org DesignIT Governance
Read the full case study