Security Architecture · Product Security · AI Security Governance · Detection & Response
I build security programs for regulated environments — medical devices, healthcare data, federal and defense authorization, financial-reporting integrity, and converged IT/OT. Ten-plus years taking organizations from "what are our risks?" through architecture, prevention, detection, response, and governance.
This profile is a body of method. Every repository here is a synthetic reference implementation — no employer data, no proprietary architecture, no real findings. What it demonstrates is how the work is actually done.
I can assess it. Threat modeling, security architecture review, product security assessment, medical-device cybersecurity, security risk assessment, configuration baselining, multi-framework compliance.
I can secure it. Identity and privileged access architecture, cloud security, application and pipeline security, supply-chain integrity, OT segmentation, hardening.
I can detect attacks against it. Detection engineering across identity, endpoint, cloud control plane, and network telemetry — with a deliberate telemetry strategy behind it rather than a rule pile.
I can respond when it is compromised. Incident triage, investigation, containment with business cost weighed, eradication, recovery, evidence handling, executive and regulatory communication.
I can govern, fund, sequence, and report on it. Program charters, maturity roadmaps, control libraries crosswalked across regimes, risk acceptance, metrics, and board-level reporting.
Each repository carries a DECISIONS.md. That file — the trade-offs, the constraints, the things deliberately not done — is the point. Implementation shows what can be built. Decision records show what should be.
| Repository | What it contains |
|---|---|
| security-program-blueprint | Full security program design: charter, decision rights, RACI, capability maturity model, 12-quarter roadmap with sequencing rationale, staffing model, metrics catalog, board reporting pack, risk-acceptance records |
| compliance-control-crosswalk | One control library mapped across NIST SP 800-53 Rev 5, CSF 2.0, SOC 2, HIPAA, FedRAMP, CMMC, ISO 27001:2022, ISA/IEC 62443, NERC CIP, SOX ITGC, and GDPR — with evidence reuse and an automated gap-report generator |
| ai-security-governance | Enterprise AI security program: intake and risk-tiering, review pathways, 40+ controls mapped to OWASP GenAI LLM Top 10 2026, NIST AI RMF 1.0, and MITRE ATLAS; threat patterns for RAG, tool-calling, and agents; adversarial test plan; human-approval gate design |
| Repository | What it contains |
|---|---|
| threat-model-library | Six fully worked threat models — SaMD device, RAG/agent application, converged IT/OT network, cloud identity plane, CI/CD supply chain, patient-facing API — plus methodology for scaling threat modeling across many teams without becoming the bottleneck |
| samd-cyber-submission-package | Complete premarket cybersecurity documentation package for a fictional Class II connected device, structured to FD&C Act section 524B: threat model, ISO 14971-traced security risk assessment, SBOM, vulnerability analysis, post-market monitoring, coordinated disclosure, traceability matrix |
| vulnerability-management-program | The lifecycle as a program rather than a scanner: risk-based prioritization beyond CVSS, coverage gaps, remediation coordination across teams you don't manage, exception frameworks, OT patching constraints, executive metrics |
| Repository | What it contains |
|---|---|
| appsec-sdlc-controls | Security gates as code — SAST, DAST, SCA, container, secret, and IaC scanning — plus the policy layer that makes them stick: thresholds, break-build rules, SLAs, exceptions, and secure repository governance as auditable configuration |
| sbom-supply-chain-pipeline | End-to-end SBOM generation, storage, diffing, and VEX triage on CycloneDX 1.7 and SPDX 3.0.1, with a reachability-and-exploitability prioritization engine and policy-as-code gates |
| identity-security-architecture | Cloud identity plane design: IAM role and permission-boundary patterns, privilege-escalation path analysis, conditional-access matrices, workload and service-account governance, PAM and just-in-time elevation, access certification that isn't rubber-stamping |
| stig-scap-hardening | Configuration baselines as declarative code with SCAP validation, automated evidence generation, compensating-control process, and 800-53 control inheritance |
| it-ot-security-reference | Purdue-model segmentation, ISA/IEC 62443 zones and conduits with security-level targets, IT-to-OT attack paths, NERC CIP evidence mapping, and why standard IT controls fail in OT |
| Repository | What it contains |
|---|---|
| detection-library | 30+ vendor-neutral Sigma detections across identity, cloud control plane, endpoint, and network — each with telemetry prerequisites, ATT&CK mapping, false-positive profile, and analyst response — behind a telemetry strategy with honest coverage-gap analysis |
| incident-response-playbooks | Eight operational playbooks including OAuth consent abuse, device-code and token theft, cloud control-plane compromise, and an AI-application incident — each with containment options priced by business cost — plus communication templates, regulatory notification decision aids, and tabletop packs |
Cloud and identity — AWS · Azure · Microsoft Entra ID · Okta · Delinea · AWS IAM · AWS Config · CIS Benchmarks
Security operations — CrowdStrike · SentinelOne · Tanium · BloodHound · Tenable · Sigma · MITRE ATT&CK
Application and supply chain — SonarQube · SecureFrame · SAST/DAST/SCA · CycloneDX · SPDX · VEX · GitHub Actions
Governance — NIST SP 800-53 Rev 5 · NIST CSF 2.0 · NIST AI RMF 1.0 · OWASP Top 10 · OWASP GenAI LLM Top 10 2026 · MITRE ATLAS · ISO 27001:2022 · ISO 14971:2019 · IEC 62304 · ISA/IEC 62443 · NERC CIP · FDA 524B / 510(k) · FedRAMP · DoD RMF · CMMC · SOC 2 · HIPAA · GDPR · SOX ITGC
M.Sc. Cybersecurity · B.Sc. Information Technology · ISA/IEC 62443 Cybersecurity for Industrial Automation and Control Systems · CISSP (in progress) · Databricks Generative AI Fundamentals · Databricks AI Security
Experience spans regulated medical-device software and FDA premarket submissions, enterprise AI governance for a large technology organization, multi-business-unit HIPAA and SOX audit readiness, FedRAMP readiness and DoD RMF authorization, and security of converged IT/OT infrastructure in the energy sector.
