Security is not a technology problem that occasionally involves governance. It is a governance problem that happens to involve technology. Most organizations that get hurt are not behind on features — they are carrying risk nobody has measured, written down, or assigned an owner to.

Running a security program

I lead cybersecurity, network, and infrastructure operations for a 600-employee municipal government across 10 sites, including regulated public-safety functions. In practice that means vulnerability management, endpoint protection, identity and access management, and incident readiness across a multi-site fiber network — plus the policies and standards that make those things repeatable rather than heroic.

The unglamorous controls are the ones that matter. Privileged access review and employee offboarding are boring, and they are what audits find. I would rather be excellent at the boring things than sophisticated at the interesting ones.

Audits and examinations

You don’t prepare for an audit — you operate so the audit is uneventful.

Findings should never surprise the person responsible for the program. If an auditor tells me something I did not already know, I failed at my own risk assessment before they ever arrived. I keep a live remediation tracker with named owners and dates, and I close findings before the next cycle rather than at the deadline.

I have been on the receiving end of grant and financial audits as Principal Investigator on more than $500,000 in federal and state awards — including NSF and Maryland Department of Labor programs. Auditors and examiners want the same three things: show me the policy, show me that you followed it, and show me what you did when you didn’t. That discipline transfers cleanly between regulatory regimes.

Business continuity and disaster recovery

The only question that matters about a DR plan is whether it has been tested end to end — not whether it has been documented. A recovery objective the business never signed off on is a number somebody made up.

I validate recovery objectives against what operations actually needs, test against them, and report the gap honestly when one exists.

Vendor and third-party risk

In most organizations today, the data lives at the vendor — and at the vendor’s subcontractors. You own the response and the notification clock; you do not own the remediation. That asymmetry has to be managed in the contract, before the incident.

That means knowing every critical contract’s term and renewal date, actually reading the SOC 2 rather than filing it, and knowing who the fourth parties are. I manage vendor negotiation, SaaS licensing, and renewals today, and I managed $2.5M in vendor contracts earlier in my career.

Artificial intelligence — defense before offense

Most organizations need an AI policy before they need an AI product. Vendors are already shipping AI features into platforms you have licensed, and employees are already pasting internal information into public chatbots. Acceptable-use policy, data-loss posture, and vendor AI review come first.

Where AI earns its place at modest scale, it is usually in alert triage, document handling, and internal knowledge assistance — not a customer-facing chatbot. And nothing goes near a consequential decision about a person without model risk governance and a fairness review. That is a fast way to fail an examination and a slow way to get sued.

Explaining risk to leadership

One page. Three columns: what could happen, what it costs in dollars and customer impact, and what we are doing about it. No acronyms. Ranges rather than false precision. Always a recommendation, never a menu.

Credentials

  • MS in Cybersecurity, Wilmington University (4.0 GPA)
  • 15 active CompTIA certifications, including Security+, CySA+, Cloud+, Network+, Server+, Data+, DataSys+, A+, and the CSAP, CSIS, CCAP, CSCP, CNIP, and IT Operations Specialist stackable credentials
  • FERPA and accessibility (WCAG) trained; NIST, HIPAA, and PCI-DSS informed control design
  • Built and taught a college cybersecurity degree program, including a virtual Security Operations Center for red/blue team instruction
  • Taught cybersecurity ethics and developed the AI degree pathway