Skip to content
Open to board advisory and board seats — 2H 2026, then CY 2027–2028.
See details →
Practice

Work & case studies

Roles, scope, and outcomes from 30 years in technology building security and platform programs in regulated, high-growth environments.

Experience

2022 - Present

VP, Information Security & DevOps

SavvyMoney

fintech · 1,500+ financial institutions

Full-time · San Francisco Bay Area

Lead the information security and DevOps functions for SavvyMoney, a fintech platform serving 1,500+ financial institutions as they deliver credit and financial-wellness products. A dual mandate — owning both the pipelines and cloud architecture that ship the product and the controls that protect it.

  • Built and matured a program scoring above the industry average on the NIST Cybersecurity Framework, sustained through SOC 2 Type II attestation and a CSA STAR Level II continuous-audit posture.
  • Designed a multi-region AWS architecture with warm-standby failover for business continuity.
  • Drove security-operations automation to reallocate the team toward higher-judgment work.
  • Established a recurring threat-intelligence program that turned security into a relationship and sales asset.
  • Building AI governance frameworks for financial services — the controls layer for automated decision-making, from audit trails to the boundary between outputs a system can act on and those that need a human first.

2020 - 2022

Head of Technology & Information Security

Altais

a Blue Shield of California company · healthcare

Full-time · Oakland, CA

Dual leadership role with enterprise-wide responsibility for platform operations, cloud security, corporate infrastructure, and IT governance — progressing from Head of Platform Operations & Information Security. Reported into the executive leadership team and engaged the board and compliance stakeholders on risk posture, technology strategy, and regulatory readiness.

  • Led the cross-functional effort to achieve HITRUST certification — implementing controls aligned with healthcare compliance and securing PHI workflows.
  • Built and scaled a cloud-native AWS platform anchored by Kubernetes, improving uptime and deployment velocity while reducing overhead.
  • Presented directly to executive leadership and the board on cyber risk, mitigation plans, audit findings, and resilience strategy.
  • Formalized the incident-response program — playbooks, drills, and escalation protocols — to minimize downtime.
  • Aligned the security stack (identity, access, cloud configuration, logging, threat detection) to HIPAA, NIST, and enterprise risk frameworks.
  • Modernized corporate IT and endpoint security: network design, workstation lifecycle, asset management, and helpdesk.

2019 - 2020

VP, Information Security & Infrastructure

Xolv Technology Solutions

healthcare services · cloud-first

Full-time · San Francisco Bay Area

Brought in on the leadership team to modernize IT strategy, scale infrastructure for aggressive growth, and build a secure, compliant cloud-first foundation for a fast-evolving healthcare services organization.

  • Designed a risk-based security governance model tailored to the organization's regulatory obligations (HIPAA, SOC 2) and aligned to board-level objectives.
  • Led infrastructure, security, and DevOps to >99.95% uptime while cutting operational spend ~10% YoY through automation and resource reallocation.
  • Architected the move from legacy infrastructure to a containerized, serverless environment (Docker, Kubernetes) without compromising clinical-data compliance.
  • Built and mentored technical teams with agile practices and measurable SLAs.

2017 - 2019

VP, Information Security & Infrastructure

Easterseals Northern California

nonprofit · disability & community services

Full-time · Dublin, CA

Grew from running cloud operations into leading the information-security and infrastructure functions — owning the security program and the systems and cloud environment behind the organization, and advancing from Director, Cloud Operations to VP.

  • Owned the compliance program across SOC 2 Type II, CSA STAR, and HITRUST.
  • Ran the cloud environment and core infrastructure across a multi-site nonprofit.

2016 - 2017

Head of Information Security

Captricity

ML/AI data-as-a-service · reported to the CEO

Full-time · Oakland, CA

Recruited to lead security and DevOps transformation for a cloud-native, data-as-a-service company using ML/AI to convert handwritten forms into structured data. Reported to the CEO with full accountability for cybersecurity, compliance, DevOps, infrastructure, and IT operations.

  • Delivered a full FedRAMP ATO — took over a project four months behind schedule and brought it to authorization on time and on budget.
  • Spearheaded SOC 2, HIPAA, EU-privacy, and FedRAMP readiness under a unified risk-management framework, across a regulatory surface that also spanned DoD SRG, CJIS, CMMC, ITAR, and ISO 27001.
  • Built the SecDevOps function — embedding security into the CI/CD pipeline and product lifecycle.
  • Cut annual AWS infrastructure cost ~40% through architectural redesign and vendor rationalization, reinvesting in ML initiatives.
  • Automated a geo-distributed AWS estate (Ansible, Chef, Puppet) across hundreds of instances with continuous deployment.
  • Owned enterprise incident-response planning and standardized Secure SDLC and cross-team workflows on JIRA.

2014 - 2016

Head of Infrastructure & Security

Starwood Waypoint Residential Trust

NYSE: SWAY · publicly-traded REIT

Full-time · Oakland, CA / Scottsdale, AZ

Led infrastructure, cybersecurity, and IT operations for a publicly-traded real estate investment trust — $2B+ in assets and 600+ employees across 27 locations — with end-to-end accountability for IT strategy and an eight-figure operating and capital budget.

  • Led the IT and security workstreams through the company's IPO and subsequent acquisition — operational readiness, auditability, and cybersecurity maturity during financial and regulatory due diligence.
  • Built a four-team security organization — Red (offensive), Blue (defensive), Security Engineering, and Trust & Compliance — for visibility, separation of duties, and faster response.
  • Managed a nationwide fleet of 10,000+ devices spanning end-user systems, servers, networks, telecom, and branch IT buildouts.
  • Introduced KPI-based security measurement (vulnerability trends, patch SLAs, incident frequency, remediation timelines) tied to board-level reporting.
  • Drove IT governance and vendor consolidation to $1.2M one-time and $300K recurring annual savings.

Case Studies

SavvyMoney ·

Continuous, Provable SOC 2 Compliance

Moved from point-in-time certification to continuous assurance: SOC 2 Type II, CSA STAR Level II, and NIST CSF maturity above the industry average.

Attestation
SOC 2 Type II
Continuous audit
CSA STAR Level II
NIST CSF maturity
Above industry avg
ComplianceSOC 2NIST CSF
Read the full case study