CAREER EXPERIENCE (Full-time & Contracting)
vCISO On Call (formerly 180security.com) | 2019–PRESENT | Founder & Chief Consultant
Aledade | 2024–2025 | Security & Head of GRC
Disney Streaming / Hulu | 2019–2023 | Head of Security GRC, Data Protection & Content Security
Global Eagle | 2015–2019 | Head of Information Security, Risk & Compliance
Banc of California | 2014–2015 | Information Security / Deputy CISO Leader
AAA of Southern California | 2012–2013 | Third-Party Information Protection Risk Management
PCV Murcor | 2010–2011 | Head of Information Security
Experian | 2008–2010 | Enterprise Information Security
Zions Bancorporation | 2007–2008 | Privacy Officer & Information Compliance Leader
CoreLogic (formerly First American CoreLogic) | 2007 | Information Security Management Leader
ACC Capital Holdings | 2005–2007 | Information Security & Privacy
PacifiCare Health Systems | 2004–2005 | HIPAA Privacy & Security Program Management
CompPartners | 2002–2004 | HIPAA Compliance Officer & Technical Documentation Leader
HNC Software | 1998–2000 | Software Technical Writing, Quality Assurance & Regulatory Research
EDUCATION
Master of Information Technology (MIT), Internet Security — 2004
Bachelor of Business Administration (BBA) — 1997
CERTIFICATIONS
CISSP — Certified Information Systems Security Professional
CIPP/US — Certified Information Privacy Professional
CIPT — Certified Information Privacy Technologist
CDPSE — Certified Data Privacy Solutions Engineer
FIP — Fellow of Information Privacy
GSTRT — GIAC Strategic Planning, Policy & Leadership
GLEG — GIAC Law of Data Security & Investigations
GSLC — GIAC Security Leadership Certification.
GRC, AI ASSURANCE & GOVERNANCE, AND PERSONAL SOFTWARE PROJECTS
AI Agent Trust & Transparency Platform — Provides visibility into what autonomous and semi-autonomous AI agents are actually doing, not just what they are saying. It discovers agents, tracks identities and ownership, maps data lineage, tools and APIs, monitors downstream dependencies and cross-boundary activity, and produces live agent transparency and trust reporting.
AI Governance Module for Integrated Governance, Risk & Compliance Platform — The embedded AI governance capability within the integrated governance, risk and compliance platform. It provides governance around AI use, including inventory, ownership, risk classification, lifecycle oversight, policy and control requirements, assessments, approvals, and alignment with frameworks such as the NIST AI RMF.
AI Governance, Assurance & Testing Platform — An AI assurance platform designed to continuously test, evaluate, and monitor AI systems using multiple testing and evaluation engines. It turns technical AI testing into governance and executive-level visibility across security, safety, reliability, compliance, and trust.
Accessible Reading & Audiobook Platform — A personal reading and listening platform for PDF and EPUB libraries that combines traditional reading with natural text-to-speech and read-along capabilities. It supports local OCR for scanned books, highlights, notes, bookmarks, definitions, pronunciation corrections, customizable reading modes, library-wide search, metadata and genre organization, collections, reading status, and exportable notes and highlights.
Compliance Visibility & Evidence Platform — A standalone compliance management platform designed to make regulatory and framework obligations understandable and operational. It maps requirements to controls and evidence, identifies gaps and overlaps, and gives organizations a clearer view of compliance posture across multiple frameworks rather than managing each one in isolation.
Cyber Risk Quantification & Scenario Modeling Platform — A standalone quantitative risk platform using FAIR-based analysis and Monte Carlo simulation to translate cyber scenarios into financial exposure. It helps leadership understand probable loss, compare mitigation options, evaluate investment decisions, and communicate cyber risk in business terms.
Decision-Centric GRC Platform — Reimagines GRC around the decision rather than the control, risk, or compliance requirement. It connects obligations, interpretations, controls, evidence, risk, appetite, approvals, agent activity, and decision receipts so organizations can understand not only whether a decision was permitted, but why it was made and whether it remains valid as conditions change.
End-of-Life Planning & Family Information Platform — A separate death doula/midwife-focused platform designed to help individuals organize the information, wishes, documents, contacts, accounts, and personal details their families may need at the end of life. Its purpose is to make an extraordinarily difficult period less confusing for the people left to handle everything and covers what medical and legal documentation does not address.
Enterprise Risk Register & Risk Management Platform — A practical risk management platform for capturing, assessing, prioritizing, assigning, treating, accepting and continuously monitoring organizational risk. It is intentionally designed to be easier and more intuitive than many of the complex risk and GRC offerings available today, while providing a structured alternative to the spreadsheets many organizations still rely on for risk management.
ISO Management & Certification Readiness Platform — A purpose-built platform for managing ISO 27001 implementation, ongoing compliance, and certification readiness. It connects requirements, controls, risks, evidence, ownership, gaps, corrective actions, and audit activity in one operational environment, with support for ISO 27002 guidance and ISO 42001 AI management capabilities as organizations expand their programs.
Infrastructure Governance & Assurance Platform — A governance-first Infrastructure as Code platform that connects source control, CI/CD, cloud environments, IaC tools, and security scanners to continuously evaluate infrastructure changes and deployed environments. It identifies misconfigurations, policy violations, drift, control gaps, and exceptions while maintaining ownership, approvals, evidence, and traceability from code through deployment.
Integrated Governance, Risk & Compliance Platform — A unified GRC platform bringing risk, compliance, third-party risk, AI governance, security operations, privacy, resilience, and executive reporting together. It serves as the integrated environment that brings the specialized capabilities of the broader portfolio into a single operational view.
Local AI Agent Development & Testing Platform — A local environment for building, configuring and testing AI agents, their tools, integrations and behaviors while maintaining greater visibility and control over the development environment. It provides a practical workspace for experimenting with agent capabilities and understanding how agents interact with models, data, APIs and external systems before they are introduced into more consequential environments.
Personal Music Memory & Life Soundtrack Platform — A consumer music storytelling platform that connects songs with the memories, people, places, photos, and moments that give them meaning. It can use music libraries and listening history to help surface significant songs and build personal soundtracks for everyday memories and major life events, including birthdays, weddings, anniversaries, and celebrations of life, with integration into end-of-life planning platform for memorial music and storytelling.
Regulatory & Standards/Frameworks Change Monitoring Platform — Monitors regulatory, legislative and standards/frameworks developments across AI governance, privacy and information security, tracking proposals, approvals and implementation milestones so organizations can prepare before requirements take effect. Retains supporting evidence, distinguishes confirmed changes from unverified announcements, and provides searchable, topic-filtered views tailored to an organization or project.
Risk Assessment & Security Maturity Management Platform — A streamlined platform for conducting security, privacy, compliance and AI governance risk and maturity assessments without turning the assessment itself into an administrative burden. It brings together framework requirements, interviews, observations, evidence, findings, maturity scoring, risk, remediation priorities and roadmaps while keeping maturity and finding severity distinct and maintaining traceability from assessment through action.
Security Representation Assurance Platform egulatory — Continuously verifies whether what an organization says about its security is actually true. Identifies security representations across contracts, questionnaires, policies, audits, insurance applications, Trust Centers, and other sources, links claims to supporting evidence and operational reality, and detects contradictions, unsupported assertions, and changes that could invalidate prior commitments.
Third-Party Risk Intelligence Platform — A standalone third-party risk management platform for evaluating and continuously understanding vendor risk. It combines evidence and document analysis, security and privacy assessment, regulatory and framework mapping, contracts, insurance, subprocessors, geographic exposure, AI usage, exceptions, and year-over-year risk intelligence into a consolidated vendor view.
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.