CISSP since 2018. Framework fluency earned the hard way: HIPAA, HITECH, FERPA, GLBA, SOC 2, ISO 27001, PCI DSS, CMMC, NIST CSF.
Ransomware hit in 2022. Restoring operations within two days meant staff could return to child and family services instead of waiting on technology. I then led the remediation across data ownership, continuity, recovery, and incident response. The federal Office for Civil Rights investigated the event and closed its review without a finding.
Most security programs become visible to executives only during an audit or incident. I turned ours into a live operating system tied directly to policy. Leaders can see what is protected, what is due, where evidence exists, and which gaps require a decision. Audits now test the same environment used to run the work instead of a binder assembled after the fact.
A suspected phishing message or infected computer can force a senior security leader through hundreds of checks before deciding whether the organization is in danger. I built investigation applications that perform those checks consistently and produce the complete after-action record. A near miss that consumed six hours now takes about five minutes, which means faster decisions and less chance that one missed step becomes the next incident.
Security is also the ability to keep working when a system, site, or vendor fails. I built redundancy across datacenters, identity, connectivity, and cloud recovery, then paired it with access controls, data protection, threat detection, and automated response. The result is fewer incidents that need a person overnight and a more resilient organization when something does break.
I built ElectriCISO to change how our own security program operated: one place for compliance, vendor review, threat intelligence, evidence, and day-to-day decisions. The model received national recognition and is now being commercialized for broader distribution. I carried it from the original problem and product design through pricing, channel strategy, MSP partnerships, and go-to-market execution.