Owning and Maturing a PCI DSS Level 1 Compliance Program
A payments SaaS company needed stable, deeply integrated leadership for its PCI DSS Level 1 program — the highest compliance tier — across multiple operating entities.
View case studySecurity & Compliance Executive
Founding-team executive with 25+ years building security, compliance, and IT organizations from the ground up, across multiple entities, frameworks, and continents.
Selected Work
A payments SaaS company needed stable, deeply integrated leadership for its PCI DSS Level 1 program — the highest compliance tier — across multiple operating entities.
View case studyA newly formed healthcare technology entity required a complete information security management system and compliance program built from zero, including HIPAA and ISO 27001 alignment.
View case studyFrom the Blog
PCI DSS 4.0 finally gives you two legitimate ways to drop forced password expiry. Here is when MFA alone is enough, and how to build a customized approach that survives your QSA.
Read moreThe AWS us-east-1 outage was a reminder that every architecture is a bet on availability. Here's how to make sure yours is a deliberate one.
Read moreWhen there's nothing to inherit — no policies, no risk register, no documentation — here's how to build an information security management system that actually works.
Read moreBackground
Founding-team technology executive with 15+ years building a complete technology organization from the ground up: software development, IT infrastructure, DevOps, and enterprise security and compliance programs across multiple business entities.
When the opportunity arose to bring compliance and security under long-tenured leadership, I stepped up, pursuing CISM and CISSP certifications and taking ownership of the program. My decade-plus of IT and development experience, combined with years working alongside our original compliance leadership, gave me a unique ability to integrate security deeply into operations rather than running it as a siloed function.
Read full bioOpen to conversations about leadership roles, advisory work, and hard compliance problems.
Get in Touch