InfoSec Director / Officer at Cricket Health / Interwell Health (2021-01 – Present)
Leading information security program for healthcare technology company through startup growth, M&A integration, and enterprise transformation.
- Report directly to board on cybersecurity program status, $500K+ budget allocation, and risk posture
- Navigated merger and integration to become a reporting segment of Fresenius Medical Care
- Lead cross-functional alignment with Product, Legal, Compliance, and Privacy on security strategy and regulatory requirements
- 3x HITRUST r2 certifications (ISO, SOC, HIPAA, NIST) with zero critical audit findings
- Oversee 3rd-party risk for 50+ vendors, AWS and Azure environments, Salesforce Health Cloud, and Epic EMR
- Launched internal security awareness campaign (FakeBobby meme) that reduced phishing susceptibility by 60%+
- Enable secure AI adoption across Dev and Product teams, supporting 2-3x improvement in patient engagement
- Transformed VPN network into Zero Trust architecture spanning multiple cloud providers and SaaS applications
- Direct secure development practices in GitHub and Azure DevOps; established Vulnerability Disclosure Program (VDP)
- Developed and executed BCP and DR exercises across the organization
Product Security Lead at Honeywell (2018-01 – 2021-12)
Buildings and Homes Division
- Developed and delivered modular, repeatable cybersecurity processes adopted by the Honeywell Product Security team across multiple groups and continents within the global Buildings business
- Performed offensive testing on embedded, web, mobile, and cloud products in the Honeywell Buildings portfolio; consulted on remediation of weaknesses across applications, firmware, and hardware
- Engaged dev teams to design and verify secure architecture for software and hardware deliverables in both waterfall and agile environments, meeting timelines and security requirements
Cyber Security Engineer at TCF Bank (2017-01 – 2018-12)
- Led attack and pen testing and risk analysis of TCF assets across the US using in-house Python tooling and outsourced teams (OWASP Top 10 focus)
- Solved complex SOX, FIPS, and PCI DSS data security problems for PKI and SaaS solutions using obfuscation, tokenization, and encryption
Lead Architect at CenturyLink / Lumen (2001-01 – 2016-12)
- Pen tested residential embedded systems: wireless attacks, CAN/CVE vulnerabilities, UPnP exploits, web applications, XML injection, and Wi-Fi security standards
- Led evaluation and deployment of IoT devices supporting 5M+ broadband subscribers at 99.9%+ network reliability