Director Offensive Security and Vulnerability Management - Comerica Bank - Frisco, TX
(2024-01)
Own $20M+ enterprise cybersecurity portfolio delivering NIST-aligned security governance, IAM, PAM, SOC monitoring, and operational resilience programs across regulated financial systems.
- Lead enterprise-wide Red Team, penetration testing, threat modeling, and vulnerability management programs protecting critical banking platforms and cloud environments.
- Direct a global team of penetration testers, security engineers and vulnerability management professionals supporting hybrid cloud and on-prem infrastructure.
- Established risk-based remediation SLAs that reduced critical vulnerability exposure while improving executive accountability across engineering organizations.
- Partner with CTOs VP Engineering and DevOps leaders to balance security requirements with product delivery timelines.
- Developed engineering standards and pre-approved cloud configurations that accelerate secure software releases.
- Integrated vulnerability scanning IaC validation container security and misconfiguration assessments directly into GitHub Actions Jenkins, and CI/CD pipelines.
- Led Purple Team initiatives that improved security monitoring coverage and detection effectiveness through direct collaboration between Red Team and SOC operations.
- Implemented enterprise threat modeling practices utilizing STRIDE and PASTA methodologies for cloud native applications and microservices architectures.
- Established engineering requirements framework converting recurring Red Team findings into long term architectural improvements.
- Regularly brief executive leadership and Board-level committees on cyber-risks remediation progress and security strategy.
Senior Manager Red Team Application Security - BNY Mellon - Remote
(2022-04 - 2023-12)
Managed enterprise cybersecurity risk and regulatory compliance programs aligned with NIST CSF, OCC, FFIEC, SOX, GLBA.
- Managed enterprise penetration testing and adversary simulation programs across web applications, APIs, cloud services, and internal infrastructure.
- Conducted advanced Red Team exercises simulating nation-state and financially motivated threat actors.
- Led assessments focused on OWASP Top 10 vulnerabilities, authentication bypasses, privilege escalation, and cloud security weaknesses.
- Collaborated with software engineering teams to integrate security controls within Agile and Dev Sec Ops delivery models.
- Implemented automated security testing within GitLab CI and Jenkins environments reducing manual review efforts.
- Developed remediation prioritization framework aligned to business risk and asset criticality.
- Guided engineering teams through secure design reviews involving Kubernetes, microservices, and serverless architectures.
- Partnered with Security Operations teams to improve detection of use cases and threat hunting capabilities based on offensive security findings.
Manager Vulnerability Management and Security - Bank of America - Addison, TX / Remote
(2018-08 - 2022-03)
Managed enterprise cybersecurity risk and regulatory compliance programs aligned with NIST CSF, OCC, FFIEC, SOX, GLBA.
- Led enterprise vulnerability management program supporting thousands of servers, applications, and cloud assets.
- Directed internal and third-party penetration testing engagements.
- Implemented risk-based vulnerability prioritization processes that improved remediation efficiency by 60%.
- Conducted application security reviews utilizing OWASP and CWE frameworks.
- Established governance processes for vulnerability remediation tracking and executive reporting.
- Collaborated with infrastructure and application teams to resolve security issues without impacting operational performance.
- Supported cloud migration initiatives by embedding security controls into deployment pipelines.
Cybersecurity & IT Risk Manager - Citi - Irving, TX
(2015-04 - 2018-08)
- Managed PAM/IAM transformation integrating privileged access discovery and onboarding with resiliency governance.
- Defined and executed risk technology transformation of roadmaps spanning cybersecurity, data protection, automation, and analytics.
- Coordinated multi-region risk assessments and audit engagements for privileged access and operational continuity.
- Defined recovery metrics and resiliency playbooks for core IT services supporting financial and consumer platforms.
IT Portfolio & Product Risk Manager - CVS Health / Caremark - Irving, TX
(2012-03 - 2015-03)
- Led healthcare payer IT modernization, integrating Salesforce & BI platforms with built-in business continuity controls.
- Directed HIPAA & GDPR compliance programs ensuring secure product design, data protection, and system resilience.
- Partnered with Risk leadership to design and implement automation solutions by leveraging low-code tools, data pipelines, and reporting platforms.
- Enabled risk data storytelling by integrating security, operational, and third-party risk indicators into executive dashboards.
IT Project Manager - UnitedHealthcare - Stamford, CT
(2011-03 - 2012-03)
- Delivered electronic records platform upgrades in compliance with federal mandates
- Oversaw healthcare billing, claims, and security system transformations
Technology Project Manager - Capital One - Richmond, VA & Plano, TX
(2008-10 - 2011-03)
- Directed TSYS and Empower migration programs for card/mortgage lines
- Managed a blended team of 20+ developers across mainframe, SOA, and DWH
Project/Lead Manager - JP Morgan Chase - Wilmington, DE
(2005-05 - 2008-10)
- Directed TSYS and Empower migration programs for card/mortgage lines
- Led QA/Dev teams on investment banking and consumer banking IT initiatives
- Migrated TSYS card data infrastructure platform from legacy systems
IT Lead - Frontier Airlines
- QA automation & portfolio governance for ticketing systems
Senior Consultant/BA - Boots Pharmacy (UK)
- Defined QA frameworks, managed portfolio testing
Consultant/BA - NatWest Bank (UK)
- Supported IT portfolio testing & business requirement management