At InVitaHealthcareTechnologies, I built and direct the enterprise Information Security Program, setting its governance, strategy, and operational oversight across six global business divisions. I lead security for a 30+ application SaaS platform and partner with executives to align investments with business objectives and risk appetite.
I achieved SOC 2 Type II certification and developed governance policies mapped to HITRUST, ISO 27001, GDPR, and HIPAA. I also led deployment of Arctic Wolf SOCaaS to improve threat detection and incident response maturity.
At CircleInternetFinancialRemoteWork, I designed the enterprise Third-Party Risk Management program and led implementation of ProcessUnity and Black Kite. I conducted more than 250 vendor security assessments and redesigned onboarding workflows, reducing assessment turnaround time by 50%.
At BrownAdvisory, I led security programs including vulnerability management, disaster recovery, and third-party risk. I helped obtain ISO 27001:2013 certification, developed the firm's vulnerability and patch management strategy, and established its Business Continuity and Disaster Recovery program.

