I've built third-party risk management programs from zero at Upgrade, assessed more than 70 critical vendors within 90 days, and contributed to a SOC 2 Type II certification with no TPRM-related findings.
Across Kaiser Permanente, Hexion, Arvest Bank, Western Union, and Leidos, I've led control testing, framework mapping, audit readiness, remediation tracking, and executive reporting. I implemented OneTrust GRC and Risk Management at Hexion and created first-time HITRUST and NIST control testing processes at Kaiser Permanente.
I work closely with business, technology, audit, legal, privacy, procurement, and vendor teams to turn complex compliance requirements into clear controls, actionable gaps, and organized programs.
