At Third Bridge, I run cross-functional security and GRC reviews across application, data, identity, change, incident, and resilience controls. I assess secure SDLC practices with Product, Engineering, and Compliance, including security requirements, risk reviews, testing evidence, and remediation.
I assess cloud and GenAI use cases for security and privacy risk, including least-privilege access, data classification, encryption, and prompt-injection risks. Where relevant, I apply Amazon Bedrock security patterns such as Guardrails, KMS, CloudTrail, CloudWatch, and private connectivity.
Previously, at Tide and Amazon, I supported security governance and technology-risk reviews in regulated fintech and enterprise customer environments. I also founded Aspen, where I established security and governance processes and built BCMS and recovery governance covering business impact analysis, recovery priorities, and backup and restore procedures.

