At Oracle Health / Oracle Cloud Infrastructure, I manage security risk assessments across cloud-hosted healthcare products, clinical systems and AI-enabled technologies. Since May 2025, I’ve delivered 400+ pre-risk profile questionnaires and approximately 50 full assessment reports.
I use RSA Archer to assess risks, coordinate treatment plans and document exceptions and formal risk acceptance. I review evidence against ISO 27001, NIST, HIPAA, HITRUST and SOC 2-aligned requirements, and support certification and customer assurance work.
I co-developed a controlled AI-assisted assessment workflow with version control, management oversight and human validation. It enabled two people to deliver work previously requiring four.
At KPMG LLP, I led cyber, privacy, governance and assurance engagements, including five workstreams in a global pharmaceutical privacy transformation. Before that, as Head of Information Governance & Data Protection Officer at South Tees Hospitals NHS Foundation Trust, I owned risk registers, policies and reporting to the Trust Board and committees, and directed ISO 27001 and NHS DSP Toolkit-aligned assurance.

