What I Do

Strategic Services for a Complex Risk World

Every engagement is built around your organization's specific risk profile — not a generic framework checklist. Here's how I help.

Compliance

Turn regulatory complexity into competitive advantage.

Regulatory requirements are growing faster than most organizations can track. I help you build compliance programs that don't just satisfy auditors — they create operational discipline that scales with your business.

SOC 2ISO 27001HIPAAPCI-DSSGDPRCCPA

Capabilities

  • SOC 2 Type I & II readiness and audit support
  • ISO 27001 certification preparation and gap analysis
  • HIPAA Security Rule compliance programs
  • PCI-DSS scoping, remediation, and QSA coordination
  • GDPR and CCPA data privacy program design
  • Continuous compliance monitoring and evidence automation

AI Governance

Deploy AI responsibly — before regulators require it.

AI is moving faster than governance frameworks. I help organizations establish the policies, controls, and oversight structures needed to use AI confidently — and demonstrate that confidence to regulators, customers, and boards.

NIST AI RMFEU AI ActISO 42001Model Risk Mgmt

Capabilities

  • AI risk assessment and model inventory
  • NIST AI Risk Management Framework implementation
  • EU AI Act readiness and classification
  • Model bias auditing and fairness evaluation
  • AI governance policy and board reporting frameworks
  • Third-party AI vendor risk assessment

CyberSecurity

Security architecture grounded in real adversary tactics.

Checkbox security doesn't stop sophisticated threats. I bring a practitioner's understanding of how attackers think and operate to help you build defenses that actually work — and can be explained to your board.

NIST CSFMITRE ATT&CKZero TrustCIS Controls

Capabilities

  • Security architecture review and design
  • Threat modeling using STRIDE and MITRE ATT&CK
  • Zero Trust architecture planning and implementation
  • Incident response planning and tabletop exercises
  • Cloud security posture assessment (AWS, Azure, GCP)
  • Security program maturity assessment (NIST CSF)

Risk Controls

Connect boardroom strategy to operational risk reality.

Risk management only works when it speaks the language of business. I help organizations build enterprise risk programs that quantify exposure, prioritize investment, and communicate clearly to executives and directors.

COSO ERMISO 31000FAIRNIST RMF

Capabilities

  • Enterprise risk management program design (COSO ERM)
  • Cyber risk quantification using FAIR methodology
  • Risk appetite and tolerance framework development
  • Third-party and vendor risk management programs
  • Board and executive risk reporting
  • Control design, testing, and deficiency remediation

Not sure where to start?

Most engagements begin with a strategic assessment. Let's identify your highest-priority gaps and build a plan from there.