Fractional CISO and GRC advisory for post-Series B and PE-backed companies under real investor, customer, or regulatory pressure.
A control matrix gets filled in, the auditor is satisfied, and no one has decided what risk the company is actually willing to carry.
Work runs in the order the standard is written, not the order the business needs it — so the expensive controls land before the load-bearing ones.
Consultants advise, the team executes, and the trade-off between a control and a business decision sits unmade until an audit forces it.
An ongoing retainer where the security decisions have a named owner — board reporting, roadmap, and the judgment calls in between.
SOC 2, ISO 27001, and PCI — scoped, sequenced, and evidenced to pass the first time rather than the second.
For companies with no security function yet: policy, control set, and operating cadence stood up in the order that actually reduces risk.
Answering the questionnaire that's blocking a deal, and reviewing the vendors the business depends on — same judgment, either seat at the table.
Risk stated in terms a board can act on, with the posture and the open trade-offs both on the page.
Most GRC methods skip straight from assessment to implementation. Decide is where scope, sequence, risk tolerance, and the practical approach for each requirement get set and owned — before a single control is built.
What is actually in scope, what is already true, and where the real exposure sits.
Scope, sequence, risk tolerance, and the approach for each requirement — set, written down, and owned.
Controls, policy, and tooling implemented against the decisions already made.
Audit, diligence, and customer review — the program held up under someone else's scrutiny.
The operating cadence that keeps it true after the certificate is issued.
Faced with a control that assumed a tool we couldn't justify buying, I made the call to build a compensating approach instead and defended it as meeting the requirement's intent. It cleared on the first pass.
Faced with no playbook for AI in the development pipeline, I worked with engineering to understand not just how they were using it, but why — so the controls could bound the risk without slowing the work. Then I made the call: accept the residual risk for the speed it bought us. Not risk-free — bounded.
The one enterprise buyers ask for. Scoped tightly so it closes deals without swallowing the roadmap.
A management system rather than a point-in-time report — the right choice when the buyers are international.
Cardholder data, scoped to shrink the environment first and certify second.
The common language for boards and regulators when no certificate is required.
Three roles, three different kinds of pressure: public-company scrutiny, startup speed, and platform scale.
LinkedInOwned security and GRC across four business units in a public fintech — chairing the ERM committee, building the payments program to PCI Level 1, and authoring the company's SEC cybersecurity disclosure.
Owned the full security function as an individual contributor embedded with engineering, taking ISO 27001 from zero to certificate in six months while keeping PCI continuous through the Azure-to-AWS migration and the 3.2.1-to-4.0 transition.
Led third-party risk and security compliance for PlayStation — including the first PCI 3DS assessment of the PSN storefront, risk assessments of its most critical systems, and business continuity planning across the program.
Most conversations start with a short call to determine whether this is the right engagement.
Engagements are scoped after that conversation, then structured as project or retainer work depending on what the risk posture requires.