Chief Information Security Officer
Piedmont Health Partners · Raleigh, NC
Jan, 2021 · Present
Own a $28M security budget and 64-person organization spanning SecOps, IAM, AppSec, GRC and privacy across 11 hospitals and 140 clinics
Delivered a 3-year zero-trust roadmap: MFA coverage from 61% to 99.6% and privileged access vaulting for 2,300 admin accounts
Reduced mean time to respond (MTTR) from 38 hours to 3.5 hours by standing up a 24x7 fusion center with SOAR playbooks
Passed 4 consecutive HIPAA, HITRUST r2 and SOC 2 Type II audits with zero material findings
Cut third-party risk backlog 72% by tiering 1,800 vendors and automating security questionnaires
Brief the board audit and risk committee quarterly; secured cyber insurance renewal at an 18% lower premium
VP, Security Engineering
Carolina Ledger Financial · Charlotte, NC
Apr, 2017 · Dec, 2020
Built security engineering from 9 to 31 engineers covering cloud security, AppSec and detection engineering
Migrated 420 workloads to AWS with guardrails-as-code (SCPs, Terraform policy checks), achieving PCI DSS certification in 7 months
Embedded SAST/DAST and secrets scanning into 260 CI/CD pipelines, reducing critical production vulnerabilities by 81%
Launched a bug bounty program that closed 140+ valid findings at one-fifth the cost of external pen testing
Led incident response for a credential-stuffing campaign, containing it within 6 hours with no customer funds lost
Director, Security Operations
Triangle BioSystems · Durham, NC
Jun, 2013 · Mar, 2017
Ran a 22-person SOC monitoring 9,000 endpoints and 3 data centers, triaging 1.2M alerts per month
Replaced legacy SIEM with Splunk ES and CrowdStrike EDR, cutting false positives 64% and licensing cost $1.1M per year
Created threat-hunting and purple-team programs that lifted MITRE ATT&CK detection coverage from 34% to 78%
Built the company's first ransomware recovery plan and tested restores of 300 TB within a 24-hour RTO
Senior Security Architect
Atlantic Mutual Insurance Group · Richmond, VA
Aug, 2008 · May, 2013
Designed network segmentation and identity architecture for 6,500 users, closing 2 high-risk audit findings
Rolled out enterprise PKI and SAML SSO for 85 applications, reducing help-desk password tickets 47%
Authored 40+ security standards aligned to NIST 800-53 and ISO 27001, adopted company-wide
Led architecture reviews for 120+ projects per year, embedding security requirements before build