Resume
CHIEF INFORMATION SECURITY OFFICER /
VP OF INFORMATION SECURITY
Strategic Security Leader | Enterprise Cybersecurity Officer | AI Security & Cyber Defense Innovator
Executive Cybersecurity Leader with 20+ years of progressive security leadership across Fortune 50 Healthcare, Financial Services, and Public Sector organizations. Proven track record of architecting enterprise cyber defense programs, executing M&A integrations and corporate divestitures, and engineering AI-driven SOC transformations that cut MTTR by 95% while reducing annual operating costs by $1M+. Trusted C-suite and Board advisor adept at translating complex technical risks into FAIR quantitative models, driving customer retention, and ensuring strict regulatory compliance across HIPAA, HITRUST, NIST, CMMC, FedRAMP, and PCI-DSS.
CORE COMPETENCIES
- Security Strategy & Vision: Cyber Governance | Executive & Board Alignment | FAIR Quantitative Risk Management | M&A Security Due Diligence & Divestitures | Budget Management ($M+) | Process Optimization
- Cyber Defense & Operations: SOC Transformation | AI-Driven Threat Forensics | Incident Response | Threat Intelligence | SIEM/SOAR Optimization | Zero Trust Architecture
- AppSec & Cloud Security: DevSecOps Modernization | Secure SDLC | Vulnerability Management | AWS Cloud Security | Wiz | Snyk | CNAPP
- Governance, Risk & Compliance: NIST CSF/800-53/800-171 | ISO 27001 | HIPAA | HITRUST | FedRAMP | CMMC | SOC 2 | PCI-DSS | BISO Leadership | ITSM/ITIL
EXECUTIVE CERTIFICATIONS
- Active: Certified Information Systems Security Professional (CISSP) | Certified Cloud Security Professional (CCSP) | Certified Information Security Manager (CISM) | Certified in Risk and Information Systems Control (CRISC) | Certified in Data Privacy Solutions Engineer (CDPSE) | Factor Analysis of Information Risk (FAIR) | ITILv3 | MITRE ATT&CK & Purple Teaming | Lean Six Sigma Yellow Belt
- Upcoming: ISACA Advanced in AI Security Management (AAISM)
PROFESSIONAL EXPERIENCE
MAGELLAN HEALTH / CENTENE | Phoenix, AZ
Vice President, Cybersecurity | August 2021 – January 2026
Direct enterprise cybersecurity strategy, operations, and GRC functions across multi-million-dollar annual operational budgets. Lead a multidisciplinary security organization spanning Threat Intelligence, Incident Response, Detection Engineering, Application Security, Vulnerability Governance, and Business Continuity.
- SOC Transformation & AI Integration: Replaced a third-party MSSP with an internal, high-performing Cyber Defense team and integrated agentic AI for automated threat forensics; reduced false positives by 90%, improved MTTR by 95%, and yielded $1M in direct annual savings.
- Application Security Modernization: Transitioned legacy AppSec tooling to an integrated DevSecOps framework, reducing tool costs by 80%+ while drastically improving developer remediation workflows.
- Vulnerability & Risk Reduction: Engineered an enterprise risk-based vulnerability management program with automated remediation workflows, eliminating 94% of enterprise vulnerabilities.
- M&A & Corporate Divestitures: Led cybersecurity integration throughout the Centene/Magellan acquisition (2021–2023), aligning security architectures and compliance programs across both enterprises. Directed data segregation, system offboarding, and risk management for two major line-of-business divestitures with zero compliance gaps or security incidents.
- Supply Chain & Crisis Leadership: Redesigned Third-Party Risk Management (TPRM) post-vendor incident, embedding mandatory contractual security controls, implementing continuous monitoring, and securing executive funding for modern TPRM tooling.
Director of GRC & Business Information Security Officer (BISO) | August 2020 – August 2021
Served as the primary strategic cybersecurity bridge between business operations, client stakeholders, and enterprise security.
- Revenue Retention & Sales Enablement: Partnered with Sales, Legal, and Compliance to negotiate complex enterprise security contracts and RFPs, directly enabling multi-million-dollar contract awards and renewals.
- Revenue Protection: Stepped in as interim dedicated BISO for a major account post-breach, secured C-suite alignment to increase dedicated staffing, and successfully preserved a multi-million-dollar client relationship.
- Common Controls Framework: Standardized control evidence reuse across HIPAA, HITRUST, SOX, SOC 2, and NIST, reducing compliance preparation time by 60%.
- BISO Organization Growth: Co-designed and scaled the enterprise BISO model, aligning dedicated security officers directly with business unit executives. Promoted to VP within 12 months.
CSAA INSURANCE GROUP | Phoenix, AZ
IT GRC Manager | August 2013 – August 2020
Led the enterprise GRC organization, overseeing PCI compliance, regulatory audits, and risk assessment functions.
- GRC Platform Deployment: Successfully deployed the RSA Archer GRC platform after two prior organization-wide failed attempts, delivering full audit tracking, risk registers, and executive risk acceptance workflows.
- PCI DSS Compliance Leadership: Led the organization to its initial PCI DSS compliance certification, mapping controls and demonstrating effectiveness to external Qualified Security Assessors (QSAs).
- Control Harmonization: Implemented a unified Common Controls Framework based on the Secure Controls Framework (SCF), cutting redundant documentation by 70% across ISO 27001, PCI DSS, SOC 2, and Department of Insurance requirements.
EARLIER CAREER HIGHLIGHTS
- Wells Fargo | Operational Risk Consultant (2012 – 2013): Executed system risk assessments daily, evaluating inherent and residual risks for business line owners and framing mitigation strategies for executive decision-making.
- Arizona Department of Education | Chief Information Security Officer | (2010 – 2012): Directed agency-wide security operations, incident response, vulnerability management, and audit liaison activities. Configured and deployed an enterprise ITSM platform to modernize IT governance and change management.
- Corbins Electric | Director, IT & Security (2008 – 2010): Directed total IT/Security infrastructure operations; led headquarters relocation over a single weekend with zero operational downtime.
- Nationwide Insurance | Sr. Information Security Analyst (2004 – 2008): Architected custom XML/LDAP identity management provisioning system; pioneered early FAIR risk quantification modeling using Monte Carlo simulations.
- Arizona Dept. of Health Services | Information Security Manager (2002 – 2004): Achieved initial departmental HIPAA compliance certification; established state bioterrorism threat intelligence alert system (precursor to H-ISAC).
- Alltel Communications | Sr. Technical Analyst (2000 – 2002): Directed post-acquisition systems integration of 250+ servers; successfully contained and eradicated Nimda malware outbreak without data loss.
- First Horizon National Corporation | Regional IT Coordinator (1999-2000): Served as the primary IT coordinator for Southwest US, acting as the remote liaison between regional offices and the central IT organization. Managed IT infrastructure, coordinating deployment and support for desktops, servers, printers, and Cisco network equipment.
- Arizona Dept. of Corrections | Network Specialist (1996-1999): Supported enterprise IT operations across the department, including help desk, network management, server administration, and user provisioning, maintaining system alignment with state and CJIS compliance mandates.
- United States Marine Corps | Corporal, Crew Supervisor (1992 – 1996): Supervised aircraft ordnance maintenance and night-crew teams for VMA-311 Harrier Squadron post-Desert Storm. Honored for operational discipline and leadership.
EDUCATION
Bachelor of Science in Information Technology (2004): University of Phoenix, Phoenix, AZ
