CISSP · MBA · JD Candidate
Cybersecurity Executive · Enterprise Risk & Governance
Originator of the Qualys TruRisk methodology
Nineteen years across security operations, threat intelligence, vulnerability and exposure management, and enterprise risk governance — built in national intelligence, defense-adjacent manufacturing, global technology, and regulated financial services.
Eight years of people and program leadership: standing up a malware reverse-engineering capability in the Air Force from charter through budget and staffing, directing a six-analyst research unit at Qualys, and owning enterprise security programs end to end at FLIR and MassMutual.
MBA-trained and pursuing a JD, which is less a credential stack than a working method — the financial and legal fluency to translate technical exposure into risk narratives that executives, regulators, and boards can actually act on.
The pattern across all of it: find the structural principle a system can't see about itself, make it measurable, and make it legible to the people who need to act on it.
Originated Qualys TruRisk — the exploitability- and threat-actor-weighted scoring model that replaced CVSS-only prioritization across a platform serving 10,000+ enterprise customers, and became a reference point for risk-based vulnerability management.
Drafted and drove adoption of a firm-wide 48-hour SLA covering all patchable vulnerabilities and known misconfigurations at a regulated financial institution. Written in response to AI-accelerated vulnerability discovery collapsing the exploitation window; moved from proposal to full program adoption in two months.
Built the root-cause program that identified third-party and vendor dependencies as the dominant driver of missed remediation — moving recurring failures out of accountability dispute and into owned vendor-risk treatment with named owners.
Published research establishing a 19.5-day mean time to weaponize against a 30.6-day mean time to remediate, with only 57.7% of weaponized vulnerabilities ever patched — findings that reset remediation SLA expectations across a global customer base.
Stood up the malware reverse-engineering capability for a U.S. Air Force intelligence unit — charter, SOPs, policy designations, budget, lab acquisition, and analyst training — then transitioned it to permanent leadership.
Multi-year security strategy, target-state capability definition, control framework architecture, and ownership of transformation programs from current-state assessment through operational handoff.
Cyber risk taxonomy, scenario development, risk appetite calibration, aggregation into enterprise risk reporting, and documented risk acceptance at the right level of authority.
Exploitability modeling, threat-informed prioritization, and remediation sequencing at both enterprise and platform scale — the discipline behind TruRisk and the QCRF.
NIST 800-53 and CSF, CIS Controls, CMMC, ISO 27001 concepts. Policy and standards architecture, control assurance, audit coordination, and third-party cyber risk.
Adversary tracking, APT investigation, MITRE ATT&CK coverage analysis, behavioral analytics, and threat hunting — from MSTIC casework to directing research at platform scale.
Board and senior-leadership reporting, KRI and KPI definition, investment prioritization, and written analysis across Legal, Audit, Finance, and business functions.
This book began as a theoretical model developed during the MBA — an attempt to turn a gut-level reaction to the national debt into something testable and falsifiable. What started as a single framework for examining fiscal distortion accelerated into four: the Corporate Welfare Equation, the ALE Standard, the Marketing Integrity Test, and the Market Integrity Equation. Each is rooted in the philosophical and financial methods the MBA demanded, and each is built to expose a specific type of economic distortion that traditional metrics allow to remain hidden.
Read more about the book →Quantitative risk research developed independently of any employer, plus four economic-accountability frameworks from Ethical Business (2025). Different domains, same method: take a distortion a system can't see about itself and make it measurable.
Developed after my time at Qualys. The framework builds on actuarial principles to evaluate risk in two complementary areas: CVE-based risk (known vulnerabilities with dynamic real-world adjustments for time-to-exploit, MTTR, and active exploitation trends) and non-CVE infrastructure risk (aging systems, failing controls, and operational dependencies benchmarked against industry standards). Both formulas produce numeric scores mapped to actionable tiers — designed to translate technical exposure into executive-ready risk posture.
Published as original research, implemented as an interactive calculator, and routed to CISA via FS-ISAC government coordination.
Quantifies the net public cost of private success — exposing the gap between declared profitability and hidden dependence on public subsidy, regulatory shelter, and externalized harm.
A philosophical filter sitting above GAAP/IFRS. Tests whether financial statements are Accountable, Logical, and Equitable — not just legally compliant.
Formula-based evaluation of whether marketing matches delivery — or manufactures belief through the Figma Fallacy, behavioral manipulation, and asymmetric information.
Tests whether a firm's market valuation reflects actual contribution or speculative narrative. FMET provides a companion lens for ethically sound firms the market systematically undervalues.