Security Architecture
How systems should be designed — trust boundaries, data flows, access patterns, encryption decisions. Design-level input before problems get built in, or a structured review of what already exists.
Security Advisory
I've spent 25 years working inside the infrastructure most advisors have only read about — banking systems, classified DoD weather intelligence, satellite telemetry for national weather programs, PCI-compliant payment platforms, and enterprise cloud at scale. I know what failure looks like.
The Challenge
The credentials sitting in a git commit. The IAM role that's been overprivileged for two years. The database cluster that's one crash away from a bad week. None of these look like threats until they become incidents.
In 20+ years on incident response teams, the pattern is consistent: companies don't lack protection — they lack an accurate picture of what they actually have and where they're actually exposed.
Services
How systems should be designed — trust boundaries, data flows, access patterns, encryption decisions. Design-level input before problems get built in, or a structured review of what already exists.
Security embedded in how your team ships. Pipeline hardening, cloud posture, IAM hygiene, IaC scanning, secrets management. Built into the process — not discovered during an audit.
I've been the technical point of contact with auditors across multiple sectors. Controls that reflect how you actually operate — not how a framework template assumes you do.
Strategic security leadership without the full-time headcount. A consistent cadence, a clear priority list, and someone who can translate security risk into language the board can act on.
Background
Banking at First National of Omaha — where early CERT work included forensic investigations into datacenter customer intrusions and a developer network compromise that involved the FBI. Classified DoD weather intelligence at Northrop-Grumman/AFWA, satellite telemetry processing for the NASA/NOAA JPSS program at Raytheon, fintech payments at PaymentSpring, e-commerce at The Buckle, and agricultural R&D at Corteva — each sector has its own security pressures, its own compliance demands, and its own version of the problem.
Large organizations have consistently brought me in to become the subject-matter expert on whatever the hardest technical problem was. That's the context behind the advice I give.
In Practice
25+ multi-region AWS accounts, all of them protecting proprietary agricultural research that took decades to produce. Vendor tooling kept generating noise; I built what was actually needed in Python and Go. Working directly with engineering teams, we cut through 25,000+ findings and moved overall posture from below 85% to 93%.
The more interesting moment: an S3 honeypot I instrumented with XDR telemetry caught a legitimate employee who couldn't resist clicking on a tantalizingly named bucket. He admitted he was just being nosy. I explained we were trying to catch intruders using stolen credentials to exfiltrate secrets — which is exactly why the bucket had that name.
Five years on the same platform — long enough to see what accumulates when security is treated as a compliance checkbox. Ran five consecutive SOC 2 and SOX cycles; cut audit prep time by 60% by building evidence pipelines into GitLab instead of recreating the chaos each year.
The closest call wasn't an audit — it was a MariaDB/Galera cluster that had been quietly degrading for months. Executed a full migration to modern HA architecture across six new servers before it took production down with it. It was close.
When you're building PCI-DSS Level 1 infrastructure at a startup, there's no prior version to reference — I built it right the first time because there wasn't a second chance. HSMs, a five-shard geographically-distributed key custodian program, quarterly pen testing. We passed the first audit. A lot of that work was also just explaining cryptographic key management to people who'd never had to care about it before.
The most memorable afternoon there: the CISO and one of our own infosec engineers came to town without telling anyone and tried to walk into our office as part of a red team exercise across three locations. I caught them. We were the only office that did. The CTO heard about it.
How I Work
Frameworks are useful reference points. They're terrible starting guns. Every engagement starts with understanding what you actually have — your systems, your team, your constraints, and your actual risk tolerance. Assumptions are expensive in this work.
Your environment, your team, your actual risk — not the NIST CSF template of your risk.
What's real, what's theoretical, what's a priority. An honest picture of where you stand.
A ranked, actionable list. What to fix first, what can wait, what the tradeoffs are.
I can stay involved to guide remediation, validate controls, and prepare for audits.
Working Together
Boutique means each engagement gets real attention. That means I'm selective.
Contact
Start with a 15-minute call. Tell me what you're dealing with — I'll tell you honestly whether I'm the right fit and what a useful first step looks like.
Book a 15-min clarity call [email protected]If you know what you need: include company size, cloud stack, compliance goals, and current concerns.