Small Manufacturing Company (VA)

Actively serving as vCISO (since March 2025), reporting to President of the company’s Managed Service Provider (MSP) and the company’s IT Director.  Performed the company's first ever formal information risk assessment based on NIST 800-171, created a risk registry, and developed a project roadmap to mitigate selected risks.  Developed a complete set of information security policies and processes.  Developed the company's first ever incident response plan. Developed and currently administer the company's third-party risk management program. 

Wi-Fi Infrastructure Service Provider (NH)

Actively serving as vCISO (since May 2024), reporting to the Director of IT.  Perform annual information risk assessment "refresh" based on NIST 800-171, update the risk registry, and develop a revised project roadmap to mitigate selected risks.  Perform annual review and update of information security policies and processes. Administer the company's third-party risk management program. Serve as the company's Data Protection Officer and respond to law enforcement search warrants and judicial subpoenas.  

Insurance Claim Adjustment & Forensic Engineering Companies (KS)      

Actively serving as vCISO (since July 2024), reporting to President of the companies’ MSP and the companies’ vCIO.  Performed the first ever formal information risk assessment of both companies based on NIST 800-171, created a risk registry, and developed a project roadmap to mitigate selected risks.  Developed a complete set of information security policies and processes.  Developed the companies’ first ever incident response plan. Developed and currently administer the companies’ third-party risk management program. Complete risk assessment questionnaires received from new potential insurance company clients.   

Travel Services Company (Australia & NJ)

Served as vCISO for North American operations (Canada, Mexico & U.S.) for 15 months, reporting to the company’s CTO.  Performed Information security controls assessment using a commercially available tool that generates maturity “scores.”  Identified projects to close security “gaps.”  Repeated controls assessment quarterly as projects were completed.  Developed an information security mission and strategy.  Revised several outdated information security policies. Revised the organization’s incident response plan and facilitated tabletop exercises to validate and test the plan.  Prepared reports and presentations for executive management and the Board of Directors.  

Real-Estate Development & Management Company (MA)  

Engaged as vCISO for 36 months, reporting to the company’s CIO, following a major security incident. Proposed and led projects in collaboration with the organization’s MSP to implement new solutions to close security “gaps” that contributed to the security incident, including a security awareness training platform, secure email gateway, multi-factor authentication, vulnerability management program, and a 24/7 managed detection and response service. Developed a comprehensive set of information security policies. Created a comprehensive incident response plan and third-party risk management program. Prepared reports and presentations for executive management.  Recruited, hired, coached & mentored the organization's first full-time information security manager.       

Integrated Agri-Business (MN)

Engaged as vCISO for 21 months, reporting to IT Director.  Conducted a comprehensive information risk and controls maturity assessment of 30 information security processes and made recommendations to avoid, accept, assign, or mitigate identified risks. Created a multi-year roadmap of proposed projects to enhance the company's cyber resilience based on available resources and the organization's tolerance for risk. Following presentation of assessment results and the proposed project roadmap to senior leadership, retained to lead the implementation of multiple projects identified in the roadmap until a full-time security professional was hired.

Non-Profit Providing Financial & Emotional Support to Families with a Child Diagnosed with Cancer (MN)

Assisted the organization in finding a new Managed Service Provider (MSP). Wrote the RFP, sourced potential providers, reviewed vendor proposals, interviewed the final candidates, and made hiring recommendation.  Performed a comprehensive information risk and controls assessment of 27 information security processes and made recommendations to avoid, accept, assign, or mitigate identified risks to the organization's Board of Directors. Developed a revised information security policy for inclusion in the employee handbook. 

Non-Profit Providing Emergency Shelter & Residential Programs for Homeless Youth, Sexually Trafficked Girls & Adult Men​​ (MN)

Conducted a comprehensive information risk and controls assessment of 27 information security processes and made recommendations to avoid, accept, assign, or mitigate identified risks. Developed an information security policy for inclusion in the employee handbook.