CISSP | CISM | vCTO Practice Lead
vCTO Practice Lead at Abacus — serving hedge funds and private equity firms with $50B+ in combined AUM. Twenty years in IT and cybersecurity across financial services and healthcare.
Automated, repeatable assessments covering Entra ID, Exchange Online, SharePoint, Defender, Conditional Access, and AI Tool Discovery & Controls. Built the PowerShell-based collection engine — accelerated with AI tooling — that drives consistent, auditable output across a portfolio of financial services clients.
Executive summaries, remediation roadmaps, and access review dashboards built in Power BI. Complex DAX, Deneb/Vega custom visuals, and data models designed for client-ready delivery to boards and compliance teams.
Built and managed teams of 15+ across MSP environments. Owned client IT budgets in the $500K–$1M+ range, managed vendor and partner relationships, and developed the standardized frameworks, playbooks, and intake processes that make advisory practices scalable.
ZTNA design and implementation for financial services environments, including Entra Private Access and Cisco Umbrella SIG as a VPN replacement and layered network security model.
SEC-aligned technology assessments, HIPAA Security Risk Assessments, and AI governance frameworks for regulated clients. Evaluating and mapping AI platforms — M365 Copilot, Claude Enterprise, ChatGPT, Gemini — against SEC/FINRA requirements, compliance logging obligations, and supervisory control frameworks.
Turning ad-hoc security advisory into scalable, repeatable practices — standardized workflows, intake questionnaires, engineer playbooks, and tiered deliverables across client portfolios. AI tooling applied throughout to accelerate development, documentation, and delivery.
Frameworks & Standards
Client details anonymized. Outcomes are real.
A financial services client was deploying Claude Enterprise across multiple access paths — browser, Claude Desktop, Cowork, and direct API — without a clear picture of where compliance coverage existed and where it didn't. With SEC examination cycles in view, compliance leadership needed a definitive map of what was captured, what wasn't, and what compensating controls were required.
Conducted a structured analysis of all three Claude access paths against six compliance dimensions: device management, Conditional Access, identity and access, file scope, agentic security visibility, and compliance capture and archiving. Identified that Cowork operates outside the Compliance API perimeter by design and requires a separate OTLP archiving pipeline to achieve partial coverage. Documented the key gaps — BYOD exposure via Conditional Access, API key usage bypassing web auth, Cowork session content not natively captured — and designed a layered control model using Entra ID, Cisco Umbrella DNS enforcement, and an AI gateway for programmatic API paths.
Delivered a controlled deployment reference document mapping every access path to its compliance posture, with explicit notation of coverage gaps and required compensating controls. Framework was presentable directly to compliance leadership and external counsel.
The CTM practice lacked a consistent, scalable way to assess client M365 security posture. Assessments were largely manual, inconsistent across engineers, and didn't produce structured data that could drive reporting or track remediation over time. With a growing portfolio of hedge funds and PE firms, the practice needed a repeatable process that could be run reliably by any engineer and deliver uniform client-facing output.
Designed and built a PowerShell-based assessment engine from scratch, covering 16 modules across Entra ID, Exchange Online, SharePoint, and Microsoft Defender. Migrated from deprecated MSOL and AzureAD modules to MS Graph SDK v2 and Exchange Online REST. Defined a Content_ID-keyed data schema producing structured JSON output consumed directly by a Power BI reporting layer — including an Executive Summary page, Deneb/Vega swimlane Remediation Roadmap, and control scoring dashboards. Authored a 38-task CTM Engineer Playbook standardizing the assessment workflow across the team.
Assessment engine deployed and running against live financial services clients. Consistent, automated data collection replaced manual processes. Power BI template provides uniform client-ready deliverables across the practice regardless of which engineer runs the engagement.
A community health center serving 34,000+ patients annually had a badly damaged relationship with their IT provider. Trust was low, projects had stalled, and leadership was weighing a full transition. Inherited the engagement mid-crisis as the technical lead on day one.
Prioritized relationship repair through transparency — assessed the environment honestly, communicated clearly about what was broken and what a realistic path forward looked like, and delivered quickly on the highest-visibility issues. Conducted a full IT SWOT analysis, then designed and scoped a multi-year technology strategy across four focus areas: security enhancements, hardware modernization, network and VoIP upgrades, and EHR transition support. Drove execution across all 12 concurrent projects including M365 migration, HIPAA SRA, Windows 10 refresh of 100+ devices, Meraki network upgrade, MFA deployment, and eClinicalWorks implementation support.
Relationship fully recovered. All 12 projects delivered. Client remained a managed services partner for seven years.
A multi-site rural FQHC had accumulated significant technical debt across every layer of its environment — end-of-life routers and switches, self-hosted infrastructure with no redundancy, 1,000+ stale AD computer accounts, unmonitored UPS systems, no MDM, legacy Exchange still running, and critical OS versions well past end-of-support. A security assessment surfaced 30+ high and critical findings across network, identity, endpoint, and infrastructure.
Scoped and structured a phased remediation program across four execution tracks: immediate fixes, hardware procurement, post-deployment configuration, and ongoing managed services onboarding. Replaced aging Cisco routers with Meraki MX SD-WAN firewalls across all sites, refreshed LAN switches and wireless infrastructure, migrated self-hosted servers to a HIPAA-compliant data center, deployed Intune MDM, and led an identity remediation sprint disabling stale accounts and enforcing MFA across M365 and VPN. Decommissioned legacy Exchange and restructured network segmentation with VLANs.
All critical and high findings resolved. Cloud-managed SD-WAN deployed across all sites. Self-hosted infrastructure decommissioned and migrated. Identity posture materially improved with over 1,000 stale accounts addressed and MFA enforced organization-wide.
A large urban health center was operating on aging workstations, unsupported servers, and outdated SQL infrastructure with no formal patch management, minimal endpoint security, and VPN access that hadn't been meaningfully reviewed in years. The organization needed a partner to own the full technology roadmap — not just respond to tickets.
Assessed the environment, prioritized findings, and designed a comprehensive multi-year modernization program. Scoped and managed a hardware and services budget in excess of $500K covering hyperconverged infrastructure, workstation and server replacement, Meraki network refresh across all sites, and software licensing. Led execution across data center consolidation, M365 migration, MFA deployment, VPN modernization, SQL upgrades, MDM rollout, and encryption compliance — coordinating procurement, vendors, and project delivery across all tracks simultaneously.
Full technology modernization delivered. Organization transitioned from reactive break-fix to a managed, proactive model with documented policies, automated patching, cloud-managed infrastructure, and enforced endpoint security.
You put in the work, fixed the obvious issues, tightened controls, and suddenly the environment behaves the way it always could. That's a win — but it's also when your value proposition has to change. On showing value after the chaos is gone.
→NIST, ISO, and CIS aren't out of reach for smaller organizations. Most teams are already patching, backing up, running MFA, and managing EDR — they just don't think of it in control numbers. On bridging the gap between real-world practice and framework language.
→AI is great at aggregating and connecting data. End users are notoriously bad at providing it. "It just doesn't work" isn't a ticket — it's a guess. The next big improvement in support isn't automation, it's better intake.
→Tickets closed, MTTR, CSAT, uptime — the numbers tell you what changed, but connecting the dots takes context and judgment. A drop in ticket volume could mean users are happier, or it could mean they've given up. On measuring progress, not just motion.
→Diversification reduces single-vendor exposure — but every tool you add creates new pathways for incidents to travel. Before expanding your stack, it may be smarter to understand the connections you already have inside your environment.
→Leading the Client Technology Management practice for a portfolio of hedge funds and PE firms with $50B+ in combined AUM. Building automated assessment tooling, Power BI reporting infrastructure, and standardized advisory frameworks for financial services clients.
Eleven years across four roles at a healthcare-focused MSP/MSSP. Served as vCTO for some of the largest Federally Qualified Health Centers in the country — delivering multi-site infrastructure modernizations, HIPAA security programs, M365 migrations, and EHR transition support across organizations serving hundreds of thousands of patients. Managed SOC and NOC operations with a team of 15+, sustained 95%+ client satisfaction, and reduced DR/BCP costs by 50% across the client base.
Started through an MSP engagement and transitioned to a full-time director role. Led HIPAA and PCI-DSS compliance programs, reduced the server footprint by 75% through VMware virtualization, and managed Windows Server and Exchange migrations for a growing multi-site nonprofit serving Washington, D.C.
Security programs succeed when they're built to scale — not just to pass an audit.
I manage the vCTO practice at Abacus, a financial services MSP where I own the assessment and advisory relationship for a portfolio of hedge funds and private equity firms with $50B+ in combined assets under management. My work sits at the intersection of technical delivery, practice standardization, and client-facing security leadership — building the tooling and frameworks that let a team deliver consistent, credible advisory at scale.
Before Abacus, I spent eleven years at BlueNovo / Medicus IT in roles from Senior Consultant through VP of IT — running SOC and NOC operations, driving cloud migrations for 20+ clients, and building security programs across a healthcare MSP/MSSP environment. Prior to that, I led IT for SOME, a nonprofit in Washington D.C., where I ran HIPAA and PCI-DSS compliance work and reduced the server footprint by 75% through virtualization.
I hold the CISSP and CISM and bring a practitioner's perspective to every engagement — equally focused on technical outcomes and business impact. I actively apply AI tooling across assessment development, documentation, and client advisory work, and have developed formal AI governance frameworks for regulated clients navigating SEC examination exposure.
Open to conversations about director and VP-level IT and cybersecurity roles, security practice development in financial services, and M365 security consulting engagements.