15+ years securing enterprise cloud, AI, and infrastructure — from architecture to boardroom.
TOGAF Certified Enterprise Architect · CISSP · CISM · CCZT
Strategic cybersecurity architect with 15+ years designing Zero Trust frameworks, securing 100+ cloud-native applications, and advising C-suite leadership on multi-cloud (AWS, Azure) security strategy.
My architecture practice is grounded in TOGAF — in which I'm certified — for enterprise architecture and ADM-driven governance, and I apply SABSA's risk-driven, business-attribute-led methodology for security architecture — so security decisions trace cleanly from board-level strategy down to controls and engineering guardrails.
Deep expertise across regulated healthcare, banking, insurance, and SaaS environments spanning US, Europe, Australia, and Asia-Pacific — from control design to incident response, and from engineering review to board reporting. Current focus areas include AI Agentic Security (agent identity, tool-use risk, MCP governance) and Zero Trust across multi-cloud estates.
I partner with security and executive teams that need clarity, speed, and a defensible architecture — not another framework deck.
Focused engagements for security-critical teams — architecture, advisory, and program leadership.
Design Zero Trust frameworks, secure network and cloud architectures, and multi-year security roadmaps aligned to business outcomes.
Design security architecture using TOGAF ADM phases and SABSA's business-attribute-driven risk methodology — connecting security controls to business capability, governance gates, and enterprise architecture roadmaps.
Named specialty in AI Agentic Security — securing autonomous AI agents and LLM deployments across agent identity & permissions, tool-use risk, prompt injection defence, MCP and agent governance, data lineage for AI, and model access controls.
Multi-cloud reference architectures, migration security, workload hardening, and cloud-native application protection.
SOC 2 Type II, ISO 27001, GDPR, and HIPAA readiness, control design, gap remediation, and audit support.
Executive briefings, board-level threat narratives, and role-based upskilling that build durable security culture.
Ongoing strategic advisory — program leadership, vendor selection, and board reporting without a full-time CISO hire.
Roles, industries, and outcomes — company names withheld for confidentiality.
Share a few details and I'll be in touch within 1–2 business days.