I am a Security compliance leader and technical director with extensive experience advising small to mid-sized enterprises on ISO/IEC 27001 and 42001 compliance, AI governance, and software supply chain security. I specialize in embedding security-by-design principles into software architecture and implementing secure SDLC frameworks to improve resilience, accelerate audit readiness, and meet evolving regulatory requirements such as NIS 2, DORA, and CRA. In my diverse roles, I have led governance initiatives, developed scalable compliance frameworks, and contributed to open source security communities. I am passionate about privacy and security, particularly in emerging AI and cloud computing environments, and actively contribute to technical advisory boards and standards development groups while driving innovation in enterprise security and AI governance.

I am a Security compliance leader and technical director with extensive experience advising small to mid-sized enterprises on ISO/IEC 27001 and 42001 compliance, AI governance, and software supply chain security. I specialize in embedding security-by-design principles into software architecture and implementing secure SDLC frameworks to improve resilience, accelerate audit readiness, and meet evolving regulatory requirements such as NIS 2, DORA, and CRA. In my diverse roles, I have led governance initiatives, developed scalable compliance frameworks, and contributed to open source security communities. I am passionate about privacy and security, particularly in emerging AI and cloud computing environments, and actively contribute to technical advisory boards and standards development groups while driving innovation in enterprise security and AI governance.

Available to hire

I am a Security compliance leader and technical director with extensive experience advising small to mid-sized enterprises on ISO/IEC 27001 and 42001 compliance, AI governance, and software supply chain security. I specialize in embedding security-by-design principles into software architecture and implementing secure SDLC frameworks to improve resilience, accelerate audit readiness, and meet evolving regulatory requirements such as NIS 2, DORA, and CRA.

In my diverse roles, I have led governance initiatives, developed scalable compliance frameworks, and contributed to open source security communities. I am passionate about privacy and security, particularly in emerging AI and cloud computing environments, and actively contribute to technical advisory boards and standards development groups while driving innovation in enterprise security and AI governance.

See more

Experience Level

Expert
Intermediate
Intermediate
Intermediate
Intermediate

Work Experience

Technical Director & Security Compliance Consultant at GadflyAI
April 1, 2023 - Present
Provide governance and compliance consulting to SMEs, aligning AI product development with ISO/IEC 27001 and 42001, improving audit readiness and reducing regulatory risk exposure. Designed and implemented scalable compliance frameworks integrating secure development lifecycles (SDLC), reducing time-to-audit readiness by up to 30%. Established security baselines aligned with NIST CSF, OpenSSF best practices, and AI risk management standards for projects under GadflyAI.
Technical Advisor at OurWorlds, Inc.
December 1, 2021 - Present
Serve as a cybersecurity and privacy expert on the Technical Advisory Board for a communication platform using extended reality to transform public and private spaces, focusing initially on Native Americans. Bring knowledge of Native American tribal privacy law, ensuring respect and protection of privacy rights for participants providing sensitive language and cultural data for the virtual reality product.
Technical Community Architect at Confidential Computing Consortium, Linux Foundation (Contract)
February 28, 2025 - August 15, 2025
Led cross-member governance initiatives to adopt OpenSSF Scorecard, SLSA, and Sigstore for improved supply chain integrity across global privacy-preserving compute projects from Microsoft, NVIDIA, ARM, and TikTok. Developed compliance-aligned community frameworks supporting EU NIS 2/DORA/CRA readiness in cloud and confidential computing environments.
Director of Open Source, AI DevSecOps at EscherCloud AI
November 30, 2023 - August 15, 2025
Built an ISO/IEC 27001-compliant technical organization embedding security-first standards across OpenStack, Kubernetes, and AI workloads. Established AI governance controls aligned with ISO/IEC 42001 and NIST AI RMF 1.0 to ensure secure, sustainable HPC and AI deployments.
Open Source Developer Advocate at Sonatype
November 30, 2022 - August 15, 2025
Expanded security outreach for open-source supply chain resilience by applying federal security experience to accelerate zero-day vulnerability awareness and remediation. Advocated for adoption of SBOM standards (SPDX, CycloneDX) and SLSA compliance in enterprise DevSecOps pipelines, organizing the first successful CNCF-wide Security Slam in 2022.
Product Strategist, Developer Advocate (Contract) at Reliably
June 30, 2021 - August 15, 2025
As product strategist for a command line tool, enabled engineers to seamlessly test cloud system reliability across AWS and Azure, leveraging expertise in distributed system telemetry, CI/CD, site reliability engineering, chaos engineering with Kubernetes, and optimizing deployment and reliability across AWS, GCP, and Azure.
NLP Solutions Architect (Contract) at Unseen Insight
June 30, 2021 - August 15, 2025
Designed secure automated NLP pipelines that reduced NGO feedback loops from 3.5 years to 1 day, embedding privacy-enhancing protocols for sensitive humanitarian data.
Senior Data Scientist, Reinforcement Learning Engineer at ATA Labs, LLC
July 31, 2020 - August 15, 2025
Led development of a predictive ecosystem of ML models for insider threat behavior under a Missile Defense Agency contract, designing scalable architectures, continuous hyperparameter optimization, load balancing, and distributed computing efficiency. Subsequently designed high-performance compute systems supporting generative and reinforcement learning techniques for a US Air Force Agile Software Incubator contract.
Technical Director & Security Compliance Consultant at GadflyAI
April 1, 2023 - Present
Provided governance and compliance consulting to SMEs, aligning AI product development with ISO/IEC 27001 and 42001 standards, improving audit readiness and reducing regulatory risk exposure. Designed and implemented scalable compliance frameworks integrating secure development lifecycles (SDLC), reducing time-to-audit readiness by up to 30%. Established security baselines aligned with NIST CSF, OpenSSF best practices, and AI risk management standards across GadflyAI projects.
Technical Advisor at OurWorlds, Inc.
December 1, 2021 - Present
Served as cybersecurity and privacy expert on the Technical Advisory Board. Applied knowledge of Native American Tribal privacy law to ensure respect and protection of participant privacy rights in virtual reality products using extended reality to create interactive environments, focusing on sensitive language and cultural data.
Technical Community Architect at Confidential Computing Consortium, Linux Foundation (Contract)
February 28, 2025 - August 15, 2025
Led cross-member governance initiatives to adopt OpenSSF Scorecard, SLSA, and Sigstore for improved supply chain integrity across global privacy-preserving compute projects from Microsoft, NVIDIA, ARM, and TikTok. Developed compliance-aligned community frameworks supporting EU NIS 2/DORA/CRA readiness in cloud and confidential computing environments.
Director of Open Source, AI DevSecOps at EscherCloud AI
November 1, 2023 - August 15, 2025
Built ISO/IEC 27001-compliant technical organization embedding security-first standards across OpenStack, Kubernetes, and AI workloads. Established AI governance controls aligned with ISO/IEC 42001 and NIST AI RMF 1.0 to ensure secure, sustainable HPC and AI deployments.
Open Source Developer Advocate at Sonatype
November 1, 2022 - August 15, 2025
Expanded security outreach for open-source supply chain resilience by applying federal security experience to accelerate zero-day vulnerability awareness and remediation. Advocated adoption of SBOM standards (SPDX, CycloneDX) and SLSA compliance in enterprise DevSecOps pipelines and organized the first successful CNCF-wide Security Slam in 2022.
Product Strategist, Developer Advocate (Contract) at Reliably
June 30, 2021 - August 15, 2025
Strategized and developed a command line tool enabling engineers to test cloud system reliability across AWS and Azure. Expertise included distributed system telemetry, CI/CD, site reliability engineering, chaos engineering with Kubernetes, and optimizing deployment and reliability across AWS, GCP, and Azure.
NLP Solutions Architect (Contract) at Unseen Insight
June 30, 2021 - August 15, 2025
Designed secure automated NLP pipelines significantly reducing NGO feedback loops from 3.5 years to 1 day, embedding privacy-enhancing protocols for sensitive humanitarian data.
Senior Data Scientist, Reinforcement Learning Engineer at ATA Labs, LLC
July 31, 2020 - August 15, 2025
Led development of a predictive ML ecosystem for insider threat behavior on the Missile Defense Agency contract. Designed scalable architectures, implemented continuous hyperparameter optimization, ensured load balancing and distributed computing efficiency. Led Enterprise AI/ML group for the US Air Force Agile Software Incubator contract, designing high-performance compute systems supporting generative and reinforcement learning techniques.
Cloud Computing Course Developer at Organization for Human Brain Mapping
May 1, 2017 - Present
Developed an online course for over 700 students providing foundational technical knowledge for open source cloud computing for brain imaging with strong emphasis on open source software, reproducibility, version control, and cloud computing.
Technical Director & Security Compliance Consultant at GadflyAI
April 1, 2023 - Present
Provide governance and compliance consulting to SMEs, aligning AI product development with ISO/IEC 27001 and 42001, improving audit readiness and reducing regulatory risk exposure. Designed and implemented scalable compliance frameworks that integrate secure development lifecycles, reducing time-to-audit readiness by up to 30%. Established security baselines aligned with NIST CSF, OpenSSF best practices, and AI risk management standards for projects under the GadflyAI umbrella.
Technical Advisor at OurWorlds, Inc.
December 1, 2021 - Present
Serve as a cybersecurity and privacy expert on the Technical Advisory Board for a communication platform using extended reality to transform public and private spaces into interactive environments, focusing on Native American communities. Bring knowledge of Native American Tribal privacy law to ensure respect and protection of privacy rights for participants providing sensitive language and cultural data.
Technical Community Architect at Confidential Computing Consortium, Linux Foundation (Contract)
February 28, 2025 - August 15, 2025
Led cross-member governance initiatives to adopt OpenSSF Scorecard, SLSA, and Sigstore for improved supply chain integrity across global privacy-preserving compute projects. Developed compliance-aligned community frameworks supporting EU NIS2/DORA/CRA readiness in cloud and confidential computing environments.
Director of Open Source, AI DevSecOps at EscherCloud AI
November 30, 2023 - August 15, 2025
Built an ISO/IEC 27001-compliant technical organization embedding security-first standards across OpenStack, Kubernetes, and AI workloads. Established AI governance controls aligned with ISO/IEC 42001 and NIST AI RMF 1.0 to ensure secure, sustainable HPC and AI deployments.
Open Source Developer Advocate at Sonatype
November 30, 2022 - August 15, 2025
Expanded security outreach for open-source supply chain resilience by applying federal security experience to accelerate zero-day vulnerability awareness and remediation. Advocated for adoption of SBOM standards (SPDX, CycloneDX) and SLSA compliance in enterprise DevSecOps pipelines, organizing the first successful CNCF-wide Security Slam in 2022.
Product Strategist, Developer Advocate (Contract) at Reliably
June 30, 2021 - August 15, 2025
As a Product Strategist for a command line tool to allow engineers to seamlessly test cloud system reliability across AWS and Azure, focused on distributed system telemetry, CI/CD, site reliability engineering, chaos engineering with Kubernetes, and optimizing deployment and reliability across AWS, GCP, and Azure.
NLP Solutions Architect (Contract) at Unseen Insight
June 30, 2021 - August 15, 2025
Designed secure automated NLP pipelines reducing NGO feedback loops from 3.5 years to 1 day, embedding privacy-enhancing protocols for sensitive humanitarian data.
Senior Data Scientist, Reinforcement Learning Engineer at ATA Labs, LLC
July 31, 2020 - August 15, 2025
Contributed to Missile Defense Agency contract leading development of a predictive ecosystem of ML models as a service for insider threat behavior, designing scalable architectures, implementing continuous hyperparameter optimization, and ensuring load balancing and distributed computing efficiency. Led Enterprise AI/ML group designing high-performance compute systems to support generative and reinforcement learning techniques for US Air Force's Agile Software Incubator contract.
Cloud Computing Course Developer at Organization for Human Brain Mapping
May 1, 2017 - Present
Developed an online course for over 700 students focused on foundational technical knowledge for open source cloud computing for brain imaging, with strong emphasis on open source software, reproducibility, version control, and cloud computing.

Education

PhD (Joint) at National Institutes of Mental Health and University College London
January 1, 2016 - December 31, 2018
BA Cognitive Science specializing in Neuroscience at University College San Diego
January 1, 2010 - December 31, 2015
BA Political Science specializing in Public Law at University College San Diego
January 1, 2010 - December 31, 2015
Joint PhD at National Institutes of Mental Health and University College London
January 1, 2016 - January 1, 2018
BA, Cognitive Science specializing in Neuroscience at University College San Diego
January 1, 2010 - January 1, 2015
BA, Political Science specializing in Public Law at University College San Diego
January 1, 2010 - January 1, 2015
PhD (Joint) at National Institutes of Mental Health and University College London
January 1, 2016 - December 31, 2018
BA Cognitive Science specializing in Neuroscience at University College San Diego
January 1, 2010 - December 31, 2015
BA Political Science specializing in Public Law at University College San Diego
January 1, 2010 - December 31, 2015

Qualifications

Add your qualifications or awards here.

Industry Experience

Computers & Electronics, Software & Internet, Government, Education, Non-Profit Organization, Healthcare, Professional Services