vCISO Retainer
Security leadership embedded in your compliance posture. Risk, policy, audit readiness, and board reporting on a fractional schedule that matches your audit calendar.
Learn more →
vCISO & Fractional CISO · Massachusetts
I built ShieldBrief — an AI-curated threat intelligence platform for CISOs and security teams, with CVE enrichment, IOC extraction, and MITRE ATT&CK mapping baked in. I also run a fractional security-leadership practice for commercial regulated industries across Massachusetts and beyond: pharma, public companies, healthtech, and fintech.
CISSP · 20+ years IT · 11+ years cybersecurity leadership · GxP, SOX, NIST, ISO experience
Security leadership embedded in your compliance posture. Risk, policy, audit readiness, and board reporting on a fractional schedule that matches your audit calendar.
Learn more →Risk assessments and control documentation aligned to the frameworks your auditors actually run — NIST, ISO 27001, SOX 404, GxP. Audit-ready outputs, not security theater.
Learn more →Incident response plans, executive tabletops, and the documented chain of evidence your audit committee needs after an event — not just during one.
Learn more →"Most compliance failures aren't technical. They're failures of judgment, scoped wrong or sequenced wrong."
Diagnose
Risk read against your relevant frameworks; quick-wins list with audit-cycle priority.
Build
Core policies, IR plan, TPRM process, control-owner assignments — the foundation that survives an audit.
Operate
Monthly security review cadence, audit-committee reporting cycle, control-evidence collection running ahead of audits.
"You want a CISO who's been in the room when an FDA auditor asked how change control got bypassed. I have."
Writing on vCISO practice, regulated-industry security, and audit readiness.
May 2, 2026
When the auditor opens the change-control log, they're not looking for what you did. They're looking for what you didn't document.
May 2, 2026
Most fractional CISO content is written for SaaS startups. Regulated environments work differently — the cadence is the audit cycle, not the sprint.
Based in Massachusetts, serving regulated mid-market companies across the Commonwealth and beyond.