Eleven Security Programs.
Eleven Sets of Evidence.
Every project on this page was built, not theorized. Each one has a problem statement, a documented approach, measurable outcomes, and downloadable evidence artifacts. This is what five-plus years of hands-on security program delivery looks like.
A community financial institution with no existing security function, no policies, no board reporting, no vulnerability management, and an OCC examination on the horizon. As the sole security hire, I had 12 to 18 months to build a defensible, auditable program from absolute zero.
Complete cybersecurity program built and operational. 30+ policies, NIST CSF implementation, ISO 27001-aligned ISMS, Board Risk Committee quarterly reporting with 12 KRIs, vulnerability management, and security awareness achieving 97% completion. OCC examination cleared with zero material findings - first clean examination in the institution's history.
Policies, playbooks, workbooks, dashboards, and detection rules - nine evidence artifacts available for download. Not claims. Documented, verifiable deliverables from real programs at regulated organizations.
Available for Senior GRC Manager, Cloud Security Architect, and CISO roles across Alberta and Canada from September 2026. Happy to walk through any project in detail.