IT & SECURITY EXECUTIVE
dollop.technology — IT and security leadership. 20+ years building systems and leading what comes next. CISO leadership: board-level risk ownership and strategy. Security assessments: scored, prioritized, and actionable. Incident response: planned before you need it. GRC: SOC 2, ISO 27001, HIPAA, NIST CSF 2.0. IT operations: budgets, infrastructure, helpdesks, teams. Built it. Ran it. Can run yours.
What I do
Executive ownership of risk, strategy, and board reporting — the same accountability you'd expect from any CISO on your leadership team.
A clear-eyed audit of where your security posture actually stands — infrastructure, identity, endpoints, and process — scored and prioritized into a report your team can act on immediately.
Preparation before something goes wrong, and steady, experienced leadership when it does — incident response planning, tabletop exercises, and hands-on management through resolution.
End-to-end ownership of governance, risk, and compliance programs — SOC 2, ISO 27001, HIPAA, and NIST frameworks — brought to audit-ready status and kept there.
Full ownership of the IT function itself — not just its security layer. Budgets negotiated alongside your CFO, help desks built to a standard where people actually want to call IT, and physical infrastructure stood up office by office, data center by data center.
Proof of work
A guided self-assessment that shows an IT department exactly where it stands against the NIST Cybersecurity Framework 2.0 — scoring all 6 Functions, 22 Categories, and 106 Subcategories, then turning the results into a prioritized gap report leadership can actually act on.
View live assessment ↗Track record
Built a HIPAA-compliant AWS environment solo — from a standing start, with infrastructure-as-code via Terraform, for a healthcare organization handling sensitive patient data.
Owned SOC 2 Type II and ISO 27001 end to end across a 4.5-year tenure, while integrating cloud infrastructure and security controls across six M&A transactions without breaking continuity.
Scaled IT and security from 100 to 2,000 employees across 15 international offices over 11 years. Built the office and datacenter infrastructure at each new location, owned multi-million-dollar budgets alongside the CFO, and grew from hands-on systems work into leading a team of 30+ across multiple layers of management.
Lead HIPAA and SOC 2 compliance programs today as primary security and IT liaison to executive leadership and the board of a healthcare nonprofit.
Outside the day job
A unified OSINT platform aggregating open-source intelligence streams into a single operational view.
aerialpredator.com ↗San Francisco's transit system reimagined as a generative composition — every bus, train, and cable car producing live musical tones.
munimusic.com ↗A community resource for Fort Bragg and the Mendocino Coast — real-time weather, tides, and local services in one view.
noyomap.com ↗Get in touch
Whether you're hiring for a full-time VP/CISO or Director-level role, need fractional CISO coverage, or want a one-time security assessment — tell me what you're working with and I'll tell you honestly whether I'm the right fit.