Cybersecurity Implementation

Security
Implementation

Hands-on experience implementing cybersecurity controls and processes within enterprise environments -- translating security requirements into day-to-day IT practice across financial services, healthcare, and regulated industries.

25+
Years in Enterprise IT
3
Regulated Sectors
3
Compliance Frameworks Worked Within

Implementation Experience

Where I Work on Security

Practical, hands-on implementation work across several security areas -- executing on security requirements as part of broader IT operations and infrastructure roles.

🔐

Identity & Access

Implementing Conditional Access policies, MFA rollouts, and Entra ID configurations -- hands-on work configuring and maintaining access controls across the environment.

📋

Security Documentation

Writing and maintaining security policies, standards, runbooks, and procedures that support compliance requirements and day-to-day operations.

🏗️

Security Architecture

Contributing to the implementation of Zero Trust principles, network segmentation, and secure hybrid cloud configurations as part of broader infrastructure work.

⚠️

IT Risk Committee

Active participant on the IT Risk Committee -- contributing to risk identification, documentation, and tracking of remediation efforts across the organization.

🔍

Security Tooling

Implementing and supporting EDR platforms, endpoint security configurations, and security tooling -- focused on deployment and ongoing operations.

🛡️

Policy & Governance

Supporting security governance processes including policy reviews, access reviews, and control documentation tied to audit and compliance cycles.


Frameworks & Standards

Frameworks I've Implemented Within

Practical experience implementing controls and processes within environments governed by these frameworks -- not a certified specialist, but a practitioner who has worked within each.

NIST CSF
SOC 2 Type II
HIPAA Security Rule
CIS Controls
Zero Trust Principles
FINRA

Perspective

How I Think About Security

Principles that guide how I approach security implementation work as part of day-to-day IT operations.

Risk-Aware
Security decisions should be tied to real risk, not just compliance requirements -- I bring that lens to IT conversations at all levels.
Least Privilege
Identity and access are managed conservatively -- access granted minimally, reviewed regularly, and removed promptly when no longer needed.
Documentation First
Good security practices only stick when they're written down, communicated clearly, and easy for teams to follow.
Collaborative
Security works best when IT, compliance, and business teams are aligned -- I focus on being a bridge, not a bottleneck.

Working in a Security-Conscious Environment?

Happy to connect with teams where security awareness and practical IT experience matter.

Get in Touch Back to Home