Cybersecurity LeaderCyber Risk Assessments & AssuranceDesign, Build, Activate & Operate Cyber ProgramsCyber Go-To-MarketOrigination & SalesPeople Development & Mentorship

Denver, CO · 14 years · EY, PwC
$10M+closed engagements, every fiscal year
$250K → $10Mnew logo grown to a top account in two years
34countries in one NIST CSF assessment
1M+connected assets under product security governance
0 → 3+CMMI maturity, enterprise program
10+direct reports; 5+ promoted
Read this resume through one lens

Fourteen years in cybersecurity consulting at EY and PwC. I build and run the security programs CISOs depend on, turn what works into offerings, and sell the work — mostly in regulated industries: healthcare, pharma, automotive, consumer products, and energy.

  • Exceeded $10M in closed cybersecurity engagements every fiscal year as an EY pursuit leader.
  • Directed a $10M+, 10-workstream transformation securing a connected-product portfolio worth $24B+ in services revenue.
  • Closed a material NERC CIP finding carrying $1M+ per-violation, per-day exposure.
  • Ran a NIST CSF assessment across 34 countries and turned it into a board-approved roadmap.
  • Recently led an AI governance readiness assessment against the NIST AI RMF.
Professional journey

EY (Ernst & Young LLP)

Denver, CO · Chicago, IL · Cybersecurity Strategy, Risk & Program Transformation
Aug 2022 — Feb 2026

Senior Manager — Cybersecurity Risk & Program Management

Business development & origination
  • Carried a $5M–$10M annual sales goal as pursuit leader and exceeded $10M in closed cybersecurity engagements every fiscal year.
  • Owned pursuits end to end — opportunity identification, qualification, proposal development, pricing, and staffing models — presenting each deal to EY Americas Deal Governance leadership for approval prior to closing.
  • Originated a new healthcare brand for the practice: entered on a $250K security assessment and converted it into a $10M account in year two by translating findings into a funded multi-workstream cybersecurity transformation.
  • Ran the full cycle with CISOs and their leadership teams — identifying and qualifying opportunities, shaping and pricing solutions, and closing consistently across multiple industry sectors.
Solutions & offerings
  • Co-developed a new connected product security program offering alongside a client, then packaged and positioned it for other clients in the same sector — turning a single engagement into a repeatable go-to-market play.
  • Embedded within a newly formed CISO organization at a $6.2B publicly traded CPG leader; led executive workshops with the CISO, CIO, CFO, and corporate strategy to align business drivers and constraints into a 3-year cybersecurity strategy and roadmap.
  • Planned and executed an AI governance readiness assessment aligned to the NIST AI Risk Management Framework — AI use-case inventory, model risk, third-party AI exposure, and governance structures — and delivered the prioritized roadmap to close gaps.
Delivery in regulated markets
  • Directed a $10M+ multi-year transformation across 10 workstreams and 20+ professionals, embedding cybersecurity into connected product design, development, and operations — enabling the secure rollout of a portfolio generating $24B+ in services revenue.
  • Developed a product security governance program for 1M+ connected assets globally — ISO 21434 and SAE J3061-aligned control frameworks, ServiceNow-based product cataloging and GRC, product security testing, and executive reporting.
  • Delivered a board-ready multi-year cybersecurity roadmap for automotive operations by managing a NIST CSF assessment across thirty-four countries in Europe, Asia, the Middle East, and the Americas, with business cases supporting next-generation connected vehicles.
  • Directed a 6-member global team with 10+ SMEs on a cybersecurity maturity assessment for a leading healthcare organization across IT, medical OT, and supply chain, presenting to the C-suite to secure funding; then ran the transformation — 10 in-flight initiatives, 20+ professionals across GRC, data protection, cloud security, medical OT, third-party risk, IAM, and cyber PMO.
  • Led an SEC cybersecurity disclosure readiness assessment across a publicly traded media and entertainment holding company and seven portfolio companies — materiality determination, escalation, and disclosure processes — and designed the approach standardizing 10-K and 8-K disclosures.
  • Guided an enterprise security program from 0 to a 3+ CMMI maturity rating over multiple years, protecting a global portfolio of consumer brands; recognized by the CISO in a LinkedIn recommendation for sustained program leadership.
Executive & team leadership
  • Established the operating cadence for a client Office of the CISO — operating models, steering committee structure, governance workshops, and reporting touchpoints.
  • Drove board, audit committee, and executive steering committee reporting for CISOs across multiple sectors, translating technical risk into funding and prioritization decisions; managed OPEX/CAPEX forecasting, resource planning, and sourcing models for $5M+ program budgets.
  • Held performance oversight for 10+ direct reports globally; advanced 5+ through promotions by tracking KPI progress and presenting their cases to leadership.
Oct 2018 — Aug 2022

Manager — Cybersecurity Risk, Controls & Compliance

  • Led a $2M+ program to remediate a material NERC CIP audit finding carrying regulatory exposure of $1M+ per violation, per day; operationalized a NIST RMF-based cyber risk program and stood up enterprise risk oversight that closed the finding and eliminated ongoing penalty risk.
  • Partnered with Archer GRC developers to design, pilot, and deploy cyber risk management capability enabling enterprise-wide risk tracking, measurement, and remediation.
  • Designed and activated third-party risk management programs, cyber risk operating models, cybersecurity policies, and metrics/reporting frameworks.
  • Built executive dashboards and persona-based reporting that converted cyber risk metrics into leadership decision inputs rather than compliance status.
  • Advanced client cyber programs from initial to defined maturity over 2–3 years through risk-prioritized roadmaps tailored to sector, threat profile, and business context.
Jul 2015 — Sep 2018

Senior Consultant — Cybersecurity Risk & Audit

  • Executed cybersecurity program and controls assessments against NIST CSF, NIST RMF, and ISO standards, producing risk-prioritized findings and remediation roadmaps.
  • Facilitated workshops with cyber leadership, internal audit, engineering, and business stakeholders to evaluate program maturity and define target-state capability.
  • Authored cybersecurity policies, standards, and control documentation, and drove activation across client operating models.
  • Built cyber metrics and reporting dashboards to track program maturity against target state and developed business cases supporting multi-year investment decisions.

Core competencies

Business development & go-to-market

Signings & revenue attainment · Pipeline origination · Opportunity identification & qualification · Pursuit & proposal leadership · Pricing, deal structuring & deal governance · Solution & offering development · Account planning & expansion · CISO and C-suite relationship management · SOW & scope definition

Security strategy & risk

Cyber risk management · Risk assessment · Controls design & testing · Risk register & issue management · Control libraries · Audit readiness & finding remediation · Regulatory compliance · Risk quantification

Frameworks

NIST CSF 2.0 · NIST RMF · NIST AI RMF · ISO 27001 · ISO 21434 / SAE J3061 · SOX · SSAE 16 / SOC 2 · SEC cyber disclosure readiness · HIPAA · NERC CIP · Policy & standards development

Third-party risk

TPRM program design · Vendor tiering · Due diligence · Contractual security requirements · Continuous monitoring

Program & executive

Cybersecurity PMO · Board & audit committee reporting · Executive dashboards & metrics · Roadmaps and business case development · OPEX/CAPEX planning · Resource and staffing models · Team leadership

Platforms

RSA Archer · ServiceNow GRC · AuditBoard · SAP Security

Education & certifications

2010 — 2012

Master of Science, Information Systems

Kelley School of Business, Indiana University Bloomington

2005 — 2009

Bachelor of Engineering, Information Technology

University of Mumbai

Certifications
CISSP Microsoft Certified: Azure AI Fundamentals AWS Certified Cloud Practitioner