Programs I built and ran.
Governance — NOBULL
An agentic AI program governed before it shipped
Leadership wanted AI capability across the company. I built the control structure first — the AI Acceptable Use Policy and an MCP Permission Policy governing a 17-permission delegated access model, mapped to NIST AI RMF 1.0 and ISO/IEC 42001 — took it through executive approval, then matched the tooling to the work rather than standardizing on one vendor: ChatGPT and Microsoft Copilot for the whole office, Claude for power users and code, Perplexity for research and market analysis.
Four enterprise AI platforms in production under written policy, each matched to a real need rather than accumulated by department demand.
Brand protection — NOBULL
A hundred counterfeit storefronts taken down
Customer-facing commerce properties were exposed at the edge and the brand was being counterfeited at scale. I run the takedown program against storefronts trading on the name, and architected the WAF and DDoS protection standing behind it.
100+ counterfeit storefronts removed. The perimeter absorbed 60 DDoS attacks over 12 months and now turns away 46% of inbound traffic as malicious, roughly 72.7M bot requests a month.
Compliance — Elkus Manfredi Architects
Taking a 300-person firm through certification
I led the firm to ISO/IEC 27001 certification and SOC 2 Type II attestation, owning control design, evidence collection, and auditor engagement end to end — then implemented Vanta for continuous compliance and vendor risk monitoring, while tuning the estate and remediating recurring root causes.
Certified and attested. Monthly security alert volume down 20%, from 110 to 88.
Principal Consultant / vCISO — Independent practice
The security executive for firms that could not hire one
Small law practices and nonprofits carrying real exposure with no in-house security function. I served as their security executive — setting direction, aligning the environment to security and compliance requirements, hardening Microsoft 365 and identity, then pressure-testing it with leadership tabletops and penetration testing.
Four organizations brought into compliance alignment. Exploitability proven rather than assumed, with risk-ranked remediation and retest validation.
Consolidation — NOBULL
Two endpoint stacks collapsed into one
Devices were managed across overlapping tools with no single source of enrollment truth. I retired the redundant MDM and merged the survivors into one co-managed stack — one plane owning enrollment, zero-touch provisioning, compliance policy, and conditional access; the other owning RMM, patching, scripting, and ticketing.
$12K in annual recurring license spend eliminated and machine sprawl ended, with zero end-user downtime.
Automation — NOBULL
Three days of onboarding down to one
Joiners and leavers moved through a manual checklist across half a dozen systems. I automated the path end to end across Microsoft Graph, Slack, the service desk, and serverless edge workers.
Onboarding and offboarding cut from 3 days to 1.
Platform — NOBULL
MCP infrastructure with identity underneath it
I wrote the internal MCP servers that broker agent access to Snowflake, GitHub, Slack, and Azure Container Apps — Entra ID External OAuth, per-role token acquisition via managed identity, a self-healing IT operations agent with a three-tier autonomy model, and an audit evidence layer. It runs on Azure Container Apps, the managed Kubernetes-based platform, with every environment defined as infrastructure as code in Terraform and Bicep, network security groups segmenting it, and CI/CD doing the deploys — secrets held in 1Password and injected at deploy time rather than committed to source. I administer and govern the Snowflake and GitHub organizations those servers reach into.
Delegated agent access that survives an audit. Plus an executive BI command center on Cloudflare Workers with Snowflake as single source of truth.
Cost — Elkus Manfredi Architects
Three hundred thousand out of a $1.7M budget
A decade owning the IT budget and the full vendor portfolio for a 300-person firm. I consolidated overlapping vendors and renegotiated contracts against what the business actually consumed.
$300K in recurring annual savings — 18% of the budget.
Operations — Education Development Center
Five thousand endpoints, a hundred thousand alerts
Security operations and tooling ownership across a 5,000-machine estate for a federally funded research organization, on the Rapid7 platform.
100,000+ alerts triaged annually. Environment hardened to FedRAMP, FISMA, ISO/IEC 27001, SOC 2, and HIPAA control requirements.
Leadership — U.S. Army
Thirty people, five thousand users, three deployments
Led Signal and Cyber Operations teams across domestic bases and three overseas sites, accountable for training, readiness, performance, and career development — while owning the communications and information systems the mission ran on, including the deployed comms Civil Affairs teams operated on for partner-nation and interagency missions.
Zero mission-impacting outages. Training programs cut user-driven incidents 35%.