A Bit About Me
Over the past 10 years I've gone deep on cloud security across AWS, Azure, and GCP — from architecting secure multi-account foundations to operationalizing enterprise CNAPP platforms end-to-end. My current focus is CNAPP, CSPM, CWPP, DSPM, and identity risk.
Cloud security leader and practitioner with a proven track record advising customers and internal stakeholders on cloud security best practices, remediating CIS, NIST, IAM, secrets, container vulnerabilities, and building dashboards to measure security posture maturity. Comfortable operating as both technical practitioner and trusted advisor translating complex cloud risk into clear, actionable guidance for engineering teams and executive stakeholders.
At Barracuda Networks, I led the full lifecycle Wiz deployment across 400+ cloud accounts, implementing CSPM/CNAPP, workload protection, data security posture (DSPM), and cloud entitlement auditing. The result: a 75% reduction in critical and high-severity cloud findings through structured, risk-based remediation workflows.
Work Experience
Manager, Cloud Security Infrastructure
Barracuda Networks
June 2025 - April 2026
Manager, Cloud & Tech Ops
Deepwatch
May 2021 - February 2023
Architect, Cloud & Tech Ops
Deepwatch
March 2019 - May 2021
Security Engineer II
GuidePoint Security
September 2017 - March 2019
Security Analyst/Security Engineer
ReliaQuest
December 2015 - August 2017
-
Owned and operationalized Wiz CNAPP as the primary cloud security platform across AWS, Azure, and GCP — driving adoption across CSPM, CWPP, DSPM, identity risk, network exposure, and IaC scanning
-
Established risk-based triage and remediation workflows that reduced critical and high-severity findings by 75% across over 400 cloud accounts
-
Lead a team of cloud security engineers managing day-to-day operations and technical direction for cloud security infrastructure across AWS, Azure, and GCP
-
Implemented and expanded Wiz DSPM to identify, classify, and reduce sensitive data exposure
-
Drove container and workload security visibility using Wiz CWPP, implementing scanning for containers and Kubernetes environments
-
Assessed cloud security posture across multi-account AWS and Azure environments, remediating CIS, NIST, and cloud-native compliance violations
-
Performed cloud entitlement reviews and IAM remediation — addressing excessive permissions, privilege escalation paths, and identity misconfigurations
-
Acted as the primary Wiz platform SME, partnering with engineering, platform, and cloud teams to translate findings into actionable architectural guidance
-
Drove internal enablement and adoption by leading “Wiz Jam Sessions”, educating teams on attack paths and best practices
-
Integrated Wiz security scanning into CI/CD workflows to identify cloud misconfigurations.
-
Maintained strong partnerships with Wiz, cloud service providers, and security vendors, influencing roadmap discussions and feature adoption
-
Mentored and onboarded cloud security engineers, strengthening both technical execution and cross-functional communication
-
Owned cloud and tech operations for multi-cloud environments (AWS, Azure, GCP) while leading a fully distributed team of engineers, architects, and IT specialists supporting a national workforce
-
Operationalized Wiz CSPM to improve risk visibility and remediation velocity; implemented continuous CIS Benchmark monitoring and automated security tooling
-
Directed employee onboarding and offboarding, including identity provisioning & deprovisioning, access management, asset management and device readiness
-
Optimized service desk operations supporting national workforce, reducing average ticket response times by 50% through process improvements, team enablement, and strategic resource allocation
-
Advised business units on cloud strategy and operational best practices
-
Led initiative to achieve AWS MSSP Level 1 Competency, validating cloud security maturity and strengthening customer trust
-
Managed strategic vendor relationships and 24x7x365 cloud and business support model
-
Recruited, mentored, and conducted performance management for distributed technical team
-
mplemented cost optimization strategies and served on change advisory board (CAB) for business-critical infrastructure decisions
-
Architected platform monitoring and observability to improve reliability and incident response
-
Architected and deployed AWS Control Tower in a multi-account environment, designing the organizational structure, OU hierarchy, SCPs, and baseline guardrails for 100+ accounts
-
Implemented AWS Identity Center (SSO) integration with Okta, designing permission sets, role based access patterns, and automated user provisioning workflows
-
Architected centralized logging and security monitoring solution aggregating CloudTrail, Config, GuardDuty, and Security Hub findings into S3 for integration to Splunk
-
Built secure lab and sandbox environments to enable safe experimentation, cost controls, training, and cloud adoption across engineering teams
-
Performed CIS Benchmark assessments across cloud workloads and identified remediation paths
-
Architected and implemented 100+ Okta SAML/OIDC identity federations with customer identity providers, designing secure authentication flows and session management
-
Certified Splunk Architect leading implementation projects for 20+ enterprise customers
-
Performed Splunk Enterprise upgrades across distributed environments with zero downtime
-
Conducted security gap analysis and translated findings into actionable security use cases
-
Served on the implementation team with a focus on onboarding new customers in a 24/7/365 MSSP environment
-
Conducted log source integrations from various systems to Splunk Enterprise
-
Deployed and maintained Splunk Enterprise in clustered and highly available environments
-
Completed necessary technical documentation
-
Participated and engaged in customer status calls and working sessions
-
Subject matter expert in ArcSight SIEM (ESM, Logger, ArcMC, Connectors) — log source integrations, platform upgrades, technical documentation, and SOPs
-
Tier 1 SOC analyst for 24/7/365 MSSP operations — security event analysis, incident response, and incident runbook development standardizing IR processes across SOC teams
