Chief Information Security Officer · Pharmaceutical & Life Sciences
Nearly 30 years leading enterprise cybersecurity across biopharmaceutical, financial services, and technology sectors. The common thread: problems nobody had fully solved yet, environments without playbooks, and risk that does not wait for the next budget cycle.
The work I'm doing now is a full-program transplant – function for function, tool for tool, control for control – all while the business stays protected. I'm currently leading that build at CHI (Capsules & Health Ingredients), a pharmaceutical ingredients manufacturer completing its divestiture carveout from Lonza Group to Lone Star Funds. My team's mission is to protect a global manufacturing network serving approximately 60 percent of the global market in pharmaceutical gelatin capsules, ensuring the supply chain patients depend on doesn't stop.
This isn't the first time I've started without a foundation. At Amgen, I built the global cyber defense function from fragmented capabilities into a unified program: 28 people, 75,000 assets across four continents, IT and OT domains running in parallel. In the 13 years before that, I built consulting practices that advised CISOs across 200+ organizations through Symantec and my own independent firm. My first opus was a division security program at Transamerica, where the audit position ranked last in the company when I arrived and first when I left.
Every role has been a variation on the same puzzle. I'm drawn to structurally hard problems: situations where the risk is real, the governance is immature, and the margin for error is low. Post-quantum cryptography, AI data governance, OT security in GxP manufacturing environments – these are the problems most security organizations are still deciding to prioritize. Problems like these require someone who can translate the technical reality into decisions the board can actually make.
I'm currently pursuing a Juris Master in Cybersecurity Governance at Florida State University.
I've been CISSP-certified since 2000.
Led Amgen's response to the 2024 CrowdStrike outage across 30,000+ systems and nine GxP manufacturing sites, restoring 85% of operations within 18 hours and outperforming virtually all global peers in a situation where extended downtime risked tens of millions in irreplaceable product.
Directed cyber due diligence and Day 1 integration controls across eight acquisitions throughout my career, including the $27B Horizon Therapeutics transaction. The challenge is defining security postures within M&A timelines before the deal closes, without becoming the friction that stops it.
Secured capital approval for a five-year post-quantum cryptography roadmap at a top-10 global biopharma. Most security organizations are just now realizing it's on the horizon.
Moved a Transamerica division from the lowest-ranked to the highest-performing audit position within 12 months by building the organization's first ISO 27001-aligned ISMS.
Expanded Amgen's data protection coverage from 20,000 to nearly 60,000 employees across US, EU, and APAC, simultaneously strengthening regulatory posture and operating consistency across jurisdictions with different requirements.
For speaking, expert commentary, and board advisory engagements, reach out through the form below.